Skip to main content
Hata Logo Explore
Loading chart…

What is Safe (SAFE)?

Safe (formerly Gnosis Safe) is a smart-account infrastructure platform providing programmable, non-custodial smart-contract accounts across Ethereum and other EVM-compatible networks. A Safe account can require a configurable threshold of owner approvals—for example, 2-of-3—before executing transactions, replacing the single-private-key authorization model of conventional externally owned accounts. Its origins trace back to Gnosis, with the original Gnosis Multisig introduced in 2017 and the Gnosis Safe architecture subsequently developed into a broader smart-account platform before being spun out and rebranded as Safe in 2022. The protocol provides programmable self-custody infrastructure for individuals, organizations, DAOs, and institutions through features such as modules, guards, transaction batching, and customizable authorization policies, and has become one of the most widely adopted smart-account infrastructures in the EVM ecosystem. The SAFE token is the ERC-20 governance token of the Safe ecosystem and SafeDAO, and also gained a role in the network's economic and security model through staking-related mechanisms, expanding its utility beyond governance. (Source: Safe | Safe Documentation | Safe Foundation) 

Risk Associated to the Digital Asset 

SAFE is a governance token whose value is distinct from the assets that Safe smart accounts secure. Participants should weigh the following: 

  • Market Volatility Risk: SAFE is highly volatile and trades well below earlier levels. When the token became transferable in April 2024 it changed hands around $2.80; by June 2026 it traded near $0.10 — a decline of roughly 95%. (Source: CoinGecko)

  • Regulatory & Adoption Risk: As a DAO governance token, SAFE's value is tied to the continued adoption of the Safe smart-account standard against growing competition (e.g. Argent, ZeroDev, Biconomy, Coinbase Smart Wallet, and Squads on Solana), and to the still-developing utility of the token itself. (Source: eco.com support)

  • Cybersecurity & Custody Risk: While SAFE is a simple ERC-20 and the Safe protocol's smart contracts have a strong audit record, the wider Safe ecosystem's off-chain infrastructure was the vector for the largest crypto theft on record (the February 2025 Bybit incident — see Operational Description). That event was a front-end / supply-chain compromise rather than a smart-contract flaw, but it is highly material to anyone assessing the Safe ecosystem. Self-custody of SAFE also carries ordinary private-key and phishing risk. (Source: Safe / BleepingComputer) 

  • Concentration & Liquidity Risk: SAFE is a small-cap token with notably thin daily turnover (often only a few hundred thousand to a few million dollars), so larger orders can move the market materially. A large share of supply is held in DAO-controlled treasuries and foundation/contributor allocations rather than by dispersed holders (Source: CoinGecko | EtherScan).

  • Governance & Centralisation Risk: The token was non-transferable for roughly two years after its airdrop, a substantial portion of supply remains under SafeDAO/GnosisDAO treasury control, and the new Safenet validator set launched as a small, permissioned group of genesis validators. (Source: The Block | Safe Foundation)

  • Emission / Dilution Risk: SAFE has a fixed 1 billion maximum supply with no mining, but roughly a quarter of supply remains locked and continues to vest over multi-year schedules (treasury allocations extend up to eight years), creating ongoing dilution as tokens unlock. (Source: CryptoRank)

Customers should ensure they fully understand the nature, mechanics and risks of this asset — including that it is a governance token separate from the assets Safe accounts hold, its thin liquidity, and its vesting/unlock profile — before trading, and should only commit capital they can afford to lose. 

