Squid Router Disowns $3.2M Third-Party Gnosis Module Hack
On May 26 Squid Router publicly disowned the exploited SquidRouterModule, stressing its core protocol remained untouched. The clarification follows the May 25 incident in which attackers drained roughly 3.07–3.2 million DAI from 86 Gnosis Safe wallets on Ethereum and Base by compromising the third-party module rather than Squid’s primary contract 0xce16F6. Security researchers PeckShield and Blockaid traced the theft to an attacker who funded the exploit with 2.1 ETH from Tornado Cash and laundered proceeds through attacker-controlled Uniswap V3 pools. Squid had announced a $6 million funding round only days earlier; market reaction stayed limited to reputational noise around Ripple-linked DeFi projects.