Gnosis Pay users have been urgently told to withdraw all funds after an active exploit linked to the platform's Zodiac delay module. Gnosis co-founder Martin Köppelmann posted on X: "If you are a Gnosis Pay user – unfortunately I have to recommend: withdraw all funds (EURe and GNO)." Security firm PeckShield echoed the warning, stating "Users are strongly urged to withdraw all funds (EURe and GNO)" and advising users to check their exposure as they might be affected.
Delay module bug under the spotlight
Köppelmann later clarified: "The bug is related to the Zodiac delay module." The attacker can initiate transactions from Safes that use this module. Gnosis Pay uses Safe-based accounts with smart contract modules. According to its own documentation, each account relies on a Delay Module and a Roles Module to support card payments while keeping users in control – the delay is supposed to add a short wait before outgoing transactions execute, giving users time to react. That very safeguard turned into an attack vector.
No technical root cause has been published yet, but security analysts suspect the module fails to properly validate who can trigger a transaction. PeckShield warned that any Safe using the delay module could be at risk, with GNO and EURe being the most exposed assets.
Containment and loss coverage
"We are doing various measures to contain the damage like asking bridge validators to pause," Köppelmann said. Bridge validators handle cross-chain movements; pausing them helps slow the flow of stolen funds to other networks. "Rest assured, Gnosis will cover all user losses," he added. As of this writing, no final loss figure has been released, nor has a full post-mortem explaining how many accounts were affected or whether all attacker activity has stopped.
Gnosis Pay itself is not described as shut down. The product, which allows self-custody card spending at Visa merchants, remains operational but the team is asking users to withdraw while they contain the exploit. The incident puts a fresh spotlight on smart contract wallet permission logic and transaction timing – a safety feature became a door for attackers.
Crypto payment tools are rapidly merging on-chain wallets with real-world spending, but code-level flaws can lead to direct fund loss. The Gnosis Pay case is not the first time a delay module has been exploited; similar vulnerabilities have been flagged in the past. Until the team issues a full patch and a green light, users are advised to stay alert and monitor official channels.

