Squid Hack

TOTAL LOST $90K
Low Permit2 Token-Identity Mismatch arbitrum base bsc ethereum optimism

What happened

On 7 October 2025, attackers exploited Squid Router's Permit2-sponsored order path across BSC, Ethereum, Arbitrum, Base, and Optimism. Public incident reports place the aggregate loss at more than $90,000, primarily in USDT and USDC.

Technical Root Cause

Permit2 token identity was not bound to the order's declared input token. Token address and amount must remain consistent from permitted input through order accounting, settlement, and refunds.

Case & protocol details

Classification Cross-Chain Router / Protocol Logic
Protocol Type Exploit/Other
Official Website www.squidrouter.com/
Protocol Twitter/X @squidrouter

Attack Timeline

The vulnerable sponsorOrderUsingPermit2 path did not require the token authorized in the Permit2 payload to match order.fromToken. An attacker could submit an order that accounted for a valuable input asset while transferring in a different token. This broke the router's token-identity invariant: a later refund or order path could release the valuable USDT or USDC value credited by the order even though that asset had not been supplied.

The issue was an input-validation and accounting failure, not a Permit2 signature failure or oracle manipulation. Reports vary between $90,000 and $94,000, so this page preserves the rounded lower-bound display.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.