Trading History of Digital Asset

  • Market Capitalisation & Liquidity: SAFE is a small-cap token. As at June 2026, reported market capitalisation was roughly $72 million, with circulating supply of about 750 million SAFE (~75% of the 1 billion maximum), a fully diluted valuation near $96 million, and a CoinGecko/CoinMarketCap rank in the ~#300–#350 band. Liquidity is thin: reported 24-hour spot volume across this period was generally in the ~$0.9 million–$3.8 million range, with venues such as Bybit, Gate, OKX and Bitunix among the more active. (Source: CoinGecko | CoinMarketCap)

  • Transferability & Price History: SAFE was distributed via an airdrop in October 2022 but remained non-transferable for almost two years; after a SafeDAO vote (over 99% in favour) the token contract was unpaused and SAFE became transferable on around 23 April 2024, trading near $2.80 at the time before declining substantially. (Source: The Block)

  • Ecosystem Scale & Institutional Integration: Safe smart accounts secure assets reported in excess of $100 billion and have processed over $1.4 trillion in cumulative value, across 200+ ecosystem projects and 15+ networks, with users ranging from Vitalik Buterin to enterprises such as Shopify and Reddit, and custody/infrastructure integrations including Fireblocks, Anchorage and Coinbase Custody. (Source: CoinMarketCap | eco.com support) 

  • Historical Data Source: For full historical price and volume series, refer to the live SAFE market pages on CoinGecko and CoinMarketCap. (Source: CoinGecko | CoinMarketCap)

Incidents of Manipulation or Security Failures

SAFE itself is a standard ERC-20 governance token on Ethereum; it does not run its own Layer-1 or consensus mechanism. The asset of substance behind it is the Safe smart-account protocol — open-source, extensively audited, largely non-upgradeable contracts deployed across 15+ EVM chains using a proxy-singleton pattern — together with, since 2026, Safenet, a transaction-security validator layer in which SAFE is staked. (Source: eco.com support | Safe Foundation)

On price-manipulation history, no documented manipulation of the SAFE token market beyond ordinary volatility was identified during preparation.

On security failures, the defining event in the Safe ecosystem — and the most important item in this disclosure — was the February 2025 Bybit theft, the largest crypto heist on record (approximately $1.4–$1.5 billion, ~401,000 ETH and staked-ETH, drained from a Bybit cold wallet on 21 February 2025). (Source: NCC Group) Critically, this was not an exploit of Safe's smart contracts. Forensic investigations (Sygnia and Verichains) traced the attack to the North-Korea-linked Lazarus group, which compromised a Safe Wallet developer's workstation in early February, used the developer's AWS credentials to reach Safe Wallet's hosting infrastructure, and injected malicious JavaScript into the Safe Wallet web interface (app.safe.global) that was specifically targeted at Bybit's signers. (Source: NCC Group | BleepingComputer) 

The tampered interface displayed a normal-looking transfer while the underlying transaction was a delegatecall that altered the wallet's control logic — a "blind-signing" deception — allowing the attackers to sweep the funds. (Source: NCC Group) The forensic reviews found no vulnerability in Safe's smart contracts and no compromise of Bybit's own infrastructure; Safe stated it rebuilt and reconfigured all infrastructure, rotated all credentials, and added transaction hash/data/signature validations. (Source: Safe / DailySecurityReview) SAFE token holders did not lose funds as a direct result, but the incident demonstrated that the weakest link in a smart-account system can be its off-chain front-end and operational supply chain rather than its audited contracts. (Source: Sygnia)

On current maturity of controls, the response has been an industry-wide push toward transaction-level verification; Safe's own Safenet (launched April 2026) enforces protocol-level transaction checks on-chain before a Safe transaction executes, replacing purely centralised/off-chain warning systems. (Source: Safe Foundation)

Token Ownership Concentration

Supply: SAFE has a fixed maximum and total supply of 1 billion tokens. However, the full 1 billion SAFE was not released into circulation at launch. Safe Foundation states that the initial circulating supply was approximately 427 million SAFE (42.7%), with the remaining tokens subject to allocation-specific vesting and unlock schedules. The vesting period extends for up to approximately eight years, meaning additional SAFE tokens enter circulation progressively over time rather than through mining or an ongoing inflationary issuance mechanism. (Source: Safe Tokenomics)  

Vesting / Lock-ups for Insiders & Affiliates: Unlike a bearer commodity token, SAFE has extensive insider/affiliate lock-ups. The SafeDAO treasury allocation (reported at ~400 million SAFE) vests over eight years and the GnosisDAO allocation (~150 million) over four years; the strategic-raise backers (~80 million across 60+ investors) had a one-year lockup followed by multi-year vesting; and core-contributor allocations likewise vest over time. (Source: TokenInsight) In addition, the token was non-transferable for roughly two years after the October 2022 airdrop until SafeDAO enabled transfers in April 2024. (Source: The Block)

