Incident case file
Sign in to watchGnosis Pay — Zodiac Delay/Roles Module ERC-1271 Signature-Check Flaw — Full Reimbursement Confirmed
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x81BA8A2b895D30280bca199C2Ff75f3F058d4C6c (primary attacker wallet, confirmed by CertiK June 5, 2026). Secondary laundering address: 0xb1834575349c6eb56675c35b4109c3d3a77dd2fc. Split wallets used for Monero (XMR) conversion: 0xcce200e0df2f6d47ccffc0e64e6fddc145b13f67; 0x3eb18b54a2f7500c3a581197cf7d9fbd62516160; 0x0dda0f6aa7b3e0ec1273c4e47c56e7bed57a308c; 0x31c2c0c4ab37a89d38968735f8ad9f04e332576a.
Timeline: T-X (2026-05-29, 13:29:55 UTC): Attacker deploys 41 attack contracts on Gnosis Chain, each hard-coded to return the EIP-1271 'valid signature' magic value regardless of actual signature validity — preparation phase. T0 (2026-06-01, 06:17 UTC): Gnosis's treasury manager NOCA's monitoring infrastructure flags the attacker's first large unauthorized transfer; incident response triggered. T0+~1h49m (08:06 UTC): Root cause identified as a vulnerability in the Zodiac Delay and Roles modules. Root cause detail (per official post-mortem): to allow gasless transaction confirmation, the module used a staticcall to the signer contract's isValidSignature (ERC-1271) function, but the vulnerable check only inspected the returned value — it never verified that the staticcall itself succeeded. A contract that reverted on purpose while still returning the 'valid' magic value (0x1626ba7e) was therefore treated as a genuine, valid signature. This let the attacker queue withdrawals from Safes they did not own. The vulnerability entered the Zodiac codebase in v3.4.0, released 2023-10-30 (commit 9a9e380), when signature support was added. Separately, on-chain investigation (CertiK, June 1-5 era) traced the specific execution path: the attacker called execTransactionFromModule() on the Delay Module for 41 GnosisPay Safes; the module's moduleTxSignedBy() function parsed attacker-controlled r/s/v calldata, routing verification through a legitimate Biconomy Safe and then to the attacker's always-valid contract. T0 (same day): Card transaction processing, authorization systems, and new user onboarding are paused; the bridge to Gnosis Chain is paused by bridge validators; attacker-linked addresses are shared with stablecoin issuers to isolate funds where possible. Gnosis co-founder Martin Köppelmann publicly urges all users to withdraw EURe and GNO from their Safes, stating 'Rest assured, Gnosis will cover all user losses.' T+1-2 days (2026-06-01 to 06-02): Gnosis proactively notifies other external projects at risk from the same Zodiac vulnerability. The Zodiac modules are repaired and shared with ChainSecurity for focused review. Gnosis migrates affected users to newly issued replacement Safes linked to their existing card profiles. In this window, ~$246K USDT is bridged by the attacker to Hyperliquid and the remainder split across 4 wallets for Monero conversion. T+2 days (2026-06-03): Zodiac publicly discloses the flaw, confirming it affects Roles Modifier v2 and Delay Modifier v1.1.0 (Safe core contracts confirmed unaffected); multiple projects using these modules flagged as potentially at risk. On the evening of 2026-06-03, the first user accounts are reactivated (balance restoration, card re-enabling, normal operations resumption begins); an emergency fund is established for users in extremis. T+3 days (2026-06-04): ChainSecurity completes its independent review; internal teams also complete their review; phased service resumption begins. T+3-6 days (2026-06-04 to 06-07): Newly engineered card safe modules are deployed in tranches, linked to users' existing profiles, followed by phased restoration of full account balances. T+5 days (2026-06-05): CertiK publishes a full incident analysis, at that point confirming ~$265K in losses across the 41 Safes identified to date — this figure was later superseded by Gnosis's own July 3 post-mortem, which revealed the true scope (5,281 wallets, $1,496,151 taken + ~$300K inaccessible). T+5 days (2026-06-06): Full services restored to 99% of users; remaining accounts restored early the following week. No user lost funds in the exploit — Gnosis absorbed all losses from treasury. T+1 month (2026-07-03): Gnosis publishes its full, detailed technical post-mortem (this is the source for the corrected/final figures used in this record), confirming the exact vulnerable code path, the fix (requiring the staticcall to succeed in addition to checking the magic value), and outlining ongoing security investments: growing the security team with external researchers, a full internal review of onchain/offchain systems, an independent holistic security assessment, widened audit scope to cover external dependencies, active dependency monitoring, and the rollout of a rebuilt Gnosis Pay product (v2) optimized for observability.
Sources and coverage
- Articlegnosispay.comhttps://www.gnosispay.com/blog/post-mortem-gnosis-pay-vulnerability-exploit
- Articlecertik.comhttps://www.certik.com/blog/gnosispay-incident-analysis
- Articlethedefiant.iohttps://thedefiant.io/news/hacks/gnosis-pay-hit-by-delay-module-exploit-as-gnosis-pledges-to-cover-user-losses
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/06/05/delay-module-trick-costs-gnosispay-265k-reports-certik/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/06/03/zodiac-reveals-flaw-behind-gnosis-pay-exploit-safe-unaffected/
- Articlecrypto.newshttps://crypto.news/gnosis-pay-exploit-tied-to-zodiac-delay-module/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)