CRYPTO
Gnosis Pay Paid for a Delay Module Bug Left Unpatched
Gnosis Pay repaid a $1.5 million June drain after a 2023 Zodiac signature shortcut, quietly fixed in February, never reached live Delay copies.
Attackers took about $1.5 million from Gnosis Pay card Safes on June 1, 2026 after a delay-module check treated a failed call as a valid signature. Gnosis repaid every cardholder. The hole had been sitting in live Zodiac copies since a 2023 size cut.
Martin Köppelmann, the Gnosis co-founder, first told users to pull EURe and GNO, then deleted that warning because most people could not move funds while the queue was the attack. The bill was not a broken clock. It was an old signature shortcut that a February patch never put on the modules actually running the cards.
Köppelmann Told Cardholders to Run, Then Deleted the Warning
Treasury manager NOCA flagged the first large unauthorized transfer at 06:17 UTC. By 08:06 UTC, less than two hours later, the team had pinned the hole on Zodiac’s Delay and Roles modules. Card processing, authorizations, and new sign-ups were shut off. Bridge validators paused the path onto Gnosis Chain. Attacker addresses went to stablecoin issuers.
Köppelmann’s first public line was the one security desks amplified. PeckShield told users to check exposure and withdraw EURe and GNO. Gnosis Pay’s own account said the same: if you can move funds from the card Safe to another wallet, do it, and affected users will be reimbursed.
That door closed almost as soon as it opened. Köppelmann deleted the withdraw post and said most users would not be able to get out. He wrote that Gnosis believed it could contain most of the damage and would make users whole either way, including the line that Gnosis will cover all user losses.
Unfortunately, there is a hack related to @gnosispay and the "delay module".
Please be patient while we try to contain the damage. Rest assured, Gnosis will cover all user losses.— koeppelmann (@koeppelmann) June 1, 2026
The card app failed to load balances that morning, so the advice was hard to follow even for people who still had a window. At least one cardholder got EURe out by queueing a transfer, skipping an expired one, then executing. Monerium, which issues EURe, said the incident was not a flaw in the euro token. It sat in Gnosis Pay’s delay-module setup.
Days earlier, a separate third-party Safe module labeled SquidRouterModule had drained about $3.2 million from 86 wallets on Ethereum and Base. Monday’s event was a different bug. It landed on a market already watching modules that sit next to keys.
The Card’s Own Help Page Called the Delay a Failsafe
Gnosis Pay is a self-custodial Visa card on Gnosis Chain. Spend comes from a Safe the user owns, not from a pooled card balance. When a card is activated, two Zodiac modules are bolted onto that Safe.
The Roles module sets the spending rules: which stablecoin can move, the daily cap, and the settlement address Gnosis Pay is allowed to pay. The Delay module adds a three-minute delay on outgoing transactions. The help page sold that wait as double-spend protection and a short window to cancel anything that looked wrong.
Ownership is stacked. The user’s ordinary wallet owns the Delay module, and that module owns the card Safe. Gnosis Pay can spend only inside the Roles limits. The user is supposed to keep the admin key. That stack is why a Delay authentication bypass can move the Safe without stealing the key. The delay safeguard on Gnosis Pay cards was never a lock on the funds. It was a queue.
Short cooldowns made the queue more dangerous, not less. Three minutes is long enough for a card settlement to land. It is also short enough that a queued drain can clear before a human sees the app, even on a day when the app still loads.
A 2023 Size Cut Left the Signature Check Blind
To let an owner move funds without holding the chain’s gas token, the account asks a contract a yes-or-no question: is this signature valid? That path is ERC-1271. A contract account has no private key, so it answers by returning a magic value, 0x1626ba7e, the ERC-1271 contract signature magic value.
Safe’s CompatibilityFallbackHandler implements that answer on the Safe’s behalf. Zodiac’s Delay and Roles modules, on the signed path, made a staticcall to the purported signer and inspected the bytes that came back. The defect, in Gnosis’s own words, was simple. The checker read the answer. It did not check whether the call had succeeded.
An attacker could deploy a contract that fails on purpose while still returning the “valid” code. To the module, a forged approval looked real. That let the attacker queue withdrawals from accounts they did not own. Private keys never moved. A public call plus crafted trailing calldata was enough.
A failed signature check that happened to leave return/revert data beginning with the ERC-1271 magic value (0x1626ba7e) was accepted as a valid signature. This was only exploitable in one configuration: a Safe using the CompatibilityFallbackHandler assigned as a module on Delay Modifier v1.1.0, or as a role member on Roles Modifier v2.1.0.
Jan Nicholls Schwarz, Gnosis Guild Engineering, Zodiac post-mortem, June 19, 2026
The success check was removed on 28 October 2023 in commit 9a9e380 on the legacy @gnosis.pm/zodiac package, then shipped as Zodiac 3.4.0 on 30 October 2023. Gnosis Guild later said the cut was a bytecode-size optimization after a development Roles v2.1.0 mastercopy hit the EIP-170 contract-size limit. Delay v1.1.0 (November 2023) and Roles v2.1.0 (December 2023) were built against that package.
