discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Squid and Safe Labs say third-party module behind $3.2M exploit

A suspected module exploit drained about $3.2 million from Safe wallets on Ethereum and Base, while Squid said its core protocol was not affected.

By Helen Partz·May 25·cointelegraph.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Squid and Safe Labs say third-party module behind $3.2M exploit
Image: cointelegraph.com

Blockaid says about $3.2 million was drained from at least 86 Safe accounts after a module labeled SquidRouterModule was abused. Squid and Safe Labs say the issue was in a third-party integration, not Safe’s core wallet or Squid’s Router contract.

Why it matters

This is another reminder that wallet extensions and permissions can become an attack path even when the base protocol is not broken. It matters for users and teams relying on Safe-style smart accounts, because a trusted module can still move funds if it has broad authority.

A group of wallets lost money because a helper add-on was tricked. The main wallet system itself was not the part blamed.

Think of it like a house with a strong front door, but one borrowed key lets the wrong person open a side gate. The side gate is the problem, not the front door.

The people behind Safe said their warning system is supposed to spot risky add-ons first. The lesson is simple: even trusted tools can be dangerous if they are given too much power.

Analysis

What happened

Blockaid said a suspected exploit drained roughly $3.2 million from Safe wallets across Ethereum and Base. The activity was tied to a contract labeled SquidRouterModule, which first caused confusion because of the Squid name.

Squid later said the incident was not an attack on its own core protocol. In its view, the issue involved a third-party module integrated into Safe wallets, and the contract shared a name with Squid’s Router contract but not its code.

Why the module mattered

Safe, formerly Gnosis Safe, is a multi-signature wallet system that can be extended with optional modules. Those modules are smart contracts that can execute actions on behalf of the wallet if they have been granted permission. That flexibility is useful, but it also creates a larger attack surface.

Blockaid said at least 86 Safe accounts were affected in about two hours. The stolen tokens were reportedly swapped into Dai through attacker-controlled Uniswap V3 pools.

Safe Labs' response

Safe Labs CEO Rahul Rumalla said the affected accounts did not appear to be operated on the official Safe Wallet product, and suggested they may have been created through external integrations. He also pointed to Safe Shield, which is meant to flag malicious or unverified modules and guards before they are used.

Rumalla said the exploited module had already been flagged as malicious by Blockaid, which is part of Safe Shield’s ruleset. Cointelegraph said it contacted Safe and the CEO for comment but did not receive a response before publication.

Key points

  • Blockaid said about $3.2 million was drained from Safe wallets on Ethereum and Base.
  • The incident centered on a contract labeled SquidRouterModule, which initially caused confusion with the Squid protocol.
  • Squid said its Router contract and core protocol were not the target.
  • Safe Labs said the affected wallets did not appear to be official Safe Wallet product accounts.
  • The stolen tokens were reportedly swapped into Dai through attacker-controlled Uniswap V3 pools.

Originally reported at

cointelegraph.com

Discernion covers the story. Read the full piece at the source.

Tagscryptosecuritymarketstech

Author

Helen Partz

Intelligence analysis by

GPT-5.4 Mini

Published

May 25, 2026

Source

cointelegraph.com

Share

Topics

cryptosecuritymarketstech

Related

More from this desk

investing finance money SEC banking bitcoin cryptocurrency Paul Atkins CLARITY Act
Jul 29·decrypt.co

SEC Ready to Provide Crypto Rules if Clarity Act Flounders: Chair Atkins

SEC Chairman Paul Atkins stated that the agency is prepared to create its own rules for the crypto market if the Clarity Act fails to pass Congress. He emphasized the importance of a statute to provide future-proof certainty to the market.

Morgan Stanley offices (Sven Piper/Unsplash)
Jul 29·coindesk.com

The traditional 9-to-5 banking day is officially dying, says Morgan Stanley execs

Morgan Stanley executives say the era of traditional 9-to-5 banking is ending as markets move toward 24/7 trading and settlement. They expect tokenized assets to bring blockchain technology to mainstream investors before many buy cryptocurrencies directly.

clarity act
Jul 29·bitcoinmagazine.com

Banking Lobby CEO Talks Crypto Clarity Act as Senators Race To Pass Bill

The CEO of the American Bankers Association, Rob Nichols, has said that the banking lobby wants the Clarity Act to succeed — but small edits to the bill still need to be made. The bill was passed last year by the House of Representatives but has been in deadlock after ban…

Brale CEO Ben Milne (Brale, modified by CoinDesk)
Jul 29·coindesk.com

Stablecoin firm Brale says new protocol can remove a major hurdle to scaling custom tokens

Stablecoin infrastructure firm Brale introduced ION Protocol, an interoperability system that lets participating stablecoins move across blockchains by burning tokens on one chain and minting them on another. The testnet debut comes amid rapid growth and fragmentation in …