Galxe Hack

Reported loss $270K
Ethereum
DNS Hijack

What happened

On 6 October 2023 an attacker took over the Galxe.com domain and sent visitors to a phishing copy of the site. The attacker posed as an authorized Galxe team member, gave the domain registrar Dynadot fake documents, and got the account's login credentials reset. With that access they changed the domain's name servers. Visitors to the fake site saw a pop-up asking them to approve a transaction, and approving it drained their wallets. Galxe's smart contracts and back end were not affected.

Galxe estimated that about 1,120 users lost around $270,000. Galxe got the domain back within about three and a half hours but kept the site offline until the evening while DNS changes spread, and wallets such as MetaMask and Coinbase Wallet temporarily flagged Galxe.com as a phishing site. Galxe later announced $396,000 in refunds to more than 980 affected users, covering their losses plus an extra 10% from its treasury, paid in USDT on Polygon.

How it happened

  1. At 04:00 PDT on 6 October the attacker posed as an authorized Galxe team member and gave Dynadot support forged documents. Dynadot reset the credentials and gave the attacker temporary access to the Galxe.com account.
  2. At 06:02 PDT the attacker changed the domain's name-server (NS) records, so visitors were gradually sent to a phishing site as the DNS change spread.
  3. The phishing site asked users to approve a transaction that drained their wallets. The first theft came at 06:45 PDT (Ethereum tx 0xa3fdd20ad84f87a536b359bc5b0364c2b8978f77001577f99f8f36266b1db72e). Galxe flagged the drainer contracts 0x0000eaab14253e1421aef4F48eE539F2653C0000 and 0x00008c6Dc619b0ea53dd8d02B58Bb726aFc40000.
  4. Galxe detected the attack at 07:20 PDT, shut its API gateway and revoked access tokens, and got the domain back at 09:23 PDT. Users who signed transactions up to about 11:23 PDT, while the DNS change was still spreading, were still at risk.

Protocol details

Classification Frontend & Infrastructure
Protocol Type Other

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.