|

Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets

GalaChain’s August exploit turned failed transactions into reusable authorization, exposing a safety flaw that had survived a number of audits.

The blockchain developed by Gala (*55*) stated the attacker used historic signatures from unsuccessful transactions to empty about 2 billion GALA (about $3 million) and dozens of different tokens from 9 wallets on Aug. 18.

Its Sept. 14 postmortem depicts an operation ready earlier than the primary unauthorized switch, with mapped balances, automated submissions, and a weak spot spanning each signature verification and replay safety.

Gala patched the issues after pausing its bridge in the course of the assault. The incident now raises a broader query for blockchain operators: whether or not methods constructed round legitimate signatures and human-triggered emergency controls can reply rapidly sufficient as soon as exploitation has been automated.

Failed transactions grew to become an assault stock

The attacker arrived with 74 replayable signatures gathered from failed transactions stretching again so far as 55 days, Gala stated.

Those signatures had been paired with what seems to have been detailed information of the affected accounts. Of 59 account-token mixtures focused in the course of the incident, 56 had been drained for his or her actual stability on the primary try. The 4 largest GALA positions had been taken in descending order inside 18 seconds.

That sample suggests reconnaissance occurred earlier than exploitation started fairly than account balances being found transaction by transaction in the course of the assault.

Execution then moved quickly. Gala recorded 1,066 submissions at a median interval of 4.5 seconds, with 73.9% arriving precisely one block aside.

The historic signatures had been priceless as a result of of how GalaChain dealt with EIP-712 typed-data verification.

Before the patch, the verifier accepted sort definitions provided with the request fairly than deriving them from the invoked operation. That allowed a signature masking one set of fields to be offered whereas one other methodology executed utilizing further data the signer had by no means dedicated to.

One on-chain instance reveals a TransferToken name processing about 1.64 billion GALA though the EIP-712 structure provided for verification described an AddLiquidity operation. The vacation spot, amount, and token occasion utilized by the switch had been exterior the signed construction.

The signature itself was cryptographically legitimate. The system couldn’t assure that the account holder had licensed the financial results execution finally produced.

Gala stated investigators discovered no proof that the affected customers’ personal keys, seed phrases, or passwords had been compromised. That conclusion depends partly on inner proof that the corporate has not printed.

A separate replay weak spot expanded the pool of signatures the attacker may use.

GalaChain assigned distinctive transaction keys meant to cease the identical signed payload from being submitted greater than as soon as. But when a transaction failed, the key may roll again alongside the unsuccessful state adjustments.

The signature remained seen on the general public ledger whereas the replay key remained out there.

Gala stated 57 of the 60 historic supply transactions linked to the exploit contained not less than one failed internal operation, whereas none accomplished solely efficiently.

The mixture successfully turned unsuccessful historic requests into reusable permissions. An attacker didn’t must forge signatures or steal the personal keys behind each focused pockets as a result of genuine signatures had already been printed on-chain.

GALA audits missed the interplay between safeguards

Meanwhile, the vulnerability had survived exterior safety opinions earlier than the assault.

Gala stated the related verification logic was examined throughout an authorization-focused CertiK engagement in late 2025 and an SDK assessment by Hashlock in January. Neither recognized the signature-scope problem.

The firm has not printed these studies, making it troublesome to find out what every assessment examined or how extensively it examined the interplay between signature verification and replay safety.

Notably, the replay mechanism itself was launched after an earlier CertiK discovering.

That safety may forestall reuse after a transaction key had been consumed. The Aug. 18 attacker discovered the boundary the place the safeguard stopped making use of: failed transactions whose signed payloads had turn out to be public whereas their distinctive keys remained unused.

Gala subsequently modified each methods.

Signature verification now derives its sort data from the operation being referred to as fairly than trusting a caller-supplied definition. Requests additionally embrace identifiers that bind signatures extra carefully to the channel, contract, and methodology being licensed, whereas expiration timestamps restrict how lengthy signed payloads stay legitimate.

The replay repair persists a distinctive transaction key even when the underlying enterprise operation fails, stopping the identical historic request from remaining out there for an additional try.

Those patches shut the 2 weaknesses described within the postmortem. They don’t resolve the response-time drawback that emerges as soon as a valid-looking assault is already underway.

The first verified unauthorized switch occurred at 02:21:54 UTC. Gala paused the bridge at 05:09:19 UTC, about two hours and 47 minutes later, and started eradicating roles from the recipient tackle at 05:22.

The firm has not disclosed when its monitoring first detected the exercise, so that interval can’t be handled as its response time. Gala stated makes an attempt to maneuver belongings out via the bridge had been rejected after the pause.

The chronology nonetheless reveals the disparity dealing with operators as soon as exploitation reaches machine velocity: submissions can arrive each few seconds whereas detection, investigation and emergency intervention should require human selections.

Bridge operators face a machine-speed protection drawback

Gala stated it has since added per-identity fee limits, behavioral monitoring for high-value accounts and extra assessment for bridge withdrawals above sure thresholds.

Those measures transfer safety controls earlier within the settlement course of, the place uncommon exercise could be slowed earlier than belongings go away the system.

They additionally introduce trade-offs.

Operation-bound signatures, expirations, and replay keys largely implement the directions a consumer really signed. Rate limits and behavioral triggers require operators to resolve what constitutes irregular exercise, whereas withdrawal holds can delay authentic customers in addition to malicious ones.

Gala has described the attacker as utilizing AI-assisted tooling, however that evaluation depends on inner proof the corporate has not launched.

Related Reading

Have AI agents made the entire $148 billion DeFi sector unsafe?


That distinction issues as crypto companies more and more body security threats around artificial intelligence. For bridge operators, the extra rapid problem is whether or not automated attackers can exploit valid-looking authorization paths quicker than monitoring methods can determine and include them.

Gala stated it has filed a criticism with the FBI’s Internet Crime Complaint Center and despatched preservation and freeze requests to platforms concerned because it tracks proceeds throughout 4 chains.

The longer-term problem is now more likely to shift towards audit scope. Reviews that check signature verification, replay safety, and transaction execution individually could miss vulnerabilities that seem solely when these methods work together.

For GalaChain, future audits must set up whether or not related authorization gaps stay elsewhere in its SDK.

For bridge operators extra broadly, the business value of counting on a human-triggered pause rises with each block as soon as an attacker arrives with harvested signatures, mapped balances and an automatic submission engine.

The put up Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets appeared first on CryptoSlate.

Similar Posts