The attacker’s first contract is on Gnosis Chain at 0x5a77953caa27ed4638f4dfdc665b8064d0e97a35. Zodiac later listed 0x81ba8a2b895d30280bca199c2ff75f3f058d4c6c as an attacker address, with an example exploit transaction 0x5ea42911c803ba2cf1cb558e88129102de9023980a5c73253d59407859ce2ce5. The call path was Delay.execTransactionFromModule, then moduleOnly, then moduleTxSignedBy, then _isValidContractSignature.
February’s Patch Never Reached Live Delay Copies
On 27 February 2026, commit 11708ac in the newer zodiac-core repo put the success check back and shipped v4.0.0-alpha.0. That change fixed the signature fault in the new package line. It was a refactor. The team has said it was not aware of the vulnerability until 1 June.
Live Delay v1.1.0 and Roles v2.1.0 mastercopies stayed on the old package. Gnosis Guild wrote that production Delay v1.1.0 copies were never updated, because the security impact of the February change was not recognized at the time. Gnosis Pay’s on-chain Delay instances were still compiled against legacy @gnosis.pm/zodiac when the drain began.
The corrected line is one extra boolean. Require the call to succeed, then match the magic bytes. After June 1 the patched modules were Delay v1.1.1 and Roles v2.1.1, released after a Gnosis audit. Zodiac flagged a signature patch as a security fix on 5 June, days after the exploit began. ChainSecurity finished a focused review on 4 June.
Community Notice: Zodiac Roles Modifier v2 and Delay Modifier v1.1.0 — Security Update
We identified a vulnerability in two Zodiac modules: Roles Modifier v2 and Delay Modifier v1.1.0. It affects only accounts where one of these modules is enabled AND a Safe account with a…
— Zodiac (@zodiaceco) June 2, 2026
Zodiac’s June 2 community notice said Safe’s core contracts, Safe{Wallet} infrastructure, and UI were not affected, and that other official Zodiac modules were outside the hole. Over 95% of identifiable accounts had already been handled in private outreach before that post. Köppelmann quoted it and said several other projects were affected. He asked anyone using Delay or Roles who had not heard privately to check at once.
How Many Accounts Sat in the Blast Radius?
The public story was a card product. The same authentication code sat under every Delay v1.1.0 and Roles v2.1.0 deployment where a Safe with CompatibilityFallbackHandler was assigned as a module or a role member. EOA role members were never in the hole. The ENS endowment uses Roles v2 and was checked by kpk; its role-member Safe did not use that fallback handler, so it was not exposed.
ACCOUNTS IN THE ZODIAC HOLE
| Group | Accounts | Outcome |
|---|---|---|
| Gnosis Pay card Safes | 46,669 | Taken over by the attacker |
| GP wallets with balance of at least $1 | 5,281 | Counted in the $1.8 million card exposure |
| Non-GP Delay | about 900 | 226 taken over |
| Roles avatars | 2,227 | At risk; scoped permissions limited drains |
Those two Gnosis Pay counts are not the same pile. Forty-six thousand six hundred sixty-nine is every card Safe the attacker took over, including empty ones. Five thousand two hundred eighty-one is the subset with at least $1 that Gnosis put against the $1.8 million figure.
Roles-attributable value at risk started at about $85,474,814, mostly LSTs, COMP, and tokenized bitcoin and dollar vaults, and was worked down to about $200,000, or 99.77% secured, with no confirmed Roles loss. Non-GP Delay started at about $633,564 and ended at about $700 remaining, 99.18% secured. Confirmed realized loss outside Gnosis Pay was about $4,500 across about 30 accounts, most of them tiny. At final containment Zodiac still listed 269 Delay instances holding about $700 and 1,529 Roles instances holding about $200,000, with drain risk on Roles described as low because the permissions did not allow emptying the Safe.
The bug was live on Gnosis, Base, and Ethereum. It was armed but not executed on BNB Chain, Polygon, and Arbitrum. Gnosis Guild does not charge for the modules and said it would not run a reimbursement program for downstream users. Its job, as it framed it, was the fix, the checker app, and whitehat recovery of accounts that were still open.
New Safes, Same Cards, Zero User Loss
Gnosis absorbed the card losses and said all funds were restored to users. No cardholder was left short on the June 1 drain. An emergency fund sat ready for people in a bind while the migration ran.
THE JUNE CONTAINMENT CLOCK
- June 1, 2026, 06:17 UTC: NOCA flags the first large unauthorized transfer; emergency response starts after verification.
- June 1, 2026, 08:06 UTC: Root cause is identified in the Zodiac modules; card services go offline and the Gnosis Chain bridge is paused.
- June 1-2, 2026: Gnosis notifies other projects on the same modules; patched code goes to ChainSecurity.
- June 3, 2026: First accounts come back on Wednesday evening, with balances restored and cards turned on again.
