GalaChain said the attacker used historical signatures from failed transactions to drain about 2 billion GALA worth about $3 million. The attack affected nine wallets on Aug. 18. The attacker collected 74 replayable signatures from failed transactions dating back as far as 55 days. Of 59 targeted account-token combinations, 56 were drained for their exact balance on the first attempt. The four largest GALA positions were taken in descending order within 18 seconds. Gala recorded 1,066 submissions at a median interval of 4.5 seconds. A total of 73.9% of the submissions arrived exactly one block apart. Before the patch, GalaChain's verifier accepted type definitions supplied with each request. That allowed a signature covering one set of fields to be used while another method executed with additional information. One on-chain example processed about 1.64 billion GALA even though the supplied EIP-712 structure did not include the destination, quantity, or token instance used by the transfer. Gala said investigators found no evidence that users' private keys, seed phrases, or passwords were compromised. That conclusion partly relies on internal evidence that Gala has not published. Failed transactions could also roll back their unique replay keys. The signatures remained visible on the public ledger after those failures. Gala said 57 of the 60 historical source transactions linked to the exploit contained at least one failed inner operation. None of those 60 transactions completed entirely successfully. Gala said the relevant verification logic had been reviewed by CertiK in late 2025 and by Hashlock in January. Neither review identified the signature-scope issue. Gala has not published the review reports. Gala changed both verification and replay protection after pausing its bridge during the attack. The new verifier derives type information from the operation being called. Requests now include identifiers that bind signatures to the authorized channel, contract, and method. Expiration timestamps limit how long signed payloads remain valid. The replay fix preserves a unique transaction key even when the underlying operation fails. The first verified unauthorized transfer occurred at 02:21:54 UTC. Gala paused the bridge at 05:09:19 UTC. Gala began removing roles from the recipient address at 05:22. Gala has not disclosed when monitoring first detected the activity. Gala said bridge attempts to move assets out were rejected after the pause. Gala has added per-identity rate limits, behavioral monitoring for high-value accounts, and additional review for bridge withdrawals above certain thresholds. Gala described the attacker as using AI-assisted tooling. That assessment relies on internal evidence that Gala has not released. Gala said it filed a complaint with the FBI's Internet Crime Complaint Center and sent preservation and freeze requests to platforms involved in tracking proceeds across four chains.
GalaChain Hacker Drains $3M Using 55-Day-Old Failed Transaction Signatures
NS3Share
On-chain news reveals a GalaChain hacker drained $3 million using 55-day-old failed transaction signatures on August 18. The attacker collected 74 replayable signatures, draining 56 of 59 targeted accounts on the first attempt. GalaChain paused its bridge and updated verification logic. The attack reportedly used AI + crypto news tools, but no private key compromise was found. Gala filed an FBI complaint and requested asset freezes from tracking platforms.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.