Gala Games CEO Says Unauthorized 5B GALA Mint Contained, Law Enforcement Contacted
CIE News ·
What Happened
On May 20, 2024, Web3 gaming platform Gala Games experienced an unauthorized mint of 5 billion GALA tokens. Gala Games CEO Eric Schiermeyer acknowledged the security incident, stating that internal controls failed and the affected contract functionality was frozen. Blockchain tracking and reports indicated an address swapped a portion of the tokens for ETH before remaining tokens were blacklisted.
Why It Matters
The incident demonstrates both the systemic risk posed by centralized administrative privileges within Web3 infrastructure and the efficacy of blacklist mechanisms during ongoing attacks. While intervention prevented further liquidation of the 5 billion tokens, the event has reignited industry discussions regarding smart contract centralization, operational key security, and the trade-offs between immutable protocols and admin-controlled safeguards in decentralized gaming ecosystems.
What We Know
Confirmed (via CEO Statement):
- Gala Games CEO Eric Schiermeyer publicly acknowledged the incident, stating that internal controls failed, the issue had been isolated, and law enforcement (including the FBI and DOJ) had been engaged.
Reported:
- An unauthorized wallet address reportedly accessed Gala Games' internal administrative minting function on May 20, 2024, minting 5 billion GALA tokens without authorization.
- The wallet reportedly sold approximately 592 million to 600 million GALA on Uniswap, acquiring roughly 5,913 ETH, according to analytics tracking.
- Blockchain analytics firms PeckShield and DEXTools flagged the transaction and tracked the dumping of tokens on decentralized exchanges, which correlated with an immediate drop in GALA's market price.
- Gala Games reportedly invoked blacklist functionality within 45 minutes to freeze remaining tokens.
- Reports indicated the perpetrator later burned the remaining 4.4 billion frozen GALA tokens and returned converted ETH to a Gala-controlled wallet.
- Industry sources reported that the attacker's wallet was identified in cooperation with federal authorities and centralized exchange partners.
Pending:
- Gala Games has yet to release a comprehensive, formal post-mortem documenting the exact technical vulnerability or breach vector used to compromise administrative keys.
- Authorities and Gala Games have not formally confirmed the legal identity or jurisdiction of the individual behind the exploit.