GalaChain Hack Recycles Failed Transaction Signatures, Stealing $3M in GALA

A security breach on GalaChain has resulted in the theft of approximately 20 billion GALA (worth $3 million) and dozens of other tokens, according to CryptoSlayer. Hackers collected and reused 74 valid signatures from 60 failed transactions over a 55-day period. The vulnerability arose because when transactions ultimately failed, their unique transaction keys were rolled back, leaving the same signatures publicly available for reuse. GalaChain has since paused its bridge, modified how type information is extracted directly from invoked operations, and completed a patch that permanently disables replay keys for failed transactions.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 갈라체인 실패한 트랜잭션 서명 재활용...$300만 GALA 탈취