Ripple News: Squid Crypto closed a $6 million strategic funding round led by North Island Ventures with participation from Ripple on May 25, 2026, and in less than 24 hours, an attacker drained $3 million from the protocol.
The exploit affected a third-party liquidity aggregation module integrated into Squid’s cross-chain exchange infrastructure, not the core contracts being audited.
Squid’s official response has been to completely distance itself from the breach, stating that the team does not know who deployed the specific module responsible for the drain.
Squid functions as a meta-DEX and chain abstraction protocol, routing cross-chain trading across multiple networks through aggregated liquidity layers.
The $6 million raise was positioned as a catalyst for the expansion of this interoperability infrastructure, with Ripple’s involvement defined as strategic alignment with its broader cross-chain and payments roadmap. This narrative collapsed in a single news cycle.

Discover: The best crypto to diversify your portfolio
Ripple News: How the Squid Crypto exploit works: third-party module vulnerability
The attack vector was a liquidity aggregation edge module that Squid had recently integrated to facilitate cross-chain trading routing, a component located outside of the protocol’s suite of audited core contracts.
The attacker exploited manipulated price feeds or misconfigured access permissions in this module to directly siphon assets, thereby bypassing the security controls that governed Squid’s core contracts.

This is a structural pattern that has appeared repeatedly in the history of DeFi exploits: audits cover submitted components, not the full dependency tree.
The module in question was a third-party integration layer, meaning its trust assumptions, authorization logic, and Oracle dependencies were never subjected to the same scrutiny as Squid’s native code.
Squid Router’s ResponseSquid Router quickly released a statement distancing itself from the exploit. The team clarified that the funds drained came from a third-party Gnosis Safe module called
SquidRouterModule, which was neither built, deployed nor operated by them. They emphasized that their primary router contract was not affected and that all standard Squid users and integrators were safe.
The team noted that the module had been integrated into Squid alongside other protocols without any direct involvement from Squid, and urged the community to avoid confusing the two due to similar naming. No action was required from Squid users.
Discover: the best token presales
The post Ripple News: Squid raised $6 million with Ripple backing, then lost half of it to a hack less than 24 hours later appeared first on Cryptonews.



Blockaid has detected an exploit in progress targeting the SquidRouterModule on Ethereum and Base.