Gnosis says June 1 Gnosis Pay breach stole about $1.5 million

A postmortem said the software flaw had been present since October 2023 and enabled the card safe exploit; Gnosis said all affected users have now been fully reimbursed.

GNO

Summary

Gnosis said a June 1 security breach at Gnosis Pay led to the theft of about $1.5 million after attackers exploited signature-verification flaws in Zodiac's Delay Module and Roles Module to forge withdrawal approvals. In a postmortem, the company said the underlying software flaw had been present since October 2023. Gnosis traced the bug to ERC-1271 validation logic not verifying whether staticcall, a read-only smart contract call, had succeeded, a flaw that allowed invalid approvals to pass. It said all affected users have been fully reimbursed and that more than 99% of services had been restored. The incident also briefly left roughly $300,000 inaccessible.

Terms & Concepts
  • ERC-1271: A smart contract signature standard for validating approvals.
  • staticcall: A read-only smart contract call that cannot change state.
  • signature-verification: The process of checking whether a digital approval is valid.