Cryptocurrency [loss] $21M+

Thief wallet

2024-05-20 [vendor] Gala Games [chain] ethereum
Primary Source ↗
Financial Loss $21.5M (21,451,000 USD)
Blockchain(s) Ethereum

Incident Details

Someone was able to mint 5 billion $GALA tokens, the native token of the Gala Games blockchain gaming project. The tokens would be notionally worth around $200 million based on their paper value, although such a massive amount wouldn’t be sellable without impacting the token price. Furthermore, the Gala Games team was able to add the attacker’s address to a blocklist shortly after the theft a few hours after the attack began, preventing them from swapping more of the tokens.Altogether, the attacker was able to swap around $21 million of the GALA tokens into ETH before the address was frozen.The attacker was able to perform the exploit because they had access to a wallet with admin access to the Gala Games smart contract. It’s not clear if the attacker is a rogue employee, or if an admin wallet was compromised.As of writing, Gala Games has not publicly acknowledged the attack.

Total loss estimated at $21,451,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Gala Games

Timeline

  1. 2024-05-20 Breach occurred
  2. 2024-05-20 Publicly disclosed