Gnosis Pay Exploit Linked to Zodiac Delay Module, Users Urged to Withdraw

Gnosis Pay Exploit Linked to Zodiac Delay Module, Users Urged to Withdraw

N
News Editor 01
2026-07-23 19:55:15
Gnosis Pay hit by an active exploit tied to the Zodiac delay module. Co-founder Köppelmann and PeckShield advise withdrawing all EURe and GNO. Gnosis promises to cover losses and asks bridge validators to pause.
Gnosis PayZodiac delay modulesecurity exploitcrypto paymentswithdrawal alert

Gnosis Pay users have been urgently told to withdraw all funds after an active exploit linked to the platform's Zodiac delay module. Gnosis co-founder Martin Köppelmann posted on X: "If you are a Gnosis Pay user – unfortunately I have to recommend: withdraw all funds (EURe and GNO)." Security firm PeckShield echoed the warning, stating "Users are strongly urged to withdraw all funds (EURe and GNO)" and advising users to check their exposure as they might be affected.

Delay module bug under the spotlight

Köppelmann later clarified: "The bug is related to the Zodiac delay module." The attacker can initiate transactions from Safes that use this module. Gnosis Pay uses Safe-based accounts with smart contract modules. According to its own documentation, each account relies on a Delay Module and a Roles Module to support card payments while keeping users in control – the delay is supposed to add a short wait before outgoing transactions execute, giving users time to react. That very safeguard turned into an attack vector.

No technical root cause has been published yet, but security analysts suspect the module fails to properly validate who can trigger a transaction. PeckShield warned that any Safe using the delay module could be at risk, with GNO and EURe being the most exposed assets.

Containment and loss coverage

"We are doing various measures to contain the damage like asking bridge validators to pause," Köppelmann said. Bridge validators handle cross-chain movements; pausing them helps slow the flow of stolen funds to other networks. "Rest assured, Gnosis will cover all user losses," he added. As of this writing, no final loss figure has been released, nor has a full post-mortem explaining how many accounts were affected or whether all attacker activity has stopped.

Gnosis Pay itself is not described as shut down. The product, which allows self-custody card spending at Visa merchants, remains operational but the team is asking users to withdraw while they contain the exploit. The incident puts a fresh spotlight on smart contract wallet permission logic and transaction timing – a safety feature became a door for attackers.

Crypto payment tools are rapidly merging on-chain wallets with real-world spending, but code-level flaws can lead to direct fund loss. The Gnosis Pay case is not the first time a delay module has been exploited; similar vulnerabilities have been flagged in the past. Until the team issues a full patch and a green light, users are advised to stay alert and monitor official channels.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.