Third-Party Gnosis Safe Module Hack Drains $3.2M Across Ethereum and Base

A security flaw in a third-party module connected to Gnosis Safe wallets has resulted in more than $3.2 million in stolen crypto assets across Ethereum and Base, according to blockchain security researchers.

Cybersecurity firms Blockaid and PeckShield revealed that the exploit impacted 86 Safe wallets within roughly two hours. The vulnerable smart contract, listed on Basescan as “SquidRouterModule,” was initially mistaken as an official product tied to cross-chain protocol Squid. However, the project later clarified that the module was created and deployed independently by a third party.

Squid co-founder Fig stated on X that the compromised contract had no connection to the protocol’s internal infrastructure. The project emphasized that its core routing system remained isolated and unaffected by the incident.

According to investigators, the exploit stemmed from a major validation flaw. The module accepted a user-provided constant string as proof that transactions were secure. By supplying that string, attackers could bypass signature requirements and execute arbitrary calls from victim wallets.

Blockaid explained that the attacker leveraged Foundry-built exploit contracts through the module’s DelegateBundler pathway, impersonating approved delegates tied to the affected Safes. The stolen assets were then routed through Uniswap V3 liquidity pools and swapped into a near-worthless token labeled “u,” which had been created by the attacker.

After draining liquidity from the manipulated pools, the exploiter consolidated approximately 3.07 million DAI into a wallet beginning with “0xa447...54859,” PeckShield reported. Investigators also traced the attacker’s initial 2.1 ETH funding source back to Tornado Cash.

Squid criticized early reports that linked the exploit directly to its platform, arguing that the naming overlap caused confusion. The team stressed that the third-party module simply integrated with Squid among several protocols and operated independently from the company.

The latest breach adds to mounting losses across the decentralized finance sector. Industry data shows DeFi platforms have suffered more than $770 million in hacks and exploits so far in 2026, with April alone accounting for over $630 million in stolen funds across nearly 30 incidents.

The incident comes shortly after Squid secured $6 million in strategic funding led by North Island Ventures, with participation from Ripple, Dialectic, and Borderless.

Cross-chain infrastructure has remained one of crypto’s most vulnerable sectors, with bridges and interoperability protocols frequently targeted by attackers. Despite the broader market risks, Squid recently stated it had completed nine independent audits, maintained 99.99% uptime, and avoided any direct exploits to date.