Key takeaways
- Peckshield reported a Gravity Bridge exploit of approximately $5.4 million on May 30, including $4.3 million in USDC and 274 ETH.
- The theft adds to the more than $328 million Peckshield tracked in May 2026 bridge hacks.
- The attacker still holds 2,102 ETH (~$4.23 million), and on-chain detectives are following the laundering trail.
Funds routed through Binance and ChangeNow
Gravity Bridge, a protocol that moves tokens between Ethereum and the Cosmos ecosystem, lost around $5.4 million in a new exploit reported by blockchain security company Peckshield. The stolen assets included approximately $4.3 million in USD Coin (USDC), 274 ether ( ETH) worth approximately $553,000, $434,000 attached ( USDT) and 14,164 PAYG tokens worth almost $64,000.
The attacker wasted no time in moving the profits. According to Peckshield’s assessment, some of the loot has already been laundered through Changenow, a non-custodial exchange service, and Binance, the world’s largest exchange service. cryptocurrency exchange by trade volume. At the time of the alert, the exploiter still held approximately 2,102 ETH worth approximately $4.23 million, suggesting that most of the stolen value remained on-chain and potentially traceable.

Route funds through a centralized exchange as Binance may lead the way in mixing stolen coins with legitimate coins liquiditybut it also exposes funds to freezing if the platform’s compliance team acts quickly. Exchange services like ChangeNow are often used to convert assets into harder-to-trace tokens before they reach an exchange.
What is the gravitational bridge for?
Gravity Bridge is a cross-chain bridge (software that allows users to move tokens from one blockchain to another), connecting Ethereum to the Cosmos network of interoperable chains. Built on the Cosmos SDK, it runs on a locked and new model. Here, a token is locked on one chain and an equivalent representation is minted on the other, then burned and redeemed when the user returns.
Rather than relying on a small multi-signature wallet or a group of authorized operators, Gravity Bridge uses its set of validators to sign cross-chain transactions, a design intended to make it more decentralized and harder to compromise. This architecture did not make bridges safe from attack because, bBy design, they hold large pools of locked assets, making them one of the most lucrative targets in decentralized finance (DeFi). A single flaw in their validation logic can unlock everything at once.
A brutal year for cross-chain bridges
The Gravity Bridge incident comes amid a difficult period for cross-chain infrastructure, as Bitcoin.com News recently reported that the bridge exploits were exhausted. more than $328 million on eight separate incidents through mid-May 2026 alone.
The trend has been relentless throughout the year. On May 18, the attackers embezzled approximately $11.5 million from Verus-Ethereum Bridgethe author being funded through Tornado Cash prior to the theft. Subsequently, in April, an alleged exploit took more than $200 million from Drift protocol while a a separate breach drained 116,500 rsETH from KelpDAO Zero layer adapterexposing credit markets to possible bad debts.
Smaller successes also accrued, including a $2.4 million flash loan attack on the Shibarium Bridge. In all this, tThis repetition indicates a structural problem rather than a streak of bad luck. Bridges must reconcile the different security models of the two chains, and the code that verifies deposits and withdrawals has repeatedly proven to be the weakest link (whether due to missing validation checks, compromised keys, or governance flaws).
Guess the steps to follow
The immediate question is how much of the $5.4 million stolen can be recovered. While the attacker still has approximately $4.23 million in ETH, exchange and analytics firms have a window to report and freeze funds, and protocols are increasingly using public pressure and on-chain messages to negotiate returns. The Verus hacker, for example, ended up returned $8.5 million while still retaining a $2.8 million bonus as part of a stimulus deal.
For now, Gravity Bridge users will monitor an official incident report detailing the root cause and any plans to reimburse affected depositors. Until bridges address the validation weaknesses that continue to surface, the most important connectors of the multichain economy will likely remain the most frequently stolen.

