• bitcoinBitcoin (BTC) $ 69,152.00
  • ethereumEthereum (ETH) $ 2,025.26
  • tetherTether (USDT) $ 0.999512
  • xrpXRP (XRP) $ 1.41
  • bnbBNB (BNB) $ 622.74
  • usd-coinUSDC (USDC) $ 0.999825
  • solanaSolana (SOL) $ 83.44
  • jusdJUSD (JUSD) $ 0.999053
  • tronTRON (TRX) $ 0.277981
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • dogecoinDogecoin (DOGE) $ 0.092966
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • whitebitWhiteBIT Coin (WBT) $ 51.94
  • bitcoin-cashBitcoin Cash (BCH) $ 525.17
  • cardanoCardano (ADA) $ 0.262527
  • usdsUSDS (USDS) $ 0.999601
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • leo-tokenLEO Token (LEO) $ 8.72
  • hyperliquidHyperliquid (HYPE) $ 29.15
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 348.65
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • ethena-usdeEthena USDe (USDE) $ 0.998993
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.168932
  • chainlinkChainlink (LINK) $ 8.57
  • usd1-wlfiUSD1 (USD1) $ 0.999946
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.158790
  • daiDai (DAI) $ 0.999769
  • susdssUSDS (SUSDS) $ 1.08
  • litecoinLitecoin (LTC) $ 53.41
  • hedera-hashgraphHedera (HBAR) $ 0.090908
  • paypal-usdPayPal USD (PYUSD) $ 0.999400
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • zcashZcash (ZEC) $ 234.67
  • avalanche-2Avalanche (AVAX) $ 8.75
  • suiSui (SUI) $ 0.932840
  • wethWETH (WETH) $ 2,268.37
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.010140
  • the-open-networkToncoin (TON) $ 1.34
  • usdt0USDT0 (USDT0) $ 0.998824
  • crypto-com-chainCronos (CRO) $ 0.078010
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.107413
  • tether-goldTether Gold (XAUT) $ 5,008.84
  • memecoreMemeCore (M) $ 1.39
  • pax-goldPAX Gold (PAXG) $ 5,037.38
  • polkadotPolkadot (DOT) $ 1.29
  • uniswapUniswap (UNI) $ 3.37
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • mantleMantle (MNT) $ 0.631316
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • falcon-financeFalcon USD (USDF) $ 0.996874
  • bitget-tokenBitget Token (BGB) $ 2.42
  • aaveAave (AAVE) $ 109.75
  • aster-2Aster (ASTER) $ 0.656276
  • skySky (SKY) $ 0.068883
  • global-dollarGlobal Dollar (USDG) $ 0.999779
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • okbOKB (OKB) $ 74.96
  • pepePepe (PEPE) $ 0.000004
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • htx-daoHTX DAO (HTX) $ 0.000002
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • bittensorBittensor (TAO) $ 153.37
  • bfusdBFUSD (BFUSD) $ 0.999200
  • internet-computerInternet Computer (ICP) $ 2.39
  • ethereum-classicEthereum Classic (ETC) $ 8.34
  • nearNEAR Protocol (NEAR) $ 0.996491
  • pi-networkPi Network (PI) $ 0.137124
  • ondo-financeOndo (ONDO) $ 0.248519
  • gatechain-tokenGate (GT) $ 6.96
  • pump-funPump.fun (PUMP) $ 0.001924
  • myx-financeMYX Finance (MYX) $ 5.63
  • kucoin-sharesKuCoin (KCS) $ 8.11
  • worldcoin-wldWorldcoin (WLD) $ 0.379529
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.99
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • usddUSDD (USDD) $ 0.999833
  • hash-2Provenance Blockchain (HASH) $ 0.017798
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.091597
  • cosmosCosmos Hub (ATOM) $ 1.93
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • ethenaEthena (ENA) $ 0.114871
  • usdtbUSDtb (USDTB) $ 0.998579
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • nexoNEXO (NEXO) $ 0.834284
  • kaspaKaspa (KAS) $ 0.031117
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • flare-networksFlare (FLR) $ 0.009691
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • algorandAlgorand (ALGO) $ 0.091672
  • midnight-3Midnight (NIGHT) $ 0.048456
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • aptosAptos (APT) $ 0.995611
  • official-trumpOfficial Trump (TRUMP) $ 3.25
  • wbnbWrapped BNB (WBNB) $ 759.61
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.25
  • xdce-crowd-saleXDC Network (XDC) $ 0.035260
