← Radar

Incident case file

Sign in to watch

Gnosis Pay — Zodiac Delay/Roles Module ERC-1271 Signature-Check Flaw — Full Reimbursement Confirmed

Incident date June 1, 2026

1 views

ResolvedGnosis ChainSmart wallet module / ERC-1271 signature-verification bypassCluster: GNOSISPAY-MODULE-2026-06

Estimated loss

$1.5M

Victims identified

5281
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: 0x81BA8A2b895D30280bca199C2Ff75f3F058d4C6c (primary attacker wallet, confirmed by CertiK June 5, 2026). Secondary laundering address: 0xb1834575349c6eb56675c35b4109c3d3a77dd2fc. Split wallets used for Monero (XMR) conversion: 0xcce200e0df2f6d47ccffc0e64e6fddc145b13f67; 0x3eb18b54a2f7500c3a581197cf7d9fbd62516160; 0x0dda0f6aa7b3e0ec1273c4e47c56e7bed57a308c; 0x31c2c0c4ab37a89d38968735f8ad9f04e332576a.

Funds moved to: Per Gnosis's official July 3, 2026 post-mortem, the attacker(s) extracted a total of $1,496,151 (superseding CertiK's June 5 estimate of ~$265K, which covered only the first 41 Safes identified at the time). Asset breakdown: GNO $641,159; EURe $453,175; USDC.e $399,121; SAFE $2,202; WETH $323; xDAI $135; USDC $28; USDT $7. An additional ~$300,000 was rendered inaccessible (stuck, not attacker-controlled) and remains subject to ongoing recovery efforts. Total impact across both categories: ~$1.8M
Exploit contract (deployed 2026-05-29, verifiable on-chain): 0x5a77953caa27ed4638f4dfdc665b8064d0e97a35. Attacker deployed 41 attack contracts on Gnosis Chain starting 2026-05-29 13:29:55 UTC, each designed to always return the EIP-1271 magic value (0x1626ba7e), simulating a valid signature for any request. Safe/Biconomy path used in the attack: 0x7f59e536f083a63b67adfe3bc793a47744dba7d80. This is confirmed as the second Safe-module exploit in under a week, following the SquidRouterModule exploi

Timeline: T-X (2026-05-29, 13:29:55 UTC): Attacker deploys 41 attack contracts on Gnosis Chain, each hard-coded to return the EIP-1271 'valid signature' magic value regardless of actual signature validity — preparation phase. T0 (2026-06-01, 06:17 UTC): Gnosis's treasury manager NOCA's monitoring infrastructure flags the attacker's first large unauthorized transfer; incident response triggered. T0+~1h49m (08:06 UTC): Root cause identified as a vulnerability in the Zodiac Delay and Roles modules. Root cause detail (per official post-mortem): to allow gasless transaction confirmation, the module used a staticcall to the signer contract's isValidSignature (ERC-1271) function, but the vulnerable check only inspected the returned value — it never verified that the staticcall itself succeeded. A contract that reverted on purpose while still returning the 'valid' magic value (0x1626ba7e) was therefore treated as a genuine, valid signature. This let the attacker queue withdrawals from Safes they did not own. The vulnerability entered the Zodiac codebase in v3.4.0, released 2023-10-30 (commit 9a9e380), when signature support was added. Separately, on-chain investigation (CertiK, June 1-5 era) traced the specific execution path: the attacker called execTransactionFromModule() on the Delay Module for 41 GnosisPay Safes; the module's moduleTxSignedBy() function parsed attacker-controlled r/s/v calldata, routing verification through a legitimate Biconomy Safe and then to the attacker's always-valid contract. T0 (same day): Card transaction processing, authorization systems, and new user onboarding are paused; the bridge to Gnosis Chain is paused by bridge validators; attacker-linked addresses are shared with stablecoin issuers to isolate funds where possible. Gnosis co-founder Martin Köppelmann publicly urges all users to withdraw EURe and GNO from their Safes, stating 'Rest assured, Gnosis will cover all user losses.' T+1-2 days (2026-06-01 to 06-02): Gnosis proactively notifies other external projects at risk from the same Zodiac vulnerability. The Zodiac modules are repaired and shared with ChainSecurity for focused review. Gnosis migrates affected users to newly issued replacement Safes linked to their existing card profiles. In this window, ~$246K USDT is bridged by the attacker to Hyperliquid and the remainder split across 4 wallets for Monero conversion. T+2 days (2026-06-03): Zodiac publicly discloses the flaw, confirming it affects Roles Modifier v2 and Delay Modifier v1.1.0 (Safe core contracts confirmed unaffected); multiple projects using these modules flagged as potentially at risk. On the evening of 2026-06-03, the first user accounts are reactivated (balance restoration, card re-enabling, normal operations resumption begins); an emergency fund is established for users in extremis. T+3 days (2026-06-04): ChainSecurity completes its independent review; internal teams also complete their review; phased service resumption begins. T+3-6 days (2026-06-04 to 06-07): Newly engineered card safe modules are deployed in tranches, linked to users' existing profiles, followed by phased restoration of full account balances. T+5 days (2026-06-05): CertiK publishes a full incident analysis, at that point confirming ~$265K in losses across the 41 Safes identified to date — this figure was later superseded by Gnosis's own July 3 post-mortem, which revealed the true scope (5,281 wallets, $1,496,151 taken + ~$300K inaccessible). T+5 days (2026-06-06): Full services restored to 99% of users; remaining accounts restored early the following week. No user lost funds in the exploit — Gnosis absorbed all losses from treasury. T+1 month (2026-07-03): Gnosis publishes its full, detailed technical post-mortem (this is the source for the corrected/final figures used in this record), confirming the exact vulnerable code path, the fix (requiring the staticcall to succeed in addition to checking the magic value), and outlining ongoing security investments: growing the security team with external researchers, a full internal review of onchain/offchain systems, an independent holistic security assessment, widened audit scope to cover external dependencies, active dependency monitoring, and the rollout of a rebuilt Gnosis Pay product (v2) optimized for observability.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)