What happened
Attacker modified the airdrop destination address to a lookalike (0x70AE678b457C5E1b3fD7AD9537F234dFc1795C15 instead of 0x70ae7D3DECfB4C3aE996fb1c07092566F73D5c15).
Transaction-level mechanics
Public post-incident disclosures do not include full transaction calldata or execution traces for this incident.
TODO: Add exact Safe transaction hash, decoded actions, and the on-chain state changes once verified primary sources are available. For now, the attack vector summary above is derived from public reporting.
What independent decoding / hash verification / config scanning would have caught
Clean catch. Transaction Inspector reveals the exact destination address in the decoded calldata, exposing lookalike substitutions before a signer approves.
Verdict
Could have helped