Gnosis Safe Users Lose $3.2 Million in SquidRouterModule Exploit Across Base and Ethereum
On May 25, 2026, attackers exploited a vulnerable third-party SquidRouterModule contract to drain approximately $3.2 million from 86 Gnosis Safe wallets across Base and Ethereum networks in under two hours. The exploit targeted whitelisted module permissions rather than the core Safe protocol. Stolen funds were converted to roughly $3 million in DAI via attacker-controlled Uniswap V3 pools.
SquidRouterModule exploit
▪PeckShield and Blockaid were the first security firms to detect the SquidRouterModule exploit.
▪The SquidRouterModule exploit targeted a smart contract called SquidRouterModule.
▪Security warnings issued on May 25, 2026, indicate that about $3.2 million has been siphoned from 86 Gnosis Safes in just two hours via the Base and Ethereum blockchain networks.
▪The SquidRouterModule contract was audited by Basescan.
▪The SquidRouterModule exploit caused instant confusion in the crypto community due to the smart contract's similar name to the official Squid Router network.
Attack mechanics
▪Users had previously authorized the SquidRouterModule contracts within their Gnosis Safes with elevated privileges, without requiring user signatures.
▪The SquidRouterModule security string was clearly visible in the publicly available source code, making it possible to bypass all security measures.
▪The SquidRouterModule contract would accept an immutable string provided by the caller as proof of the message's security.
▪After the security string was provided, the SquidRouterModule allowed the execution of calldata provided within an array.
▪The SquidRouterModule had already been whitelisted as a legitimate Safe Module by the victims, enabling the attacker to withdraw funds from the Gnosis Safes regardless of the token type.
Fund flow tracking
▪The SquidRouterModule hacker used the wallet address 0xA447…54859, which was previously sent 2.1 ETH via TornadoCash.
▪The stolen funds from the SquidRouterModule exploit were instantly converted into approximately $3 million in DAI tokens via attacker-controlled Uniswap V3 pools.
▪Blockaid reported that all tokens from the 86 exploited Gnosis Safes were exchanged using liquidity pools controlled by the attacker.
Squid Router clarification
▪The exploited SquidRouterModule contract was identified as a smart wallet by a third party that decided to integrate with Squid and other projects but never contacted the Squid team.
▪The legitimate Squid Router contract at address 0xce16F69375520ab01377ce7B88f5BA8C48F8D666 uses a completely different architecture and has not been affected by the SquidRouterModule attack.
▪Squid Router stated that the exploited SquidRouterModule contract was not built, deployed, or managed by Squid.
GitHub breach response
▪Exposed API keys in the event of a GitHub breach could be used by trading bots, DeFi protocols, analytics platforms, and other related services.
▪Changpeng Zhao urged that if users have API keys in their code, even private repos, now is the time to double-check and change them.
▪Changpeng Zhao called for developers to swap their API keys after a GitHub data breach.
Perspective of Squid Router
▪Squid Router stated that the exploited SquidRouterModule contract was not built, deployed, or managed by Squid.
▪The legitimate Squid Router contract at address 0xce16F69375520ab01377ce7B88f5BA8C48F8D666 uses a completely different architecture and has not been affected by the SquidRouterModule attack.
Story comments
Loading comments…