Cosmos-native cross-chain protocol Gravity Bridge suffered a compromised-key attack over the weekend, and the losses land at roughly $5.4 million, according to blockchain sleuth Specter and security firm PeckShield, as reported by NewsBTC.
Specter said the breach may have come from a signing key compromise. That means an attacker got an unauthorized copy or disclosure of a cryptographic key that Gravity Bridge relies on to authorize transfers. In a signing key compromise, the key can enable forged digital signatures or unauthorized access, which can then be used to move funds.
The reported haul includes crypto assets worth about $5.4 million. NewsBTC lists $4.3 million in USDC, 274 wrapped Ether worth roughly $553,000, about $434,000 in USDT, and 14.16 PAXG tokens priced at about $64,000.
Why it matters
Gravity Bridge’s design helps explain why a key theft can bypass “smart contract” assumptions. NewsBTC says the protocol works by locking tokens on Ethereum and creating direct replicas on Cosmos. Transfers on Cosmos rely on validator signatures to authorize each move.
NewsBTC also notes that if an attacker obtains the signing keys, the protocol would treat forged transactions as legitimate. In other words, the failure mode can sit in access controls rather than in the underlying bridge contract code.
That fits a pattern security researchers keep seeing across 2026. NewsBTC describes recent exploits as often linked to breaches embedded in authorization logic.
Market impact
There is no claim in the provided reporting that this incident directly changed the prices of the affected assets. But the money movement is concrete. PeckShield, cited by NewsBTC, says the attacker laundered part of the stolen funds through ChangeNOW and Binance. PeckShield also reportedly believes the actor still holds more than 2,100 Ether valued at approximately $4.23 million.
The broader DeFi context matters too. NewsBTC says Gravity Bridge joins a growing list of DeFi security breaches in 2026, with bridges singled out as soft targets.
NewsBTC points to a TRM Labs report that identified April 2026 as the most hacked month in crypto history by number of incidents. It cites the $292 million Kelp DAO hack and Drift Protocol’s $285 million loss as examples.
What to watch next
Gravity Bridge’s team confirmed the attack on Saturday and told operators to stop. NewsBTC says the protocol instructed validators and orchestrators to halt operations while they investigate the exploit.
The protocol also stated that validators’ swift action has the bridge halted while investigations continue. The immediate question for users and counterparties is whether Gravity Bridge can rotate keys and restore safe operations without reintroducing the compromised authorization pathway.
On the industry side, expect more scrutiny of bridge authorization layers. If signing keys are the weak spot, incident response will hinge on key management, validator/orchestrator controls, and how quickly a system can halt.
| Item | Reported detail |
|---|---|
| Attack type | Signing key compromise, per Specter |
| Loss estimate | Roughly $5.4 million |
| Breakdown | $4.3M USDC, 274 wETH (~$553K), |
| Laundering routes | ChangeNOW and Binance, per PeckShield |
| Funds still held | Over 2,100 Ether (~$4.23M), per PeckShield |
| Response | Validators and orchestrators instructed to halt, bridge currently halted |