The post Gala quietly changes bridge keys after users flag ‘unauthorized’ withdrawals appeared on BitcoinEthereumNews.com. Concerned members of the Gala Games community have identified a series of “unauthorized” withdrawals from the GalaChain bridge. Spanning almost a month, between October 13 and November 10, the transfers total 140 million GALA, worth approximately $1.5 million at the time. Given Gala’s chequered past, community members had been “keeping a close eye” on bridging activity. Regular daily withdrawals of exactly 5 million GALA tokens on Ethereum caught their attention, and when attempting to verify their source, corresponding deposit transactions were missing on GalaScan. The group, a representative of which reached out to Protos, flagged the transactions to Gala via Discord on November 6, “tagging the CEO and community moderator.” The group claims that it wasn’t provided with an explanation, but was instead told that the missing bridge transactions may be due to block explorer GalaScan being a “work in progress.” It wasn’t until four days later that Gala took action. During this time, a further 25 million GALA tokens (approximately $250,000) were withdrawn from the Ethereum bridge. Read more: Re7 Labs threatens whistleblower over exposure to yield vault collapse ‘Unauthorized’ withdrawals total 140M GALA Beginning on October 13, 26 withdrawals of 5 million GALA each were made from the bridge almost every day. The recipients were a series of Ethereum addresses which then swapped the tokens for ETH. A further 10 million GALA was then withdrawn on November 10, just hours before the bridge was paused. The bridge’s transaction history downloaded from GalaScan is missing matching bridge transactions on the GalaChain side. Taking the first suspicious withdrawal as an example, which occurred on October 13 at 15:55 UTC, the surrounding transactions of 18,800 and 24,000 GALA are present in the GalaScan data. The 5 million GALA minted on Ethereum, however, has no corresponding deposit transaction on GalaChain. Transactions of… The post Gala quietly changes bridge keys after users flag ‘unauthorized’ withdrawals appeared on BitcoinEthereumNews.com. Concerned members of the Gala Games community have identified a series of “unauthorized” withdrawals from the GalaChain bridge. Spanning almost a month, between October 13 and November 10, the transfers total 140 million GALA, worth approximately $1.5 million at the time. Given Gala’s chequered past, community members had been “keeping a close eye” on bridging activity. Regular daily withdrawals of exactly 5 million GALA tokens on Ethereum caught their attention, and when attempting to verify their source, corresponding deposit transactions were missing on GalaScan. The group, a representative of which reached out to Protos, flagged the transactions to Gala via Discord on November 6, “tagging the CEO and community moderator.” The group claims that it wasn’t provided with an explanation, but was instead told that the missing bridge transactions may be due to block explorer GalaScan being a “work in progress.” It wasn’t until four days later that Gala took action. During this time, a further 25 million GALA tokens (approximately $250,000) were withdrawn from the Ethereum bridge. Read more: Re7 Labs threatens whistleblower over exposure to yield vault collapse ‘Unauthorized’ withdrawals total 140M GALA Beginning on October 13, 26 withdrawals of 5 million GALA each were made from the bridge almost every day. The recipients were a series of Ethereum addresses which then swapped the tokens for ETH. A further 10 million GALA was then withdrawn on November 10, just hours before the bridge was paused. The bridge’s transaction history downloaded from GalaScan is missing matching bridge transactions on the GalaChain side. Taking the first suspicious withdrawal as an example, which occurred on October 13 at 15:55 UTC, the surrounding transactions of 18,800 and 24,000 GALA are present in the GalaScan data. The 5 million GALA minted on Ethereum, however, has no corresponding deposit transaction on GalaChain. Transactions of…

Gala quietly changes bridge keys after users flag ‘unauthorized’ withdrawals

2025/12/06 03:17

Concerned members of the Gala Games community have identified a series of “unauthorized” withdrawals from the GalaChain bridge.

Spanning almost a month, between October 13 and November 10, the transfers total 140 million GALA, worth approximately $1.5 million at the time.

Given Gala’s chequered past, community members had been “keeping a close eye” on bridging activity.

Regular daily withdrawals of exactly 5 million GALA tokens on Ethereum caught their attention, and when attempting to verify their source, corresponding deposit transactions were missing on GalaScan.

The group, a representative of which reached out to Protos, flagged the transactions to Gala via Discord on November 6, “tagging the CEO and community moderator.”

The group claims that it wasn’t provided with an explanation, but was instead told that the missing bridge transactions may be due to block explorer GalaScan being a “work in progress.”

It wasn’t until four days later that Gala took action. During this time, a further 25 million GALA tokens (approximately $250,000) were withdrawn from the Ethereum bridge.

Read more: Re7 Labs threatens whistleblower over exposure to yield vault collapse

‘Unauthorized’ withdrawals total 140M GALA

Beginning on October 13, 26 withdrawals of 5 million GALA each were made from the bridge almost every day. The recipients were a series of Ethereum addresses which then swapped the tokens for ETH.

A further 10 million GALA was then withdrawn on November 10, just hours before the bridge was paused.

The bridge’s transaction history downloaded from GalaScan is missing matching bridge transactions on the GalaChain side.

Taking the first suspicious withdrawal as an example, which occurred on October 13 at 15:55 UTC, the surrounding transactions of 18,800 and 24,000 GALA are present in the GalaScan data.

