Gravity Bridge Loses $5.4M in Suspected Validator Key Breach

The Gravity Bridge hack on May 30 2026 drained roughly $5.4 million in assets from the Cosmos-based bridge to Ethereum. Security researchers attribute the

Share
Gravity Bridge Loses $5.4M in Suspected Validator Key Breach

Hero: A digital visualization of blockchain bridges connecting Ethereum and Cosmos networks with data flowing between them, highlighting a security breach point

Summary

  • The Gravity Bridge hack on May 30 2026 drained roughly $5.4 million in assets from the Cosmos-based bridge to Ethereum.
  • Security researchers attribute the loss to a suspected signing key compromise that enabled unauthorized withdrawals of USDC, ETH, USDT, and PAYG tokens.
  • The incident marks the eighth bridge exploit of 2026 and lifts cumulative losses across similar protocols to $334 million.

The Gravity Bridge hack took roughly $5.4 million from the cross-chain link between Ethereum and Cosmos. Attackers drained $4.3 million in USDC plus 274 ETH on May 30 2026, PeckShield's on-chain monitors showed. That single hit lifted total bridge losses for the year to $334 million.

The core issue looks simple enough. Someone appears to have grabbed a signing key and used it to push through withdrawals the bridge treated as valid. Teams froze operations while they hunt for the root cause, and liquidity providers now sit with frozen positions on both sides.

Loss Breakdown and Immediate Response

PeckShield spotted the exploit first on May 30. Roughly $4.3 million in USDC left the bridge along with 274 ETH. The attacker later routed some funds through ChangeNow and Binance, yet still held 2,102 ETH worth about $4.2 million days afterward.

Stolen tokens covered USDC, ETH, USDT, and PAYG. No user approvals were involved, so the attacker had direct control over bridge functions instead of hunting for a code bug. That gave them the ability to sign transactions the system accepted without question.

  • USDC accounted for the largest share at $4.3 million.
  • 274 ETH were taken in the initial drain.
  • The remaining balance of 2,102 ETH stayed in attacker-controlled wallets days after the event.

Gravity Bridge stopped all bridging right after the alerts landed. The pause blocked further outflows while teams checked contract state and validator signatures.

Signing Key Compromise Mechanics

Security teams call it a suspected signing key compromise. In these setups the keys let the bridge release wrapped assets or move cross-chain messages. Once exposed, an attacker can fire off withdrawals that look perfectly legitimate on the destination chain.

The Gravity Bridge contract accepted a string of unauthorized instructions after the exposure. This stands apart from oracle or minting attacks. The attacker simply reused the normal withdrawal path with different parameters.

"It appears the Gravity Bridge contract key may have been compromised, resulting in the theft of $5.4M."

, Specter (news.bitcoin.com)

The case spotlights how Cosmos bridges store and rotate keys. Validators or multisig setups often hold them, so a single breach can hand over the entire Ethereum-side treasury. And honestly, that's a big deal.

The attacker still sits on a sizable ETH balance, which keeps pressure on exchanges and mixers to watch for those flows.

Counterpoint: Unconfirmed Root Cause

No public forensics yet confirm a stolen key versus an insider move or a quiet contract flaw. PeckShield and on-chain watchers label it a suspected key compromise, but they stop short of final proof.

That leaves room for other explanations. A botched upgrade or loose permissions could create the same transaction pattern. The team has not released a detailed post-mortem, so any broader claims about Cosmos Ethereum bridge security rest on partial data.

The weight of on-chain evidence still points to direct control of withdrawal functions rather than an oracle hit or phishing wave. Investigators will keep digging.

Looking ahead, the incident will likely push more projects toward threshold signatures and hardware key storage. One question worth watching is whether other bridges will add mandatory rotation schedules before the next round of exploits.