Gnosis co-founder alerts users to immediately withdraw EURe and GNO from Gnosis Pay due to a critical bug in the Delay module security feature.
Security & Exploits ·
An exploit affecting Gnosis Pay has prompted co-founder Martin Koppelmann to pledge that all user losses will be covered, with containment efforts ongoing. The vulnerability targeted the Delay module, a security feature within Gnosis Pay, enabling attackers to execute unauthorized transactions from compromised wallets. Users were advised to immediately withdraw EURe and GNO tokens from the platform.
The Delay module was designed to add a time buffer before transactions execute, a safeguard that was circumvented in the attack. The breach created a window during which adversaries could initiate transfers without proper authorization, putting customer assets at direct risk. The scope of affected accounts and the total financial exposure remain unspecified in available reports.
Gnosis has committed to reimbursing impacted users in full, though the mechanics of the compensation process—including timeline, verification procedures, and any conditions—have not been detailed. The status of the platform's broader security posture and whether additional vulnerabilities exist are not yet confirmed.