GAMEE Hack

Reported token exposure $16.4M
Polygon
Repository credential exposure

What happened

In January 2024, GAMEE lost control of its Polygon deployer key after an attacker accessed an old repository in its GitLab environment. Halborn reported that approximately 600 million GMEE tokens were transferred out. Published dollar estimates differ, so token outflow should not be confused with realized sale proceeds.

Technical root cause

A deployer private key remained in an accessible historical repository. Compromise of the development environment therefore exposed authority over the token contracts.

How it happened

  1. Unauthorized access to GAMEE’s GitLab environment exposed an older repository containing the Polygon deployer private key.
  2. Control of that key enabled transfers of GMEE tokens to attacker-controlled wallets.
  3. GAMEE paused its Polygon-Ethereum bridge and moved control of affected contracts to a new address.
  4. The team patched the GitLab weakness and announced further security measures.

Protocol details

Classification Infrastructure / Key Compromise
Protocol Type Exploit/Access control
Affected asset / contract GMEE
Implementation language Solidity
Protocol links Website @GAMEEToken

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.