SlowMist's Yu Xian: Safe Wallet's SquidRouterModule flaw behind Squid-related security incident

Yu Xian, founder of blockchain security firm SlowMist, said on X that the recent Squid-related security incident stemmed from a vulnerable Safe Wallet module rather than compromised private keys. According to Yu, sampling showed the affected Safe wallets were all single-signature setups with different owners. The common factor was that these Safe addresses had enabled a module called "SquidRouterModule". He said attackers were able to forge messages, bypass validation checks and trigger follow-on swap operations, ultimately draining funds from targeted Safe wallets. Yu also published addresses he described as the attacker's profit-collection wallets. Earlier reports said a third-party Gnosis Safe module on Base and Ethereum had been exploited, causing roughly $3.2 million in losses across 86 Gnosis Safe wallets that had added the contract as a trusted module. The contract appears on Basescan under the name "SquidRouterModule". Squid later stated it was not impacted by the Gnosis Safe-related vulnerability.