Gala – Bitcoin Platform https://bitcoinplatform.com Breaking Crypto News and Blockchain updates Thu, 17 Sep 2026 11:30:00 +0000 en-GB hourly 1 https://wordpress.org/?v=7.1 https://bitcoinplatform.com/wp-content/uploads/2026/09/cropped-fevi-18-32x32.png Gala – Bitcoin Platform https://bitcoinplatform.com 32 32 GalaChain’s 2 billion GALA exploit began with failed transactions https://bitcoinplatform.com/galachains-2-billion-gala-exploit-began-with-failed-transactions/ https://bitcoinplatform.com/galachains-2-billion-gala-exploit-began-with-failed-transactions/#respond Thu, 17 Sep 2026 11:30:00 +0000 https://bitcoinplatform.com/galachains-2-billion-gala-exploit-began-with-failed-transactions/ GalaChain, a blockchain developed by Gala Games, faced a security exploit in August that exposed a critical flaw in its system. The exploit allowed the attacker to use historical signatures from failed transactions to drain approximately 2 billion GALA tokens, worth around $3 million, as well as several other tokens from nine wallets on August 18.

In their postmortem analysis on September 14, Gala revealed that the attacker had meticulously planned the operation before executing the unauthorized transfers. The attack exploited vulnerabilities in both signature verification and replay protection mechanisms of GalaChain.

The attacker managed to gather 74 replayable signatures from failed transactions that dated back as far as 55 days. With detailed knowledge of the targeted accounts, the attacker swiftly drained the balances of 56 out of 59 account-token combinations on the first attempt. The attack was executed rapidly, with 1,066 submissions made at a median interval of 4.5 seconds.

The flaw in GalaChain’s EIP-712 typed-data verification process allowed the attacker to present a signature covering one set of fields while executing a different operation using additional information not committed to by the signer. This loophole enabled the attacker to transfer large amounts of GALA tokens without proper authorization.

Despite undergoing multiple security audits by CertiK and Hashlock, the vulnerability in GalaChain’s verification logic went undetected. The flaw survived external reviews due to the oversight in testing the interaction between signature verification and replay protection.

Following the attack, Gala implemented patches to address the vulnerabilities. Signature verification now derives type information from the invoked operation, and requests include identifiers to bind signatures more closely to the authorized channel. Additionally, the replay mechanism was modified to persist unique transaction keys even after failed transactions, preventing replay attacks.

The incident highlighted the need for blockchain operators to respond quickly to automated attacks. Gala paused its bridge during the attack, but the response time raised concerns about the effectiveness of human-triggered emergency controls in thwarting machine-speed exploitation.

Moving forward, Gala has implemented additional security measures such as per-identity rate limits and behavioral monitoring for high-value accounts to detect abnormal activity earlier in the settlement process. The incident also underscores the importance of comprehensive audit scope to identify vulnerabilities that may arise from the interaction of different security mechanisms.

As blockchain operators face the challenge of defending against machine-speed attacks, the incident serves as a lesson in the evolving landscape of cybersecurity in the crypto space. Gala has taken steps to track and recover the stolen assets, while the industry as a whole will need to adapt to the increasing sophistication of automated attackers.

]]>
https://bitcoinplatform.com/galachains-2-billion-gala-exploit-began-with-failed-transactions/feed/ 0