A vulnerability tied to a third-party Safe wallet module has led to the theft of about $3.2 million across Ethereum and Base after attackers exploited delegated execution permissions to drain dozens of smart accounts within roughly two hours, according to security researchers.
Blockchain security firm Blockaid said the exploit targeted a contract identified as SquidRouterModule, affecting at least 86 Gnosis Safe wallets, before the stolen assets were converted into Dai through attacker-controlled Uniswap V3 pools. Data shared by Blockaid shows the attacker subsequently consolidated the proceeds into a wallet holding roughly 3.07 million DAI.
On-chain records linked by Blockaid identified the exploiter address as 0x9bdc730183821b6bb2b51be30b77c964fa645b91. Etherscan data cited by Lookonchain showed the address had been funded through Tornado Cash and recorded 52 transactions on May 25. The same investigation traced a drain transaction at 06:25 UTC in which stolen assets, including USDC, ENA and USDT, were routed through Uniswap V3 liquidity pools before conversion.
Key takeaways
- Price move: Not disclosed or not observed in this report.
- Catalyst: Exploit of the SquidRouterModule within a third-party Safe wallet module that bypassed verification and allowed unauthorized swaps from affected Safes.
- Key implication: Elevates security concerns around delegated permissions in modular wallet ecosystems and underscores risks from external modules connected to Safe wallets.
What drove the move
Early findings from Blockaid indicate the breach did not stem from Safe’s core infrastructure but from a flaw in the executeSameChainActions() function of the third-party module. The attacker deployed Foundry-based exploit contracts that abused the module’s DelegateBundler execution path to impersonate authorized delegates connected to victim wallets. With verification checks bypassed, the attacker could trigger arbitrary swaps directly from the affected Safes without the standard multisignature approvals.
Blockaid described the flow as allowing the attacker to exchange legitimate assets for a token created by the attacker, then extract liquidity and convert the proceeds into Dai. The analysis points to a broad set of Safes, with the attack leveraging broad execution permissions embedded in modules rather than weaknesses in Safe’s core contract logic.
Further technical commentary from researchers suggested the issue was not tied to compromised private keys. SlowMist founder Cos indicated that the affected wallets were mostly single-signature Safes owned by individual users, and that the vulnerability resided in vulnerable wallet modules attached to those accounts. Cos noted that attackers forged messages and bypassed module verification checks, enabling unauthorized redemption and transfers from the targeted Safe wallets. The consolidation wallet identified by Blockaid remains a focal point of the investigators’ trace.
Market reaction
The incident adds to a growing set of DeFi security challenges observed in 2026. Invezz previously reported a separate incident at Echo Protocol, where attackers minted roughly $76.7 million worth of unauthorized eBTC tokens through what researchers linked to an admin key compromise. Investigators stopped short of alleging a blockchain-wide breach, stressing that weak operational controls surrounding delegated permissions and mint authority can facilitate such exploits even when core networks remain intact.
Safe Labs’ CEO, Rahul Rumalla, noted that the compromised accounts do not appear to be operated on the official Safe Wallet product and could have been deployed through external integrations rather than via Safe’s official interface. Rumalla also said Safe Shield, the company’s built-in warning system powered by Blockaid, had already identified the module as malicious before the incident and would alert users when unverified modules or guards request dangerous permissions. Squid Router, for its part, denied involvement, saying the exploited contract shared the SquidRouterModule name but had no connection to Squid’s production router architecture and left its users unaffected by the incident.
From an investment perspective, the episode underscores ongoing resilience concerns in DeFi infrastructure, particularly around third-party modules and delegated execution. While there is no explicit price move to reference for specific assets in this report, risk-aware investors are likely to reassess exposure to modular wallet ecosystems and the ease with which trusted permissions can be manipulated. The broader takeaway is the potential for rapid asset movement across DeFi channels when compromised modules are leveraged to bypass multisignature protections.
Bigger picture
The event fits into a wider pattern of DeFi security incidents that have kept risk management on the agenda for investors and protocol teams. It highlights the structural fragility of permissioned execution paths within modular wallets and raises questions about the governance and vetting of third-party components connected to major wallet ecosystems. While some findings point to excluded or external wallets rather than official Safe interfaces, the incident reinforces calls for tighter controls around delegated permissions and more robust identity validation within wallet modules.
Analysts emphasize that the incident should be viewed through the lens of ongoing security improvements in the crypto space rather than as isolated misfortune. It comes as developers and researchers push for stronger module verification, faster patching cycles, and more transparent threat intel sharing to prevent similar exploits. The incident also adds another data point for policymakers evaluating the safety of DeFi infrastructure and the systemic risk implied by interconnected modules and cross-chain liquidity.
What to watch next
Investors and users will be watching for concrete patching and governance responses from Safe Labs and the broader Safe wallet ecosystem. Key items to monitor include updates to Safe Shield’s warning algorithms, a formal patch for the affected module, and any statements from the Squid team clarifying scope and exposure. Ongoing investigations by Blockaid and other researchers will likely shape how the market prices risk in modular wallet deployments. In the near term, authorities and industry groups may also weigh in on best practices for delegated permissions and threat monitoring in DeFi wallets as part of broader cybersecurity conversations in crypto markets.







