News
25 May 2026, 14:43
$3 Million Drained In Two Hours: SquidRouterModule Exploit Exposes Hidden Risks In Third-Party Wallet Integrations

Within a span of two hours, attackers had siphoned almost $3 million from several wallets during a fast and coordinated DeFi exploit that has disrupted parts of the ecosystem. The firm Blockaid says the attack targeted a vulnerable wallet module for smart wallets called SquidRouterModule, used by users on Ethereum and Base networks. Overall, the attack hit 86 Gnosis Safe wallets. Within seconds after the attack, the attacker transferred funds from various checks to pools that the attacker controls on Uniswap V3 in exchange for DAI. The speed and reach of this exploit show how quickly attackers can go from discovery to exploitation once vulnerabilities are found in wallet infrastructure. In less than a blink, assets were drained, exchanged and routed through liquidity pools, scuttling countless users without offering them much time to react. Blockaid detected an ongoing exploit targeting the SquidRouterModule on Ethereum and Base. 86 Gnosis Safes drained for ~$3M in ~2 hours. All stolen tokens swapped to DAI via attacker-controlled Uniswap V3 pools. More details in — Blockaid (@blockaid_) May 25, 2026 Exposure Found In Third-Party Module, Not Core Protocol During the course of investigation, it was realised that the exploit did not originate from the core infrastructure of Squid Router. Rather, the flaw was in a module developed outside of Squid but linked with it. This contract was initially reported as the main contract being attacked, in which case it can be confusing when hearing about a report on Basescan with the name SquidRouterModule. Squid quickly explained that, despite the similar names, this module was a separate piece of functionality and not integrated. The team reiterated the importance of clarifying that even a minor change turning out to be unauthorized did not impact its official router contract, which remains secure: in a later statement shared via Squid’s Twitter Space However, user funds or approvals or integrations that directly tied with Squid’s core infrastructure remained secure. This distinction is crucial. However, despite the exploit involving substantial losses, it did not arise from issues in Squid’s protocol itself. Instead, it illustrated an inherent risk with third-party integrations, a growing aspect of modular DeFi architecture. This incident is unrelated to Squid’s core protocol and contracts. All Squid users and integrators are unaffected and no action is needed. A third-party Gnosis Safe module was exploited today across Base and Ethereum, resulting in approximately $3.2M in losses. The vulnerable… https://t.co/I3gGmdBvE9 — squid (@squidrouter) May 25, 2026 Vulnerable Validation Logic Allowed Attack At the heart of the exploit, however, was an egregious design issue in the validation logic of a third-party module. The contract used a constant string provided by the caller as proof to construct message authenticity. But this string was available publicly in the verified source code of the contract. Thus an attacker could provide anything that matched the expected string as a way to circumvent all security layers built into the software. After recovery, the contract allowed all calls without selective calldata to go through, and this gave the attacker total control to interact with any transaction from within the wallet. The affected users added this module to their Gnosis Safe as a trusted component, so the contract was allowed to perform fund transfers without additional signatures. The attack unfolded as follows: The attacker provided the string known to pass validation The contract accepted the request as a valid Arbitrary transactions were executed Moved funds out from their wallets This vulnerability shows how simple oversights in auth logic can lead to multi-million dollar losses. Trusted Module Permissions Made The Damage Bigger One of the most important elements that amplified the damage caused by this exploit was the extent of access assigned to the compromised module. Within the Gnosis Safe, trusted modules can make transactions without requiring user signatures. This architecture allows for flexibility and automation of complex workflows. But it comes with some substantial risks too, if a badly designed or malicious module. Here, it turns out users who had enabled the vulnerable SquidRouterModule were inadvertently sending the total control of their wallet assets to the contract. The attacker completely bypassed additional security layers, since the permissions were already in place at that point. What followed was a swift, massive outflow of funds with virtually no opposition. Market Impact and Fund Movement After the exploitation, the attacker had finally drowned all of their stolen assets in a false manner through DEX. By routing funds into DAI via Uniswap V3 pools, they were able to stabilize the value of the stolen assets and reduce exposure to volatility. The total losses are estimated to be between $3 million and $3.2 million, with about $3 million being drawn within less than 120 minutes. The operation’s efficiency demonstrates a very high level of preparedness and knowledge both of the targeted system, as well as DeFi liquidity mechanics. Despite the scale of the attack, its overall impact on the market was limited. The containment is primarily the result of the exploit being confined to certain wallets, rather in broad-based protocol or asset action. Clearing Up Misunderstandings About Squid’s Function Some news reports were linking the exploit to Squid’s core router due to its name as a vulnerable contract. But it is important to separate the third-party module from the official protocol in order for an accurate reading of the incident. It also did not refer instead to Squid’s own official router contract, which is architecturally different and has a separate identifier. Funds that could be traced back to its operations were not impacted and there was nothing wrong found in its code. This case highlights a long-standing issue in DeFi: the challenge of distinguishing between official infrastructure and third-party integrations. With increased connection between ecosystems, having overlapping names and branding can cause confusion around security incidents. Security and DeFi Integration Lessons For Wallets The SquidRouterModule exploit is a reminder that DeFi security goes beyond core protocols. In fact, ever-brightening primary systems can still be at risk if terminated screens or other connected components have foreseeable vulnerabilities. Several lessons emerge: First, users need to be careful when they enable third-party modules or integrations. Wallet level permissions have a broad impact. Secondly, there are many ways developers can put in place strong validation. The presence of publicly accessible constants or weak authentication can be utilized as a vulnerability. Thirdly, it is important to be transparent about ownership and responsibility. Having a clear distinction between official and unofficial components can eliminate confusion in case of incidents and help with panic control. This event also reinforces the most universal truth, security is only as strong as the weakest link in a composable ecosystem like DeFi. With the increasing interconnection between protocols, quality of every element, and not just the core, will become important. The exploit is quantifiable in millions in terms of immediate loss, but the longer-term implications may be less tangible; a shift in how users and developers formulate trust, permissioning and integration abstractions shapes their relationship with decentralized finance. Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news !
25 May 2026, 14:42
Ethereum Drops Nearly 15% Despite Aggressive Buy Activity

