SlowMist founder Yu Xian: Squid incident traced to flaw in Safe Wallet module

ChainCatcher reported that SlowMist founder Yu Xian posted an analysis on X of the Squid security incident, saying a sample review showed the affected Safe wallets were all single-signature setups with different owners. He said the private keys were not compromised; instead, the weakness lay in a module used by those Safe addresses, SquidRouterModule. According to Yu, attackers were able to forge messages to bypass verification and then execute follow-on swap operations, draining funds from targeted Safe wallets. He also shared information tied to addresses used to accumulate the attacker's proceeds. Earlier reports said a third-party Gnosis Safe module was exploited on Base and Ethereum, leading to about $3.2 million in losses and impacting 86 Gnosis Safe wallets that had added the contract as a trusted Safe Module. The contract appears on Basescan under the name "SquidRouterModule". Squid later stated it was not affected by the Gnosis Safe-related vulnerability incident.