<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Third-Party Smart Wallet Bug Leads to $3.2 Million Crypto Theft]]></title><description><![CDATA[<p dir="auto"><img src="/forum/assets/uploads/files/1780028083895-fde28f40-c523-46e3-a6e4-3e15a0da6b7d-image.png" alt="fde28f40-c523-46e3-a6e4-3e15a0da6b7d-image.png" class=" img-fluid img-markdown" /><br />
A vulnerability in a third-party Gnosis Safe module resulted in approximately $3.2 million being stolen from dozens of wallets across Ethereum and Base. Blockchain security firms reported that attackers exploited a trusted module configuration to gain unauthorized access and transfer user funds.</p>
<p dir="auto">Investigators revealed that the compromised module accepted a publicly available string as proof of message validity, allowing attackers to execute malicious transactions without obtaining wallet owner signatures. The stolen assets were later converted into DAI through attacker-controlled liquidity pools, making recovery efforts more difficult.</p>
<p dir="auto">The exploit adds to a growing list of security incidents affecting the crypto industry in 2026. While audits remain a critical part of protocol security, recent attacks continue to show that operational configurations, third-party modules, and trusted integrations often present risks that are just as significant as vulnerabilities in smart contract code.</p>
]]></description><link>https://undeads.com/forum/topic/20714/third-party-smart-wallet-bug-leads-to-3.2-million-crypto-theft</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 04:36:43 GMT</lastBuildDate><atom:link href="https://undeads.com/forum/topic/20714.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 29 May 2026 04:14:45 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Third-Party Smart Wallet Bug Leads to $3.2 Million Crypto Theft on Fri, 29 May 2026 07:55:08 GMT]]></title><description><![CDATA[<p dir="auto">attackers discovering they did not need private keys when someone accidentally accepted a public string as proof of authorization</p>
]]></description><link>https://undeads.com/forum/post/58397</link><guid isPermaLink="true">https://undeads.com/forum/post/58397</guid><dc:creator><![CDATA[etfs]]></dc:creator><pubDate>Fri, 29 May 2026 07:55:08 GMT</pubDate></item></channel></rss>