Zodiac Releases Security Incident Report: ERC-1271 Verification Flaw Previously Enabled Attackers to Bypass Module Authentication
The Zodiac team released a security incident analysis report regarding the impact on the Zodiac Roles Modifier, disclosing that the root cause of the vulnerability lies in a flaw in the ERC-1271 transaction signature verification logic: the system determines signature validity solely based on the returned “magic value,” without verifying whether the call itself succeeded—thus potentially allowing failed verifications to be masqueraded as valid signatures and bypassing the module’s authentication mechanism.