Arama Sonuçları: "#SquidRouterModule"

3 sonuç
fredlyn l bybit | trader
SquidRouterModule Exploit Incident The #SquidRouterModule contract on #ETH was exploited due to a permission vulnerability. The attacker leveraged the flaw in the contract to compromise an on-chain Safe wallet, netting approximately $3.07M in profit.
English
0
0
0
6
GoPlus Security 🚦
GoPlus Security 🚦@GoPlusSecurity·
🧵1/6 ⚠️ Vulnerability Analysis: SquidRouterModule Exploit Incident The #SquidRouterModule contract on #ETH was exploited due to a permission vulnerability. The attacker leveraged the flaw in the contract to compromise an on-chain Safe wallet, netting approximately $3.07M in profit. Note: The exploited contract was NOT an official contract deployed by @squidrouter or @safefndn, but a third-party contract with the same name deployed by an unknown developer.
squid@squidrouter

This incident is unrelated to Squid’s core protocol and contracts. All Squid users and integrators are unaffected and no action is needed. A third-party Gnosis Safe module was exploited today across Base and Ethereum, resulting in approximately $3.2M in losses. The vulnerable contract is verified on Basescan under the name “SquidRouterModule” but this contract was not built, deployed, or operated by Squid. It is a third-party smart-wallet product that chose to integrate with Squid, among other protocols, but has not been in contact with us. The exploit worked because the third-party module accepted a caller-supplied constant string as proof that a message was secure. If you pass in this string (which is publicly available in the verified contract’s code), then you can execute an array of arbitrary calldata, stealing funds at will. The victims’ Safes had added this faulty contract as a trusted Safe Module, which gives the contract the ability to spend any tokens in the Safe without signatures. Squid’s own router (0xce16F69375520ab01377ce7B88f5BA8C48F8D666) is architecturally different and was not touched. Squid user funds, approvals, and integrations are fully secure. Early public reporting may reference “SquidRouter” due to the contract’s verified name on Basescan. The accurate framing is: a third-party SquidRouterModule was exploited, not Squid’s Router contract. The contract shares our name but is not our code. We are monitoring the situation and will share updates if anything changes materially.

English
2
1
1
2K
GoPlus中文社区
GoPlus中文社区@GoPlusZH·
1/⚠️漏洞分析:SquidRouterModule 被攻击事件分析 #ETH 上的 #SquidRouterModule 合约因权限漏洞遭攻击,攻击者利用该合约漏洞对链上的一个 Safe 钱包发起了攻击,获利约 307 万美元。 注:此次被攻击合约不是 @squidrouter @ safefndn 的官方合约,系第三方未知开发者部署的同名合约。
squid@squidrouter

This incident is unrelated to Squid’s core protocol and contracts. All Squid users and integrators are unaffected and no action is needed. A third-party Gnosis Safe module was exploited today across Base and Ethereum, resulting in approximately $3.2M in losses. The vulnerable contract is verified on Basescan under the name “SquidRouterModule” but this contract was not built, deployed, or operated by Squid. It is a third-party smart-wallet product that chose to integrate with Squid, among other protocols, but has not been in contact with us. The exploit worked because the third-party module accepted a caller-supplied constant string as proof that a message was secure. If you pass in this string (which is publicly available in the verified contract’s code), then you can execute an array of arbitrary calldata, stealing funds at will. The victims’ Safes had added this faulty contract as a trusted Safe Module, which gives the contract the ability to spend any tokens in the Safe without signatures. Squid’s own router (0xce16F69375520ab01377ce7B88f5BA8C48F8D666) is architecturally different and was not touched. Squid user funds, approvals, and integrations are fully secure. Early public reporting may reference “SquidRouter” due to the contract’s verified name on Basescan. The accurate framing is: a third-party SquidRouterModule was exploited, not Squid’s Router contract. The contract shares our name but is not our code. We are monitoring the situation and will share updates if anything changes materially.

中文
3
1
2
1.2K