Blockchain security firm CertiK Alert has detected another transfer by the Gravity Bridge attacker, who moved 1,180 ETH (approximately $2.06 million) into the privacy mixer Tornado Cash. This is part of the ongoing laundering of funds stolen in a previous exploit.
In total, the attacker stole 2,600 ETH, worth around $5.4 million at the time of the incident. On-chain data shows that 2,020 ETH have now been deposited into Tornado Cash via two separate externally owned addresses (EOAs), while the remainder has been distributed in small amounts to various centralized exchanges.
Gravity Bridge connects the Ethereum and Cosmos ecosystems, facilitating cross-chain asset transfers. The exploit highlighted security weaknesses in cross-chain bridges, which remain frequent targets for hackers. The use of Tornado Cash, a protocol that breaks transaction links, complicates tracing efforts, and funneling funds through exchanges may indicate an attempt to cash out.
CertiK Alert and other security analysts are closely monitoring the remaining funds and any interaction with known addresses. The incident underscores the importance of rigorous security audits and real-time on-chain monitoring for decentralized finance infrastructure.

