Gravity Bridge key compromise.
Early Saturday, the Gravity Bridge, which moves assets between Ethereum and the Cosmos network, lost about $5.4 million. Researchers say the code held. A signing key, the credential that authorizes the bridge to release funds, was compromised.
A bridge locks an asset on one chain and authorizes a matching release on the other. That authorization depends on a key held by the operators. Whoever holds it can move the funds, with or without permission.
The contract did what it was built to do. It honored a valid signature. When the key behind that signature is stolen, there is no second layer left to catch it.
Related
SciPHR