3.2 million dollars to learn a lesson: The integrator dares to use constants for verification when writing code, really bold.

View Original
MarsBitNews
Squid: The security incident is unrelated to the Squid core protocol and contracts; all Squid users and integrators are unaffected.
Mars Finance News: Squid posted on the X platform stating that this incident is unrelated to the Squid core protocol and contracts. All Squid users and integration partners are not affected, and no action is required. On the Base and Ethereum networks, a third-party Gnosis Safe module was attacked, resulting in losses of approximately $3.2 million. The vulnerable contract is verified on Basescan under the name “SquidRouterModule,” but this contract was not built, deployed, or operated by Squid. Instead, it is a third-party smart wallet product that chooses to integrate Squid and other protocols, and it has no connection to Squid. The attack method is that this third-party module accepts a constant string provided by the caller as a message security proof; this string is publicly visible in the verified contract code. After the attacker inputs the string, it then
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments