This incident is unrelated to Squid’s core protocol and contracts. All Squid users and integrators are unaffected and no action is needed.
A third-party Gnosis Safe module was exploited today across Base and Ethereum, resulting in approximately $3.2M in losses. The vulnerable contract is verified on Basescan under the name “SquidRouterModule” but this contract was not built, deployed, or operated by Squid. It is a third-party smart-wallet product that chose to integrate with Squid, among other protocols, but has not been in contact with us.
The exploit worked because the third-party module accepted a caller-supplied constant string as proof that a message was secure. If you pass in this string (which is publicly available in the verified contract’s code), then you can execute an array of arbitrary calldata, stealing funds at will. The victims’ Safes had added this faulty contract as a trusted Safe Module, which gives the contract the ability to spend any tokens in the Safe without signatures. Squid’s own router (0xce16F69375520ab01377ce7B88f5BA8C48F8D666) is architecturally different and was not touched. Squid user funds, approvals, and integrations are fully secure.
Early public reporting may reference “SquidRouter” due to the contract’s verified name on Basescan. The accurate framing is: a third-party SquidRouterModule was exploited, not Squid’s Router contract. The contract shares our name but is not our code. We are monitoring the situation and will share updates if anything changes materially.
welcome to this week's neutron roundup!
we've got exciting updates on docs revamp, astro emissions, mars yields, nfts, plus some haiku alpha.
🧵 Let's dive in!
Once again, Cosmos leads the way for the entire industry.
Except this time, we're winning.
Our focus on building the best stack for businesses to come on chain is now well underway. Lots to come in the next few weeks!
https://t.co/7FV0jZNcbq
🍾🎭 Flex your Many Faces of Dr.Ank!
If you got the style, now’s the time to show it.
Drop your illest mint below 👇
No biters. Just burners.
@superbolt_wtf
It would be outrageous if @krakenfx listed / supported @noble_xyz's $USDC.
With $KUJI now on Kraken, multiple great Cosmos assets already on the exchange such as $OSMO, $ATOM, $INJ, $DYDX, $JUNO & $RUNE, as well as a bunch of new exciting ones on the way, it seems an absolute no brainer for Kraken to support Noble $USDC.
Here is the reason;
Noble currently processes monthly IBC volumes of native Cosmos $USDC to the tune of 500M to 1B per MONTH.
The ONLY exchange that supports Noble USDC right now is CoinBase. Noble $USDC has become the lifeblood for on & off-ramping certainly into the Kujira ecosystem, and I can safely assume it's the same for other Cosmos chains & protocols.
If people can buy their favorite Cosmos tokens on @krakenfx, and then also send Noble $USDC straight from Kraken to their Cosmos chain of choice in a second, I truly believe that it would have an explosive impact on both Kraken volumes and uptake of Cosmos systems.
Please could everyone in the entire Cosmos help me to retweet this and get the message out there. It really works!
We love Kraken. We love Cosmos. Let's get it 🦑
@0xNedAlbo@pendle_fi Ein super Tutorial über Pendle.
Im Übrigen finde ich deine Tutorials und dein Alpha der Woche sehr gut.
Kein shilling, keine get-rich-schemes sondern pure und nüchterne Information wie alles funktioniert, weiter so.