Skip to content
The Squid security incident was caused by a vulnerability in the SquidRouterModule of Safe Wallet.

The Squid security incident was caused by a vulnerability in the SquidRouterModule of Safe Wallet.

Kucoin May 26, 2026

Yu Xian, founder of SlowMist, posted on X to analyze the Squid security incident, stating that sampling revealed all related Safe wallets were single-signature, with different owners; however, the issue was not with the private keys, but with a vulnerable module (SquidRouterModule) used by these Safe addresses. Attackers could forge messages to easily bypass validation and initiate subsequent exchange operations to transfer funds from the target Safe wallets. Yu Xian also disclosed the attacker’s profit accumulation addresses. Previously, a third-party Gnosis Safe module on Base and Ethereum was exploited, resulting in approximately $3.2 million in losses affecting 86 Gnosis Safe wallets that had added this contract as a trusted Safe module. The contract was named “SquidRouterModule” on Basescan. Subsequently, Squid clarified that it was not affected by the Gnosis Safe-related vulnerability incident.

Extracted Entities

Attack Types (1)

Companies (2)

Platforms (1)