Gnosis Pay released an ex post facto report that the theft of approximately $1.5 million of assets on 1 June was not the result of an external system intrusion, but of deficiencies in the Zodiac smart contract framework on which its card vault infrastructure was based. According to the company, all affected users have been paid in full and card services have resumed within days.
The loophole dates back to October 2023
The company disclosed that the problem appeared in version 3.4.0 of Zodiac, which had existed since 30 October 2023 but had not been detected before. The attackers took advantage of the defect on 1 June and controlled Gnosis Pay ' s decentralised part of the self-hosted payment network.
After-action reports indicate that two components of the card vault were affected, Delay Module and Roles Module, respectively. The stolen assets are mainly in GNO, EURE, USDC, e, etc.
Monitoring system positioning reasons within two hours
Gnosis Pay states that the monitoring system operated by NOCA found the first unauthorized transfer at 06:17 UTC on 1 June. The team confirmed the source of the problem within two hours of the first alert, then suspended the card service and temporarily closed the bridge to Gnosis Chain.
The company also shared the offender ' s wallet address with the issuer of the stable currency to assist in tracking the flow of funds, while notifying external projects that might be exposed to similar loopholes. Gnosis Pay published address 0x5a7 7a35.
- First irregular transfer detected: June 1st 06:17 UTC
- Number of wallets affected: 5,281
- Still pending asset recovery: approximately $0.3 million
Users paid for and services restored in stages
The company disclosed that, following the completion of the deployment of the new card-safe module, the first affected accounts had been re-acquired with access to the balance and payment card during the evening of 3 June. Over the next few days, the system continued to be installed and restored in batches, with 99 per cent of users having resumed service on 6 June and the remaining accounts having been subsequently processed.
Gnosis Pay states that this loss was borne by the company itself and that the users did not suffer financial losses as a result of the attack. Some $0.3 million of assets remain unrecovered and the related recovery continues.
Once again, the incident reflects the continuing pressure on encrypted payments and chain infrastructure at the level of smart contracts. As the method of attack evolves, payment networks, bridging modules and rights management components are becoming the focus area for security clearance.
Additional information:The subsequent report also mentioned that Gnosis Pay had contacted external projects in parallel during the disposal process that might use the same faulty components to prevent further proliferation of the problem.
