Incident case file
Sign in to watchGravity Bridge — Suspected Contract Key Compromise Drains Cross-Chain Bridge
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x7B582033061b96cC3F9421e73a749ED7C62da1F9 (primary theft address, confirmed by @SpecterAnalyst May 30 2026) | 0x4d3ca32e687e871a58b78AcAc73bE59AC37C7A47 (secondary theft address, confirmed by @SpecterAnalyst May 30 2026, held ~$4.16M ETH as of May 30) | Funded by: MISSING — pre-attack funding source not publicly disclosed
Timeline: May 30, 2026 — Early hours UTC: Attacker drains Gravity Bridge Ethereum contract (0xa4108aA1Ec4967F8b52220a4f7e94A8201F2D906), stealing $4.3M USDC, 274 WETH (~$553K), $434K USDT, and 14,164 PAXG (~$64K), totaling approximately $5.4M. The attack vector is suspected to be a compromise of the contract signing key or authorization pathway rather than a smart contract code bug. On-chain investigator @SpecterAnalyst is the first to publicly report the exploit, publishing both theft addresses (0x7B58...a1F9 and 0x4d3c...7A47) and the drained contract address. @PeckShieldAlert confirms and amplifies the alert shortly after. May 30, 2026 — Shortly after detection: The Gravity Bridge team requests validators and orchestrators to halt operations. Bridge paused. The attacker immediately begins laundering a portion of the stolen funds, routing through ChangeNow and Binance before alerts are widely circulated. Secondary address 0x4d3c...7A47 holds ~$4.16M ETH (2.065K ETH) while laundering is in progress. May 31, 2026 — @SpecterAnalyst publishes update: With support from @ChangeNOW_io, $91K of the stolen funds has been frozen. The attacker still holds the majority of funds. Arkham Intelligence portfolio shows Gravity Bridge Cosmos Exploiter cluster at ~$4.08M (2.014K ETH + 0.164 PAXG + minor WETH/USDT/USDC residuals). @SpectraAudit comments: 'The bridge-key-compromise pattern is the most common of the 2026 exploits. Code audits cannot extend across the signing setup, the key custody, or the operator.' Post May 31, 2026 — No official post-mortem published by Gravity Bridge team within the reporting window. No compensation plan announced. Bridge remains paused. Attribution: none. Law enforcement: not confirmed. Investigation: ongoing.
Sources and coverage
- Articletheblock.cohttps://www.theblock.co/post/403108/cosmos-based-gravity-bridge-drained-of-5-4-million-in-suspected-key-compromise-researchers-say
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/30/gravity-bridge-hit-in-5-4m-exploit-amid-suspected-key-compromise/
- Articlenews.bitcoin.comhttps://news.bitcoin.com/gravity-bridge-exploit-5-4-million-binance-changenow-2026/
- Articlecoinpaper.comhttps://coinpaper.com/17389/gravity-bridge-loses-5-4-m-in-suspected-key-compromise-attack
- Articlegrafa.comhttps://grafa.com/en/news/crypto/gravity-bridge-54m-exploit
- Articlemexc.comhttps://www.mexc.com/news/1119229
- Articlebitcoinethereumnews.comhttps://bitcoinethereumnews.com/bitcoin/gravity-bridge-hit-by-5-4m-exploit-as-bitcoin-etfs-bleed-2-97b-amid-peak-sentiment/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)