Gravity Bridge Attacker Continues Laundering Stolen Funds
According to on-chain monitoring by CertiK Alert, a wallet associated with the Gravity Bridge bridge exploit has once again transferred a significant amount of ether into the privacy mixer Tornado Cash. The address deposited 1,180 ETH, worth approximately $2.06 million at current market prices, earlier today. CertiK Alert's surveillance system promptly detected and reported this large transaction, marking yet another step in the attacker's laundering of the stolen funds. With this latest move, the total amount of drained ETH funneled through Tornado Cash continues to grow.
The Gravity Bridge attack resulted in the theft of 2,600 ETH in total, valued at around $5.4 million at the time of the incident. On-chain tracking data reveals that 2,020 ETH from this heist have already been deposited into Tornado Cash through two distinct externally owned accounts (EOAs). EOAs are standard Ethereum wallet addresses controlled by private keys, and using multiple addresses to make staggered deposits helps reduce the visibility of each individual transfer. Tornado Cash employs zero-knowledge proofs to pool deposits from different users and sever the link between source and destination addresses, significantly complicating blockchain tracing efforts.
The remaining ETH that has not yet entered the mixer has been split and transferred to several centralized exchange (CEX) deposit addresses. It remains unclear whether these funds have been exchanged or withdrawn, but on-chain data suggests the attacker is actively processing the leftover stolen assets. Centralized exchanges serve as major hubs for crypto trading and fiat conversion, and the practice of splitting funds across multiple platforms makes full asset recovery more challenging. Security teams continue to monitor the involved addresses closely.

