Squid Hack
What happened
On 7 October 2025, attackers exploited Squid Router's Permit2-sponsored order path across BSC, Ethereum, Arbitrum, Base, and Optimism. Public incident reports place the aggregate loss at more than $90,000, primarily in USDT and USDC.
Permit2 token identity was not bound to the order's declared input token. Token address and amount must remain consistent from permitted input through order accounting, settlement, and refunds.
Case & protocol details
Attack Timeline
The vulnerable sponsorOrderUsingPermit2 path did not require the token authorized in the Permit2 payload to match order.fromToken. An attacker could submit an order that accounted for a valuable input asset while transferring in a different token. This broke the router's token-identity invariant: a later refund or order path could release the valuable USDT or USDC value credited by the order even though that asset had not been supplied.
The issue was an input-validation and accounting failure, not a Permit2 signature failure or oracle manipulation. Reports vary between $90,000 and $94,000, so this page preserves the rounded lower-bound display.
Evidence & learning
Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.