$84,463+1.46%
BTC7D TREND
$2,699+2.29%
ETH7D TREND
$118.12+4.54%
SOL7D TREND
$775.27+1.15%
BNB7D TREND
DeFi Data →
Crypto
Crypto

Squid Protocol Hacked on Ethereum and Base for Over $3 Million

Squid Protocol was hacked on Ethereum and Base for over $3 million. This outline focuses on what happened, the cross-chain impact, and the immediate market context.

·2 min readMakeDefilibanpreferred onGoogle

Squid Protocol, a cross-chain liquidity routing platform, was exploited on both Ethereum and Base networks for over $3 million, according to blockchain security firm Blockaid.

KEY TAKEAWAYS

  • Squid Protocol was exploited across Ethereum and Base for more than $3 million
  • Security firm Blockaid flagged the exploit as targeting the SquidRouterModule across 86 Safe wallets
  • Users on both chains should monitor official channels for updates and avoid interacting with affected contracts

Blockaid Flags the SquidRouterModule Exploit

Blockchain security firm Blockaid identified the attack, which targeted the SquidRouterModule component of the protocol. The exploit affected 86 Safe multisig wallets across both networks, draining funds through what appears to have been a vulnerability in the router’s contract logic.

The Ethereum address linked to the exploit is publicly visible on Etherscan, allowing on-chain observers to track the movement of stolen funds.

ON-CHAIN DATA

  • Exploit-linked address: 0xa447f717…a859
  • Estimated loss: Over $3 million
  • Affected chains: Ethereum, Base
  • Affected wallets: 86 Safe multisig wallets

Squid Protocol functions as a cross-chain swap and liquidity routing layer, meaning its contracts handle token approvals and fund transfers across multiple networks. A vulnerability in a router module can expose users who previously granted token approvals to the affected contracts.

Why a Dual-Chain Exploit Raises the Stakes

The fact that the hack spanned both Ethereum and Base simultaneously increases its severity. Users on two separate ecosystems may have been exposed, complicating both the response effort and the scope of potential losses.

Cross-chain protocols aggregate liquidity and permissions across networks, which means a single smart contract flaw can cascade into multiple chains. For users who interacted with Squid Protocol on either Ethereum or Base, outstanding token approvals could remain a risk vector until revoked.

The broader DeFi security landscape has seen a string of incidents in recent months. Separately, spot Bitcoin ETFs logged $1.257 billion in net outflows over the past week, a reminder that risk sentiment can shift quickly across crypto markets when security events coincide with capital movements.

What Affected Users Should Do Next

Users who have interacted with Squid Protocol on Ethereum or Base should immediately check and revoke any outstanding token approvals granted to the SquidRouterModule contract. Tools like Etherscan’s token approval checker or Revoke.cash can help identify active permissions.

The Squid Router team has acknowledged the incident on X. Users should monitor the project’s official channels for a post-mortem detailing the exploit vector, the total confirmed losses, and any planned remediation or reimbursement.

Fund tracing is likely underway, given that the exploit address is publicly known. Whether the attacker can be identified or funds recovered will depend on whether the stolen assets are moved through mixers or bridges in the coming hours and days.

Incidents like this underscore the importance of minimizing token approvals and regularly auditing wallet permissions, particularly when using cross-chain routing protocols that require broad contract access across multiple networks.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Defiliban · Ada Michael

Ada Michael

Ada Michael

@ada-michael