Galxe Frontend Hack
Check if your address is affected.
Galxe is a popular Web3 platform where projects run campaigns and quests for their communities. On 6 October 2023, an attacker contacted Galxe's domain registrar, Dynadot, pretending to work for Galxe and using forged documents. This gave them access to Galxe's domain account, which they used to point the Galxe website to a copy they controlled. For a few hours, visitors who connected their wallets were asked to approve their tokens to the attacker, who then used those approvals to drain the tokens.
Over $270k was stolen before Galxe regained control of its domain later that day and restored the real website. Galxe warned users on social media, and wallets like MetaMask and Coinbase Wallet flagged the fake site as phishing. The same attacker had also been linked to a similar attack on the Balancer website about two weeks earlier. Galxe later refunded affected users in full, plus an extra 10% from its own treasury, paid in USDT on Polygon.
The Galxe website is safe to use again, but approvals given on the fake site stay active until you revoke them. If you connected your wallet to the Galxe website on 6 October 2023, check whether you approved any of the listed addresses on any chain and revoke those approvals. Revoking protects what is still in your wallet, but it does not recover funds that were already taken. Galxe also advised affected users to contact its support team.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →