Gala Hack

TOTAL LOST $21.8M
High Access Control Attacks Ethereum

What happened

On May 20, 2024, an attacker used a compromised privileged GALA minter key on Ethereum to mint 5 billion GALA tokens. Gala blocklisted the attacker within roughly 45 minutes, limiting the tokens that could be liquidated.

Technical Root Cause

A private key for an Ethereum address holding the GALA minter role was compromised. The token contract itself was not breached: the incident arose from inadequate control of a privileged key, which allowed authorized mint functionality to be abused.

Case & protocol details

Classification Private Key Compromise / Privileged Access Abuse
Smart Contract Language Solidity
Official Website gala.com/
Protocol Twitter/X @GoGalaGames

Attack Timeline

The attacker controlled an address with permission to mint GALA and used that legitimate privilege to mint 5 billion tokens. They transferred the tokens to a new wallet and swapped roughly 592 to 600 million GALA for ETH. Gala then blocklisted the exploiter, froze the remaining minted balance, and later burned the unauthorized token supply through a governance-approved process.

The incident's defensible loss measure is the realized proceeds, not the paper value of all 5 billion minted tokens. Gala reported that the ETH proceeds were returned and used for buybacks and burns, but the sources differ slightly on the returned ETH amount, so this record does not present a precise recovered-USD figure.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.