BackERC-1271

ERC-1271

Circle Gatewa
2026-08-04 16:45:21

Circle Gateway Adds ERC-1271 Support for Programmable Authorization

Circle Gateway has introduced support for ERC-1271 signatures, enabling a programmable authorization model. This allows smart contracts and smart contract wallets to use Gateway directly. Developers can leverage existing smart contract authorization logic to access a unified USDC balance system without setting up delegated approvers.

630
Circle Gateway Adds ERC-1271 Support for Programmable Authorization
Gnosis Pay
2026-07-03 13:42:26

Gnosis Pay Post-Mortem: ERC-1271 Validation Flaw Led to $1.5 Million Exploit

Gnosis Pay has released a post-mortem on its June 1 security incident, identifying the root cause as a flaw in ERC-1271 signature validation within the Zodiac module. According to the report, the system only checked the contract’s return value and failed to verify whether the call had actually executed successfully. An attacker exploited this by deploying a contract designed to fail while still returning a value interpreted as “valid,” enabling forged authorization and unauthorized withdrawals from accounts they did not own. The vulnerability was introduced in Zodiac code version 3.4.0 in October 2023 and was patched on June 5. Gnosis Pay said the attacker extracted around $1.5 million across 5,281 wallets, including roughly $641,000 in GNO, $453,000 in EURe, and $399,000 in USDC.e. Another approximately $300,000 remains locked in inaccessible accounts, with recovery options still under review. The team said it will expand its security team, bring in external audits, widen smart contract audit coverage, and has already completed a full product rebuild under v2 to improve security and incident response capabilities.

760
Gnosis Pay Post-Mortem: ERC-1271 Validation Flaw Led to $1.5 Million Exploit
Zodiac
2026-06-20 08:19:54

Zodiac Post-Mortem Says ERC-1271 Validation Flaw Allowed Module Authentication Bypass

Zodiac published a full post-mortem on the June 1 incident affecting Zodiac Roles Modifier v2.1.0 and Delay Modifier v1.1.0. The team said its ERC-1271 contract-signature check accepted signatures based only on the returned magic value without verifying that the call had succeeded, allowing a failed check to appear valid in a narrow Safe configuration.

250
Zodiac Post-Mortem Says ERC-1271 Validation Flaw Allowed Module Authentication Bypass