Gravity Bridge hit by $5.4M cross-chain exploit

Gravity Bridge lost $5.4M in a cross-chain exploit, with attackers draining USDC, ETH, USDT, and PAYG. Funds were laundered via ChangeNow and Binance; over 2,100 ETH remains with the attacker.

Gravity Bridge, a cross-chain protocol connecting Ethereum and Cosmos, suffered a $5.4 million exploit on May 30. The breach was likely caused by a compromised contract key or signing path, allowing attackers to drain approximately $4.3 million in USDC, 274 ETH (about $553,000), $434,000 in USDT, and $64,000 in PAYG tokens. Most of the stolen funds were swapped into Ethereum and partially laundered through platforms like ChangeNow and Binance. The attacker still controls over 2,100 ETH, according to on-chain analysis. Two Ethereum addresses have been linked to the hack, which targeted the bridge’s authorization system rather than exploiting a user-side vulnerability. This incident highlights the ongoing security challenges facing cross-chain infrastructure, emphasizing the importance of robust multi-signature controls and secure authorization mechanisms. Gravity Bridge has not yet released a comprehensive public postmortem on the breach.

Related Tokens

Related News