$3.2M drained from Gnosis Safes in module exploit
A third-party module exploit drained $3.2M from 86 Gnosis Safe wallets on Ethereum and Base. Attackers swapped assets into DAI. The Squid protocol itself was not affected.
A vulnerability in the third-party SquidRouterModule led to the rapid loss of approximately $3.2 million from 86 Gnosis Safe wallets on Ethereum and Base networks. Attackers exploited flaws in the module’s authentication and execution logic, allowing them to impersonate trusted users and execute unauthorized transactions over a two-hour period. Victims had previously whitelisted the module, enabling attackers to move assets and swap them into DAI stablecoin via attacker-controlled Uniswap V3 pools. The stolen funds were then consolidated into a single wallet. Security firms Blockaid and PeckShield detected and reported the breach. The Squid protocol team clarified that the compromised contract was unrelated to its core protocol, despite the similar name, and emphasized that its systems and users were unaffected. This incident highlights the risks of integrating third-party modules and the importance of thorough security reviews.