GalaChain disclosed that an attacker exploited a gap between signature verification and replay protection to steal approximately 2 billion GALA, worth $3 million, along with dozens of other tokens on August 18. The hacker had harvested 74 reusable signatures from failed transactions over a period of up to 55 days, then targeted 59 account-token combinations by executing 1,066 submissions at a median interval of 4.5 seconds, draining 56 accounts on the first attempt. The first unauthorized transfer occurred at 02:21:54 UTC and the bridge was paused approximately two hours and 47 minutes later at 05:09:19 UTC. Gala Games patched the flaws after pausing the bridge and filed a complaint with the FBI’s Internet Crime Complaint Center while tracking proceeds across four chains.
Source: Read the original article