Ethereum witnesses steady price declines despite rising buy activity across its spot and futures markets, putting its price at the verge of retesting $1,900.
25 May 2026, 14:40
Strategy skips another purchase week and leans into bonds

Strategy skipped another week of buying BTC, instead rebalancing its reserves with bonds. The playbook change arrived just a week after a peak five-digit BTC purchase. Strategy skipped another week of purchasing BTC, while Executive Chairman Michael Saylor warning the company will instead dedicate resources to a bond purchase. Saylor stated the ‘BitVac’, short for BTC vacuum, will be changing away from the usual weekly purchases. @grok what bonds his taking about? — Saman Golesorkhi (@Radiog39) May 24, 2026 The company has held up to $2.5B in cash reserves. The bonds in question refer to a repurchase of older Strategy debt, namely $1.5B in debt due in 2029. This time, Strategy did not outline the financing source of its repurchase operations. The BTC purchase delay may also be due to the US market holiday. The biggest investor fear is that Strategy may have sold some of its BTC to finance debt repurchases, making its playbook unstable. The company will still be liable to pay STRC dividends of 11.5%, soon to become bi-weekly . Additional dividends are owed for older issuance of preferred shares STRD and STRK, which have not been used for months as a source of BTC purchases. Strategy sold no STRC for the past week The market anticipated this week’s pause in BTC purchases, as there were no data on STRC trading in the suitable price range for additional sales. After a week of $2.2M in total new sales, STRC buyers also hit a pause, on a mix of skepticism and the longer waiting period until the ex-dividend date in June. In the past two months, Strategy fell into a pattern of large purchases ahead of the dividend cut-off date, followed by smaller weekly additions financed by MSTR ATM selling. Strategy’s STRC traded below its ATM price last week, leaving no extra funds for BTC purchases. | Source: BitcoinQuant . This time, Strategy did not use its common stock issuance facility, instead focusing on its cash-like reserves. MSTR fell to $159.89, down from its recent hike above $170. The BTC purchasing pause coincided with a generally lowered demand for MSTR, as the common stock does not act as a multiplier for BTC gains. Strategy changed its playbook after buying over 4% of the total BTC supply. For now, the company remains a strong holder, though it does not try to add BTC at any rate. Is Strategy losing its credibility? The biggest fear around Strategy is that its demand structure reflects the dwindling crypto sentiment. The market is no longer in ‘up only’ mode, even for BTC. As a result, only STRC is attractive for its high monthly payouts. However, Strategy carries a growing dividend burden, sparking fears the company may not be sustainable, especially during a prolonged crypto bear market. STRC will have to show stronger demand, predicted during the week ahead of June 15. Until then, skeptics have noted Strategy may gain only up to 5% in yield on more conservative bonds, while owing 11.5% for STRC. After the week of no purchases, BTC traded at $77,216, sitting just above Strategy’s average price. Selling or stagnant demand may further undermine the trust in Strategy’s playbook, without other factors sparking a BTC bull market. The smartest crypto minds already read our newsletter. Want in? Join them .
25 May 2026, 14:37
Crypto-linked donations top $500 million in 2026 US midterms

