Refreshed 1h ago· updates every 6h

Gravity Bridge (2026) — Crypto Hack

Funds Laundered
May 30, 2026·
EthereumCosmos
Amount Stolen
$5.4M
$4.3M USDC, 274 ETH, $434K USDT, $64K PAYG
Recovered
$0

Suspected signing key compromise drained $5.4M from Ethereum-Cosmos bridge

Summary

Suspected signing key compromise drained $5.4M from Ethereum-Cosmos bridge

How It Was Compromised — Private Key Compromise via Suspected signing key compromise. Single compromised key allowed unauthorized withdrawals from bridge contract. No complex smart contract exploit — just a stolen key.

Private Key CompromiseSuspected signing key compromise. Single compromised key allowed unauthorized withdrawals from bridge contract. No complex smart contract exploit — just a stolen key.

On May 30, 2026, Gravity Bridge, a cross-chain protocol connecting Ethereum and Cosmos, was drained of approximately $5.4 million in a suspected signing key compromise. Between 02:30 and 03:30 UTC, an attacker gained access to a bridge contract signing key and withdrew mixed assets: $4.3 million in USDC, 274 ETH (~$553K), $434K in USDT, and $64K in PAYG tokens. The bridge did not get tricked — it got impersonated. The attacker presented valid signed authorization, and the contract released the assets. Validators halted the bridge immediately after discovery.

Fund Flow & Laundering Analysis

The attacker wasted no time moving proceeds. Portions were routed through ChangeNow (a non-custodial swap service) and Binance. As of reporting, the attacker still held approximately 2,102 ETH (~$4.23M), suggesting the bulk of stolen value remained on-chain and potentially traceable. The speed and spread of assets pointed to a compromised signing key rather than a logic bug.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.