Gravity Bridge Halted After $5.4M Drain Hits Ethereum-Cosmos Link

Gravity Bridge Halted After $5.4M Drain Hits Ethereum-Cosmos Link

N
News Editor 01
2026-07-22 14:50:13
The cross-chain bridge lost about $5.4M on Saturday morning; security researchers suspect signing key compromise rather than contract code exploit. Operations are suspended pending investigation.
Gravity BridgeSecurity BreachBridge AttackSigning KeyCrypto

Gravity Bridge, the cross-chain link connecting Ethereum with the Cosmos ecosystem, suffered a $5.4 million drain early Saturday. On-chain analyst Specter first flagged unusual withdrawals, noting the pattern suggested the bridge's signing keys — not its smart contract code — may have been compromised. Security firm PeckShield later corroborated the assessment and released a breakdown of the stolen assets.

Stolen Funds: $4.3M USDC, 274 wETH, and More

According to PeckShield, the attackers made off with $4.3 million in USDC, 274 wrapped ether (worth about $553,000), $434,000 in USDT, and 14.16 PAXG (roughly $64,000). All funds moved to a wallet ending in 7C62da1F9. Specter identified the affected Gravity Bridge contract as an address ending in 1F2D906 and said the transaction pattern was consistent with unauthorized withdrawals approved through compromised authorization rather than a direct exploit of contract logic.

Signing Key Compromise Emerges as Lead Theory

Gravity Bridge operates by locking assets on Ethereum and minting mirrored tokens on Cosmos, with validator signatures required to authorize asset movements. Specter argued that an attacker controlling enough valid signing keys could make withdrawals appear legitimate to the system. PeckShield's report also focused on the stolen funds and their subsequent movement, without pinpointing the exact entry vector.

Funds in Motion: ChangeNow and Binance Involved

PeckShield said part of the stolen funds had already passed through ChangeNow and Binance after the attack. The firm also reported that the breached wallet still held about 2,100 ETH (valued near $4.23 million) at the time of its update. A wallet snapshot shared by Specter via Arkham showed a related address holding roughly $4.16 million in ether, indicating investigators are tracing assets across multiple services and wallets.

Gravity Team Halts Bridge, Asks Validators to Stop

The Gravity team confirmed the incident on X, asking all validators to stop their validators and orchestrators. The bridge was later halted entirely as the investigation proceeds. Built by contributors including the Althea team, Gravity Bridge is secured by the Graviton (GRAV) token. No postmortem has been released yet, so the exact entry point — whether validator infrastructure, private keys, or another operational weakness — remains unconfirmed.

Bridge Attacks in 2026: Key Management Failures Persist

If early assessments hold, the Gravity Bridge breach joins a string of 2026 bridge attacks where key-management failures, not audited contract code, played a central role. Similar concerns surfaced in the Kelp DAO and Resolv incidents earlier this year, according to security researchers. TRM Labs has reported that bridge attacks remain a major source of crypto losses in 2026. While the $5.4 million loss is smaller than historic breaches such as Nomad's $190 million exploit (2022) or Orbit Bridge's $81.5 million hack (2024), the incident reinforces the critical importance of securing signing keys in cross-chain infrastructure.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.