GANA Payment Loses $3.1M in Exploit Linked to Compromised Owner Key

GANA Payment suffered a security breach on Nov. 20 that resulted in losses exceeding $3.1 million, SlowMist founder Yu Xian said. The attacker gained access to the Owner private key for GANA Payment's Stake contract and used EIP-7702 delegate exploitation to bypass the unstake function's onlyEOA verification. By manipulating rate and fee parameters, the attacker unstaked hundreds of thousands of USDT after staking only a few hundred USDT.