Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Crypto PACs Reshape US Elections: Trump's Pro-Crypto Agenda Takes Shape
    Crypto PACs Reshape US Elections: Trump’s Pro-Crypto Agenda Takes Shape
    Bleak May 2026 $52M Stolen, $20B TVL Melt, and DeFi's Unsafe Reckoning
    Bleak May 2026: $52M Stolen, $20B TVL Melt, and DeFi’s “Unsafe” Reckoning
    Crypto’s Historic May 2026 Inside the CLARITY Act, Trump EO & Fed Shift
    Crypto’s Historic May 2026: Inside the CLARITY Act, Trump EO & Fed Shift
    CLARITY Act Shields Crypto Developers, But One Criminal Line Could Gut It
    CLARITY Act Shields Crypto Developers, But One Criminal Line Could Gut It
    The Web3 Job Scam Draining Crypto Wallets Worldwide
    The Web3 Job Scam Draining Crypto Wallets Worldwide
  • Opinion
    OpinionShow More
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Gnosis Pay Pauses Bridge Following Active Zodiac Delay Module Exploit

Co-Founder Martin Köppelmann said that most users cannot withdraw funds now but expects to contain most losses and promises full reimbursement to affected users.

Written By:
Kenrodgers Fabian

Reviewed By:
Divya Mistry

Last updated: 54 minutes ago
Published 54 minutes ago
Share
Last updated: 54 minutes ago
Published 54 minutes ago
Gnosis Pay Pauses Bridge Following Active Zodiac Delay Module Exploit
Show AI Summary
Attackers exploited a Zodiac Delay Module vulnerability to bypass security gates in Gnosis Pay’s smart contract system.
The breach manipulated a safety feature designed to introduce a time delay between transactions, allowing unauthorized actions to occur.
Gnosis Pay’s Safe wallet smart accounts, enhanced with modular components, were compromised due to the implementation flaw.

Gnosis has moved to contain a security breach affecting its Gnosis Pay after attackers exploited a vulnerability in the Zodiac Delay Module. Co-Founder Martin Köppelmann confirmed the incident on X, saying the company will compensate all affected users. 

The company asked bridge validators to pause related bridge activity as it worked to limit further damage. Köppelmann initially warned users about an active exploit, writing: “Unfortunately, there is a hack related to @gnosispay and the ‘delay module’. Please be patient while we try to contain the damage. Rest assured, Gnosis will cover all user losses.”

Deleted an earlier tweet that asked users to withdraw funds. Most users will not be able to do so, but we are actively working to contain the damage. We believe we can contain the majority of it, and in any case, we will ensure that all users are made whole.

— koeppelmann (@koeppelmann) June 1, 2026

Additionally, he also clarified that an earlier message asking users to withdraw funds had been deleted. “Most users will not be able to do so, but we are actively working to contain the damage. We believe we can contain the majority of it, and in any case, we will ensure that all users are made whole,” he said.

Anatomy of the Zodiac Delay flaw

Gnosis Pay functions by attaching self-custody crypto wallets to everyday consumer spending via a Visa-linked debit card system. To make this safe, the platform utilizes Safe wallet smart accounts enhanced by modular programming components.

One of these core layers is the Zodiac Delay Module, a smart contract modifier engineered to act as a security backstop. It forces a mandatory time delay between when an external transaction is initiated and when it actually executes on-chain. This buffer window is supposed to give defense protocols time to identify and veto unauthorized actions. 

However, the attacker discovered an implementation flaw that completely flipped this security feature. The bug allowed the exploit tool to bypass verification gates and initiate outbound transactions directly from Safes that had the module turned on.

As the exploit unfolded, Köppelmann noted that most retail users would be locked out from executing manual defensive withdrawals. In response, Gnosis teams moved to freeze the protocol by coordinating with validator networks to shut down all outbound bridge paths, cutting off the attacker’s exit routes.

