Gala Games Token Exploit - May 20, 2024
Overview
On May 20, 2024, Blockchain Game Partners Inc. experienced a security breach involving a third-party contractor that led to the unauthorized minting of 5 billion $GALA tokens.
Details of the Exploit
A malicious actor compromised the private key of an address with a minter role for the Ethereum side of the $GALA platform, minting 5 billion tokens. The attacker minted 5 billion new GALA tokens worth approximately $200 million and then sold 600 million of these newly minted tokens on the decentralized exchange Uniswap.
Financial Impact
Gala Games experienced a significant security breach that resulted in the unauthorized sale of 600 million GALA tokens, valued at $23 million. Gala Games recovered approximately $22 million in Ether following the exploit.
Response and Recovery
Gala activated their new GalaChain's blocklist protocol, successfully freezing 4.4 billion of the 5 billion newly minted GALA tokens within 45 minutes. CEO Eric Schiermeyer admitted the company "messed up our internal controls" and stated "this shouldn't have happened, and we are taking steps to ensure it doesn't happen again."
The company is working closely with the FBI, the U.S. Justice Department, and international authorities to investigate the incident and apprehend those responsible.
Sources