NewMarketTrading's SquidRouterModule vulnerable to access control bypass allowing attackers to impersonate delegates and drain user balances; ~$3M lost.
Security & Exploits ·
NewMarketTrading suffered an access control vulnerability in its SquidRouterModule that enabled attackers to drain approximately $3M from user accounts. The flaw allowed unauthorized parties to impersonate delegates and execute arbitrary token swaps and approvals on user Safe smart accounts, which the platform uses to provide non-custodial DeFi access across protocols including Aave, Yearn, and Morpho.
The vulnerability stemmed from NewMarketTrading's implementation of Axelar's expressExecuteWithToken pattern. The SquidRouterModule performed insufficient validation of the delegate address encoded in transaction payloads, trusting attacker-supplied data without gateway verification at express execution time. By crafting malicious payloads containing legitimate delegate addresses paired with unauthorized swap or approve actions, an attacker could cause any user Safe to approve and transfer its full token balance.
NewMarketTrading disclosed the issue after its monitoring system detected the initial attack and notified Squid Router accordingly. The flaw was isolated to NewMarketTrading's module wrapper rather than Squid Router itself. A sample transaction documenting the exploit mechanics is publicly visible on chain, along with the vulnerable module contract, though specifics regarding remediation timeline and whether affected users will receive compensation remain unclear.