🚨 Crypto-linked donations for 2026 US midterms have already topped $500 million. More than twice as much of this money is backing Republican candidates over Democrats. 💰 Key point: Despite industry spending, most candidates avoid mentioning $BTC or blockchain issues in their campaigns. Continue Reading: Crypto-linked donations top $500 million in 2026 US midterms The post Crypto-linked donations top $500 million in 2026 US midterms appeared first on COINTURK NEWS .
25 May 2026, 14:30
Hyperliquid Buys Back $1.16B HYPE as Token Price Hits Record Highs

Hyperliquid’s HYPE token has surged to record highs, but the rally is being powered less by institutional ETF demand and more by an aggressive protocol-driven buyback system. The mechanism has created a powerful feedback loop tying HYPE’s price directly to trading activity on the exchange. Hyperliquid’s Rally Is Being Driven by Its Buyback Machine, Not
25 May 2026, 14:30
Crypto Payments Go Autonomous As AI Agents Execute 176M Transactions

The entire machine-payment ecosystem now runs almost entirely on a single stablecoin. More than 98% of all settlements made by AI agents in the past year were processed in Circle’s USDC , according to a new report from crypto investment firm Keyrock — a concentration that researchers say carries risks the industry has largely ignored. One Stablecoin To Rule Them All Keyrock researcher Ben Harvey, writing in collaboration with Coinbase and blockchain firm Tempo, said the dependence on one issuer’s infrastructure, regulatory standing, and reserve management creates a systemic exposure that nobody in the space is publicly discussing. A regulatory challenge against Circle, a de-peg event, or even a prolonged outage would leave the agent economy with no alternative settlement option. Harvey said that risk warrants serious attention as transaction volumes continue to grow. In one year, machine payments have evolved from concept to live ecosystem, with agents settling 176M transactions. Our research with @CoinbaseDev , @tempo , and featuring @virtuals_io analyses the payment stack’s evolution, how the economics work, and what stands in the way. pic.twitter.com/W6DGGYAUC0 — Keyrock (@keyrock) May 21, 2026 The numbers behind the report are striking. From May 2025 through April 2026, AI agents settled over $70 million across 176 million transactions — an average deal size of about 31 cents. That figure alone explains why traditional payment networks were never going to work here. A standard processing fee of roughly 30 cents per transaction makes anything below a dollar completely unworkable on rails built for consumer credit cards. An agent paying three cents to call a weather API cannot route through Visa. Why Traditional Rails Were Left Behind Stablecoins filled that gap not because they were chosen but because nothing else could do the job. The economics of legacy payment infrastructure simply collapse at sub-dollar volumes, and crypto rails carry no fixed per-transaction fee that would eat the entire value of a microtransaction. By the end of the first quarter of 2026, more than 104,000 agents had been registered across 15 or more directories and registries worldwide. Harvey described the shift as going from concept to a developed ecosystem in just 12 months. Incumbents appear to have taken notice — the report says more than $8 billion has been deployed in acquisitions by established players looking to stake a position in what is emerging as a new payment stack built around autonomous software rather than human users. A Market Built On One Foundation AI agents are already being used to build Web3 applications, launch tokens, trade, and interact autonomously with protocols and services. A CoinGecko survey of 2,632 crypto users conducted last April found 87% were willing to let AI agents manage at least 10% of their crypto portfolio. Circle CEO Jeremy Allaire has predicted that billions of agents will operate with stablecoins on users’ behalf within five years. Featured image from Unsplash, chart from TradingView














































