This incident is unrelated to Squid’s core protocol and contracts. All Squid users and integrators are unaffected and no action is needed.
A third-party Gnosis Safe module was exploited today across Base and Ethereum, resulting in approximately $3.2M in losses. The vulnerable contract is verified on Basescan under the name “SquidRouterModule” but this contract was not built, deployed, or operated by Squid. It is a third-party smart-wallet product that chose to integrate with Squid, among other protocols, but has not been in contact with us.
The exploit worked because the third-party module accepted a caller-supplied constant string as proof that a message was secure. If you pass in this string (which is publicly available in the verified contract’s code), then you can execute an array of arbitrary calldata, stealing funds at will. The victims’ Safes had added this faulty contract as a trusted Safe Module, which gives the contract the ability to spend any tokens in the Safe without signatures. Squid’s own router (0xce16F69375520ab01377ce7B88f5BA8C48F8D666) is architecturally different and was not touched. Squid user funds, approvals, and integrations are fully secure.
Early public reporting may reference “SquidRouter” due to the contract’s verified name on Basescan. The accurate framing is: a third-party SquidRouterModule was exploited, not Squid’s Router contract. The contract shares our name but is not our code. We are monitoring the situation and will share updates if anything changes materially.
We are proud to announce that Squid has raised $6M in funding round led by North Island Ventures and backed by strategic investors!
Our new chapter has begun, with more news coming soon. Today we celebrate and say thank you. CHEERS 💫
Top 2 no of holders of tokenized commodities in the industry is XAUt on Celo, powered largely by Squid x MiniPay!
Real adoption for crypto helping real people. Coming after 1 soon!
Squid is live on @tempo
Cross-chain distribution meets the blockchain for real-world payments.
Bridge and swap to Tempo from any chain starting today. ✨
Squid MCP is here!
now you can get your agent to
buy the dip
rotate (ir)responsibly
bridge to 100+ chains
ape that thing your friend mentioned at dinner
AI trading with natural language via Squid MCP
◕‿◕
Squid was just added as an official XRPL validator.
We are excited to be supporting the ongoing improvement of the chain and ecosystem.
We bring a wealth of experience building alongside other chains, and we are builders on the XRPL itself, which will inform our decisions as a validator.
Looking forward to collaborating with the XRPL community and building a successful ecosystem together!
Come hear about our Gold app with MiniPay, bringing gold investment to millions of users who don’t have access to good assets otherwise. Built on Celo!
Digital Gold that you can hold, and get more from.
That's right. When you buy Digital Gold in Squid's Mini App, you get 1% back on all deposits held for 90 days.
Hold what you own and get rewarded for it. That's gold in the digital age✨
Just unlocked my Gas ID via ETHGas 🪪
I'm a Kiddo Jack with 0.058 ETH spent on gas since Beacon Chain - now fueling my climb to the Gasless Future and earned 25 Beans already.
Reveal yours at https://t.co/TIyMk6xRZo
Squid's Mini App is live on @minipay ✨
Buy and sell digital gold in seconds. Owning the world's oldest asset is now easier than ever before.
Real gold, at your fingertips in one click.
A New Mini App just dropped… and it’s pure gold! ⭐️
Thanks to the latest addition to our Discover page in a collaboration with @squidrouter you can now swap stablecoins for Tether Gold (XAUt0).
Backed by physical bars in Swiss vaults.
Buy and hold gold from as little as 1 USDT.
Get started- https://t.co/Nx4N1peeal