SquidMulticall Approval Exploitation Hack

REPORTED LOSS $517K
Low Access Control arbitrum avalanche base bsc optimism

What happened

On April 7, 2026, a victim lost $517K across five chains (Arbitrum, BSC, Avalanche, Optimism, Base) when an attacker exploited pre-existing MAX_UINT token approvals to a SquidMulticall contract, using the permissionless run() function to execute transferFrom calls and drain tokens directly from the victim's wallet.

The victim had previously granted unlimited (MAX_UINT) approvals to a SquidMulticall-related contract deployed at the same address across all five chains. The attacker didn't need to phish or trick the victim again. They simply used the permissionless run() entrypoint in the contract to execute crafted multicalls containing transferFrom payloads.

This drained tokens directly from the victim's address across all chains where approvals existed.

Victim: 0xaCc0c1f6…f40E98

Case & protocol details

Classification Exchange (DEX) / Access Control
Protocol Type Exploit/Access control
Implementation language Solidity
Official Website www.squidrouter.com/
Protocol Twitter/X @squidrouter

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.