  • ousgOUSG (OUSG) $ 114.25
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • render-tokenRender (RENDER) $ 1.31
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • filecoinFilecoin (FIL) $ 0.901172
  • vechainVeChain (VET) $ 0.007709
  • arbitrumArbitrum (ARB) $ 0.110445
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • morphoMorpho (MORPHO) $ 1.14
  • beldexBeldex (BDX) $ 0.080825
  • usual-usdUsual USD (USD0) $ 0.998038
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.09
  • usdaiUSDai (USDAI) $ 0.999654
  • ghoGHO (GHO) $ 1.00
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • bonkBonk (BONK) $ 0.000006
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • a7a5A7A5 (A7A5) $ 0.012768
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • true-usdTrueUSD (TUSD) $ 0.998235
  • sei-networkSei (SEI) $ 0.072598
  • fasttokenFasttoken (FTN) $ 1.09
  • clbtcclBTC (CLBTC) $ 76,920.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.143097
  • euro-coinEURC (EURC) $ 1.19
  • blockstackStacks (STX) $ 0.256100
  • dashDash (DASH) $ 35.41
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.33
  • tezosTezos (XTZ) $ 0.400522
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • decredDecred (DCR) $ 24.01
  • layerzeroLayerZero (ZRO) $ 2.04
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • chilizChiliz (CHZ) $ 0.040100
  • stable-2​​Stable (STABLE) $ 0.022531
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • story-2Story (IP) $ 1.16
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998625
  • pippinpippin (PIPPIN) $ 0.392352
  • optimismOptimism (OP) $ 0.183631
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006169
  • kinesis-goldKinesis Gold (KAU) $ 162.31
  • justJUST (JST) $ 0.042566
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.566683
  • c8ntinuumc8ntinuum (CTM) $ 0.083966
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • lighterLighter (LIT) $ 1.45
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.158270
  • cocaCOCA (COCA) $ 1.30
  • kite-2Kite (KITE) $ 0.193879
  • riverRiver (RIVER) $ 17.93
  • curve-dao-tokenCurve DAO (CRV) $ 0.234414
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • bittorrentBitTorrent (BTT) $ 0.00000034
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • gnosisGnosis (GNO) $ 125.25
  • sun-tokenSun Token (SUN) $ 0.016747
  • syrupMaple Finance (SYRUP) $ 0.275116
  • kaiaKaia (KAIA) $ 0.054161
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • resolv-usrResolv USR (USR) $ 0.999175
  • apenftAINFT (NFT) $ 0.00000031
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • injective-protocolInjective (INJ) $ 3.06
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • ether-fiEther.fi (ETHFI) $ 0.435445
  • kinesis-silverKinesis Silver (KAG) $ 81.65
  • usxUSX (USX) $ 0.999360
  • crvusdcrvUSD (CRVUSD) $ 0.998271
  • flokiFLOKI (FLOKI) $ 0.000030
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • iotaIOTA (IOTA) $ 0.067383
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • lido-daoLido DAO (LDO) $ 0.340888
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • the-graphThe Graph (GRT) $ 0.026625
  • hastra-primePRIME (PRIME) $ 1.02
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • bitcoin-svBitcoin SV (BSV) $ 14.03
  • celestiaCelestia (TIA) $ 0.317460
  • aerodrome-financeAerodrome Finance (AERO) $ 0.304153
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • humanityHumanity (H) $ 0.153125
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • fraxLegacy Frax Dollar (FRAX) $ 0.992165
  • spx6900SPX6900 (SPX) $ 0.292900
  • jasmycoinJasmyCoin (JASMY) $ 0.005474
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • telcoinTelcoin (TEL) $ 0.002843
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • axie-infinityAxie Infinity (AXS) $ 1.61
  • olympusOlympus (OHM) $ 17.25
  • doublezeroDoubleZero (2Z) $ 0.075927
  • adi-tokenADI (ADI) $ 2.65
  • staked-aaveStaked Aave (STKAAVE) $ 126.65

