According to the official announcement, Gnosis Pay has released a post-incident review report on the security incident of June 1, disclosing that the vulnerability stemmed from a flaw in the ERC-1271 signature verification logic within the Zodiac module.
The system only reads the contract's return result without verifying whether the call was actually executed successfully. Attackers exploit this by deploying a contract that intentionally fails but still returns a "valid" indicator, falsely authorizing the withdrawal of funds from accounts they do not own.
The vulnerability was introduced in October 2023 with Zodiac code version 3.4.0 and was patched on June 5.
The report shows that the attackers withdrew approximately $1.5 million across 5,281 wallets, including about $641,000 in GNO, $453,000 in EURe, and $399,000 in USDC.e.
An additional $300,000 in funds is locked in inaccessible accounts, and the team is exploring recovery options. Gnosis Pay stated that it will subsequently expand its security team, engage external audits, and broaden the scope of smart contract audits.
