Gravity Bridge Suffers Key-Exposure Exploit, Losing About $5.4 Million
Gravity Bridge is a cross-chain protocol connecting the Ethereum and Cosmos ecosystems, with validators jointly authorizing asset transfers. Cross-chain bridges hold large concentrations of tokens, and stolen keys can allow attackers to bypass security controls. The incident again highlights key-management risks in DeFi infrastructure.
On-chain analyst Specter raised the alarm on May 30, 2026, saying an apparent contract-key exposure had allowed about $5.4 million to be removed from Gravity Bridge. The assets included 4.3 million USDC, 274 WETH, 434,000 USDT and 14.164 PAXG, leaving only about $85,000 in the contract. The team confirmed the following day that the bridge had been paused.
All Coverage
2 original reportsThe Backstory
The history behind this eventAllbridge Halts Protocol After $1.65 Million Flash-Loan Exploit
Allbridge Core is a cross-chain bridge designed to move stablecoins between blockchains including Solana and Ethereum. Such protocols pool liquidity and coordinate transfers across otherwise separate networks, making them important infrastructure for decentralized finance. Their concentration of assets and reliance on smart-contract pricing also make them frequent targets, with any failure potentially exposing liquidity providers and disrupting users’ ability to move funds between chains.
On July 19, an attacker borrowed $1.12 million through a flash loan from Solana-based lending protocol Kamino and rapidly swapped USDC for USDT to distort Allbridge Core’s pool ratios, according to Onchain Lens. The maneuver enabled withdrawals at favorable rates and drained about $1.65 million. Allbridge paused the protocol and urged users to remove liquidity from affected pools. PeckShield and CertiK said the stolen assets were later bridged from Solana to Ethereum and deposited into privacy pools.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.