This incident is unrelated to Squid’s core protocol and contracts. All Squid users and integrators are unaffected and no action is needed.
A third-party Gnosis Safe module was exploited today across Base and Ethereum, resulting in approximately $3.2M in losses. The vulnerable contract is verified on Basescan under the name “SquidRouterModule” but this contract was not built, deployed, or operated by Squid. It is a third-party smart-wallet product that chose to integrate with Squid, among other protocols, but has not been in contact with us.
The exploit worked because the third-party module accepted a caller-supplied constant string as proof that a message was secure. If you pass in this string (which is publicly available in the verified contract’s code), then you can execute an array of arbitrary calldata, stealing funds at will. The victims’ Safes had added this faulty contract as a trusted Safe Module, which gives the contract the ability to spend any tokens in the Safe without signatures. Squid’s own router (0xce16F69375520ab01377ce7B88f5BA8C48F8D666) is architecturally different and was not touched. Squid user funds, approvals, and integrations are fully secure.
Early public reporting may reference “SquidRouter” due to the contract’s verified name on Basescan. The accurate framing is: a third-party SquidRouterModule was exploited, not Squid’s Router contract. The contract shares our name but is not our code. We are monitoring the situation and will share updates if anything changes materially.
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
⚠️ Spammers are sending fake "USDC.axl" on Osmosis. It shows the real USDC logo but is worthless and can't be swapped.
As long as you don't visit any websites linked in these transfers, your assets are safe.
The denom is leftover from a 2022 IBC vulnerability that was patched long ago. It doesn't affect users today and is only being used as phishing bait.
A wallet update with the denom blocked is pending app store review.
🚫 Never enter your seed phrase on any website
🚫 Don't click links in tx memos or "USDC claim" pages
Stay safe.
🚨SHUTDOWN: COSMOS NETWORK LEAP WALLET SHUTTING DOWN
@leap_wallet is shutting down its browser extension and mobile apps for iOS and Android, the Leap WebApp, Swapfast exchange platform, and Leap @Cosmos Hub Validator
Leap was launched in late 2021 with a $50,000 grant from Terraform Labs and later raised a $3.2 million seed round co-led by CoinFund and Pantera Capital in early 2022.
Leap originally positioned itself as a kind of go-to wallet for Terra, after it's crash they expanded and pivoted to provide support for the wider multi-chain Cosmos ecosystem
@indrawxyz Makin banyak yg menggiring opini buat bikin masyarakat panas, mereka kurang literasi mengenai program pemerintah seperti MBG, koperasi Merah Putih, atau sengaja memelintir narasi, termasuk harga BBM di jadiin isu yg ga pasti, mereka ini pengkhianat bangsa yg mau bikin rusuh.
@Makaryo0 Tujuan Koperasi merah putih itu baik, kalian harus belajar sejarah bagaimana jaman Soeharto bisa swasembada pangan, itu semu karena rantai pasok dan distribusi di kelola baik melalui koperasi desa. Ini koperasi bukan cuma mini market seperti Indomart dll. jadi beda fungsi.
@Makaryo0 Koperasi merah putih itu bukan sekedar mini market, tapi juga sebagai koprasi simpan pinjam, dimana petani dan masyarakat bisa melakukan simpan dan pinjam dengan dana murah, jadi mereka tidak terjebak oleh renternir, disana juga menjadi penerima hasil tani dan distribusi pupuk
@nurayuofficial Ga usah heran sama kendaraan di Gading serpong, disana banyak bawa dan parkir mobil dan motor ngasal, harus extra hati-hati. Beberapa bulan lalu, logo BSD yang baru di pasang aja di hajar sama warga GS. Paling males kalo ke daerah sana, SMS, Maggiore dan sekitarnya.
@Airdrops_one@cosmos There's too much internal drama and projects that only intend to harm the community, starting with Sif, Juno, Sommelier, Crescent, the sweet promises of the Gravity Bridge, Emeris,Ethermint /Evmos and several projects that use community funds that ultimately disappoint.
@Airdrops_one@cosmos Instead of working together, they are destroying each other in the ecosystem. The egos of each project leader, their disrespect for each other, and their mutual backbiting are destroying it from within.