logo

GnosisPay Incident Analysis

ID: b3af1ee6-c91c-5643-9170-48eb7dff120b

STIX ID: report--b3af1ee6-c91c-5643-9170-48eb7dff120b

Feed Name: CertiK Blog

Threat Score
72/100

Date Published: 2026-06-05

Date Updated: 2026-06-11

...
...

On 01 June 2026 an attacker exploited a signature-verification flaw in the GnosisPay Delay module to queue and later execute 41 transactions that transferred EURe and GNO from multiple GnosisPay Safes to attacker-controlled wallets (~$265K loss). The attacker used crafted nested r,s,v signature calldata so verification reached an attacker contract that returned the EIP-1271 magic value; funds were bridged and partially swapped for XMR and distributed across wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.