Gnosis to Cover Losses After Gnosis Pay Delay-Module Exploit

Gnosis announced it will reimburse users after a vulnerability in Gnosis Pay’s Zodiac delay module allowed queued transactions to be executed from Safe wallets.

On Monday, Gnosis announced it will cover all user losses after an attacker exploited a vulnerability in Gnosis Pay's Zodiac delay module that allowed queued transactions to be initiated and executed from Safe smart-contract wallets.

Gnosis co-founder and CEO Martin Koppelmann confirmed the active exploit on X, writing ‘Unfortunately, there is a hack related to Gnosis Pay and the delay module. Please be patient while we try to contain the damage. Rest assured, Gnosis will cover all user losses.' He later removed an earlier post that urged users to withdraw funds and added ‘Most users will not be able to do so, but we are actively working to contain the damage' and ‘We believe we can contain the majority of it, and in any case, we will ensure that all users are made whole.'

The flaw is in the Zodiac delay module, a permission layer that queues transactions before they execute. Gnosis reports the attacker can initiate transactions from Safe wallets that include the module.

As part of containment efforts, Gnosis asked bridge validators to pause operations while investigators work to determine the scope and whether funds were taken. The company noted forensic teams and security partners are coordinating the response. Blockchain security firm PeckShield flagged the exploit and warned users to check their exposure. Gnosis did not confirm the amount of funds drained at the time of the alert.

Gnosis Pay is built on Safe's smart-contract wallet infrastructure. Safe spun out from Gnosis in 2022 as an independent company, though the two remain closely linked. Gnosis has clarified the bug exists within the Gnosis Pay system and not within Safe's core contracts.

The alert follows an earlier incident that drained about $3.2 million from 86 Safe wallets through a vulnerable third-party module called SquidRouterModule. That prior incident involved weak identity validation in an unofficial module, which allowed attackers to execute arbitrary calldata without requiring wallet signatures.

No detailed timeline for recovery or a full remediation plan was provided in the initial statements. Gnosis has asked users to monitor their wallets and reiterated that it will reimburse users for losses that result from the exploit.

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author