Squid and Safe Labs say third-party module behind $3.2M exploit
A suspected module exploit drained about $3.2 million from Safe wallets on Ethereum and Base, while Squid said its core protocol was not affected.
Intelligence analysis by GPT-5.4 Mini

Blockaid says about $3.2 million was drained from at least 86 Safe accounts after a module labeled SquidRouterModule was abused. Squid and Safe Labs say the issue was in a third-party integration, not Safe’s core wallet or Squid’s Router contract.
A group of wallets lost money because a helper add-on was tricked. The main wallet system itself was not the part blamed.
Think of it like a house with a strong front door, but one borrowed key lets the wrong person open a side gate. The side gate is the problem, not the front door.
The people behind Safe said their warning system is supposed to spot risky add-ons first. The lesson is simple: even trusted tools can be dangerous if they are given too much power.
Analysis
What happened
Blockaid said a suspected exploit drained roughly $3.2 million from Safe wallets across Ethereum and Base. The activity was tied to a contract labeled SquidRouterModule, which first caused confusion because of the Squid name.
Squid later said the incident was not an attack on its own core protocol. In its view, the issue involved a third-party module integrated into Safe wallets, and the contract shared a name with Squid’s Router contract but not its code.
Why the module mattered
Safe, formerly Gnosis Safe, is a multi-signature wallet system that can be extended with optional modules. Those modules are smart contracts that can execute actions on behalf of the wallet if they have been granted permission. That flexibility is useful, but it also creates a larger attack surface.
Blockaid said at least 86 Safe accounts were affected in about two hours. The stolen tokens were reportedly swapped into Dai through attacker-controlled Uniswap V3 pools.
Safe Labs' response
Safe Labs CEO Rahul Rumalla said the affected accounts did not appear to be operated on the official Safe Wallet product, and suggested they may have been created through external integrations. He also pointed to Safe Shield, which is meant to flag malicious or unverified modules and guards before they are used.
Rumalla said the exploited module had already been flagged as malicious by Blockaid, which is part of Safe Shield’s ruleset. Cointelegraph said it contacted Safe and the CEO for comment but did not receive a response before publication.
Key points
- Blockaid said about $3.2 million was drained from Safe wallets on Ethereum and Base.
- The incident centered on a contract labeled SquidRouterModule, which initially caused confusion with the Squid protocol.
- Squid said its Router contract and core protocol were not the target.
- Safe Labs said the affected wallets did not appear to be official Safe Wallet product accounts.
- The stolen tokens were reportedly swapped into Dai through attacker-controlled Uniswap V3 pools.



