ChainCatcher reported that the Zodiac team has released an analysis report on a security incident affecting Zodiac Roles Modifier, disclosing that the root cause of the vulnerability lies in a flaw in the ERC-1271 transaction signature verification logic: the system determines signature validity solely based on the returned “magic value” without verifying whether the call itself was successful, which can result in failed verifications being disguised as valid signatures, thus bypassing the module’s authentication mechanism.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
