GalaChain, the blockchain platform of Gala Games, released a post-mortem report on September 14, revealing that hackers exploited failed transaction signatures accumulated over 55 days to create a "master key." On August 18, approximately 2 billion GALA (worth about $3 million) and dozens of other tokens were stolen from nine wallets. The vulnerability stemmed from flaws in the EIP-712 typed data validation and replay protection mechanisms, which allowed attackers to use a signature intended for one operation to execute another, and enabled the reuse of signatures from failed transactions. Gala has since paused its cross-chain bridge services and patched these vulnerabilities during the attack period.