GalaChain Hack 2026 — $3M Exploit Analysis

An attacker harvested 74 replayable signatures from failed GalaChain bridge transactions over 55 days and drained ~2.0B GALA plus ~37 other tokens (~$3M) from nine wallets. Gala paused the bridge, revoked roles, and deployed a permanent fix.

Details

Full Description

On August 18, 2026, an attacker drained approximately $3 million (~2.0B GALA plus ~37 other tokens) from nine GalaChain wallets by exploiting a signature-scope confusion flaw in the bridge. The attacker harvested 74 replayable signatures from failed transactions over 55 days (the oldest 432,190 blocks prior). EIP-712 verification accepted caller-supplied type definitions, so a signature covering one field set authorized a different operation, and failed transactions rolled back their unique replay keys, leaving the signatures reusable. The first unauthorized transfer occurred at 02:21:54 UTC (block 10404040, 1,639,810,337.11548495 GALA in one call), with 1,066 submissions at a median 4.5-second interval, 73.9% one block apart, and 56 of 59 account-token pairs drained to exact balance on the first attempt. Gala paused the bridge at 05:09:19 UTC, revoked roles, and deployed a permanent fix at 06:27 UTC. No private keys or seed phrases were compromised. Gala filed an FBI IC3 complaint and sent freeze requests; CertiK (late 2025) and Hashlock (Jan 2026) reviews had missed the signature-scope issue.

Laundering Analysis

The stolen proceeds were bridged out of GalaChain and traced across four chains. Gala filed an FBI IC3 complaint and sent freeze requests to exchanges and bridge operators.

Sources

Related Hacks

Back to Browse