← Radar

Incident case file

Sign in to watch

Gnosis Pay — Zodiac Delay/Roles Module ERC-1271 Signature-Check Flaw — Full Reimbursement Confirmed

Incident date 2026-05-31

1 views

ResolvedGnosis ChainSmart wallet module / ERC-1271 signature-verification bypassCluster: GNOSISPAY-MODULE-2026-06

Estimated loss

$1.5M

Victims identified

5281
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

0x81BA8A2b895D30280bca199C2Ff75f3F058d4C6c (primary attacker wallet, confirmed by CertiK June 5, 2026). Secondary laundering address: 0xb1834575349c6eb56675c35b4109c3d3a77dd2fc. Split wallets used for Monero (XMR) conversion: 0xcce200e0df2f6d47ccffc0e64e6fddc145b13f67; 0x3eb18b54a2f7500c3a581197cf7d9fbd62516160; 0x0dda0f6aa7b3e0ec1273c4e47c56e7bed57a308c; 0x31c2c0c4ab37a89d38968735f8ad9f04e332576a.

Funds moved to

Per Gnosis's official July 3, 2026 post-mortem, the attacker(s) extracted a total of $1,496,151 (superseding CertiK's June 5 estimate of ~$265K, which covered only the first 41 Safes identified at the time). Asset breakdown: GNO $641,159; EURe $453,175; USDC.e $399,121; SAFE $2,202; WETH $323; xDAI $135; USDC $28; USDT $7. An additional ~$300,000 was rendered inaccessible (stuck, not attacker-controlled) and remains subject to ongoing recovery efforts. Total impact across both categories: ~$1.8M

Linked

Exploit contract (deployed 2026-05-29, verifiable on-chain): 0x5a77953caa27ed4638f4dfdc665b8064d0e97a35. Attacker deployed 41 attack contracts on Gnosis Chain starting 2026-05-29 13:29:55 UTC, each designed to always return the EIP-1271 magic value (0x1626ba7e), simulating a valid signature for any request. Safe/Biconomy path used in the attack: 0x7f59e536f083a63b67adfe3bc793a47744dba7d80. This is confirmed as the second Safe-module exploit in under a week, following the SquidRouterModule exploi

Chronology

4 beats
  1. T+2d2026-06-03

    Zodiac publicly discloses the flaw, confirming it affects Roles Modifier v2 and Delay Modifier v1.1.0 (Safe core contracts confirmed unaffected); multiple projects using these modules flagged as potentially at risk. On the evening of 2026-06-03, the first user accounts are reactivated (balance restoration, card re-enabling, normal operations resumption begins); an emergency fund is established for users in extremis.

  2. T+3d2026-06-04

    ChainSecurity completes its independent review; internal teams also complete their review; phased service resumption begins. T+3-6 days (2026-06-04 to 06-07): Newly engineered card safe modules are deployed in tranches, linked to users' existing profiles, followed by phased restoration of full account balances.

  3. T+5d2026-06-05

    CertiK publishes a full incident analysis, at that point confirming ~$265K in losses across the 41 Safes identified to date

    this figure was later superseded by Gnosis's own July 3 post-mortem, which revealed the true scope (5,281 wallets, $1,496,151 taken + ~$300K inaccessible).

  4. T+5d2026-06-06

    Full services restored to 99% of users; remaining accounts restored early the following week. No user lost funds in the exploit

    Gnosis absorbed all losses from treasury. T+1 month (2026-07-03): Gnosis publishes its full, detailed technical post-mortem (this is the source for the corrected/final figures used in this record), confirming the exact vulnerable code path, the fix (requiring the staticcall to succeed in addition to checking the magic value), and outlining ongoing security investments: growing the security team with external researchers, a full internal review of onchain/offchain systems, an independent holistic security assessment, widened audit scope to cover external dependencies, active dependency monitoring, and the rollout of a rebuilt Gnosis Pay product (v2) optimized for observability.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)