A fresh smart contract exploit is hitting the crypto space. Blockaid, a leading blockchain security firm, issued an urgent alert on X, warning of a live attack targeting SquidRouterModule contracts on Ethereum mainnet and the Base L2 network.
86 Gnosis Safe Wallets Emptied in 2 Hours
According to Blockaid's initial detection report, the attackers moved fast, compromising and draining 86 Gnosis Safe multi-sig wallets within roughly 2 hours. Estimated cumulative losses stand at $3 million, and the attack is still ongoing, meaning the figure may climb.
Money Laundering via Custom Uniswap V3 Pools
Blockaid analysts noted that once the funds were stolen, the hackers wasted no time in laundering them. The attackers had pre-configured specific Uniswap V3 liquidity pools to swap all stolen tokens from victim wallets into the DAI stablecoin, an attempt to obscure transaction trails and preserve the stolen value.
The security team at Blockaid continues to monitor attacker addresses and transaction details. Security experts urge all users and multi-sig wallet operators who have interacted with the SquidRouterModule to immediately revoke any contract approvals to prevent further losses.

