Gravity Bridge exploited for $5.4M through fraudulent batch withdrawals using valid signatures.
Security & Exploits ·
Gravity Bridge suffered a $5.4 million exploit when an attacker submitted fraudulent batch withdrawals using valid signatures, according to PeckShieldAlert. The theft comprised $4.3 million in USDC, 274 ETH (valued around $553,000), $434,000 in USDT, and 14.164 PAYG tokens worth approximately $64,000.
The attacker has already moved a portion of the stolen funds through cryptocurrency exchanges ChangeNow and Binance. However, a substantial remainder—2.102K ETH valued at roughly $4.23 million—remains in the attacker's possession, suggesting either a staged withdrawal strategy or ongoing asset laundering efforts.
The mechanics of how valid signatures were leveraged to authorize fraudulent withdrawals and whether the vulnerability has been patched remain unclear. Additionally, the full extent of the attacker's identity, the precise timeline of the exploit, and whether additional recovery measures are underway have not been disclosed.