Gravity Bridge hack — May 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | May 30, 2026 |
| Target type | Cross-chain bridge |
| Loss | $5,400,000Price at time of incident |
| Method | Contract logic errorDenomination-mapping poisoning. The Ethereum-side deployERC20() function was permissionless and did not validate the contents of its _cosmosDenom argument, and the Gravity chain handler handleErc20Deployed wrote the resulting mapping into the denom-to-ERC20 registry without calling the existing ERC20ToDenomLookup collision check. Fabricated denomination strings embedding the real Ethereum addresses of custody assets therefore caused later withdrawal batches to release genuine custody tokens. No privileged role or stolen key was required. |
| Chains | Ethereum, Other |
| Outcome | Unresolved |
What happened
Gravity Bridge, the Cosmos-native bridge that locks assets on Ethereum and mints representations on its own chain, lost about $5.4 million on 29 to 30 May 2026. The team told validators to halt their validators and orchestrators, and the bridge was stopped within hours.
The first reports, from PeckShield and the on-chain analyst Specter, described a suspected compromise of bridge signing keys, and that framing carried into early coverage. Later technical analyses by QuillAudits and Security4Web3 concluded that no key was stolen and no privileged role was needed. The attacker instead poisoned the bridge's denomination-to-ERC20 registry. The Ethereum-side deployERC20() function was permissionless and did not validate the contents of its _cosmosDenom argument. The attacker registered a minimal validator on Gravity chain by self-delegating 80 GRAV, minted worthless tokens through the Osmosis token factory and IBC-transferred them across, then called deployERC20() with fabricated denomination strings embedding the real Ethereum addresses of USDC, USDT, WETH and PAXG. Validators acknowledged the deployments, and the handler wrote the poisoned mapping into the registry without checking whether the target token was already held in custody, a collision check that existed elsewhere in the codebase but was never called at that point. Withdrawal batches 41572 to 41575 then released the genuine custody assets.
PeckShield's breakdown was about $4.3 million in USDC, $434,000 in USDT, 274 ETH worth roughly $553,000 and 14.16 PAXG worth about $64,000. Part of the proceeds moved through ChangeNOW and Binance and some was pushed toward Tornado Cash. Bridge TVL fell from about $11.8 million to $6.2 million within a day.
Sources
- The BlockSecondary · retrieved 2026-08-01
- QuillAuditsSecondary · retrieved 2026-08-01
- Security4Web3Secondary · retrieved 2026-08-01
- AMBCryptoSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Gravity Bridge hack — May 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/gravity-bridgehttps://itokenly.com/hacks/gravity-bridgePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.