Gravity Bridge Hit by Suspected Private Key Leak, $5.4 Million Drained

Gravity Bridge Hit by Suspected Private Key Leak, $5.4 Million Drained

N
News Editor 01
2026-07-23 07:00:14
Gravity Bridge, a Cosmos cross-chain bridge, was reportedly hit by a suspected private key leak that led to roughly $5.4 million in stolen assets, leaving only about $85,000 in the contract.
Gravity Bridgecross-chain bridgeprivate key leaksecurity incidentCosmos

Gravity Bridge, a long-running cross-chain protocol in the Cosmos ecosystem, has reportedly lost about $5.4 million after a suspected compromise of its bridge contract key. On-chain analyst Specter flagged the incident on May 30, and Etherscan data showed the protocol’s Ethereum-side contract had been reduced to roughly $85,000, leaving the balance close to empty.

USDC made up most of the stolen funds

The reported stolen assets include 4.3 million USDC, 274 WETH, 434,000 USDT, and about $64,000 worth of PAYG. USDC accounted for about 79.6% of the total loss, making it the largest component of the drain.

The addresses tied to the case were listed as 0x7B58…da1F9 and 0x4d3c…C7A47. On-chain records indicate the first address was funded from Binance about seven hours earlier, then transferred the funds to the second address. That second wallet now holds around 2,065 ETH, valued in the source material at roughly $4.16 million, indicating that part of the stolen assets has already been swapped into ETH.

Security assumptions around validator signatures are in focus

Gravity Bridge was built to move assets between Cosmos and Ethereum. Its Ethereum-side security model is designed so that funds can only be moved with signatures from more than two-thirds of validators. If the key leak is confirmed, the attacker may have bypassed that multisig-style protection without exploiting a smart contract bug directly.

Second private key incident in three days

The report described this as the second private key leak disclosed within three days. On May 27, a StakeDAO deployer key was also compromised. In that case, the attacker reconfigured LayerZero v2 cross-chain peer nodes and minted more than 5.4 trillion vsdCRV on Arbitrum before swapping the tokens for ETH.

The source says at least 8 major bridge protocol attacks have taken place in 2026, with combined losses above $328 million. The largest cases cited were Kelp DAO at $293 million and Drift at $285 million, both involving stolen keys or compromised admin permissions.

As of publication, Gravity Bridge had not issued an official statement on the incident.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.