Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Beyond Bitcoin Treasuries How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    Beyond Bitcoin Treasuries: How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    Exclusive Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Exclusive: Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Crypto PACs Reshape US Elections: Trump's Pro-Crypto Agenda Takes Shape
    Crypto PACs Reshape US Elections: Trump’s Pro-Crypto Agenda Takes Shape
    Bleak May 2026 $52M Stolen, $20B TVL Melt, and DeFi's Unsafe Reckoning
    Bleak May 2026: $52M Stolen, $20B TVL Melt, and DeFi’s “Unsafe” Reckoning
  • Opinion
    OpinionShow More
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Zodiac Reveals Flaw Behind Gnosis Pay Exploit, Safe Unaffected

The flaw impacted specific Zodiac module setups, while Safe smart contracts and wallet infrastructure remained unaffected, according to teams.

Written By:
Shubham Soni

Last updated: 49 minutes ago
Published 49 minutes ago
Share
Last updated: 49 minutes ago
Published 49 minutes ago
Zodiac Reveals Flaw Behind Gnosis Pay Exploit, Safe Unaffected
Show AI Summary
Vulnerability in Zodiac modules affects user accounts with specific configurations, potentially exposing them to unauthorized transactions.
Over 95% of identifiable affected accounts have taken corrective action, with users urged to review and mitigate their configurations.
The incident highlights the importance of secure third-party module integration, as the root cause is linked to flaws in Zodiac’s Roles Modifier and Delay Modifier modules.

The team behind Zodiac has disclosed the vulnerability linked to the recent Gnosis Pay security incident, revealing that the issue stemmed from flaws in two Zodiac modules rather than the underlying Safe wallet infrastructure.

In a security update posted on X on June 2, Zodiac said the vulnerability affected Roles Modifier v2 and Delay Modifier v1.1.0 under a specific set of conditions. The disclosure follows a security incident that prompted Gnosis Pay to halt bridge activity while teams worked to contain unauthorized transactions.

Community Notice: Zodiac Roles Modifier v2 and Delay Modifier v1.1.0 — Security Update

We identified a vulnerability in two Zodiac modules: Roles Modifier v2 and Delay Modifier v1.1.0. It affects only accounts where one of these modules is enabled AND a Safe account with a…

— Zodiac (@zodiaceco) June 2, 2026

Flaw limited to specific Zodiac configurations

According to Zodiac, the vulnerability only affected accounts where either the Roles Modifier v2 or Delay Modifier v1.1.0 module was enabled and where a Safe account using a vulnerable fallback handler had been assigned as a module or role member.

The team emphasized that the issue did not affect Safe smart contracts, Safe{Wallet} infrastructure, account recovery systems, or the Safe user interface. Zodiac also said other module configurations were not impacted.

The project stated that it had been working directly with affected users before publicly disclosing the issue and that more than 95% of identifiable affected accounts had already taken corrective action. Users with either module enabled were urged to review their configurations and apply the recommended mitigation steps.

Root cause linked to third-party modules

Following Zodiac’s disclosure, Safe Labs issued a clarification stating that the vulnerability originated in two third-party Zodiac modules rather than in Safe’s core infrastructure. 

An important clarification on the issue Zodiac has disclosed:

This is a vulnerability in two third-party Zodiac modules (Roles Modifier v2 and Delay Modifier v1.1.0).

Important: Safe smart contracts, Safe{Wallet} infrastructure and UI and account recovery, are not affected.… https://t.co/fTMyMFLyg2

— Safe{Labs} (@SafeLabs_) June 2, 2026

The organization reiterated that Safe smart contracts, wallet infrastructure, and user-facing systems were not affected. Safe Labs said it is coordinating with Zodiac, Gnosis, and members of the security community as response efforts continue.

Meanwhile, Co-Founder of Gnosis Martin Köppelmann said the newly disclosed vulnerability represents the root cause of the Gnosis Pay incident and noted that several projects beyond Gnosis Pay were affected. He added that teams had attempted to notify impacted projects privately before public disclosure.

