LATEST NEWS
SELECTED FOR YOU
WEEKLY
STAY ON TOP

Best crypto insights delivered straight to your inbox.

Hackers drain $5.4M from Gravity’s Ethereum – Cosmos bridge

ByHannah CollymoreHannah Collymore
2 mins read
Hackers drain $5.4M from Gravity's Ethereum - Cosmos bridge

Hackers drain $5.4M from Gravity's Ethereum - Cosmos bridge

  • Gravity Bridge lost approximately $5.4 million in a suspected contract key compromise.
  • The attacker stole mostly USDC, along with ETH, USDT, and PAYG tokens, before swapping much of the haul into ETH.
  • The exploit adds to a growing list of bridge attacks, including the recent $11.5 million hack of the Verus-Ethereum bridge.

An attacker has drained approximately $5.4 million from Gravity Bridge, the cross-chain bridge connecting Ethereum and the Cosmos ecosystem, in what on-chain analysts suspect was a contract key compromise.

The theft, which was flagged on May 30 by blockchain security firms PeckShieldAlert and Cyvers, continues a punishing stretch for cross-chain infrastructure.

Bridges have repeatedly proven to be the most lucrative targets in DeFi, and Gravity Bridge is the latest to fall.

What did the attacker take?

The attacker siphoned four assets from the bridge’s Ethereum-side contract: $4.3 million in USDC, 274 ETH (worth roughly $553,000), $434,000 in USDT, and 14,164 PAYG tokens valued at about $64,000, according to PeckShieldAlert.

On-chain analyst Specter, who was also among the first to report the incident, identified the suspected attack vector as a compromise of the bridge contract key or signing path. Two Ethereum addresses, “0x7B58…a1F9” and “0x4d3c…7A47,” have been linked to the theft, according to CryptoAdventure.

Laundering already underway

PeckShieldAlert reported that a portion of the stolen funds had already been moved through ChangeNow and Binance.

Per PeckShieldAlert, the attacker still held roughly 2,102 ETH (approximately $4.23 million), so the bulk of the haul still remains in the exploiter’s wallet as of the time of reporting.

Cyvers confirmed the $5.4 million loss figure and said the stolen assets were swapped into native ETH.

Gravity Bridge has not published a postmortem or public statement on the incident.

Bridge exploits keep piling up

The Gravity Bridge drain comes in a month already scarred by bridge attacks. On May 18, the Verus-Ethereum bridge lost $11.5 million after a verification bypass exploit, according to DefiLlama’s hacks database. Analysts have pointed to the Verus incident as part of a growing string of cross-chain infrastructure exploits.

Cryptopolitan has previously reported on the persistent vulnerability of bridge protocols, which handle large pools of locked assets across chains and present concentrated targets for attackers. DefiLlama data shows that bridges account for $3.2 billion of the $16.6 billion in total value hacked across crypto history, a disproportionate share given how few bridge protocols exist relative to other DeFi categories.

As of reporting time, Gravity Bridge held approximately $6.2 million in total value locked, according to DefiLlama. The $5.4 million drain represents nearly a big chunk of the bridge’s TVL, effectively sending the protocol’s stored value into a nosedive.

Hackers drain $5.4M from Gravity Ethereum - Cosmos bridge
Gravity Bridge’s TVL has dropped sharply since reports of the hack. Source: DefiLlama

One community member noted the scale of remaining funds came as a surprise. “I had no idea there was even that much TVL left locked in the Gravity Bridge,” wrote Ed from AirdropGlideApp, questioning why users had not migrated to newer Cosmos bridging options.

For now, users with funds on the protocol have no official guidance, as the platform is yet to confirm or share any update on the exploit. The remaining 2,102 ETH sits in a known address, giving exchanges and compliance teams a window to flag or freeze the funds before further laundering occurs.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

FAQs

What was stolen from Gravity Bridge?

The attacker drained approximately $5.4 million in total: $4.3 million in USDC, 274 ETH (about $553,000), $434,000 in USDT, and $64,000 in PAYG tokens.

How was Gravity Bridge exploited?

On-chain analyst Specter identified the suspected attack vector as a compromise of the bridge contract key or signing path, though Gravity Bridge has not released a public postmortem confirming the method.

Has the attacker moved the stolen funds?

PeckShieldAlert reported that a portion was laundered through ChangeNow and Binance, but the attacker still held roughly 2,102 ETH (about $4.23 million) at the time of the alert.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore

Hannah Collymore

Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.

MORE … NEWS
DEEP CRYPTO
CRASH COURSE