Zodiac Releases Security Incident Report: ERC-1271 Verification Flaw Previously Allowed Attackers to Bypass Module Authentication

robot
Abstract generation in progress

Deep Tide TechFlow News, June 20th, the Zodiac team released an security incident analysis report regarding the impact on Zodiac Roles Modifier, revealing that the root cause of the vulnerability lies in a flaw in the ERC-1271 transaction signature verification logic: the system only determines the validity of the signature based on the returned “magic value” and does not verify whether the call itself was successful, potentially disguising failed verifications as valid signatures and bypassing module authentication mechanisms.

Zodiac clarified that this vulnerability can only be exploited under specific configurations, and EOA role members and other deployments not using the relevant modules are unaffected. Currently, affected users have been notified and self-service detection and repair tools have been launched, and a joint effort with white hat teams is underway to recover assets. Over 99% of the potentially at-risk funds have been protected, and the related contracts have been repaired and passed independent audits, with services restored to normal.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned