← Radar

Incident case file

Sign in to watch

SquidRouterModule (Third-Party Gnosis Safe Module) — Constant-String Auth Bypass, 86 Safes Drained

Incident date May 25, 2026

0 views

ContainedEthereumBaseSmart contract exploit / malicious Safe moduleCluster: SRM-MOD-2026-05

Estimated loss

$3.2M

Victims identified

86
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: 0x9bdc730183821b6bb2b51be30b77c964fa645b91 (exploiter, per Blockaid). Consolidation wallet (per PeckShield): 0xA447...54859 (reported expansion 0xa447f71782135ab96a71374271a749ff7aa54859 — verify on Etherscan). Funded with 2.1 ETH from Tornado Cash ~14h prior.

Funds moved to: Stolen assets (USDC, USDT, ENA and others) swapped through attacker-controlled pools and consolidated into ~3.07M DAI in the exploiter's wallet; no recovery as of cutoff.
Exploiter: 0x9bdc730183821b6bb2b51be30b77c964fa645b91. Consolidation wallet holding ~3.07M DAI (PeckShield): 0xA447...54859 (full form reported as 0xa447f71782135ab96a71374271a749ff7aa54859 — verify on Etherscan). Pre-attack funding: 2.1 ETH from Tornado Cash. Squid's legitimate router, which was NOT affected: 0xce16F69375520ab01377ce7B88f5BA8C48F8D666. The malicious module was a third-party Gnosis Safe module verified on Basescan under the confusing name 'SquidRouterModule', unrelated to the

Timeline: On 25 May 2026, a malicious third-party Gnosis Safe module verified on Basescan as 'SquidRouterModule' (no relation to the official Squid Router protocol) was used to drain about $3.2M from 86 Gnosis Safe wallets across Ethereum and Base in roughly two hours. Per Squid's own statement, the module accepted a caller-supplied constant string -- publicly readable in the verified contract's code -- as proof that a message was secure; supplying that string allowed execution of an arbitrary array of calldata. Any Safe that had added the module as a trusted Safe Module had effectively granted it unconditional execution power. The attacker (0x9bdc7301...645b91), funded with 2.1 ETH from Tornado Cash about 14 hours earlier, forced fake Uniswap V3 swaps from real tokens into a worthless 'u' token in attacker-controlled pools, then consolidated proceeds into ~3.07M DAI. An example drain transaction confirmed at 06:25:23 UTC on 25 May. Blockaid raised the public alert around 08:39 UTC, PeckShield corroborated shortly after, and Squid clarified within hours that the module was a third-party contract unrelated to its core router (0xce16F6...8D666, unaffected). A Common Prefix post-mortem reportedly cited a higher figure of $3.98M across 88 Safes; that figure could not be corroborated against accessible tier-1 sources, so the convergent $3.2M / 86 Safes figure (Blockaid, Squid, The Block, PeckShield) is used here. Affected users were advised to revoke the module from their Safes. Recovery: 0%.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)