Loading market data...

Gravity Bridge Loses $5.4M in Apparent Signing Key Compromise

Gravity Bridge Loses $5.4M in Apparent Signing Key Compromise

Gravity Bridge lost about $5.4 million on May 30 after a suspected signing key compromise drained assets from the bridge's Ethereum-side contract. The attacker made off with $4.3 million in USDC, 274 ETH ($553,000), $434,000 in USDT, and 14.164 PAYG tokens worth $64,000. On-chain investigators attribute the exploit to a compromised signing key, not a smart-contract vulnerability.

What got taken and where it went

The haul breaks down to four main tokens, with stablecoins making up the bulk. The attacker quickly swapped most of the USDC and USDT into ether, leaving them with roughly 2,102 ETH — worth about $4.23 million at current prices. A portion of the stolen crypto was then laundered through ChangeNow and Binance. The remaining ETH stash is fully traceable on Etherscan, but the funds can still be split, mixed, or bridged to other chains, complicating recovery efforts.

Another month, another bridge exploit

PeckShield counted eight major bridge exploits in May 2026 totaling $328.6 million, including this one. That's a grim reminder that cross-chain bridges remain a favorite target. Past incidents like Ronin and Poly Network show how a single compromised signing key can become a catastrophic single point of failure. Gravity Bridge connects Ethereum to the Cosmos ecosystem via IBC and had about $11.5 million in total value locked before the drain — now most of that is gone.

The limits of blacklisting

Stablecoin issuers can blacklist addresses in minutes, which might have helped if the attacker hadn't swapped so quickly. But funds routed through non-custodial services like ChangeNow are harder to retrieve. The attacker's decision to use both a centralized exchange (Binance) and a non-custodial swap suggests a deliberate attempt to muddy the trail.

No word from the team yet

The Gravity Bridge team has not issued a public response as of this report. Users who had assets stuck in the bridge are left guessing whether there's a plan for restitution or any fix in the works. Until the team speaks up, the silence speaks louder than any statement.