GANA Payment Hack
What happened
On 20 November 2025, GANA Payment's BNB Chain staking system was drained for about $3.1 million after an attacker gained control of privileged contract administration. Forensic reporting says the attacker increased the gana_Computility reward rate, bypassed the contract's EOA-only unstake gate using EIP-7702 transactions, and withdrew inflated GANA rewards before proceeds were moved through BSC and Ethereum mixers.
A single privileged authority could change reward-rate parameters, while an EOA-only tx.origin check was not a durable authorization boundary under EIP-7702 delegation. Reward-rate changes and high-value withdrawals require constrained permissions, multisig control, delays, and monitoring.
How it happened
- The available chain evidence supports a privileged-key takeover, but cannot distinguish a stolen key from misuse by its holder.
- With administrative control, the attacker altered reward-rate parameters, then used an EIP-7702 delegated transaction to pass the contract's msg.sender == tx.origin gate and call unstake.
- The inflated reward rate made the withdrawal path drainable.
- This was not a confirmed phishing or social-engineering incident, so those labels are removed.
- The response should focus on the actual security boundary: one powerful admin credential and an authorization check that did not remain safe under delegated EOA execution.
Protocol details
Evidence
- report Report theblock.co
- report The Block: GANA Payment exploit report theblock.co
- analysis Website reference t.me
- analysis DeFiLlama defillama.com
- analysis Hacken: GANA Payment incident analysis hacken.io
- analysis Halborn: GANA Payment hack explained halborn.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.