SquidMulticall Approval Exploitation Hack
What happened
On April 7, 2026, a victim lost $517K across five chains (Arbitrum, BSC, Avalanche, Optimism, Base) when an attacker exploited pre-existing MAX_UINT token approvals to a SquidMulticall contract, using the permissionless run() function to execute transferFrom calls and drain tokens directly from the victim's wallet.
The victim had previously granted unlimited (MAX_UINT) approvals to a SquidMulticall-related contract deployed at the same address across all five chains. The attacker didn't need to phish or trick the victim again. They simply used the permissionless run() entrypoint in the contract to execute crafted multicalls containing transferFrom payloads.
This drained tokens directly from the victim's address across all chains where approvals existed.
Victim: 0xaCc0c1f6…f40E98
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.