Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets

1 hour ago 1



GalaChain’s August exploit turned failed transactions into reusable authorization, exposing a security flaw that had survived multiple audits.The blockchain developed by Gala Games said the attacker used historical signatures from unsuccessful transactions to drain about 2 billion GALA (about $3 million) and dozens of other tokens from nine wallets on Aug. 18.Its Sept. 14 postmortem depicts an operation prepared before the first unauthorized transfer, with mapped balances, automated submissions, and a weakness spanning both signature verification and replay protection.Gala patched the flaws after pausing its bridge during the attack. The incident now raises a broader question for blockchain operators: whether systems built around valid signatures and human-triggered emergency controls can respond quickly enough once exploitation has been automated.Failed transactions became an attack inventoryThe attacker arrived with 74 replayable signatures gathered from failed transactions stretching back as far as 55 days, Gala said.Those signatures were paired with what appears to have been detailed knowledge of the affected accounts. Of 59 account-token combinations targeted during the incide...

Read Entire Article