Here is the root cause of the current Gnosis Pay incident. Several other projects are affected. We tried to inform everyone privately in advance, but if you haven’t heard yet and are using a Zodiac module — Delay or Roles — please urgently check whether you are affected 👇 https://t.co/NtC1i8CRgb

— koeppelmann (@koeppelmann) June 2, 2026

How the exploit impacted Gnosis Pay

The vulnerability came to light after Gnosis Pay disclosed an active exploit involving the Zodiac Delay Module. Gnosis Pay connects self-custody crypto wallets to a Visa-linked payment card system using Safe smart accounts and modular security components. One of those components, the Zodiac Delay Module, is designed to impose a waiting period between transaction approval and execution, providing time to detect and block unauthorized activity.

Investigators found that the vulnerability allowed attackers to bypass intended security controls and execute transactions from affected Safes. As the exploit unfolded, Gnosis coordinated with bridge validators to pause bridge operations and limit further movement of funds.

At the time of the incident, Köppelmann said the company expected to contain most losses and pledged that affected users would be fully reimbursed.

Gnosis Pay begins recovery process

As response efforts continued, Gnosis Pay said on June 2 that the incident had been fully contained and that operations would begin resuming in phases starting Wednesday evening (GMT+2).

In a detailed X thread, the company said every user will receive a new card-linked Safe connected to their existing card and identity profile. For users affected by the exploit, the new Safe will be funded with the same balance that was held previously. Unaffected users will be required to migrate funds from their existing Pay Safe to the new account structure.

Gnosis Pay also said it plans to release additional details about the incident at a later date and warned users to remain vigilant against scammers and impersonators attempting to exploit the situation. The company stressed that team members would not contact users privately or request funds through direct messages.

Post-mortem expected

Zodiac said a full post-mortem will be published once the investigation is complete. The team apologized for the disruption caused by the incident and said it continues to assist affected users.

The disclosure provides the clearest explanation so far of the technical issue behind the Gnosis Pay exploit, while narrowing its scope to a specific combination of Zodiac modules and Safe account configurations rather than a broader flaw in Safe’s wallet infrastructure.

Also Read: Coinbase Backs Ethena as ENA Surges on Adoption Expectations

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Shubham Soni Crypto Content Editor
By Shubham Soni
Follow:
Shubham Soni is a veteran content editor and journalist with over three years of experience leading digital editorial strategies across the U.S. and Indian markets. With a background in high-pressure newsrooms, Shubham specializes in the rigorous fact-checking, structural editing, and narrative development of complex news and explainers. Throughout his career at prominent digital publications like Sportskeeda and Opoyi, he has managed fast-paced desks covering global politics, sports, and entertainment. His expertise lies in transforming technical information into accessible, high-impact reporting while maintaining strict adherence to editorial ethics and accuracy. At The Crypto Times, Shubham oversees the editorial workflow, mentoring writers to ensure all cryptocurrency research and analysis meets the highest standards of clarity and journalistic integrity.

Latest News

CLARITY Act Reaches Senate Calendar as Crypto Awaits Verdict
CLARITY Act Reaches Senate Calendar as Crypto Awaits Verdict
XRP Enters Rare Oversold Zone as Traders Watch for Historic Reversal
XRP Enters Rare Oversold Zone as Traders Watch for Historic Reversal
Ethereum to Build Its “Quantum Shield” for Next Era of Crypto
Ethereum to Build Its “Quantum Shield” for Next Era of Crypto
Coinbase Backs Ethena as ENA Surges on Adoption Expectations
Coinbase Backs Ethena as ENA Surges on Adoption Expectations
Ethereum Price Falls 13% This Week as Breakdown Puts $1,600 in Focus
Ethereum Price Falls 13% This Week as Breakdown Puts $1,600 in Focus

Find Us on Socials

You may also like

Bitwise USCC Shares Cross $120M as Collateral on Aave Horizon

Bitwise USCC Shares Cross $120M as Collateral on Aave Horizon

TSR Token Collapses 99% Following 99M Token Mint Exploit on BNB Chain

TSR Token Collapses 99% Following 99M Token Mint Exploit on BNB Chain

Zcash Executes Emergency Fork After Critical Orchard Vulnerability Discovery

Zcash Executes Emergency Fork After Critical Orchard Vulnerability Discovery

Kelp DAO Hacker Finishes Laundering $220M, Only $1.7M Left in Main Wallet

Kelp DAO Hacker Finishes Laundering $220M, Only $1.7M Left in Main Wallet

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information