I didn't think Gallery was popular enough to be targeted by automated scripts. I thought CAPTCHAs could stop them. I was quite wrong. I upgrade Gallery to 2.3 and got me a WordPress API key for Akismet, which I'm now using in MT and Gallery.
I also looked at my logs, and found that 99% of my Gallery spam comments came from a limited set of IPs. Since I started blocking them at the firewall, I've seen 13,000 attempted hits from them. Here they are. If you're running Gallery, ban them now.
91.121.108.25
91.121.110.118
91.121.111.27
91.121.111.28
91.121.120.173
91.121.143.168
91.121.169.207
91.121.179.28
91.121.71.155
91.121.81.48.3
91.121.81.48.5
91.121.84.162
91.121.110.118
91.121.111.27
91.121.111.28
91.121.120.173
91.121.143.168
91.121.169.207
91.121.179.28
91.121.71.155
91.121.81.48.3
91.121.81.48.5
91.121.84.162