September 17, 11:30

Hacker used 55 days of failed transactions to drain $3 million from GalaChain wallets

Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets

CryptoSlate

GalaChain said the attacker used historical signatures from failed transactions to drain about 2 billion GALA worth about $3 million. The attack affected nine wallets on Aug. 18. The attacker collected 74 replayable signatures from failed transactions dating back as far as 55 days. Of 59 targeted account-token combinations, 56 were drained for their exact balance on the first attempt. The four largest GALA positions were taken in descending order within 18 seconds. Gala recorded 1,066 submissions at a median interval of 4.5 seconds. A total of 73.9% of the submissions arrived exactly one block apart. Before the patch, GalaChain's verifier accepted type definitions supplied with each request. That allowed a signature covering one set of fields to be used while another method executed with additional information. One on-chain example processed about 1.64 billion GALA even though the supplied EIP-712 structure did not include the destination, quantity, or token instance used by the transfer. Gala said investigators found no evidence that users' private keys, seed phrases, or passwords were compromised. That conclusion partly relies on internal evidence that Gala has not published. Failed transactions could also roll back their unique replay keys. The signatures remained visible on the public ledger after those failures. Gala said 57 of the 60 historical source transactions linked to the exploit contained at least one failed inner operation. None of those 60 transactions completed entirely successfully. Gala said the relevant verification logic had been reviewed by CertiK in late 2025 and by Hashlock in January. Neither review identified the signature-scope issue. Gala has not published the review reports. Gala changed both verification and replay protection after pausing its bridge during the attack. The new verifier derives type information from the operation being called. Requests now include identifiers that bind signatures to the authorized channel, contract, and method. Expiration timestamps limit how long signed payloads remain valid. The replay fix preserves a unique transaction key even when the underlying operation fails. The first verified unauthorized transfer occurred at 02:21:54 UTC. Gala paused the bridge at 05:09:19 UTC. Gala began removing roles from the recipient address at 05:22. Gala has not disclosed when monitoring first detected the activity. Gala said bridge attempts to move assets out were rejected after the pause. Gala has added per-identity rate limits, behavioral monitoring for high-value accounts, and additional review for bridge withdrawals above certain thresholds. Gala described the attacker as using AI-assisted tooling. That assessment relies on internal evidence that Gala has not released. Gala said it filed a complaint with the FBI's Internet Crime Complaint Center and sent preservation and freeze requests to platforms involved in tracking proceeds across four chains.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.