GalaChain exploit turns failed transactions into $3M drain as blockchain malware surges 440%

1 hour ago 2 sources negative

Key takeaways:

  • GALA's $3M replay exploit exposes audit gaps, pressuring trust in cross-chain bridge security.
  • Chainalysis reports 440% malware rise across TRON, Aptos, BNB Chain, demanding stricter wallet monitoring.
  • Watch GALA bridge freezes and BTC dead-drops as state actors shift multi-chain stealth.

GalaChain’s August exploit turned failed transactions into reusable authorization, exposing a security flaw that had survived multiple audits. The blockchain developed by Gala Games said the attacker used historical signatures from unsuccessful transactions to drain about 2 billion GALA, worth around $3 million, and dozens of other tokens from nine wallets on Aug. 18. A postmortem published on Sept. 14 depicts an operation prepared before the first unauthorized transfer, with mapped balances, automated submissions, and weaknesses in both signature verification and replay protection.

The attacker arrived with 74 replayable signatures gathered from failed transactions stretching back as far as 55 days. Of 59 account-token combinations targeted, 56 were drained for their exact balance on the first attempt. The four largest GALA positions were taken in descending order within 18 seconds. In total, 1,066 submissions were recorded at a median interval of 4.5 seconds, and 73.9% arrived exactly one block apart. The issue stemmed from how GalaChain handled EIP-712 typed-data verification: before the patch, the verifier accepted type definitions supplied with the request rather than deriving them from the operation being called. One on-chain example shows a TransferToken call processing about 1.64 billion GALA even though the EIP-712 structure supplied for verification described an AddLiquidity operation. A separate replay weakness meant transaction keys could roll back when a transaction failed, leaving the signed payload public and reusable. Gala said 57 of the 60 historical source transactions contained at least one failed inner operation.

Audits missed the interaction between safeguards. Gala said the relevant logic was examined during a CertiK engagement in late 2025 and a Hashlock SDK review in January, but neither identified the signature-scope issue. After the attack, Gala patched both flaws, added per-identity rate limits, behavioral monitoring for high-value accounts, and additional review for bridge withdrawals above certain thresholds. The first verified unauthorized transfer occurred at 02:21:54 UTC, and the bridge was paused at 05:09:19 UTC, about two hours and 47 minutes later. Gala has filed a complaint with the FBI’s Internet Crime Complaint Center and sent preservation and freeze requests as it tracks proceeds across four chains.

Separately, Chainalysis reported that blockchain malware, or instructions hidden inside public-blockchain transactions, rose about 440% in under a year. Daily malicious on-chain writes climbed from about two to eleven, with state-linked groups from North Korea and Iran now producing most of the activity. The firm ties the surge to mid-2025 Chinese open-source AI models with no guardrails against generating malicious code. By the second quarter of 2026, state-linked groups accounted for 51% of attributed blockchain dead-drop writes, compared with 49% for criminal groups.

Chainalysis connected previously unattributed activity across Tron, Aptos, and BNB Smart Chain to North Korea’s UNC5342. Tron served as the primary route and Aptos as a fallback, while an encrypted BNB Smart Chain transaction held server addresses. Disrupting the operation would require action across all three chains simultaneously. Suspected Iranian operators used a variation by writing tiny Bitcoin payments to an address historically tied to Satoshi Nakamoto and hiding routing data inside them. The report underscores a broader shift: TRM Labs attributed about 76% of crypto hack value in early 2026 to North Korea, and CrowdStrike estimated state-affiliated hackers drove more than $2 billion in crypto losses in 2025. Open-weight AI models have erased the skill barrier that once kept such attacks rare, creating what Chainalysis calls a machine-speed defense problem for blockchain operators.

Previously on the topic:
Sep 15, 2026, 4:49 p.m.
MEV Bot Front-Runs $7.8M rsETH Exploit on Ethereum
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.