Zodiac Discloses ERC-1271 Verification Flaw That Bypassed Module Authentication in Security Incident
2026-06-20 16:19

Woofun AI reports that Zodiac has published a post-mortem analysis regarding the security incident involving the Zodiac Roles Modifier. The investigation identified the root cause as a critical flaw in the ERC-1271 transaction signature verification logic, where the system validated signatures solely based on the returned 'magic value' without confirming the success of the underlying call. This oversight permitted failed verifications to be misinterpreted as valid signatures, enabling attackers to circumvent the module authentication mechanism. Zodiac clarified that exploitation required specific configurations, leaving EOA role members and deployments not utilizing the affected module unimpacted.

Concurrently, the team has deployed self-service detection and remediation tools for affected users. Collaborating with white-hat security teams, Zodiac has successfully secured over 99% of the at-risk funds. The compromised contracts have been patched and subjected to independent audits, resulting in the full restoration of normal service operations.

Disclaimer: Views are the author's own and do not represent the platform. Do not reproduce without permission. Content is for reference only, not investment advice. Trade at your own risk.
Tags:
Zodiac
Zodiac Roles Modifier
Share:
back