Close Menu
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
What's Hot

Indonesia Blocks Polymarket After Users Bet on Prabowo Leaving Office Before 2029

May 25, 2026

Squid rushes to separate brand from $3 million Gnosis Safe module exploit

May 25, 2026

Is $20 Actually Within Reach This Cycle?

May 25, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
CatchTheBullCatchTheBull
  • Home
  • Crypto News
  • Bitcoin
  • Altcoin
  • Blockchain
  • Airdrops News
  • NFT News
CatchTheBullCatchTheBull
Bitcoin

Squid rushes to separate brand from $3 million Gnosis Safe module exploit

By WebDeskMay 25, 20264 Mins Read
Squid rushes to separate brand from  million Gnosis Safe module exploit
Share
Facebook Twitter LinkedIn Pinterest Email

Squid has moved quickly to stress that a recent $3 million exploit targeted a third party Gnosis Safe module called SquidRouterModule, not its core cross chain routing contracts, after 86 wallets on Ethereum and Base were drained in under two hours.

Summary

  • Blockaid flagged an active exploit on the SquidRouterModule affecting 86 Gnosis Safes
  • Around $3 million to $3.2 million was stolen and swapped into DAI via Uniswap
  • The vulnerability was a fixed string “message security” check that attackers reused
  • Squid says its main 0xce16F router contract and user funds are unaffected

According to on chain security firm Blockaid, the attack centered on a Gnosis Safe module named SquidRouterModule deployed on Ethereum and Base, which was used by some multisig owners to route cross chain transactions involving Squid and other protocols.

Blockaid reported that over roughly two hours the attacker siphoned funds from 86 Gnosis Safe wallets, with total losses of about $3 million to $3.2 million, before consolidating the proceeds into a single address holding just over 3.07 million DAI.

In a detailed summary, KuCoin’s news desk cites Blockaid and Squid as saying the stolen tokens were swapped into DAI via a custom Uniswap V3 pool set up by the attacker, who then aggregated the drained funds into one wallet to simplify laundering.

The core bug sat inside the SquidRouterModule’s “message security” logic: Binance Square coverage explains that the module simply accepted a constant string provided by the caller as proof that a message was valid, which meant anyone who could see the contract code could copy the string and pass arbitrary call data.

CoinNess reports that the attacker exploited this public fixed string verification to execute arbitrary calls from the affected Safes, effectively granting themselves permission to move assets out of the multisigs without owner confirmation.

How did the SquidRouterModule exploit drain 86 Gnosis Safes?

Binance’s incident note describes it bluntly, saying the design “accepted a fixed string provided by the caller for message security,” a pattern that eliminated any real authentication and opened a direct path for draining funds from integrated wallets.

This is a known class of risk for Gnosis Safe modules, as earlier research by OpenZeppelin showed that any attached module can execute transactions from a wallet without owner approval if its internal checks are weak or misconfigured.

In this case, the unsafe module was branded with the Squid name but was developed and deployed by a third party integrator, not by the Squid team or its core protocol maintainers.

Why is Squid distancing its core router from the hack?

In an official X post, Squid stated that “this incident is unrelated to Squid’s core protocol and contracts,” and emphasized that its main routing contract, identified on chain as 0xce16F69375520ab01377ce7B88f5BA8C48F8D666, “was not involved in any of the malicious transactions.”

This incident is unrelated to Squid’s core protocol and contracts. All Squid users and integrators are unaffected and no action is needed.

A third-party Gnosis Safe module was exploited today across Base and Ethereum, resulting in approximately $3.2M in losses. The vulnerable… https://t.co/I3gGmdBvE9

— squid (@squidrouter) May 25, 2026

KuCoin’s write up notes that Squid clarified the SquidRouterModule “was neither developed, deployed, nor operated by them; the name was independently chosen by a third party when integrating with Squid,” and that it sits completely outside the architecture of the core router.

The team further stressed that users’ funds, existing approvals and protocol level integrations remain secure, and that “Squid’s core cross chain routing remains unaffected,” while it continues to monitor the situation and coordinate with security firms.

Despite this, the optics are bad: as the KuCoin piece points out, headlines inevitably pair “Squid” with “hack,” even though the blast radius is limited to a sloppy Safe module whose only real connection to the project is the branding and its use of Squid as one of several integrated routers.

Security researchers have long warned that Gnosis Safe’s power comes with a caveat that any module plugged into a Safe can execute transactions without owner confirmations if its logic is flawed, which is exactly what happened here once the fixed string check was bypassed.

For the broader cross chain and wallet extension ecosystem, the SquidRouterModule incident is another concrete example of how composability plus lazy security assumptions in peripheral modules can open attack surfaces completely outside a protocol’s own contracts and audits.

