Skip to content
The Squid security incident was caused by a vulnerability in the Safe Wallet module.

The Squid security incident was caused by a vulnerability in the Safe Wallet module.

Kucoin May 26, 2026

ChainCatcher report: Yu Xian, founder of SlowMist, posted on X to analyze the Squid security incident, stating that sampled analysis revealed all related Safe wallets were single-signature, with different owners. However, the issue was not with private keys, but with a vulnerability in the module (SquidRouterModule) used by these Safe addresses—attackers could forge messages to easily bypass verification and initiate subsequent exchange operations to transfer funds from the target Safe wallets. Additionally, Yu Xian disclosed information the attacker’s profit accumulation addresses. Previously, a third-party Gnosis Safe module exploited on Base and Ethereum resulted in approximately $3.2 million in losses, affecting 86 Gnosis Safe wallets that had added this contract as a trusted Safe Module. The contract is named “SquidRouterModule” on Basescan. Subsequently, Squid clarified that it was not affected by the Gnosis Safe-related vulnerability incident.

Extracted Entities