A postmortem said the software flaw had been present since October 2023 and enabled the card safe exploit; Gnosis said all affected users have now been fully reimbursed.
Gnosis said a June 1 security breach at Gnosis Pay led to the theft of about $1.5 million after attackers exploited signature-verification flaws in Zodiac's Delay Module and Roles Module to forge withdrawal approvals. In a postmortem, the company said the underlying software flaw had been present since October 2023. Gnosis traced the bug to ERC-1271 validation logic not verifying whether staticcall, a read-only smart contract call, had succeeded, a flaw that allowed invalid approvals to pass. It said all affected users have been fully reimbursed and that more than 99% of services had been restored. The incident also briefly left roughly $300,000 inaccessible.