At least 80 Ethereum wallets emptied by hackers
A security exploit allowed the theft of approximately $3 million in cryptocurrency from 86 wallets in just two hours, according to a report by cybersecurity firm Blockaid on May 25.
At the time of the incident, researchers noted that the vulnerability remained active and could continue to be exploited.
The affected wallets operated on the Ethereum and Base networks and shared a common characteristic: they all had a Squid Router integration module enabled. This tool allows for token swaps between different blockchain networks directly from the wallet, simplifying transactions for users.
Unlike other attacks where criminals obtain victims' private keys, in this case, the attacker exploited a vulnerability in the external module. Thanks to this flaw, they were able to impersonate an authorized operator within the wallets and execute transactions with seemingly legitimate permissions, without compromising user credentials.
These wallets require multiple signatures to authorize asset transfers, which typically enhances security. However, they also allow the installation of external modules that expand their capabilities, and one of these modules, Squid Router, is believed to have been the entry point used by the attacker.
Following the incident, Rahul Rumalla, CEO of Safe, clarified that the affected wallets did not use the official Safe Wallet product. He also explained that the Squid Router module had already been flagged as potentially risky within Safe Shield, an alert system that warns about third-party modules and extensions considered dangerous.
This case demonstrates that multi-signature wallets are not immune to security risks. Although they offer an additional layer of protection, the integration of external modules can create new attack vectors. Each third-party integration increases the attack surface and can become a vulnerable point if it contains security flaws or if users ignore warnings about its risks.
Source:
Komentarze