- June 4-6, 2026: ChainSecurity finishes its review; new card Safe modules roll out in tranches; full service returns for 99% of users by June 6, with the rest early the following week.
Every Gnosis Pay user received a new card Safe tied to the same physical and virtual cards. No plastic had to be reissued. Affected users found the old balance on the new Safe. Unaffected users had to migrate. Gnosis Pay’s June 6 update was blunt about the old address: anything sent there, on chain or via IBAN, would be lost.
ASSETS TAKEN FROM CARD SAFES
| Asset | USD value taken |
|---|---|
| GNO | 641,159 |
| EURe | 453,175 |
| USDC.e | 399,121 |
| SAFE | 2,202 |
| WETH | 323 |
| xDAI | 135 |
| USDC | 28 |
| USDT | 7 |
| Total | about 1,496,151 |
GNO was the largest slice, then EURe, then bridged USDC. The $1.5 million “taken” line and the ~$1,496,151 asset total are the same drain rounded two ways. About $300,000 more sat in accounts the team could not reach and was listed separately, which is how the write-up reached about $1.8 million across those 5,281 wallets.
WHAT GNOSIS SAID IT WOULD CHANGE
- People: Grow the security team and bring in outside researchers beside them.
- Scope: Extend smart-contract audits to external contracts the product depends on, and watch those dependencies for upstream fixes.
- Product: Ship the rebuilt Gnosis Pay v2 stack, which the team said is built for faster observation and operations.
May had been a high-water month for the card, with 218,573 payments and a May card volume of $10.13 million. Weekly active users fell to 3,129 in the outage week, then recovered to 4,805 by June 29. The Q2 report said the product kept roughly 80% of volume through the incident and was back at median usage by the end of June.
The July 3 post-mortem, last updated August 28, 2026, still said Gnosis was exploring recovery of about $300,000 left inaccessible. Cardholders had already been made whole from the company’s own pocket. The leftover is the company’s, not a balance still missing from a user’s new Safe.
Frequently Asked Questions
How Did the Gnosis Pay Delay Module Hack Work?
The attacker called Delay.execTransactionFromModule with extra signature bytes after the normal arguments, forced a Safe CompatibilityFallbackHandler check to fail while leaving revert data starting with 0x1626ba7e, then waited out the cooldown and ran executeNextTx. EOA role members were never at risk; only a contract member on that fallback-handler path could be impersonated, and no owner key had to move.
How Much Money Was Stolen in the Gnosis Pay Hack?
Gnosis counted about $1.5 million taken plus about $300,000 left inaccessible, or about $1.8 million across 5,281 wallets that held at least $1. The same authentication bug was armed on BNB Chain, Polygon, and Arbitrum but was not executed there; confirmed loss outside Gnosis Pay was about $4,500.
Did Gnosis Pay Reimburse Users After the June 2026 Exploit?
Yes. Gnosis absorbed the losses, restored balances onto new card Safes, and kept the same physical and virtual cards, with no reissue. Users were told not to send funds or IBAN transfers to the old Safe address, because those payments would not be recovered.
Was Safe Wallet Hacked in the Gnosis Pay Incident?
No. Safe’s core contracts, Safe{Wallet} infrastructure, and UI were not the bug. The hole was in Zodiac Delay v1.1.0 and Roles v2.1.0 when a Safe with CompatibilityFallbackHandler was assigned as a module or role member. The ENS endowment’s Roles v2 setup was reviewed and left outside that setup.
Which Zodiac Delay and Roles Versions Were Vulnerable?
Delay Modifier v1.1.0 and Roles Modifier v2.1.0, both built on the legacy @gnosis.pm/zodiac package after the 28 October 2023 size cut. The patched mastercopies are Delay v1.1.1 and Roles v2.1.1. Other official Zodiac modules were not in the affected set.
Why Did a February 2026 Zodiac Patch Fail to Stop the Attack?
The 27 February 2026 change lived in zodiac-core v4.0.0-alpha.0 as part of a refactor, not as a security advisory, and Gnosis Guild has said it did not see the security impact until June 1. Production Delay v1.1.0 instances, including Gnosis Pay’s, stayed compiled against the old package and kept the blind signature check.
The July 3 write-up, touched again on August 28, still listed about $300,000 as inaccessible and under recovery work. Card users were already whole. That leftover is the last open line on a bug that spent more than two years in production copies after a size cut threw away a single boolean.
Disclaimer: This article is news reporting and analysis of a completed security incident and is for information only. It is not investment advice, not a recommendation to buy, sell, or hold GNO, SAFE, EURe, or any other token, and not guidance on how to configure a Safe, a Zodiac module, or a crypto card. Readers who hold assets in a smart-account wallet or a card Safe should talk with a qualified security engineer or licensed financial adviser before moving funds or changing modules. Figures, patched versions, and recovery status come from the Gnosis and Gnosis Guild write-ups cited above, including an August 28, 2026 update, and may change if those teams publish later totals.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
