Community Notice: Zodiac Roles Modifier v2 and Delay Modifier v1.1.0 — Security Update
We identified a vulnerability in two Zodiac modules: Roles Modifier v2 and Delay Modifier v1.1.0. It affects only accounts where one of these modules is enabled AND a Safe account with a vulnerable fallback handler is itself assigned as a module or role member to the affected module.
Safe smart contracts, Safe{Wallet} infrastructure & UI are not affected.
Other Zodiac modules and setups are also not affected.
We've been working directly with affected users since identifying the issue. Over 95% of identifiable accounts have already resolved it.
If you have either module enabled and have not yet acted, check your account and follow the steps:
app.zodiac.eco/public/fallba…
We apologize for the disruption and concern this incident has caused. Our team is working as quickly as we can to support affected users and help wherever possible.
A full post-mortem will follow.
If you have any questions, reach us at security@gnosisguild.org