Gnosis Safe生態模組遭利用,Squid澄清未直接參與
Coinpaper
05-26 17:14
Ai Focus
Gnosis Safe 生態第三方模組遭利用,約 320 萬美元資產被轉走。 Squid 表示涉事合約並非由其建置、部署或營運。
Helpful
No.Help

以太坊與 Base 上一款連接 Gnosis Safe 生態的第三方模組遭到利用,約 320 萬美元資產在兩小時內從 86 個 Safe 錢包中被轉走。由於涉事合約在 Basescan 上顯示為“SquidRouterModule”,事件初期一度被外界誤認為與跨鏈協議 Squid 直接相關。

Squid稱並未部署合約

Squid 隨後回應稱,存在漏洞的合約並非由專案方建置、部署或運營,只是一個獨立模組接入了 Squid 以及其他協議。團隊表示,攻擊期間 Squid 的核心路由基礎設施不受影響。

專案方也批評了早期公開資訊中的錯誤關聯,稱問題合約只是名稱中帶有 Squid,並不代表模組屬於 Squid 協議本身。

兩小時波及 86 個 Safe

區塊鏈安全公司 Blockaid 和 PeckShield 較早披露了事件細節。兩家機構稱,攻擊發生在 Gnosis Safe 生態的第三方模組層面,影響橫跨以太坊和 Base 網路。

  • 受影響錢包數量為 86 個 Safe
  • 被轉走資產總額約 320 萬美元
  • 資金隨後被歸集為約 307 萬枚 DAI

漏洞繞過簽章校驗

根據公開分析,模組接受了由呼叫方提供的固定字串,並將其作為交易訊息安全性的證明。攻擊者藉此繞過簽章驗證,向受害錢包執行任意呼叫資料。

Squid 稱,這項缺陷讓攻擊者無需獲得合法錢包授權,就能動用受影響 Safe 中持有的代幣。安全研究人員表示,攻擊利用了基於 Foundry 的利用合約,並針對該模組的 DelegateBundler 執行路徑展開。

資金流向已被追蹤

Blockaid 表示,攻擊者冒充與各個 Safe 關聯的授權代理人,透過 Uniswap V3 流動性池發動任意代幣交換。被盜資產隨後被換成一種名為“u”的無價值代幣,這些流動性池由攻擊者預先佈置並控制。

在資產經過這些池子後,攻擊者移除流動性,並將所得資金歸集。 PeckShield 表示,相關資金目前存放在以「0xa447...54859」開頭的錢包位址中。

Tip
$0
Like
0
Save
0
Views 382
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Web3: Demand for Bitcoin options as a safe haven cools ahead of the Fed rate decision.
The Bitcoin options market calmed down ahead of the Federal Reserve's interest rate decision, with short-term safe-haven demand declining significantly.
CoinDesk
·2026-07-27 20:02:15
833