Incident case file
Sign in to watchSquidRouterModule (Third-Party Gnosis Safe Module) — Constant-String Auth Bypass, 86 Safes Drained
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x9bdc730183821b6bb2b51be30b77c964fa645b91 (exploiter, per Blockaid). Consolidation wallet (per PeckShield): 0xA447...54859 (reported expansion 0xa447f71782135ab96a71374271a749ff7aa54859 — verify on Etherscan). Funded with 2.1 ETH from Tornado Cash ~14h prior.
Timeline: On 25 May 2026, a malicious third-party Gnosis Safe module verified on Basescan as 'SquidRouterModule' (no relation to the official Squid Router protocol) was used to drain about $3.2M from 86 Gnosis Safe wallets across Ethereum and Base in roughly two hours. Per Squid's own statement, the module accepted a caller-supplied constant string -- publicly readable in the verified contract's code -- as proof that a message was secure; supplying that string allowed execution of an arbitrary array of calldata. Any Safe that had added the module as a trusted Safe Module had effectively granted it unconditional execution power. The attacker (0x9bdc7301...645b91), funded with 2.1 ETH from Tornado Cash about 14 hours earlier, forced fake Uniswap V3 swaps from real tokens into a worthless 'u' token in attacker-controlled pools, then consolidated proceeds into ~3.07M DAI. An example drain transaction confirmed at 06:25:23 UTC on 25 May. Blockaid raised the public alert around 08:39 UTC, PeckShield corroborated shortly after, and Squid clarified within hours that the module was a third-party contract unrelated to its core router (0xce16F6...8D666, unaffected). A Common Prefix post-mortem reportedly cited a higher figure of $3.98M across 88 Safes; that figure could not be corroborated against accessible tier-1 sources, so the convergent $3.2M / 86 Safes figure (Blockaid, Squid, The Block, PeckShield) is used here. Affected users were advised to revoke the module from their Safes. Recovery: 0%.
Sources and coverage
- Articletheblock.cohttps://www.theblock.co/post/402487/we-dont-know-who-deployed-this-squid-distances-itself-from-3-2-million-third-party-module-exploit
- Articlecrypto.newshttps://crypto.news/blockaid-flags-3m-squidroutermodule-exploit-across-86-safes/
- Articlebeincrypto.comhttps://beincrypto.com/squid-disowns-3-2m-squidroutermodule-exploit/
- Articlex.comhttps://x.com/PeckShieldAlert/status/2058887446268645747
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/25/gnosis-safe-users-hit-by-3m-exploit-tied-to-fake-token-scheme/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)