Dormant Admin Key Lets Someone Mint $216M in GALA Before Blacklist Kicks In
A compromised admin account on the GALA token contract allowed an attacker to mint 5 billion new GALA tokens — worth roughly $216 million on paper — and rapidly sell off 592 million of them for about $21.8 million in ETH before Gala Games managed to blacklist the address.
The activity was first flagged by a user known as Devops199fan, who noticed the minted tokens being dumped in batches of 100 ETH through 0x Protocol. Gala Games confirmed the exploit a few hours later, describing it as an isolated incident and saying it was cooperating with law enforcement to identify those responsible. Once the team caught the activity, it used the blocklist function built into its contract to freeze the attacker's address and limit further damage — a capability Gala had added to its V2 contract roughly a year earlier, which turned out to be timely.

A Gala representative going by Benefactor stated that the Ethereum contract for GALA itself remained secure, protected by a multi-sig wallet that was never compromised, and said the team believed it had identified the culprit and was working with the FBI, DOJ, and international authorities.
The timing was unfortunate for the token: just before the exploit, Bloomberg Intelligence analyst Eric Balchunas had raised his odds of SEC approval for a spot Ethereum ETF to 75% from 25%, and the broader market rallied hard on the news. GALA moved in the opposite direction, initially dropping around 20% as investors reacted to the breach, even as most other tokens climbed on the ETF optimism. The price recovered somewhat in the following hours, but the token never managed to participate in the broader rally that day.
The day after the incident, the funds were sent back by the exploiter, leaving open the question of who was actually behind the attack.
Sourcing for this account includes The Vulture Trade, Gala Games, Hacken, Benefactor, The Block, Crypto Times, and Tay.
Anatomy of the breach
At the root of the near-$216 million incident was an access-control failure: the attacker allegedly gained unauthorized control of an all-powerful admin account tied to the GALA token contract.
Per Hacken's breakdown of the attack, it fell into the "Access Control" category — a dormant MINTER account that had gone unused for 180 days was compromised, then used to mint 5 billion GALA tokens to a newly created address that has since been dubbed "Gala Game Exploiter."
The sequence of on-chain events:
- Attack transaction: 0xa6d90abe17d17743a9cecab84bcefb0fd0bbfa0c61bba60fd2f680b0a2f077fe
- The compromised MINTER account then sent 2 ETH to the exploiter address, apparently to cover gas for subsequent transactions.
- The exploiter began converting the newly minted GALA into ETH, executing swaps in chunks up to 100 ETH each. GALA-for-ETH swap activity: 0xe2ca471124b124831e231fb835778840ad100f97
- Roughly 2 hours and 16 minutes after the minting began, Gala's admins blocked the exploiter's account, cutting off further transfers. Blocked account reference: 0x15129c219a94e24d40541e622757973c0664338f117ff6c4b68d845854b167b9
- The exploiter then sent all the stolen ETH back to the original Minter account. Minter account reference: 0x273c6b54fea8b0d616fb3270698dd4387ec3fefc7b0e290330b4019c35a984b1
- Finally, the ETH moved from the Minter account to a new externally owned account, likely controlled by the Gala team to secure the recovered funds. Externally owned account reference: 0x16a96053f8e6382a32caa1a4461bf8c500d788019685b803ad3a3194fa5dd290
A suspicious backdrop
Three days prior to the exploit, Jason Brink — known as Bitbender — announced that he was stepping down from his role as President of Blockchain at Gala to become an unpaid advisor, adding that several colleagues would also be leaving to launch an external venture called LFG ("Let's Fight Giants"). The proximity of that announcement to the exploit has fueled speculation, especially given Gala's history.
In early 2021, Gala Games lost $130 million after roughly 8.65 billion GALA tokens were stolen, an episode that led co-founder Eric Schiermeyer to sue fellow co-founder Wright Thurston, alleging his involvement in the theft. Thurston countersued, claiming Schiermeyer misused company funds for personal purposes, as The Block previously reported. Separately, the SEC sued Thurston and another of his companies in March 2023 over an alleged $18 million in unregistered securities sales tied to GREEN, a token connected to a proposed decentralized power-grid project.

In November 2022, Gala had to calm its community after unfounded rumors of a multibillion-dollar rug pull or hack sent the token briefly crashing 25.6%. That panic followed reports that a single wallet had appeared to mint over $2 billion in GALA out of nowhere — a pattern that echoes uncomfortably with the latest incident.
Between the earlier unexplained mints and the $130 million insider dispute, this newest $216 million episode has drawn suspicion that it may involve some form of internal involvement rather than a purely external attacker.
The shadow of these earlier controversies — insider disputes, litigation, and prior mint anomalies — continues to color how the community reads this latest event, compounded by the departure of senior figures just days beforehand.
The day after the exploit, DWF Labs announced it had purchased 28 million GALA tokens (about $1.2 million) to help stabilize the token's price and signal continued support.
Whether this incident prompts lasting scrutiny of Gala Games or simply fades from memory as the market moves on remains an open question — one that will depend on how transparently the company handles what comes next.
Get new scam files the moment we publish them — usually 2–3 emails a week.