Delay module faces new scrutiny

At press time, Gnosis Pay has not yet released an estimate of the total losses from the security breach. The company has also not published a full technical report on how the exploit occurred. As a result, it remains unclear how many users or accounts were affected. The project said it is still investigating whether all malicious activity has been fully stopped.

The incident has also renewed attention on risks linked to smart contract-based payment systems. Gnosis Pay connects self-custody crypto wallets to everyday spending through a Visa-linked card system.

While this setup allows users to spend crypto in real-world transactions, it also means that weaknesses in permission controls or smart contract modules can expose users to financial risk.

Recent attacks add context

The latest incident comes after another security breach involving infrastructure linked to Gnosis Safe. In that earlier attack, hackers stole about $3 million from 86 Safe wallets across Ethereum and Base, according to blockchain security firm Blockaid. The firm said the exploit was tied to a vulnerable third-party module called SquidRouterModule.

Blockaid reported that attackers took advantage of a flaw in the module’s executeSameChainActions() function. This allowed them to act as trusted delegates and approve transactions without authorization. The stolen funds were then swapped into DAI using liquidity pools on Uniswap V3 controlled by the attackers.

Separately, Gnosis has recently taken a more active approach to recovering lost funds. In April, Gnosis Chain carried out a hard fork that recovered $9.4 million linked to the November 2024 Balancer hack. The recovered assets were moved into a DAO-controlled wallet, while the community debated how the funds should be distributed.

The incidents highlight ongoing challenges in balancing user protection, decentralization, and rapid incident response in crypto systems.

Also Read: Whitehat Hacker Unlocks $2M Stuck in 2016 Ethereum ICO Contract

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Divya Mistry - Content Editor at The Crypto Times
By Divya Mistry
Follow:
Divya Mistry is a Content Editor with over 9 years of experience in news, PR, marketing, and research. Armed with a Master’s Degree in English Literature from the University of Mumbai, she specializes in crafting and refining long-form content across digital and print platforms. Over the years, Divya has contributed to and shaped content for leading brands across a range of industries, including real estate, healthcare, vertical transport, entertainment, lifestyle, education, EdTech, tech, and finance. Her research work has been featured on platforms like DNA India, Forbes, and Elevator World India. She now brings her editorial and research skills to explore the rapidly evolving world of cryptocurrency.

Latest News

Japan’s Ruling Party Demands Yen Stablecoins and Crypto ETFs
Japan’s Ruling Party Demands Yen Stablecoins and Crypto ETFs
Binance Adds 7,000 U.S. Stocks and Plans bStocks on BNB Chain
Binance Adds 7,000 U.S. Stocks and Plans bStocks on BNB Chain
ECB Warns Dollar-Backed Stablecoins Threaten Global Monetary Sovereignty
ECB Warns Dollar-Backed Stablecoins Threaten Global Monetary Sovereignty
Sen. Lummis U.S. Will 'Watch From the Sidelines' Without CLARITY Act
Sen. Lummis: U.S. Will ‘Watch From the Sidelines’ Without CLARITY Act
Vietnam Proposes Using Digital Assets as Loan Collateral for SMEs 
Vietnam Proposes Using Digital Assets as Loan Collateral for SMEs 

Find Us on Socials

You may also like

Whitehat Hacker Unlocks $2M Stuck in 2016 Ethereum ICO Contract

Whitehat Hacker Unlocks $2M Stuck in 2016 Ethereum ICO Contract

May Crypto Exploits Drop 90% to $68.3M Despite Severe Bridge Hacks

May Crypto Exploits Drop 90% to $68.3M Despite Severe Bridge Hacks

Aave Restores rsETH Backing in Full, but $71M Court Battle Drags On

Aave Restores rsETH Backing in Full, but $71M Court Battle Drags On

BullX Suspends Trading App to Focus on Next-Gen Version Upgrades

BullX Suspends Trading App to Focus on Next-Gen Version Upgrades

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information