Close Menu
Stocks Breaking News
    Stocks Breaking News
    • Home
    • Markets
      • Stocks
      • Crypto
    • Business
    • About
    • Contact
    RSS Facebook
    Stocks Breaking News
    Home » Hackers siphon $3.2M from Gnosis Safe wallets on Ethereum and Base
    Crypto Markets

    Hackers siphon $3.2M from Gnosis Safe wallets on Ethereum and Base

    Stocks Breaking NewsStocks Breaking News2 months agoUpdated:1 month ago5 Mins Read
    Facebook Twitter LinkedIn Telegram Reddit WhatsApp Email
    Follow Us
    Google News Facebook
    Hackers Siphon $3.2m From Gnosis Safe Wallets On Ethereum And Base
    Hackers Siphon $3.2m From Gnosis Safe Wallets On Ethereum And Base

    A vulnerability tied to a third-party Safe wallet module has led to the theft of about $3.2 million across Ethereum and Base after attackers exploited delegated execution permissions to drain dozens of smart accounts within roughly two hours, according to security researchers.

    Blockchain security firm Blockaid said the exploit targeted a contract identified as SquidRouterModule, affecting at least 86 Gnosis Safe wallets, before the stolen assets were converted into Dai through attacker-controlled Uniswap V3 pools. Data shared by Blockaid shows the attacker subsequently consolidated the proceeds into a wallet holding roughly 3.07 million DAI.

    On-chain records linked by Blockaid identified the exploiter address as 0x9bdc730183821b6bb2b51be30b77c964fa645b91. Etherscan data cited by Lookonchain showed the address had been funded through Tornado Cash and recorded 52 transactions on May 25. The same investigation traced a drain transaction at 06:25 UTC in which stolen assets, including USDC, ENA and USDT, were routed through Uniswap V3 liquidity pools before conversion.

    Key takeaways

    • Price move: Not disclosed or not observed in this report.
    • Catalyst: Exploit of the SquidRouterModule within a third-party Safe wallet module that bypassed verification and allowed unauthorized swaps from affected Safes.
    • Key implication: Elevates security concerns around delegated permissions in modular wallet ecosystems and underscores risks from external modules connected to Safe wallets.

    What drove the move

    Early findings from Blockaid indicate the breach did not stem from Safe’s core infrastructure but from a flaw in the executeSameChainActions() function of the third-party module. The attacker deployed Foundry-based exploit contracts that abused the module’s DelegateBundler execution path to impersonate authorized delegates connected to victim wallets. With verification checks bypassed, the attacker could trigger arbitrary swaps directly from the affected Safes without the standard multisignature approvals.

    Blockaid described the flow as allowing the attacker to exchange legitimate assets for a token created by the attacker, then extract liquidity and convert the proceeds into Dai. The analysis points to a broad set of Safes, with the attack leveraging broad execution permissions embedded in modules rather than weaknesses in Safe’s core contract logic.

    Further technical commentary from researchers suggested the issue was not tied to compromised private keys. SlowMist founder Cos indicated that the affected wallets were mostly single-signature Safes owned by individual users, and that the vulnerability resided in vulnerable wallet modules attached to those accounts. Cos noted that attackers forged messages and bypassed module verification checks, enabling unauthorized redemption and transfers from the targeted Safe wallets. The consolidation wallet identified by Blockaid remains a focal point of the investigators’ trace.

    Market reaction

    The incident adds to a growing set of DeFi security challenges observed in 2026. Invezz previously reported a separate incident at Echo Protocol, where attackers minted roughly $76.7 million worth of unauthorized eBTC tokens through what researchers linked to an admin key compromise. Investigators stopped short of alleging a blockchain-wide breach, stressing that weak operational controls surrounding delegated permissions and mint authority can facilitate such exploits even when core networks remain intact.

    Safe Labs’ CEO, Rahul Rumalla, noted that the compromised accounts do not appear to be operated on the official Safe Wallet product and could have been deployed through external integrations rather than via Safe’s official interface. Rumalla also said Safe Shield, the company’s built-in warning system powered by Blockaid, had already identified the module as malicious before the incident and would alert users when unverified modules or guards request dangerous permissions. Squid Router, for its part, denied involvement, saying the exploited contract shared the SquidRouterModule name but had no connection to Squid’s production router architecture and left its users unaffected by the incident.

    From an investment perspective, the episode underscores ongoing resilience concerns in DeFi infrastructure, particularly around third-party modules and delegated execution. While there is no explicit price move to reference for specific assets in this report, risk-aware investors are likely to reassess exposure to modular wallet ecosystems and the ease with which trusted permissions can be manipulated. The broader takeaway is the potential for rapid asset movement across DeFi channels when compromised modules are leveraged to bypass multisignature protections.

    Bigger picture

    The event fits into a wider pattern of DeFi security incidents that have kept risk management on the agenda for investors and protocol teams. It highlights the structural fragility of permissioned execution paths within modular wallets and raises questions about the governance and vetting of third-party components connected to major wallet ecosystems. While some findings point to excluded or external wallets rather than official Safe interfaces, the incident reinforces calls for tighter controls around delegated permissions and more robust identity validation within wallet modules.

