Incident case file
Sign in to watchGnosis Pay — Zodiac Delay/Roles Module ERC-1271 Signature-Check Flaw — Full Reimbursement Confirmed
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
4 beats- T+2d2026-06-03
Zodiac publicly discloses the flaw, confirming it affects Roles Modifier v2 and Delay Modifier v1.1.0 (Safe core contracts confirmed unaffected); multiple projects using these modules flagged as potentially at risk. On the evening of 2026-06-03, the first user accounts are reactivated (balance restoration, card re-enabling, normal operations resumption begins); an emergency fund is established for users in extremis.
- T+3d2026-06-04
ChainSecurity completes its independent review; internal teams also complete their review; phased service resumption begins. T+3-6 days (2026-06-04 to 06-07): Newly engineered card safe modules are deployed in tranches, linked to users' existing profiles, followed by phased restoration of full account balances.
- T+5d2026-06-05
CertiK publishes a full incident analysis, at that point confirming ~$265K in losses across the 41 Safes identified to date
this figure was later superseded by Gnosis's own July 3 post-mortem, which revealed the true scope (5,281 wallets, $1,496,151 taken + ~$300K inaccessible).
- T+5d2026-06-06
Full services restored to 99% of users; remaining accounts restored early the following week. No user lost funds in the exploit
Gnosis absorbed all losses from treasury. T+1 month (2026-07-03): Gnosis publishes its full, detailed technical post-mortem (this is the source for the corrected/final figures used in this record), confirming the exact vulnerable code path, the fix (requiring the staticcall to succeed in addition to checking the magic value), and outlining ongoing security investments: growing the security team with external researchers, a full internal review of onchain/offchain systems, an independent holistic security assessment, widened audit scope to cover external dependencies, active dependency monitoring, and the rollout of a rebuilt Gnosis Pay product (v2) optimized for observability.
Sources and coverage
- Articlegnosispay.comhttps://www.gnosispay.com/blog/post-mortem-gnosis-pay-vulnerability-exploit
- Articlecertik.comhttps://www.certik.com/blog/gnosispay-incident-analysis
- Articlethedefiant.iohttps://thedefiant.io/news/hacks/gnosis-pay-hit-by-delay-module-exploit-as-gnosis-pledges-to-cover-user-losses
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/06/05/delay-module-trick-costs-gnosispay-265k-reports-certik/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/06/03/zodiac-reveals-flaw-behind-gnosis-pay-exploit-safe-unaffected/
- Articlecrypto.newshttps://crypto.news/gnosis-pay-exploit-tied-to-zodiac-delay-module/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)