Gnosis co-founder and CEO Martin Koppelmann confirmed to The Block that the Zodiac delay module associated with the Gnosis Pay system is currently under active exploitation. Gnosis Pay is a payment platform that enables users to spend assets from their Safe multisig wallets for everyday purchases, with the Zodiac delay module designed to add a mandatory waiting period to every transaction. However, attackers discovered a way to bypass this safety mechanism and are initiating unauthorized transactions from Safe wallets that have integrated the module. Gnosis stressed that the vulnerability resides solely within the Gnosis Pay system, and the core Safe smart contracts remain unaffected.
Exploit Details and Impact Scope
The Zodiac delay module serves as a buffer, preventing immediate execution of transfers. By exploiting the flaw, malicious actors could potentially move funds through cross-chain bridges, prompting Gnosis to immediately reach out to relevant bridge validator nodes and request they suspend operations to contain the risk. The company noted that an earlier public advisory urging users to urgently withdraw EURe and GNO tokens has been retracted because the vast majority of ordinary users lack the technical means to self-custody and extract funds directly, and continuing to push that instruction would have been counterproductive.
Mitigation Measures and Compensation Pledge
Koppelmann stated unequivocally that Gnosis will absorb all user losses resulting from the exploit. The team is working intensively to control the situation, minimize the damage, and guarantee that every affected user receives full compensation without any additional conditions. Gnosis is collaborating closely with security teams and bridge validators to patch the issue and evaluate follow-up upgrades to prevent recurrence.
The incident highlights that even in a mature multisig wallet ecosystem, the security of peripheral modules is just as critical as core contracts. Nevertheless, the official statement reiterated that the Safe core contract design and code were not exploited in this attack, and assets held through standard Safe accounts remain secure.

