New Market Trading hack — May 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | May 25, 2026 |
| Target type | Other |
| Loss | $3,070,000Published estimates range $3,000,000 to $3,780,000Price at time of incident |
| Method | Access control flawNew Market Trading's SquidRouterModule exposed an express-execution entry point inherited from Axelar's gateway interface. It checked a caller-supplied sourceAddress string against the expected router address, with no binding to msg.sender, and then read the authorised delegate address out of the attacker's own payload instead of deriving it from the caller. Because the permissions registry holding each Safe's delegate was public on-chain, any Safe's delegate could be forged. |
| Chains | Ethereum, Base, Arbitrum |
| Outcome | Unresolved |
What happened
New Market Trading is a non-custodial onchain wealth-management service. Clients keep assets in their own Safe smart accounts and grant a New Market Trading module permission to execute trades on their behalf through a registered delegate.
On 25 May 2026 that module, named SquidRouterModule, was drained through an access-control bypass. The module exposed an express-execution entry point inherited from Axelar's gateway interface, guarded by two checks that an unauthenticated caller could satisfy. The first compared a sourceAddress string supplied in the call data against the expected router address, with nothing tying that string to msg.sender. The second checked whether a delegate held approval rights over a given Safe, but decoded the delegate address from the caller's own payload rather than deriving it from the actual sender; the missing safeguard was a check that msg.sender equalled the delegate. Because the PermissionsManager registry storing each Safe's delegate was public on-chain, an attacker could read the correct delegate for every Safe and forge a payload that passed both checks. The forged calls approved tokens, granted Permit2 allowances and swapped each Safe's balance through Uniswap V3 with minimum output set to zero.
Loss estimates differ. Blockaid, which detected the attack while it was running, counted 86 Safes on Ethereum and Base and traced about 3.07 million DAI consolidated into a single address. QuillAudits counted 88 Safes across Ethereum, Base and Arbitrum and put victim losses at about $3.78 million. Blockaid reported that the attacker's address had been funded through Tornado Cash.
Squid stated that its main router contracts and user funds were never affected and that its core team had no hand in building, deploying or operating the module despite the similar name; reporting also noted that Gnosis's core Safe infrastructure was not affected, only users who had approved the third-party module. New Market Trading sent the attacker two on-chain messages offering a white-hat bounty if 80% of the drained funds were returned. No return has been reported.
Sources
- QuillAuditsSecondary · retrieved 2026-08-01
- DarkNavySecondary · retrieved 2026-08-01
- DeFi Planet (reporting Blockaid)Secondary · retrieved 2026-08-01
- Coin EditionSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "New Market Trading hack — May 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/new-market-tradinghttps://itokenly.com/hacks/new-market-tradingPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.