The hacker responsible for the Gravity Bridge exploit transferred an additional 1,180 ETH, worth approximately $2.06 million, to cryptocurrency mixing service Tornado Cash, according to blockchain security firm CertiK. This latest transaction brings the total amount of stolen funds sent through the mixer to 2,020 ETH.
Details of latest transactions
CertiK reported that the funds were transferred via two External Accounts (EOAs) in a series of transactions over the past 24 hours. The total amount stolen in the initial exploit was 2,600 ETH, worth approximately $5.4 million at the time of the hack. Of this amount, the majority has now been routed through Tornado Cash, a protocol designed to hide transaction traces on the Ethereum blockchain.
The remaining stolen assets were spread across multiple centralized exchanges (CEX), according to the security firm’s on-chain analysis. This trend of moving funds through mixers and exchanges is a common tactic used by hackers to launder illicit proceeds and evade law enforcement.
Gravity Bridge exploit background
The Gravity Bridge hack, which occurred in mid-2024, exploited a vulnerability in the cross-chain bridge protocol. The attacker drained over 2,600 ETH from the bridge’s smart contract, triggering an immediate investigation by CertiK and other blockchain forensic teams. The incident highlighted the ongoing security risks associated with cross-chain infrastructure, which remains a frequent target for attackers due to the complexity of cross-blockchain communication.
The continued movement of stolen funds through Tornado Cash highlights ongoing blockchain security and regulatory enforcement challenges. Despite sanctions imposed by the US Treasury Department against the mixer in 2022, the protocol remains operational and continues to be used to launder stolen cryptocurrencies. This case also illustrates the difficulty of recovering assets once they enter mixed services, as transaction history becomes almost impossible to trace.
For users and investors, the Gravity Bridge incident serves as a reminder of the risks associated with cross-chain protocols and the importance of thorough audits of smart contracts. It also highlights the current cat-and-mouse dynamic between blockchain security companies and malicious actors.
Conclusion
The Gravity Bridge hacker’s latest move to funnel over $2 million in stolen ETH through Tornado Cash brings the total laundered through the mixer to over 2,000 ETH. With the remaining funds dispersed across exchanges, the case remains active and CertiK continues to monitor the wallets involved. The incident reinforces the need for stronger security measures in cross-chain protocols and the ongoing challenge of tracing and recovering stolen digital assets.
![]()



