Safe{Wallet}
Summary
Safe{Wallet}, operated by the Safe Ecosystem Foundation, is the dominant smart-contract multisig platform on Ethereum and EVM-compatible chains, securing approximately $35 billion in assets across 61 million accounts as of Q1 2026. In February 2025, a developer machine compromise by North Korea's Lazarus Group (TraderTraitor) allowed attackers to inject malicious JavaScript into the app.safe.global frontend, enabling the theft of approximately $1.5 billion in ETH from Bybit — the largest cryptocurrency heist in history. The Safe smart contracts themselves were not compromised; the attack was entirely at the infrastructure and frontend layer. Safe has since rebuilt its infrastructure and launched Safenet, a decentralized transaction-security network, as a structural response.
Connected Entities
1 entities · 10 linked investigations- + 5 more
Timeline(16 events)
2017-01-01
Safe launched as Gnosis Multi-signature Wallet, the first version of what would become the industry-standard Ethereum multisig.
History of Safe — Safe Foundation2018-01-01
Gnosis Safe released, introducing a proxy-singleton architecture and modular design, replacing the original Gnosis Multisig.
History of Safe — Safe Foundation2022-04-20
Project rebranded from Gnosis Safe to Safe; SAFE governance token launched with 1 billion total supply.
Safe — IQ.wiki2023-01-01
Safe Ecosystem Foundation formally incorporated; SafeDAO formed following strategic fundraise from investors.
History of Safe — Safe Foundation2024-04-25
SAFE token reached its all-time high of approximately $2.69–$4.48 per token.
Safe Price History — CoinMarketCap2025-02-04
A Safe{Wallet} developer's macOS workstation was compromised via social engineering. The developer downloaded a Docker project ('MC-Based-Stock-Invest-Simulator-main') containing malware that exploited a PyYAML RCE vulnerability.
Sygnia Investigation into the Bybit Hack2025-02-05
Attackers used the developer's extracted AWS credentials to access Safe's cloud infrastructure, hijacking an active session token to bypass MFA.
Sygnia Investigation into the Bybit Hack2025-02-19
Attackers injected malicious JavaScript into the file '_app-52c9031bfa03da47.js' in Safe's AWS S3 bucket. The payload was designed to activate only when Bybit's contract addresses were detected.
Sygnia Investigation into the Bybit Hack2025-02-21
Bybit's signers used the compromised app.safe.global interface to authorize what appeared to be a routine cold-wallet transfer. The malicious JavaScript silently replaced the transaction's destination, resulting in approximately 400,000 ETH (~$1.5 billion) transferred to attacker-controlled addresses at approximately 14:13 UTC.
FBI/IC3 Public Service Announcement2025-02-21
Approximately two minutes after the malicious transaction was executed (~14:15 UTC), attackers uploaded clean JavaScript files back to Safe's AWS S3 bucket to erase forensic evidence.
Sygnia Investigation into the Bybit Hack2025-02-26
FBI formally attributed the Bybit theft to North Korea's TraderTraitor threat group via IC3 public service announcement. Safe and Bybit issued competing statements on responsibility.
FBI/IC3 Public Service Announcement2025-02-28
Safe Ecosystem Foundation published its official statement, confirming the developer machine compromise, confirming smart contracts were unaffected, and announcing full infrastructure rebuild and credential rotation.
Statement by the Safe Ecosystem Foundation2025-03-03
Safe co-founder Martin Koeppelmann confirmed ten UI security improvements had been shipped, including displaying full raw transaction data and removing hardware wallet integrations that raised security concerns.
Safe Wallet responds to Bybit hack with major security improvements — Crypto.news2025-03-20
Approximately 86% of the stolen ETH had been converted to Bitcoin and dispersed across thousands of addresses, according to tracking by blockchain analytics firms.
Bybit Hack 2025: $1.5B Stolen by North Korea — Cloudskope2025-07-01
Rahul Rumalla joined the Safe ecosystem as VP of Product and Engineering; later became CEO of Safe Labs as the subsidiary took direct operational control of Safe{Wallet}.
Non-custodial crypto wallet Safe reports fivefold revenue jump — The Block2026-04-02
Safe Foundation launched Safenet Beta at EthCC in Cannes, a decentralized transaction-security network using cryptographic attestations to address the blind-signing vulnerability class. Six genesis validators each staked a minimum of 3.5 million SAFE tokens.
Safe Launches Safenet Beta — Safe FoundationDecision Log
- hash: BwW5nmiWSK4QzNEGw59mUyY7SwHftixBwr6oxfjnBhD1
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 6/3/2026, 12:07:45 AM
last updated: 6/3/2026, 12:07:51 AM
avoid.net — verified advice for a post-truth world