The 5 million GALA minted on Ethereum, however, has no corresponding deposit transaction on GalaChain.

Transactions of 18,800 and 24,000 GALA are present in the GalaScan data…However, the 5 million GALA minted on Ethereum has no corresponding transaction on GalaChain.

The same pattern was repeated across subsequent daily withdrawals of 5 million GALA each until the bridge was paused.

The group believes these one-sided bridge withdrawals “indicate a likely compromise of privileged access.”

This theory appears supported by the team’s decision to execute a change authorities transaction shortly after pausing the bridge on November 10.

Gala’s response

The group claims that Gala hasn’t publicly disclosed the incident, nor confirmed the cause. Discord announcements about pausing the Ethereum and Solana bridges simply cite “community feedback and concerns.”

Protos has reached out to Gala, but hasn’t heard back before publication of this article. It will be updated in the event we receive a reply.

The incident bears resemblance to a May 2024 hack in which 600 million GALA was sold for $21 million. Gala’s CEO Eric Schiermeyer stated at the time, “We messed up our internal controls… This shouldn’t have happened and we are taking steps to ensure it doesn’t ever again.”

Read more: DeFi karma: Garden hacked for $11M after bridging Lazarus’ loot

The group notes the “similarity between the two incidents, both involving privileged credential misuse, delayed detection, and emergency authority rotation.”

It argues that the pattern of behaviour “suggests ongoing risks to Gala’s infrastructure and token holders.”

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/gala-quietly-changes-bridge-keys-after-users-flag-unauthorized-withdrawals/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

“Bitcoin After Dark” ETF targets gains while the world sleeps

“Bitcoin After Dark” ETF targets gains while the world sleeps

The post “Bitcoin After Dark” ETF targets gains while the world sleeps appeared on BitcoinEthereumNews.com. A proposed exchange-traded fund is built to chase Bitcoin’s price action while the U.S. market is shut on Wall Street. The product is named the Nicholas Bitcoin and Treasuries AfterDark ETF, according to a filing dated December 9 was sent to the Securities and Exchange Commission. The fund opens Bitcoin-linked trades “after the U.S. financial markets close” and exits those positions “shortly after the next day’s open.” Trading is locked into the overnight window, and of course the fund will not hold Bitcoin directly. At least 80% of assets would be used on Bitcoin futures, exchange-traded products, other Bitcoin ETFs, and options tied to those ETFs and ETPs. The rest can sit in Treasuries. The filing said that the goal is to use price action that forms when the equity market is offline. Exposure stays inside listed products only. No spot tokens, no on-chain custody, and all positions reset each morning after the open. After-hours trading drives ETF flows Bespoke Investment Group tracked a test using the iShares Bitcoin Trust ETF (IBIT), and reported that “buying at the U.S. market close and selling at the next open since January 2024 produced a 222% gain.” The same test flipped to daytime only showed “a 40.5% loss from buying at the open and selling at the close.” That gap is the return spread the AfterDark ETF is built to target. Source: Bespoke Bitcoin last traded at $92,320, down nearly 1% on the day, down about 12% over the past month, and little changed since the start of the year. ETF filings across crypto keep expanding. Products tied to Aptos, Sui, Bonk, and Dogecoin are now in the pipeline. The pace picked up after President Donald Trump pushed for softer rules at the SEC and the Commodity Futures Trading Commission. After that push,…
Share
BitcoinEthereumNews2025/12/11 07:46
‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies

‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies

The post ‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies appeared on BitcoinEthereumNews.com. Topline Critics have hailed Paul Thomas Anderson’s “One Battle After Another,” starring Leonardo DiCaprio, as a “masterpiece,” indicating potential Academy Awards success as it boasts near-perfect scores on review aggregators Metacritic and Rotten Tomatoes based on early reviews. Leonardo DiCaprio stars in “One Battle After Another,” which opens in theaters next week. (Photo by Jeff Spicer/Getty Images for Warner Bros. Pictures) Getty Images for Warner Bros. Pictures Key Facts “One Battle After Another” boasts a nearly perfect 97 out of a possible 100 on Metacritic based on its first 31 reviews, making it the highest-rated movie of this decade on Metacritic’s best movies of all time list. The movie also has a 96% score on Rotten Tomatoes based on the first 56 reviews, with only two reviews considered “rotten,” or negative. The Associated Press hailed the movie as “an American masterpiece,” noting the movie touches on topical political themes and depicts a society where “gun violence, white power and immigrant deportations recur in an ongoing dance, both farcical and tragic.” The movie stars DiCaprio as an ex-revolutionary who reunites with former accomplices to rescue his 16-year-old daughter when she goes missing, and Anderson has said the movie was inspired by the 1990 novel, “Vineland.” Most critics have described the movie as an action thriller with notable chase scenes, which jumps in time from DiCaprio’s character’s early days with fictional revolutionary group, the French 75, to about 15 years later, when he is pursued by foe and military leader Captain Steven Lockjaw, played by Sean Penn. The Warner Bros.-produced film was made on a big budget, estimated to be between $130 million and $175 million, and co-stars Penn, Benicio del Toro, Regina Hall and Teyana Taylor. When Will ‘one Battle After Another’ Open In Theaters And Streaming? The move opens in…
Share
BitcoinEthereumNews2025/09/18 07:35