Squid: The security incident was unrelated to Squid's core protocol and contract, and all Squid users and integrators were unaffected
Comparing the news, Squid posted an article on the X platform stating that the incident had nothing to do with Squid's core agreement and contract, that none of Squid users and integrators were affected, and no action was required. Today, a third-party Gnosis Safe module on the Base and Ethereum networks was attacked, which cost around $3.2 million. The vulnerability contract was verified as “SquidRouterModule” on Basescan, but the contract was not built, deployed, or operated by Squid, but rather a third-party smart wallet product that chose to integrate Squid and other protocols, and was not linked to Squid. The principle of the attack is that the third party module accepts a constant string provided by the caller as a message security certificate. The string is publicly visible in the verified contract code, and the attacker can execute an arbitrary calldata array after input to steal funds at will. The victim's Safe wallet added the problematic contract as a trusted Safe Module, allowing the contract to control any token within Safe without signing. Squid's own routing contract (0xce16... D666) architecture is different and unaffected, and Squid user funds, authorizations, and integrations are completely secure. Early public reports may have mentioned “squidRouter” due to the contract verification name on Basescan. The accurate statement should be that the third party SquidRouterModule was attacked, not Squid's Router contract. The contract name is the same as Squid, but not the Squid code. Squid is continuously monitoring the situation and will update the information if there are significant changes.




