pNetwork 2022 pGALA contract-control incident
A deployment misconfiguration allowed covert takeover of the pGALA token contract on BNB Chain. pNetwork stopped processing pGALA bridge operations and performed an emergency whitehat drain of the PancakeSwap pool; the GALA collateral on Ethereum was not stolen from the bridge.
Incident facts
- Incident title
- pNetwork 2022 pGALA contract-control incident
- Bridge
- pNetwork
- Incident date
- 2022-11-03
- Incident type
- Security Misconfiguration
- Major incident
- Yes
- Affected chains
- Ethereum, BNB Chain
- Affected assets
- GALA, BNB
- Attack category
- Contract Ownership Misconfiguration
- Reported loss
- No bridge collateral loss reported
- Amount confidence
- High
- Loss amount basis
- Official PNetwork Postmortem
- Recovery
- Whitehat Recovery
- Reimbursement
- Announced
- Restart
- Token Replacement Planned
- Current outcome
- Affected Token Deprecated
- Postmortem
- Full
- Resolution
- Unresolved
- Last reviewed
- 2026-06-15
- Last verified
- 2026-06-15
Amount and valuation
pNetwork stated that no funds were stolen from the GALA cross-chain bridge. Losses and disputes involving DEX pools and centralized exchanges are not treated as bridge collateral loss.
The 12,977 BNB collected by the whitehat operation is a recovery amount, not a stolen-fund amount.
Why this remains unresolved
- The announced redistribution of 12,977 BNB was delayed for legal and compliance reasons, and final distribution completion is not established in this batch.
Timeline events
pGALA contract-control issue detected2022-11-03
pNetwork identified a deployment misconfiguration, secured the Ethereum collateral, and stopped processing pGALA bridge operations.
pNetwork conducted an emergency whitehat pool drain2022-11-03
pNetwork minted uncollateralized pGALA to drain the vulnerable PancakeSwap pool before malicious use and ultimately collected 12,977 BNB.
The recovered BNB is not classified as stolen bridge collateral.
pGALA replacement and recovery plan announced2022-11-05
pNetwork described replacing the compromised pGALA contract and returning whitehat-collected BNB according to snapshots.
pGALA redistribution delayed2022-11-11
pNetwork said legal and compliance requirements delayed the planned 12,977 BNB redistribution.
Final completion remains unverified.
Evidence records
- pGALA post-mortem and recovery planpNetwork · Tier 1 · High reliability · primary · 2022-11-05Claim scope: Incident Case
Primary timeline, whitehat recovery amount, replacement plan, and delay update.
- Lessons learnt from the pGALA exploitpNetwork · Tier 1 · High reliability · primary · 2022-11-28Claim scope: Root Cause
Primary follow-up on root cause and operational lessons.
- pGALA: What Happened and the Dangers of DecentralizationGala Games · Tier 1 · High reliability · primary · 2022-11-04Claim scope: Incident Case
Affected-project perspective on the emergency response.
- SlowMist analysis of the pGALA eventSlowMist · Tier 2 · High reliability · secondary · 2022-11-04Claim scope: Root Cause
Independent analysis; differing key-exposure descriptions remain explicit.
- pGALA post-mortem and recovery planpNetwork · Tier 1 · High reliability · primary · 2022-11-05Claim scope: Recovery
Event-scoped duplicate supporting the emergency whitehat pool drain and recovered BNB amount.
- pGALA post-mortem and recovery planpNetwork · Tier 1 · High reliability · primary · 2022-11-05Claim scope: Recovery
Event-scoped duplicate supporting the replacement contract and snapshot-based recovery plan.
- pGALA post-mortem and recovery planpNetwork · Tier 1 · High reliability · primary · 2022-11-05Claim scope: Reimbursement
Event-scoped duplicate supporting the legal and compliance delay to the planned redistribution.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Final whitehat-fund distribution is unverified.
- Exchange-specific user losses and remedies remain outside the bridge collateral calculation.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.