On May 25, 2026, an attacker exploited a vulnerable third party Gnosis Safe module named SquidRouterModule, draining approximately $3 million (3.07 million DAI) from 86 wallets on Ethereum and Base in under two hours. The exploit struck just three days after cross chain router Squid announced a $6 million funding ro...

Create a landscape editorial hero image for this Studio Global article: What happened in the recent SquidRouterModule exploit, including the amount stolen, the timeline relative to Squid's $6 million funding roun. Article summary: ## SquidRouterModule Exploit — May 25, 2026. Topic tags: general, general web. Reference image context from search candidates: Reference image 1: visual subject "A digital wallet dashboard displays multiple transactions involving stolen assets, with a highlighted balance of approximately $3.06 billion, linked to the SquidRouterModule exploi" Reference image 2: visual subject "A futuristic cityscape illuminated by neon signs features a prominent holographic display of the word "Blockaid" with a stylized "S" above it, referencing the SquidRouterModule exp" Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail,
On May 25, 2026, blockchain security firm Blockaid detected an active exploit that drained approximately $3 million from 86 Gnosis Safe wallets across Ethereum and Base in roughly two hours . The attacker targeted a smart contract called SquidRouterModule, swapped the stolen tokens into about 3.07 million DAI, and consolidated the funds into a single wallet
. The timing was especially awkward: the incident came just three days after cross-chain protocol Squid publicly announced a $6 million strategic funding round led by North Island Ventures with participation from Ripple and others
.
Squid moved immediately to distance its core routing protocol from the exploited module, stating that SquidRouterModule was a third-party Gnosis Safe module that it did not develop, deploy, or operate . The attacker funded the exploit address through Tornado Cash, and the stolen DAI remains in the attacker's wallet as of the latest reports with no freeze or recovery
.
The attack centered on a vulnerability in the SquidRouterModule's executeSameChainActions() function, which accepted arbitrary calldata and used a fixed-string verification that attackers could easily reuse . The technical sequence unfolded in four rapid steps:
This specific attack vector—abusing a third-party module's weak verification to override wallet security—differs from other major 2026 exploits that primarily relied on forged cross-chain messages .
The SquidRouterModule exploit arrived at a particularly sensitive moment for the Squid brand:
Squid responded within hours, clarifying through multiple channels that the compromised module was "unrelated to Squid" and structurally different from its core cross-chain routing contracts . The company emphasized that no Squid user funds or core protocol contracts were affected
. This rapid brand defense was necessary because the module's name created a direct association with Squid in public reporting
.
The SquidRouterModule incident is the latest in a devastating series of cross-chain attacks that have made 2026 the worst year on record for bridge security:
According to blockchain security firm PeckShield, eight major bridge-related hacks had stolen a combined $328.6 million from cross-chain protocols by mid-May 2026 . The total crypto hack figure across all categories exceeded $750 million by late May, with bridges representing the single largest attack vector
.
The attack patterns vary but reveal recurring weaknesses. Forged cross-chain messages enabled the largest exploits, including the KelpDAO attack that minted 116,500 fake rsETH tokens and the Verus bridge hack that tricked the protocol into sending funds from its reserves
. Private key compromises, as seen in the IoTeX ioTube bridge attack
, and smart contract logic flaws, as in the CrossCurve hack
, remain persistent threats. The SquidRouterModule exploit adds a newer pattern: abusing third-party wallet module permissions to bypass established security frameworks
.
As of the latest available reports from May 25-26, 2026, the approximately 3.07 million DAI remains in the attacker's wallet with no reported freeze, recovery, or return . The attacker's address was funded through Tornado Cash, a privacy mixer commonly used in DeFi exploits to obscure the origin of transaction funds
. No arrests or fund movements have been publicly reported.
The incident underscores a persistent challenge in DeFi security: even well-audited wallet infrastructure can be compromised through third-party modules that users integrate without fully vetting their security properties. For Gnosis Safe users, the lesson is clear—every module added to a Safe expands the attack surface, and module vulnerabilities can override the multi-signature protections that make Safes otherwise secure.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
On May 25, 2026, an attacker exploited a vulnerable third party Gnosis Safe module named SquidRouterModule, draining approximately $3 million (3.07 million DAI) from 86 wallets on Ethereum and Base in under two hours.
On May 25, 2026, an attacker exploited a vulnerable third party Gnosis Safe module named SquidRouterModule, draining approximately $3 million (3.07 million DAI) from 86 wallets on Ethereum and Base in under two hours. The exploit struck just three days after cross chain router Squid announced a $6 million funding round, but the company quickly clarified the compromised module was not part of its core protocol.
The attack adds to a brutal year for cross chain security, with bridge related hacks surpassing $328 million in 2026, including a $292 million exploit of KelpDAO in April.