Gnosis Pay suffered an active exploit on June 1, 2026 through the Zodiac delay module, allowing attackers to initiate transactions from Safe wallets. Co-founder Martin Koppelmann pledged Gnosis will cover all user losses. The bug sits within Gnosis Pay's permission layer, not Safe's core contracts. Safe spun out from Gnosis in 2022 after raising $100 million. Days earlier, a separate exploit drained $3.2 million from 86 Gnosis Safe wallets via the SquidRouterModule.
Gnosis Pay exploit details
- ▪The Gnosis Pay exploit allowed the attacker to initiate transactions from Safe wallets carrying the Zodiac delay module
- ▪Gnosis asked bridge validators to pause as part of its containment response to the Gnosis Pay exploit
- ▪Gnosis Pay suffered an active exploit on June 1, 2026
- ▪Gnosis is an Ethereum infrastructure organization co-founded by Martin Koppelmann
Zodiac delay module vulnerability
- ▪Blockchain security firm PeckShield flagged the active Gnosis Pay exploit and warned users to check their exposure
- ▪The delay-module bug sits within the Gnosis Pay system, not Safe's core contracts
- ▪The Gnosis Pay exploit exploited the Zodiac delay module, a permission layer that allows transactions to be queued before execution
User reimbursement commitment
- ▪Martin Koppelmann is the co-founder and CEO of Gnosis
- ▪Martin Koppelmann confirmed on June 1, 2026 that Gnosis will cover all user losses from the Gnosis Pay exploit
- ▪Martin Koppelmann deleted an earlier post that urged all Gnosis Pay users to withdraw EURe and GNO immediately
- ▪Martin Koppelmann stated that Gnosis will ensure all Gnosis Pay users are made whole regardless of containment success
Safe wallet infrastructure
- ▪Safe spun out from Gnosis in 2022 as an independent entity after raising $100 million
- ▪Gnosis Pay is built on Safe's smart contract wallet infrastructure
- ▪Safe secures the self-custodial wallets underlying every Gnosis Pay card
Recent SquidRouterModule incident
- ▪A separate exploit drained $3.2 million from 86 Gnosis Safe wallets via a vulnerable third-party module called SquidRouterModule days before June 1, 2026
- ▪The SquidRouterModule incident involved weak identity validation in an unofficial module, allowing attackers to execute arbitrary calldata without requiring wallet signatures
Story comments
Loading comments…