It also underlines a painful reality for infrastructure teams like Squid, which Axelar describes as “a protocol that enables cross chain liquidity routing and swaps through a single SDK”: even when your own contracts are sound, third party wrappers can still drag your brand into exploit headlines if they fail basic security hygiene.


Credit:
Source link

Previous ArticleIs $20 Actually Within Reach This Cycle?
Next Article Indonesia Blocks Polymarket After Users Bet on Prabowo Leaving Office Before 2029

Related Posts

Indonesia Blocks Polymarket After Users Bet on Prabowo Leaving Office Before 2029

May 25, 2026

Eric Trump Sets A “Beyond Catastrophic” Bar To Sell Bitcoin — How Far Are We From That?

May 25, 2026

American Mega Bank Is Dumping Its Ethereum Holdings, Here’s What It’s Buying

May 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Indonesia Blocks Polymarket After Users Bet on Prabowo Leaving Office Before 2029

May 25, 2026

Squid rushes to separate brand from $3 million Gnosis Safe module exploit

May 25, 2026

Is $20 Actually Within Reach This Cycle?

May 25, 2026

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

Advertisement Banner

Welcome to CatchTheBull, your trusted source for the latest Crypto News and Airdrops. We bring you real-time updates, expert insights, and opportunities to stay ahead in the crypto world. Discover trending projects, market analyses, and airdrop details all in one place.

Join us on this journey to navigate the ever-evolving blockchain universe!

Facebook X (Twitter) Instagram YouTube
Top Insights

VALR Gets Provisional Cayman VASP License for Global Expansion

Why XRP Price Is Not Moving Forward?

Arthur Hayes Called $150 for HYPE, Then a Linked Wallet Sold at $54 and Paid $62 to Get Back In

Get Informed

Subscribe to Updates

Get the latest Crypto, Blockchain and Airdrop News from us to Catch The Bull.

© 2026 CatchTheBull. All Rights Are Reserved.
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$77,491.001.19%
  • ethereumEthereum(ETH)$2,125.181.32%
  • tetherTether(USDT)$1.000.03%
  • binancecoinBNB(BNB)$662.321.18%
  • rippleXRP(XRP)$1.360.81%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.840.65%
  • tronTRON(TRX)$0.3724791.39%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
  • dogecoinDogecoin(DOGE)$0.1029741.07%
  • HyperliquidHyperliquid(HYPE)$61.64-3.10%
  • USDSUSDS(USDS)$1.000.00%
  • zcashZcash(ZEC)$658.45-1.55%
  • leo-tokenLEO Token(LEO)$9.99-0.41%
  • cardanoCardano(ADA)$0.2461951.72%
  • moneroMonero(XMR)$384.91-2.53%
  • bitcoin-cashBitcoin Cash(BCH)$350.150.35%
  • chainlinkChainlink(LINK)$9.571.53%
  • whitebitWhiteBIT Coin(WBT)$57.091.11%
  • CantonCanton(CC)$0.165431-0.48%
  • the-open-networkToncoin(TON)$2.0516.58%
  • stellarStellar(XLM)$0.1507803.05%
  • USD1USD1(USD1)$1.00-0.02%
  • Ethena USDeEthena USDe(USDE)$1.000.04%
  • daiDai(DAI)$1.00-0.01%
  • suiSui(SUI)$1.051.43%
  • litecoinLitecoin(LTC)$52.920.34%
  • avalanche-2Avalanche(AVAX)$9.401.95%
  • hedera-hashgraphHedera(HBAR)$0.0889540.67%
  • MemeCoreMemeCore(M)$2.931.91%
  • RainRain(RAIN)$0.0079826.10%
  • paypal-usdPayPal USD(PYUSD)$1.000.02%
  • nearNEAR Protocol(NEAR)$2.7211.54%
  • shiba-inuShiba Inu(SHIB)$0.0000061.15%
  • crypto-com-chainCronos(CRO)$0.0693960.65%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • Global DollarGlobal Dollar(USDG)$1.000.01%
  • tether-goldTether Gold(XAUT)$4,547.700.99%
  • BittensorBittensor(TAO)$279.361.10%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • mantleMantle(MNT)$0.650.28%
  • polkadotPolkadot(DOT)$1.281.68%
  • pax-goldPAX Gold(PAXG)$4,557.130.96%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.130.38%
  • uniswapUniswap(UNI)$3.35-0.78%
  • OndoOndo(ONDO)$0.434814-1.29%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0618761.94%
  • HTX DAOHTX DAO(HTX)$0.0000020.69%
  • AsterAster(ASTER)$0.70-0.44%
  • okbOKB(OKB)$83.390.79%