GANA Payment Hack

Reported loss $3.1M
BNB Chain
Privileged Key Compromise

What happened

On 20 November 2025, GANA Payment's BNB Chain staking system was drained for about $3.1 million after an attacker gained control of privileged contract administration. Forensic reporting says the attacker increased the gana_Computility reward rate, bypassed the contract's EOA-only unstake gate using EIP-7702 transactions, and withdrew inflated GANA rewards before proceeds were moved through BSC and Ethereum mixers.

Technical root cause

A single privileged authority could change reward-rate parameters, while an EOA-only tx.origin check was not a durable authorization boundary under EIP-7702 delegation. Reward-rate changes and high-value withdrawals require constrained permissions, multisig control, delays, and monitoring.

How it happened

  1. The available chain evidence supports a privileged-key takeover, but cannot distinguish a stolen key from misuse by its holder.
  2. With administrative control, the attacker altered reward-rate parameters, then used an EIP-7702 delegated transaction to pass the contract's msg.sender == tx.origin gate and call unstake.
  3. The inflated reward rate made the withdrawal path drainable.
  4. This was not a confirmed phishing or social-engineering incident, so those labels are removed.
  5. The response should focus on the actual security boundary: one powerful admin credential and an authorization check that did not remain safe under delegated EOA execution.

Protocol details

Classification Infrastructure / Access Control
Protocol Type Exploit/Other
Implementation language Solidity
Protocol links Website @GANA_PayFi

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.