← Radar

Incident case file

Sign in to watch

Gravity Bridge — Suspected Contract Key Compromise Drains Cross-Chain Bridge

Incident date May 30, 2026

0 views

PausedEthereumCosmosBridge / Key CompromiseCluster: GRAVITY-KEYCOMP-2026-05

Estimated loss

$5.4M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: 0x7B582033061b96cC3F9421e73a749ED7C62da1F9 (primary theft address, confirmed by @SpecterAnalyst May 30 2026) | 0x4d3ca32e687e871a58b78AcAc73bE59AC37C7A47 (secondary theft address, confirmed by @SpecterAnalyst May 30 2026, held ~$4.16M ETH as of May 30) | Funded by: MISSING — pre-attack funding source not publicly disclosed

Funds moved to: Partial laundering via ChangeNow and Binance within hours of the exploit. As of May 31 2026: ~2,102 ETH (~$4.23M) still held in attacker wallets. $91K frozen by ChangeNow with support from @SpecterAnalyst (confirmed May 31 2026). Majority of funds not yet moved as of last update. No CEX deposit confirmed for the bulk of ETH.
Contract drained: 0xa4108aA1Ec4967F8b52220a4f7e94A8201F2D906 (Gravity Bridge Ethereum contract, confirmed by @SpecterAnalyst May 30 2026). TVL pre-exploit: ~$11.82M. TVL post-exploit: ~$6.24M (DeFiLlama). Composition drained: $4.3M USDC + 274 WETH (~$553K) + $434K USDT + 14,164 PAXG (~$64K). Secondary attacker wallet 0x4d3ca32e687e871a58b78AcAc73bE59AC37C7A47 held 2.065K ETH (~$4.16M) as of May 30. Arkham Intelligence cluster label: Gravity Bridge Cosmos Exploiter.

Timeline: May 30, 2026 — Early hours UTC: Attacker drains Gravity Bridge Ethereum contract (0xa4108aA1Ec4967F8b52220a4f7e94A8201F2D906), stealing $4.3M USDC, 274 WETH (~$553K), $434K USDT, and 14,164 PAXG (~$64K), totaling approximately $5.4M. The attack vector is suspected to be a compromise of the contract signing key or authorization pathway rather than a smart contract code bug. On-chain investigator @SpecterAnalyst is the first to publicly report the exploit, publishing both theft addresses (0x7B58...a1F9 and 0x4d3c...7A47) and the drained contract address. @PeckShieldAlert confirms and amplifies the alert shortly after. May 30, 2026 — Shortly after detection: The Gravity Bridge team requests validators and orchestrators to halt operations. Bridge paused. The attacker immediately begins laundering a portion of the stolen funds, routing through ChangeNow and Binance before alerts are widely circulated. Secondary address 0x4d3c...7A47 holds ~$4.16M ETH (2.065K ETH) while laundering is in progress. May 31, 2026 — @SpecterAnalyst publishes update: With support from @ChangeNOW_io, $91K of the stolen funds has been frozen. The attacker still holds the majority of funds. Arkham Intelligence portfolio shows Gravity Bridge Cosmos Exploiter cluster at ~$4.08M (2.014K ETH + 0.164 PAXG + minor WETH/USDT/USDC residuals). @SpectraAudit comments: 'The bridge-key-compromise pattern is the most common of the 2026 exploits. Code audits cannot extend across the signing setup, the key custody, or the operator.' Post May 31, 2026 — No official post-mortem published by Gravity Bridge team within the reporting window. No compensation plan announced. Bridge remains paused. Attribution: none. Law enforcement: not confirmed. Investigation: ongoing.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)