Cosmos-Based Gravity Bridge Halts After Reported $5.4M Exploit
Gravity Bridge paused after a suspected key compromise drained about $5.4 million, according to onchain analysts and PeckShield.
Intelligence analysis by GPT-5.4 Mini

Validators halted Gravity Bridge after onchain sleuths and PeckShield said a suspected signing-key compromise drained funds and sent part of the loot through instant-swaps and Binance.
Gravity Bridge is like a bridge that lets coins cross from one blockchain town to another. If someone steals the bridge key, they can try to take coins that are passing through.
That is what the article says happened here. People watching the blockchain saw strange money moves, and a security team said about $5.4 million may have been taken.
The bridge was stopped so it could be checked. It is like locking a door after noticing a broken window, so no more money can be moved until the problem is fixed.
Analysis
What happened
Gravity Bridge, a decentralized bridge connecting Ethereum and Cosmos, was reportedly drained of about $5.4 million. Onchain analyst Specter said the contract key may have been compromised after spotting unusual outflows, and security firm PeckShield later confirmed the exploit.
PeckShield’s breakdown put the stolen assets at roughly $4.3 million in USDC, 274 WETH worth about $553,000, $434,000 in USDT, and 14.164 PAXG worth around $64,000. The firm also said some of the funds had already moved through instant-swap service ChangeNow and Binance, while the theft wallet still held about 2,102 ETH, valued at roughly $4.23 million at the time of the report.
Gravity Bridge acknowledged the incident on X and told validators to halt their validators and orchestrators while the case was being investigated. The team later confirmed the bridge had been halted.
Why it matters
Gravity Bridge is designed to move assets between Ethereum and Cosmos in both directions, including to venues such as Osmosis and Uniswap. The article notes that it uses its full validator set to authorize transfers, which is meant to make it more decentralized than bridges that depend on a small set of private signers.
That design does not remove risk. If a key or authorization path is compromised, a bridge can still become a large target because it controls assets across ecosystems. The story lands in a period when bridge security is already under pressure, with the article citing JPMorgan analysts warning about the challenge and pointing to recent bridge attacks that have added up to hundreds of millions of dollars in losses.
Gravity Bridge’s native token, GRAV, was also trading lower on the day of the report, reflecting the immediate market strain that often follows a bridge incident.
Key points
- Gravity Bridge was halted after a suspected compromise drained about $5.4 million.
- Onchain analyst Specter first flagged unusual outflows, and PeckShield later confirmed the exploit.
- PeckShield said the stolen assets included USDC, WETH, USDT, and PAXG, with some funds already routed through ChangeNow and Binance.
- Gravity Bridge told validators to stop operations while the investigation continued.
- The incident adds to broader concern about bridge security and cross-chain infrastructure.