Holder Distribution & Concentration: Ownership is heavily concentrated in DAO-controlled treasuries (SafeDAO and GnosisDAO) and foundation/contributor vesting contracts, so the largest on-chain balances are predominantly treasury, vesting and exchange wallets rather than dispersed individual owners. With the launch of Safenet, additional SAFE is now also locked in validator/staking arrangements (genesis validators staked a minimum of 3.5 million SAFE each). (Source: SafeDAO Tokenomics | Safe Foundation)

Security Audit 

SAFE functions as an application-layer ERC-20 governance and utility token securing the Safe smart account ecosystem. Rather than executing an independent Layer-1 consensus network, its baseline security relies on Ethereum (and supported EVM deployment chains), open-source smart account contracts, and the decentralized Safenet validator network.

  • Ackee Blockchain & Multi-Firm Smart Contract Audits: Safe’s core contract codebase (github.com/safe-global/safe-smart-account) has undergone extensive third-party security audits and formal verifications by firms including Ackee Blockchain Security, OpenZeppelin, Runtime Verification, and G0 Group. An extensive review by Ackee Blockchain evaluated Safe Smart Account contracts and ERC-4337 compatibility handlers, confirming zero Critical or High vulnerabilities. A single Medium-severity deployment proxy callback front-running vector (SafeProxyFactory) was identified and remediated without affecting active deployed accounts.

  • Safenet Security Layer & Economic Staking: Launched in Beta, Safenet expands $SAFE beyond voting governance into an economic security asset. Independent validators stake SAFE tokens (supported by holder delegation) to evaluate proposed transactions against protocol-level security rules before execution. A specialized on-chain Safe Guard verifies validator attestations prior to transaction finalization, blocking invalid calls automatically.

  • On-Chain Enforcement vs. Front-End Vulnerabilities: Following industry-wide UI/DNS attacks (such as the February 2025 Bybit front-end incident), Safenet enforces transaction verification directly within the EVM execution path. It replaces client-side web browser warnings with on-chain rules that block unauthorized delegate call attempts, untrusted module integrations, and unverified fallback handler modifications.

  • Modular Account Abstraction (ERC-4337 & ERC-7579): Safe smart accounts implement standardized Account Abstraction modules, including gas-sponsored paymasters, passkey execution drivers, and isolated timelocked recovery modules. Extensions and fallback managers operate in isolated execution environments to prevent unauthorized module permissions from altering core account thresholds.

Hata Custody Controls

For client assets held on Hata, Hata maintains its standard institutional custody and compliance framework: SOC 2 Type II certified custody, multi-signature (Multi-Sig) withdrawal authorisation, segregation of client assets, audited operational governance, continuous blockchain-analytics monitoring, and FATF Travel Rule compliance aligned with major regimes (EU/MiCA, Singapore, Japan and the UAE). These controls govern how Hata safeguards SAFE held with the exchange and are independent of the asset's own protocol-level security.

Sources

Disclaimer & Warning

The information provided here is presented "as is" and is intended for general informational and educational purposes only. It does not come with any representation or warranty of any kind. This content should not be interpreted as financial, legal, or other professional advice, and it is not intended to endorse or recommend the purchase of any specific product or service. It is advisable to consult with appropriate professional advisors for personalized guidance. In cases where the article is contributed by a third-party author, please note that the expressed views belong to the author alone and may not necessarily reflect the opinions of Hata. For further details, we encourage you to read our complete disclaimer. Please be aware that the prices of digital assets can be highly volatile. The value of your investment may increase or decrease, and there is a risk that you may not recover the full amount invested. You are solely responsible for making your own investment decisions, and Hata cannot be held liable for any losses you may incur. This material is not to be construed as financial, legal, or other professional advice. For more information, please refer to Hata’s Term of Use and Risk Warning.