Squid clarifies it was not directly involved in the misuse of Gnosis Safe ecosystem modules.
Coinpaper
05-26 17:14
Ai Focus
A third-party module within the Gnosis Safe ecosystem was exploited, resulting in the theft of approximately $3.2 million in assets. Squid stated that the contract in question was neither built, deployed, nor operated by them.
Helpful
No.Help

A third-party module on Ethereum and Base that integrates with the Gnosis Safe ecosystem was exploited, resulting in the theft of approximately $3.2 million in assets from 86 Safe wallets within two hours. Because the contract in question was listed as "SquidRouterModule" on Basescan, the incident was initially mistakenly believed to be directly related to the cross-chain protocol Squid.

Squid stated that it has not deployed any contracts.

Squid subsequently responded, stating that the vulnerable contract was not built, deployed, or operated by the project team; it was merely a standalone module integrated with Squid and other protocols. The team stated that Squid's core routing infrastructure was unaffected during the attack.

The project team also criticized the incorrect associations in the early public information, stating that the problematic contract only had "Squid" in its name and did not mean that the module belonged to the Squid protocol itself.

Two hours affected 86 Safe

Blockchain security firms Blockaid and PeckShield were among the first to disclose details of the incident. The two organizations stated that the attack occurred at the level of a third-party module within the Gnosis Safe ecosystem, impacting both the Ethereum and Base networks.

  • The number of affected wallets is 86 Safe.
  • The total amount of assets transferred was approximately US$3.2 million.
  • The funds were subsequently pooled into approximately 3.07 million DAI.

Vulnerability bypasses signature verification

According to publicly available analysis, the module accepts a fixed string provided by the caller and uses it as proof of the transaction message's security. Attackers can use this to bypass signature verification and execute arbitrary data calls to the victim's wallet.

Squid stated that this flaw allows attackers to access tokens held in affected Safes without obtaining authorization from legitimate wallets. Security researchers indicated that the attack exploited a Foundry-based exploit contract and targeted the DelegateBundler execution path of that module.

The flow of funds has been tracked

Blockaid stated that the attackers impersonated authorized agents associated with various Safes and initiated arbitrary token swaps through Uniswap V3 liquidity pools. The stolen assets were then exchanged for a worthless token called "u," and these liquidity pools were pre-set and controlled by the attackers.

After the assets passed through these pools, the attackers removed the liquidity and pooled the proceeds. PeckShield stated that the funds are currently held in a wallet address that begins with "0xa447...54859".

Tip
$0
Like
0
Save
0
Views 319
HKWDB reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Solana Mainnet enables 4096-byte transactions: More space, but also brings upgrade pressure on indexers
Solana will enable v1 transaction-related functions on the mainnet Epoch on September 15th at 01:20 UTC. The maximum size of a single transaction will be increased from 1232 bytes to 4096 bytes, which is approximately 3.3 times the original size. The official upgrade page indicates that the activation is expected to occur at this time, and the mainnet status will be marked as activated. The new format provides more space for zero-knowledge proofs, large multi-signatures, batch processing, and some on-chain signature schemes, reducing the need for developers to split a single operation into multiple transactions. The existing legacy and v0 transactions will continue to function, so this is not a hard fork that requires all wallets and applications to switch immediately.
币界网
·2026-09-16 10:17:03
184
Final Launches Shannon Development Network: An "Adaptive Blockchain" Begins with Restricted Testing
The new public chain Final announced on September 15th that its first major version, Shannon, is already running on the development network. The project positions itself as an “adaptive blockchain network” and showcases a structure composed of a main chain and a transaction chain, with plans to provide core facilities such as derivatives, spot trading, and stablecoins at the protocol layer. What needs to be clarified at this point is that what has been launched is Devnet, not the mature mainnet intended for everyone. The official website states that Shannon will be open to the public “in the near future,” and the current page still provides an application access link; functions such as wallets, bridges, and documentation are also marked as upcoming.
币界网
·2026-09-16 10:15:56
165
Canadian wholesale sales rose slightly by 0.3% in July: Building materials saw strength, but actual sales decreased by 0.6%
On September 15, Statistics Canada announced that in July 2026, wholesale sales increased by 0.3% month-on-month at current prices, reaching C$91.4 billion. This figure does not include oil, petroleum products, and other hydrocarbons, nor does it include oilseeds and grains. On the surface, there was little change in sales amounts, with growth even observed in the building materials and food sectors; however, when calculated at constant prices, total sales volume decreased by 0.6%. The increase in nominal amounts while the actual quantity decreased indicates that price factors supported the data for that month, and it also serves as a reminder to the market that one positive growth figure alone should not be used to conclude that demand has strengthened.
币百科
·2026-09-16 10:14:46
41
Google Launches Engineering Center in Singapore: The Next Step for AI Competition is to Turn Research into a Deployable System
Google Cloud launched on September 15th in Singapore as Singapore Engineering Center. This is not a traditional regional sales or after-sales office. According to the company's positioning, the center will bring together professionals in AI, machine learning, data, computing, core networking, storage, and frontline support, working together with enterprises to transform basic research into deployable cloud and AI systems. It is located at the same site as Google DeepMind's first research laboratory in Southeast Asia, aiming to bring research, product engineering, and customer implementation closer together on a shorter chain of operations. Google also mentioned that the center had already been publicly announced in February of this year.
CoinMeta
·2026-09-16 10:12:25
46
Gemini Integrates seven business systems into Workspace: AI Assistant begins to compete for corporate job inflows
On September 15th, Google announced the opening of a batch of third-party connectors in Gemini, for, and Google Workspace. The initial list includes Asana, Atlassian Rovo, HubSpot, Intuit Mailchimp, Intuit QuickBooks, monday.com, and Salesforce. The connection method uses the model context protocol MCP. For ordinary users, the change is quite direct: when asking questions in the sidebars of Docs, Sheets, Slides or within Google Chat, Gemi
CoinMeta
·2026-09-16 10:10:42
40
View More