Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • Indices
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Indices
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Delay Module Trick Costs GnosisPay $265K, Reports CertiK

Attackers abused a Delay module verification bug and EIP-1271 signature validation to drain funds from 41 GnosisPay Safes.

Written By Sharmistha Suman
Fact Checked by Jahnu Jagtap
Published 2026-06-05·Updated 1 month ago
Make The Crypto Times preferred on GoogleGoogle
Delay Module Trick Costs GnosisPay $265K, Reports CertiK

Key Highlights

  • CertiK reported a $265,000 exploit targeting GnosisPay Safes on June 1.
  • Attackers exploited a signature-verification flaw in the Delay module.
  • The exploit affected 41 Safes and drained EURe and GNO tokens.

Blockchain security firm Certik has published a comprehensive analysis of a sophisticated exploit targeting GnosisPay Safes on the Gnosis Chain, which occurred on June 1, 2026. The attack resulted in the drainage of funds from dozens of safes, with total losses estimated at approximately $265,000 in EURe and GNO tokens.

According to Certik’s report, the exploit centered on a signature-verification flaw within the GnosisPay Delay module. This module is designed to add a security layer through time-delayed transaction execution, requiring signatures for authorization. However, the attacker exploited how the module’s moduleTxSignedBy() function parses r, s, and v values from the msg.data calldata.

#CertiKInsight 🚨

On 1 June, GnosisPay was exploited, resulting in a loss of ~$265K.

To learn more about what happened, read our full analysis here 👇https://t.co/VIFD5sjrLO

— CertiK Alert (@CertiKAlert) June 5, 2026

Unfolding the attack 

The attack unfolded in carefully orchestrated stages. On May 29, the attacker first deployed 41 specialized attack contracts. These contracts were engineered to always return the EIP-1271 magic value when called via isValidSignature(), effectively impersonating legitimate signers without providing valid cryptographic proof.

The core exploitation occurred on June 1 at approximately 5:26 AM. The attacker invoked Delay.execTransactionFromModule(), crafting a complex msg.data payload. During verification in the moduleOnly() modifier, the function extracted signature components from the unparsed section of the calldata. 

The verification process traversed through a legitimate Biconomy Safe before reaching the attacker-controlled contract. By manipulating the r value, the system was tricked into accepting the malicious transaction. Although a static call to the attack contract technically reverted, the returned magic value was misinterpreted as valid authorization.

Following a mandatory cooldown period enforced by the Delay module, the attacker executed the queued transactions around 5:57 AM on the same day. Each transaction transferred EURe and GNO from victim Gnosis Safes directly to attacker-controlled wallets. In total, 41 such transactions were processed, systematically draining the affected accounts.

Certik’s report provides granular details on the technical root cause: improper handling of nested signature data in moduleTxSignedBy(), where the entire msg.data influenced verification rather than strictly the intended transaction parameters. This allowed the attacker to layer signatures, leveraging an intermediate Biconomy Safe and ultimately an always-compliant malicious contract.

Flow of funds in the attack 

Beyond the technical mechanics, fund flow analysis reveals the attacker’s post-exploit laundering efforts. The primary exploit wallet (0x81BA8A2b895D30280bca199C2Ff75f3F058d4C6c) bridged roughly $246,000 worth of USDT from Ethereum to the Hyperliquid network. 

Funds were subsequently routed to another address (0xb1834575349c6eb56675c35b4109c3d3a77dd2fc), where portions were swapped for Monero (XMR), a privacy-focused cryptocurrency often used to obscure trails.

Complexities in established protocols 

The GnosisPay incident serves as a stark reminder of the complexities involved in securing modular smart contract systems. Gnosis Safes, widely regarded for their multi-signature security features, were compromised not through direct key theft but via a subtle flaw in an integrated delay mechanism. This attack demonstrates how even established protocols can fall victim to advanced calldata manipulation and EIP-1271 signature validation bypasses.

Such incidents underscore the need for more rigorous auditing of interdependent modules and improved isolation between transaction data and signature verification logic. As DeFi continues to mature, projects must prioritize defensive programming patterns that guard against nested or malformed calldata attacks.

The exploit, while relatively modest in scale compared to some past DeFi hacks, illustrates the persistent cat-and-mouse game between security teams and adversaries. With blockchain ecosystems handling billions in value, incidents like this reinforce the critical importance of continuous security research and proactive vulnerability disclosure.

Also Read: Congress Eyes Sweeping Crypto Tax Reform Through Seven Drafts

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BlockchainCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Tokenized Stock Market Cap Hits $3.1B All-Time High
Core DAO Fixes Reward Exploit, Claws Back 186M CORE
Core DAO Fixes Reward Exploit, Claws Back 186M CORE
Lummis Says CLARITY Act Could Protect Crypto Users From Exchange Failures 
Lummis Says CLARITY Act Could Protect Crypto Users From Exchange Failures 
XRPL Agent Payments Exceed 4 Million Transactions
XRPL Agent Payments Exceed 4 Million Transactions
LeBron James Partners With Prediction Platform Polymarket
LeBron James Partners With Prediction Platform Polymarket

Find Us on Socials

You may also like

Kyrgyz President Outlines Crypto and Blockchain Goals

Kyrgyz President Advances Crypto and Blockchain Goals

Nasdaq-Listed Tron Inc. Adds 151,270 TRX to Treasury

Nasdaq-Listed Tron Inc. Adds 151,270 TRX to Treasury

Robinhood Chain Activity Raises Questions Over New-User Adoption

Robinhood Chain Activity Raises Questions Over New-User Adoption

Router Protocol logo on a dark wall

Router Protocol To Shut Down by September 30 as Cross-Chain Bridging Economics Turn Negative

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information