The DeFi Report - Sponsor Image The DeFi Report - Industry-leading crypto research trusted by finance pros. Friend & Sponsor Learn more

Gnosis Pay Hit with Module Attack

Victims will be reimbursed, but questions about the attack vector remain.
Gnosis Pay Hit with Module Attack
Listen
0
0
0:00 0:00

Subscribe to Bankless or sign in

Gnosis Gnosis confirmed a bug and ensuing exploit tied to Gnosis Pay's Zodiac delay module today. In the wake of the attack, Gnosis cofounder Martin Koppelmann said the company "will cover all user losses."

What's the Scoop?

  • The Vector: The Zodiac delay module was compromised in a way that let the attacker push transactions into users' queues across many wallets simultaneously. Notably, the attack didn't touch users' private keys, and the full extent of losses hasn't been confirmed yet.
  • Possible Pattern: The incident comes on the heels of a separate exploit last week that drained +$3M from dozens of Gnosis Safe wallets through a compromised community module, SquidRouterModule. It's unclear if the exploits are connected, but either way the module attack surface deserves more scrutiny now.


No Responses
Rechercher sur Bankless