Gala quietly changes bridge keys after users flag ‘unauthorized’ withdrawals

0 0


Concerned members of the Gala Games community have identified a series of “unauthorized” withdrawals from the GalaChain bridge.

Spanning almost a month, between October 13 and November 10, the transfers total 140 million GALA, worth approximately $1.5 million at the time.

Given Gala’s chequered past, community members had been “keeping a close eye” on bridging activity.

Regular daily withdrawals of exactly 5 million GALA tokens on Ethereum caught their attention, and when attempting to verify their source, corresponding deposit transactions were missing on GalaScan.

The group, a representative of which reached out to Protos, flagged the transactions to Gala via Discord on November 6, “tagging the CEO and community moderator.”

The group claims that it wasn’t provided with an explanation, but was instead told that the missing bridge transactions may be due to block explorer GalaScan being a “work in progress.”

It wasn’t until four days later that Gala took action. During this time, a further 25 million GALA tokens (approximately $250,000) were withdrawn from the Ethereum bridge.

Read more: Re7 Labs threatens whistleblower over exposure to yield vault collapse

‘Unauthorized’ withdrawals total 140M GALA

Beginning on October 13, 26 withdrawals of 5 million GALA each were made from the bridge almost every day. The recipients were a series of Ethereum addresses which then swapped the tokens for ETH.

A further 10 million GALA was then withdrawn on November 10, just hours before the bridge was paused.

The bridge’s transaction history downloaded from GalaScan is missing matching bridge transactions on the GalaChain side.

Taking the first suspicious withdrawal as an example, which occurred on October 13 at 15:55 UTC, the surrounding transactions of 18,800 and 24,000 GALA are present in the GalaScan data.

The 5 million GALA minted on Ethereum, however, has no corresponding deposit transaction on GalaChain.

Transactions of 18,800 and 24,000 GALA are present in the GalaScan data…

However, the 5 million GALA minted on Ethereum has no corresponding transaction on GalaChain.

The same pattern was repeated across subsequent daily withdrawals of 5 million GALA each until the bridge was paused.

The group believes these one-sided bridge withdrawals “indicate a likely compromise of privileged access.”

This theory appears supported by the team’s decision to execute a change authorities transaction shortly after pausing the bridge on November 10.

Gala’s response

The group claims that Gala hasn’t publicly disclosed the incident, nor confirmed the cause. Discord announcements about pausing the Ethereum and Solana bridges simply cite “community feedback and concerns.”

Protos has reached out to Gala, but hasn’t heard back before publication of this article. It will be updated in the event we receive a reply.

The incident bears resemblance to a May 2024 hack in which 600 million GALA was sold for $21 million. Gala’s CEO Eric Schiermeyer stated at the time, “We messed up our internal controls… This shouldn’t have happened and we are taking steps to ensure it doesn’t ever again.”

Read more: DeFi karma: Garden hacked for $11M after bridging Lazarus’ loot

The group notes the “similarity between the two incidents, both involving privileged credential misuse, delayed detection, and emergency authority rotation.”

It argues that the pattern of behaviour “suggests ongoing risks to Gala’s infrastructure and token holders.”



Source link

Leave A Reply

Your email address will not be published.