
Gnosis Pay Hack Root Cause
The vulnerability was tied to Zodiac, an operating layer for Safe wallets. Any project using impacted Zodiac modules should check their exposure.
Gnosis Pay has fully contained a hack tied to a vulnerability in Zodiac, an operating layer for Safe wallets. The bug affected two specific modules, Roles Modifier v2 and Delay Modifier v1.1.0, which impacted accounts where one of the modules was enabled and a Safe with a vulnerable fallback handler was assigned as a module. The incident traces back to last week's delay module hack disclosure.
The vulnerability extended beyond just Gnosis Pay. Any project using Zodiac's Delay or Roles modules should check their exposure immediately. Safe smart contracts, Safe{Wallet} infrastructure, and other Zodiac modules are not affected. Gnosis Pay plans to begin restoring operations in batches over the coming days.
Gnosis Pay user will receive a new card Safe. Affected users will have funds migrated automatically. Unaffected users will go through a manual migration step.

ETHConf lands in NYC June 8-10, bringing together 5,000+ attendees, 150+ speakers, and 100+ companies across Ethereum, stablecoins, and institutional adoption.
Get your tickets at ethconf.com and use code ETHDAILY for 30% off General and 20% off VIP.
Disclaimer: Content is for informational and educational purposes only and does not constitute financial, investment, legal, or other professional advice. No representations or warranties are made as to accuracy, completeness, or timeliness. Use of this content is at your own risk, and you should consult a qualified professional before making decisions. No fiduciary or advisory relationship is created

Gnosis Pay Delay Module Hack
Gnosis Pay disclosed a bug in its delay module, and temporarily disabled the Gnosis Chain bridge as a precautionary measure.
Gnosis Pay disclosed a bug in its delay module, the component that sits between the Gnosis Pay card and the underlying Safe wallet. Gnosis Pay is a payments network that issues Visa debit cards linked directly to self-custodial Safe wallets, allowing users to spend crypto at any Visa-accepting merchant. Users were urged to withdraw funds from their Gnosis Pay card to their wallet.
Gnosis co-founder Martin Köppelmann confirmed the hack and said that all impacted funds will be reimbursed. As a precautionary measure, the Gnosis Chain bridge was temporarily disabled by bridge validators while the issue was investigated. No official all-clear has been issued as the incident is still developing.

ETHConf lands in NYC June 8-10, bringing together 5,000+ attendees, 150+ speakers, and 100+ companies across Ethereum, stablecoins, and institutional adoption.
Get your tickets at ethconf.com and use code ETHDAILY for 30% off General and 20% off VIP.
Disclaimer: Content is for informational and educational purposes only and does not constitute financial, investment, legal, or other professional advice. No representations or warranties are made as to accuracy, completeness, or timeliness. Use of this content is at your own risk, and you should consult a qualified professional before making decisions. No fiduciary or advisory relationship is created

L2BEAT Adds Gnosis Chain To L2 Tracker
L2BEAT lists Gnosis Chain, an EVM-compatible Ethereum sidechain with over $300 million in assets secured through its canonical bridge.
L2BEAT added Gnosis Chain to its Ethereum L2 analytics tracker. Gnosis Chain is an Ethereum sidechain with over $300 million in assets secured through its canonical bridge. The listing comes amid growing interest in the Ethereum Economic Zone (EEZ), a proposed framework that could eventually enable synchronous interoperability between EVM-compatible chains like Gnosis Chain.
L2Beat noted that the Gnosis bridge is secured by two 4/7 multisigs and administered by an 8/15 multisig. The central validator deposit contract, which escrows all staked GNO, is also upgradable by the 8/15 multisig. L2Beat highlighted Gnosis Chain's censorship resistance as it uses Ethereum's same single-proposer model. Gnosis is also piloting Shutterized Gnosis Chain Beta, an out-of-protocol, encrypted mempool implementation by Shutter Network.

Disclaimer: Content is for informational and educational purposes only and does not constitute financial, investment, legal, or other professional advice. No representations or warranties are made as to accuracy, completeness, or timeliness. Use of this content is at your own risk, and you should consult a qualified professional before making decisions. No fiduciary or advisory relationship is created
