Gnosis Pay released a post-incident report stating that the theft of approximately $1.5 million in assets on June 1st was not caused by an external system intrusion, but rather by a flaw in the Zodiac smart contract framework upon which its card vault infrastructure relied. The company stated that all affected users have received full compensation, and card services were restored within days.
The vulnerability dates back to October 2023.
The company disclosed that the issue appeared in Zodiac version 3.4.0 and had existed since October 30, 2023, but had not been detected previously. Attackers exploited this flaw on June 1 to gain control of a portion of the assets in the Gnosis Pay decentralized self-custodied payment network.
Subsequent reports indicated that the primary affected components were two parts of the card vault: the Delay Module and the Roles Module. The stolen assets mainly consisted of tokens such as GNO, EURE, and USDC.e.
The monitoring system located the cause within two hours.
Gnosis Pay stated that its monitoring system, operated by the fund manager NOCA, detected the first unauthorized transfer at 06:17 UTC on June 1st. The engineering team identified the source of the problem within two hours of the initial , subsequently suspending card services and temporarily closing the bridging channel to Gnosis Chain.
The company also shared the attacker's wallet address with stablecoin issuers to help track fund flows, and notified external projects that might be exposed to similar vulnerabilities. Gnosis Pay disclosed the affected address as 0x5a7…7a35.
- The first abnormal transfer was detected at 06:17 UTC on June 1st.
- Number of affected wallets: 5,281
- Assets still pending recovery: approximately $300,000
The user has received compensation, and services are being restored in phases.
The company disclosed that after the new card-safe module was deployed, the first batch of affected accounts regained their balance and payment card access on the evening of June 3. Over the next few days, the system continued to be installed and restored in batches, and by June 6, 99% of users had their service restored; the remaining accounts were subsequently processed.
Gnosis Pay stated that the company will bear the losses itself, and users did not suffer any financial loss as a result of the attack. Approximately $300,000 in assets remain unrecovered, and the recovery efforts are ongoing.
This incident once again highlights the ongoing pressure that crypto payments and on-chain infrastructure face at the smart contract level. As attack methods continue to evolve, payment networks, bridging modules, and access control components are becoming key areas of focus for security audits.
Additional information:The post-incident report also mentioned that Gnosis Pay contacted external projects that might be using the same vulnerable component during the process to prevent the problem from spreading further.











