LIVE MARKET DATA THU 13 AUG 2026 UTC [ VIEW ALL COINS ]
// DeFi

Gnosis Pay’s $1.5M Zodiac breach: 06:17 UTC alert, 2-hour containment, zero socialized loss

Postmortem data: 5,281 wallets drained, 100% reimbursed from company funds, and a $300K gap between internal and external loss estimates.

James Corrigan · ·upd ·2 min read
Gnosis Pay’s $1.5M Zodiac breach: 06:17 UTC alert, 2-hour containment, zero socialized loss

Gnosis Pay’s July 3, 2026 postmortem quantifies a June 1 exploit that hit its card-safe infrastructure: roughly $1.5 million pulled from 5,281 wallets. All 5,281 accounts have been made whole, with the full deficit covered from company funds rather than spread across users.

Detection window: 06:17 UTC to isolation in ~2 hours

Treasury manager NOCA’s monitoring stack caught the first unauthorized transfer at 06:17 UTC on June 1. Gnosis Pay’s engineering team isolated the root cause — a flaw in a Zodiac module embedded in the card safe stack — within approximately two hours of that flag.

Response moved on two fronts simultaneously: card services were suspended network-wide, and the bridge connecting to Gnosis Chain was halted to cut off further transfer paths. Attacker addresses were passed to stablecoin issuers to support tracing and potential freezes, and other projects running the same Zodiac module configuration were notified of the underlying vulnerability.

$1.5M internal figure vs. $1.8M external estimate

Gnosis Pay’s own accounting puts the loss at roughly $1.5 million — meaningfully below the approximately $1.8 million figure that circulated in some outside coverage. The postmortem doesn’t reconcile that ~$300K gap; it states the lower total and treats full restitution of all 5,281 wallets as the operative outcome regardless of which number is used.

No per-wallet loss breakdown or asset composition has been published alongside the aggregate figures, leaving the distribution of the $1.5 million across accounts undisclosed. On X, the company’s public statement was terse: “On 1 June, Gnosis Pay experienced a security incident affecting card accounts. All affected balances were restored. Post-mortem here.”

Self-custodial rails, centralized backstop

Gnosis Pay operates as a self-custodial payment network, meaning funds normally sit under user control with no automatic backstop when the smart contract layer fails. A Zodiac module compromise inside the card safe stack is precisely that failure mode — infrastructure-level risk with no custodian contractually on the hook.

By publishing a timestamped detection-to-remediation log and absorbing the shortfall from company funds instead of user balances, Gnosis Pay sets a data point other self-custodial card providers will likely get benchmarked against. The postmortem stops short of naming concrete code fixes or audit commitments tied to the Zodiac module, so the prevention roadmap remains unpublished for now.

Read more: Tokenized RWA Market Hits $60B But Liquidity Concerns Persist, Experts Say

Sources

More DeFi