Gala Hack
Incident Overview
Gala was exploited on the Binance chain. The attacker used a privileged function to mint 55,628,400,000 $GALA tokens to an EOA address.
Gala is a metaverse including Gala Games, Gala Music, and Gala Films. The project's token smart contract on the Binance chain was used to mint large an amount of $GALA tokens. The total worth of the newly minted tokens reached 1,156,000,000 $USD. The attacker managed to swap the part of tokens for 4,540,655 $USD worth of $BNB. All the stolen funds remain at the initial EOA address at the moment. Funds on the Ethereum chain and collateral of the bridges were not affected.
The pNetwork team calls for calm, claiming that the incident was just a drain of the liquidity pool to safeguard potential vulnerabilities. And there was no hack or rug.
Attacker address:
https://bscscan.com/address/0xe8710dad…9bd20f
Wallet holding the funds:
https://bscscan.com/address/0x6891A233…44e8C1
Malicious transactions:
https://bscscan.com/tx/0x4b239b0a…515c2e
https://bscscan.com/tx/0x439aa6f5…fe616d
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Gala, these are the critical security checks that could have prevented this incident (November 2022).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
-
01
Source 1 https://gala.com/
Learn to Prevent the Next Gala
The Gala hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.