Gnosis Pay discloses the reason for the $1.5 million theft.
crypto.news
07-04 05:48
Ai Focus
Gnosis Pay stated that the $1.5 million theft stemmed from a long-undetected smart contract flaw, and affected users have received full compensation.
Helpful
No.Help

Gnosis Pay released a post-incident report stating that the theft of approximately $1.5 million in assets on June 1st was not caused by an external system intrusion, but rather by a flaw in the Zodiac smart contract framework upon which its card vault infrastructure relied. The company stated that all affected users have received full compensation, and card services were restored within days.

The vulnerability dates back to October 2023.

The company disclosed that the issue appeared in Zodiac version 3.4.0 and had existed since October 30, 2023, but had not been detected previously. Attackers exploited this flaw on June 1 to gain control of a portion of the assets in the Gnosis Pay decentralized self-custodied payment network.

Subsequent reports indicated that the primary affected components were two parts of the card vault: the Delay Module and the Roles Module. The stolen assets mainly consisted of tokens such as GNO, EURE, and USDC.e.

The monitoring system located the cause within two hours.

Gnosis Pay stated that its monitoring system, operated by the fund manager NOCA, detected the first unauthorized transfer at 06:17 UTC on June 1st. The engineering team identified the source of the problem within two hours of the initial , subsequently suspending card services and temporarily closing the bridging channel to Gnosis Chain.

The company also shared the attacker's wallet address with stablecoin issuers to help track fund flows, and notified external projects that might be exposed to similar vulnerabilities. Gnosis Pay disclosed the affected address as 0x5a7…7a35.

  • The first abnormal transfer was detected at 06:17 UTC on June 1st.
  • Number of affected wallets: 5,281
  • Assets still pending recovery: approximately $300,000

The user has received compensation, and services are being restored in phases.

The company disclosed that after the new card-safe module was deployed, the first batch of affected accounts regained their balance and payment card access on the evening of June 3. Over the next few days, the system continued to be installed and restored in batches, and by June 6, 99% of users had their service restored; the remaining accounts were subsequently processed.

Gnosis Pay stated that the company will bear the losses itself, and users did not suffer any financial loss as a result of the attack. Approximately $300,000 in assets remain unrecovered, and the recovery efforts are ongoing.

This incident once again highlights the ongoing pressure that crypto payments and on-chain infrastructure face at the smart contract level. As attack methods continue to evolve, payment networks, bridging modules, and access control components are becoming key areas of focus for security audits.

Additional information:The post-incident report also mentioned that Gnosis Pay contacted external projects that might be using the same vulnerable component during the process to prevent the problem from spreading further.

Tip
$0
Like
1
Save
1
Views 354
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Ethereum: Standard Chartered is bullish on the Arbitrum ecosystem, stating that ARB may benefit from tokenized assets
Standard Chartered expects that by ARB, it may rise to $10 by 2030. Robinhood Chain and tokenized assets are seen as the main drivers, and large-scale whale transactions on the chain are also heating up.
CoinPedia
·2026-09-15 22:28:18
20
web3: Binance will take offline 5 margin trading pairs
Binance will take offline 5 full-position margin trading pairs on September 18th, and will also stop the spot trading of USDP on September 24th.
U.Today
·2026-09-15 22:28:17
18
Foreign media: AI's slowdown commitment cannot withstand the pressure of business and Sino-US competition
Foreign media analysis suggests that if AI company lacks mandatory safety standards and independent supervision, its commitment to slowing down research and development may fail under the pressure of commercial competition and Sino-US tensions.
Coinpaper
·2026-09-15 22:28:15
17
AI Security Startup AIUC Completes $40 Million Series A Financing
AI Security startup completes $40 million Series A financing, focusing on enterprises AI Acting as third-party audit and certification.
TechCrunch
·2026-09-15 21:31:22
25
web3: BlackRock Bitcoin holdings increase again, IBIT continues to attract funds
BlackRock's Bitcoin ETF continues to attract funds, with the holding scale further expanding; Grayscale recorded capital outflows during the same period.
U.Today
·2026-09-15 20:36:14
41
View More