Hacker Turned 55 Days of Failed Transactions Into a $3 Million Master Key
GalaChain's August exploit wasn't a hack in the traditional sense. An attacker spent 55 days harvesting signatures from failed transactions, then used them as a reusable master key to drain roughly $3 million in GALA and dozens of other tokens. Multiple audits missed it.
Most exploits take minutes. This one took 55 days of setup, and the attacker didn't even have to work for it. GalaChain's August exploiter collected signatures from failed transactions, then walked through the front door with them and drained about 2 billion GALA, worth roughly $3 million, along with dozens of other tokens.
The 55-Day Setup
Gala Games says it shut the exploit down within 45 minutes and identified the culprit. That's quick. It's also 44 minutes too late when the damage is already signed and bridged out.
Here's the part that should scare you. The attacker didn't break anything. He collected. Every reverted transaction on GalaChain over that 55-day window spat out a signature, and those signatures piled up like spare keys nobody bothered to shred. Then he reused them as authorization.
Signed intent that should've expired was still valid. Multiple audits missed it.
And that's the real story here. Audits look at code paths. They don't always look at state that outlives a failed transaction. Who checks whether a signature from a reverted tx should still mean anything 40 days later? Nobody, apparently.
What Actually Broke
The ledger timestamps tell the story. Signed intents accumulated over 55 days. The SDK let them. The bridge accepted them. That's a three-layer failure, and the bridge was the last one holding the door open.
Anon, let me explain. The chain just records whatever you let it record. And for 55 days, this chain recorded a master key growing in public view.
The impact runs past $3 million. GALA holders felt the drain directly. But every chain running the same signed-intent pattern should be sweating right now. If your bridge trusts a signature without re-checking it at execution time, you're running the same setup.
The patches confirm Gala knew. SDK updates shipped to add automatic checks before funds reach a bridge. That's the fix. It should've been there on day one.
What Comes Next
Watch the SDK patch rollout. If it's live across GalaChain tooling by early fall, the attack surface closes. If partners lag on upgrading, the same door stays cracked.
More importantly, watch for copycats. Fifty-five days of harvested signatures isn't a one-off. It's a template. Any chain sitting on unexpired reverted-tx signatures is a target, and attackers now have a working playbook.
The fix is boring. Signed intent needs automatic validation at execution, not just at signing. Bridges need to treat every message like it's fresh. And audits need to check state lifetime, not just code paths.
I've been saying this for weeks. Security teams audit what you write. Attackers exploit what you keep.
The $3 million is gone. Gala's 45-minute response saved whatever was left. But the lesson isn't about speed. It's about expiration. Real talk: if your protocol doesn't know when a signature dies, neither does your attacker. That's the whole problem.
Check your reverted transactions. They might still be live.