Gnosis Pay Hack

Reported loss $1.5M
Gnosis Chain
Signature Verification Flaw

What happened

On June 1, 2026, attackers exploited the Zodiac Delay and Roles modules used by Gnosis Pay card safes. Gnosis reported approximately $1.496 million taken, a further roughly $300,000 made inaccessible, and 5,281 wallets with at least $1 in exposure; Gnosis restored all user balances.

Technical root cause

The ERC-1271 signature check used by the affected Zodiac modules inspected returned bytes but did not require the underlying static call to succeed. A deliberately reverting contract could therefore return the ERC-1271 magic value and be accepted as a valid signer.

How it happened

By making a failed signature-validation call appear valid, the attackers forged approvals and queued withdrawals from card safes they did not own. Gnosis paused affected services, repaired the modules, and restored balances during a phased recovery.

Protocol details

Classification Input Validation
Protocol Type Crypto Card Issuer
Implementation language Solidity
Protocol links Website @gnosisdao

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.