
Hacker used signatures from failed transactions to drain $3 million from GalaChain
- —About 2 billion GALA (~$3 million) and other tokens drained from 9 wallets
- —Attacker used 74 signatures from failed transactions over 55 days
- —56 of 59 account-token pairs were zeroed on the first attempt, 1,066 sends at 4.5-second intervals
- —Gala bridge was halted 2 hours 47 minutes after the first theft
Why it matters: The incident shows audits can miss the combination of signature verification and replay protection, and manual response cannot keep up with automated attacks.
Source: CryptoSlate