Gnosis Pay Hack: Exploit Forces Users to Immediately Withdraw All Funds!

Gnosis Pay exploit tied to Zodiac delay module as users exit

Gnosis Pay users were advised to remove their money from the platform after a security issue was discovered in its Zodiac delay module, as reported by Gnosis co-founder Martin Köppelmann and blockchain security experts PeckShield.

Summary

  • Gnosis Pay users were told to withdraw EURe and GNO after a delay module exploit.
  • Köppelmann said the bug lets an attacker initiate transactions from Safes using the module.
  • Gnosis said it would cover user losses while asking bridge validators to pause activity.

Martin Köppelmann has advised Gnosis Pay users to withdraw all their funds, including EURe and GNO, due to recent developments.

He reported a problem with the delay feature and cautioned users that it could cause issues. He advised users to temporarily remove their EURe and GNO tokens from Gnosis Pay while the team fixed the bug.

PeckShield advises users to immediately withdraw all of their EURe and GNO funds, according to a recent alert.

I’m seeing reports of an active exploit impacting Gnosis Pay. I strongly recommend that all users immediately withdraw any funds they have on the platform, including EURe and GNO tokens. It’s crucial to check your accounts to see if you might be affected.

— PeckShieldAlert (@PeckShieldAlert) June 1, 2026

The blockchain security company stated that Köppelmann had alerted them to a current security issue with Gnosis Pay. They advised users to review their accounts to see if they were impacted.

Zodiac delay module bug tied to attack

“The bug is related to the Zodiac delay module,” Köppelmann said in a later update.

According to him, the attacker can start transactions within Safes that utilize the delay feature. This update provides a more detailed explanation of how the security flaw works, expanding on the initial alert which only mentioned a problem with the delay module.

The issue involves the “Zodiac delay module,” which allows someone to start transactions from Safes even with a delay in place. We’re taking steps to limit the impact, including requesting that bridge validators temporarily pause operations.

— koeppelmann (@koeppelmann) June 1, 2026

Gnosis Pay utilizes accounts built on Safe technology, enhanced with smart contract features. According to Gnosis Pay’s documentation, these accounts employ a Delay Module and a Roles Module, which enable card payments while still giving users full control over their funds.

The Delay Module adds a brief pause before transactions are processed. This allows users a short window to review and potentially react before the transfers finalize.

Gnosis moves to contain damage

We’re taking steps to limit the harm, including requesting bridge validators to temporarily stop their work,” Köppelmann explained.

Gnosis is collaborating with external services to address the recent security incident. Because bridge validators are involved in transferring assets between blockchains, temporarily pausing these processes could limit the flow of compromised funds.

“Rest assured, Gnosis will cover all user losses,” Köppelmann said.

As of now, the total financial loss remains unknown. The team hasn’t yet shared a complete report detailing the scope of the incident, including how many accounts were impacted or if the attack is fully contained.

Wider payment security context

As crypto.news reported earlier, Gnosis Pay has released a card that lets users spend their cryptocurrency at any Visa-accepting business, all while maintaining full control of their funds. The card bridges the gap between digital wallets and everyday purchases.

This design positions Gnosis Pay among the increasing number of crypto payment tools leveraging smart contracts for daily purchases. It also highlights the importance of the code governing wallet access and when transactions happen.

The recent announcement doesn’t state that Gnosis Pay is closing. Instead, it advises users to withdraw their EURe and GNO tokens while the team addresses a security issue.

Read More

2026-06-01 12:47