$3.2M Vanishes in 2 Hours as Safe Wallet Module Exploit Drains 86 Crypto Vaults
Key Takeaways: About $3.2M was siphoned from both the Ethereum and Base networks using a third-party Safe module exploit. Attackers exploited 86 Safe wallets and swapped them for DAI. Squid has confirmed that its core pr...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Key Takeaways:
- About $3.2M was siphoned from both the Ethereum and Base networks using a third-party Safe module exploit.
- Attackers exploited 86 Safe wallets and swapped them for DAI.
- Squid has confirmed that its core protocol, router contracts were not impacted.
A possible exploit in a third-party wallet module caused a company’s Safe assets to be drained over the past few hours, leading to millions of dollars in losses for all users. A third party wallet app vulnerability enabled a hasty hack that caused significant losses to users of Safe accounts across both the Ethereum and Base chains, with millions of dollars lost within hours.
The attacker exploited internal privileges to the module to conduct unauthorized token swaps and send profits to stablecoins, security researchers said.
86 Safe Wallets Drained in Coordinated AttackBlockchain security firm Blockaid reported that attackers targeted a contract known as SquidRouterModule, affecting at least 86 Safe wallets in roughly two hours. The stolen assets were immediately swapped through attacker-controlled Uniswap V3 pools before being consolidated into approximately $3.07 million worth of DAI.
🚨 Blockaid detected an ongoing exploit targeting the SquidRouterModule on Ethereum and Base.
86 Gnosis Safes drained for ~$3M in ~2 hours.
All stolen tokens swapped to DAI via attacker-controlled Uniswap V3 pools.
More details in 🧵
— Blockaid (@blockaid_) May 25, 2026
According to the investigation, the exploit likely originated from a flaw in the module’s executeSameChainActions() function. According to the attacker, they used custom exploit contracts to exploit the DelegateBundler mechanism of the module, enabling them to conduct transactions from the wallets of the victim by faking being an authorized delegate.
Once access was obtained, assets from each Safe were exchanged for a nearly worthless token called “u”, which had minimal market activity and only a small number of holders.
Read More: $5.87M Ethereum Hack Drains TrustedVolumes as 1inch Denies Any Security Breach
How the Swap Scheme WorkedResearchers believe the attacker created and funded Uniswap V3 liquidity pools pairing the fake token with legitimate crypto assets. Victim funds were swapped into the attacker-controlled token, enabling the exploiter to extract valuable assets while leaving wallets holding effectively worthless tokens.
Squid Distances Itself From the Exploited ContractThe incident initially sparked confusion because the compromised contract carried the name “SquidRouterModule.” But the cross-chain protocol Squid said the impacted contract was by others and not developed, deployed or operated by its team.
The design flaw that made the exploit possible, according to Squid, came from a third party smart-wallet module that assumed that a publicly visible constant string was sufficient to convey that something was secured.
Read More: $290M KelpDAO Hack Exposes Fatal LayerZero Setup Flaw, Lazarus Suspected
Safe Labs Highlights Existing Security WarningsSafe Labs CEO Rahul Rumalla said preliminary findings suggest the affected accounts were not operated through official Safe Wallet products. Rumalla also revealed that the compromised module had previously been identified as malicious by Blockaid and included within Safe Shield’s risk-detection framework.
This incident is a reminder of how vulnerabilities of external wallet extensions are increasing especially when they are granted broad powers of execution on users’ assets. The attack is a reminder that smart wallet security isn’t just about the smart wallet itself; it’s also about every module and integration that it’s connected to.
Keep checking CryptoNinjas.net for up-to-date crypto news resources and data-driven research on digital assets and blockchain adoption.
The post $3.2M Vanishes in 2 Hours as Safe Wallet Module Exploit Drains 86 Crypto Vaults appeared first on CryptoNinjas.
Why this matters
Ethereum is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoNinjasRelated market context
RedStone launches settlement layer to unlock $30 billion in idle tokenized assets for DeFi
Unlocking idle tokenized assets for DeFi could enhance liquidity and market efficiency, but centralization risks may challenge dec...
Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone
Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed ph...
As Ethereum turns 11 years old it hosts $148B in stablecoins, but daily mainnet revenue just fell to $330k
Ethereum turned 11 on July 30, the anniversary of the day users generated and loaded the Frontier genesis block in 2015. In its fi...
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affe...
Binance founder CZ calls for wallet diversification after $70 million Coldcard exploit
Binance founder Changpeng Zhao says hardware wallets can still have bugs and suggests spreading funds across multiple wallets afte...
Bitcoin And Ethereum Edge Higher As Traders Watch Altcoin Rotation
Bitcoin and Ethereum edged higher into July 31, while a small shift in market dominance suggested traders were again watching whet...