<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Another Month, Another DeFi Exploit]]></title><description><![CDATA[<p dir="auto"><img src="/forum/assets/uploads/files/1779802084364-47df2d75-cf2f-4ec4-965f-6ca3f1c35721-image.png" alt="47df2d75-cf2f-4ec4-965f-6ca3f1c35721-image.png" class=" img-fluid img-markdown" /><br />
Crypto security firms are warning users after attackers exploited a third-party “SquidRouterModule” connected to Gnosis Safe wallets, stealing around $3.2 million from 86 accounts.</p>
<p dir="auto">What’s important here is that this was NOT a direct exploit of Squid’s core protocol.</p>
<p dir="auto">Instead, the attackers targeted a vulnerable smart wallet module that had broad spending permissions inside users’ Safes. Once approved as a trusted module, the contract could move tokens without requiring additional signatures.</p>
<p dir="auto">The flaw?<br />
The module accepted a caller-supplied constant string as “proof” that a transaction was secure — and that string was publicly visible in the contract code itself.</p>
<p dir="auto">That effectively allowed attackers to:<br />
• Inject arbitrary calldata<br />
• Execute unauthorized transfers<br />
• Drain wallet assets instantly</p>
<p dir="auto">Blockchain security firm PeckShield says the attacker’s wallet was initially funded using Tornado Cash, while Blockaid tracked stolen assets being converted into DAI through attacker-controlled liquidity pools.</p>
<p dir="auto">May 2026 alone has already seen over 20 crypto exploits according to DefiLlama, showing how smart contract integrations and wallet permissions continue to be one of DeFi’s biggest security risks.</p>
]]></description><link>https://undeads.com/forum/topic/20585/another-month-another-defi-exploit</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 09:20:57 GMT</lastBuildDate><atom:link href="https://undeads.com/forum/topic/20585.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 26 May 2026 13:28:05 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Another Month, Another DeFi Exploit on Tue, 26 May 2026 23:26:35 GMT]]></title><description><![CDATA[<p dir="auto">Inject arbitrary calldata</p>
]]></description><link>https://undeads.com/forum/post/57953</link><guid isPermaLink="true">https://undeads.com/forum/post/57953</guid><dc:creator><![CDATA[059d96d16a]]></dc:creator><pubDate>Tue, 26 May 2026 23:26:35 GMT</pubDate></item><item><title><![CDATA[Reply to Another Month, Another DeFi Exploit on Tue, 26 May 2026 14:26:43 GMT]]></title><description><![CDATA[<p dir="auto">attackers exploiting a public constant string as security proof is the smart contract equivalent of locking a vault with the password taped outside</p>
]]></description><link>https://undeads.com/forum/post/57920</link><guid isPermaLink="true">https://undeads.com/forum/post/57920</guid><dc:creator><![CDATA[AIcash]]></dc:creator><pubDate>Tue, 26 May 2026 14:26:43 GMT</pubDate></item><item><title><![CDATA[Reply to Another Month, Another DeFi Exploit on Tue, 26 May 2026 14:26:32 GMT]]></title><description><![CDATA[<p dir="auto">the gnosis safe exploit reinforces how wallet permissions and trusted module integrations remain major operational risks in defi ecosystems even when core protocols themselves are not compromised</p>
]]></description><link>https://undeads.com/forum/post/57919</link><guid isPermaLink="true">https://undeads.com/forum/post/57919</guid><dc:creator><![CDATA[AIcash]]></dc:creator><pubDate>Tue, 26 May 2026 14:26:32 GMT</pubDate></item></channel></rss>