    Analysts emphasize that the incident should be viewed through the lens of ongoing security improvements in the crypto space rather than as isolated misfortune. It comes as developers and researchers push for stronger module verification, faster patching cycles, and more transparent threat intel sharing to prevent similar exploits. The incident also adds another data point for policymakers evaluating the safety of DeFi infrastructure and the systemic risk implied by interconnected modules and cross-chain liquidity.

    What to watch next

    Investors and users will be watching for concrete patching and governance responses from Safe Labs and the broader Safe wallet ecosystem. Key items to monitor include updates to Safe Shield’s warning algorithms, a formal patch for the affected module, and any statements from the Squid team clarifying scope and exposure. Ongoing investigations by Blockaid and other researchers will likely shape how the market prices risk in modular wallet deployments. In the near term, authorities and industry groups may also weigh in on best practices for delegated permissions and threat monitoring in DeFi wallets as part of broader cybersecurity conversations in crypto markets.

    Share. Facebook Twitter LinkedIn Telegram Email WhatsApp
    Previous ArticleDePIN Capital Flows to AI as VCs Back DGrid’s Verifiable AI Infra
    Next Article Render Eyes $2.50 After Clearing Key EMA Levels
    Stocks Breaking News
    • Website

    Stocks Breaking News is a financial media platform delivering real-time coverage of global markets, equities, commodities, and macro trends. The editorial approach focuses on clarity, relevance, and data-driven insights, helping readers understand what is moving markets and why it matters.

    Related Posts

    Premarket Movers: Gm, 3m, Novartis, And Nebius Lead

    Premarket Movers: GM, 3M, Novartis, and Nebius Lead

    15 minutes ago
    Upbeat Earnings Lift Wall Street As Stocks Eye A Quick Rebound

    Upbeat Earnings Lift Wall Street as Stocks Eye a Quick Rebound

    28 minutes ago
    U.s.-Iran Tensions Rise: Investors Reassess Market, Sector Risks

    U.S.-Iran Tensions Rise: Investors Reassess Market, Sector Risks

    1 hour ago
    Wall Street Poised For Higher Open As Markets Track Positive Signals

    Wall Street Poised for Higher Open as Markets Track Positive Signals

    1 hour ago
    Synchrony Misses In Q2 As It Reaffirms Fy2026 Outlook

    Synchrony Misses in Q2 as it Reaffirms FY2026 Outlook

    3 hours ago
    Bitcoin Rebounds Above $65,000 As Traders Eye $70,000 Next

    Bitcoin Rebounds Above $65,000 as Traders Eye $70,000 Next

    3 hours ago

    Search

    Latest News

    Premarket Movers: Gm, 3m, Novartis, And Nebius Lead

    Premarket Movers: GM, 3M, Novartis, and Nebius Lead

    15 minutes ago
    Upbeat Earnings Lift Wall Street As Stocks Eye A Quick Rebound

    Upbeat Earnings Lift Wall Street as Stocks Eye a Quick Rebound

    28 minutes ago
    U.s.-Iran Tensions Rise: Investors Reassess Market, Sector Risks

    U.S.-Iran Tensions Rise: Investors Reassess Market, Sector Risks

    1 hour ago
    Wall Street Poised For Higher Open As Markets Track Positive Signals

    Wall Street Poised for Higher Open as Markets Track Positive Signals

    1 hour ago
    Synchrony Misses In Q2 As It Reaffirms Fy2026 Outlook

    Synchrony Misses in Q2 as it Reaffirms FY2026 Outlook

    3 hours ago
    Bitcoin Rebounds Above $65,000 As Traders Eye $70,000 Next

    Bitcoin Rebounds Above $65,000 as Traders Eye $70,000 Next

    3 hours ago
    Mercantile Bank Lifts Q2 Income, Signals Stronger Profit Trend

    Mercantile Bank Lifts Q2 Income, Signals Stronger Profit Trend

    4 hours ago
    Animoca’s Evan Auyang: Agentic Ai Could Accelerate Blockchain Adoption

    Animoca’s Evan Auyang: Agentic AI could accelerate blockchain adoption

    4 hours ago
    Tom Lee Names Two Cryptos He Expects To Surge In Gains

    Tom Lee Names Two Cryptos He Expects to Surge in Gains

    5 hours ago
    Ondo Surges 13% On Dtcc Link Hopes As Investors Reassess Token Flow

    ONDO Surges 13% on DTCC Link Hopes as Investors Reassess Token Flow

    5 hours ago

    About Stocks Breaking News

    About Stocks Breaking News

    StocksBreaking is a financial news platform covering global markets, equities, commodities, and macroeconomic trends. We focus on what moves prices, why it happens, and what investors should watch next. From earnings and Federal Reserve decisions to sector rotations and market momentum, our goal is to deliver clear, data-driven insights without noise or hype.

    Facebook RSS
    © 2026 StocksBreaking.com | All rights reserved | Powered by Web3 Digital

    • Privacy Policy
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.