Hashvard watches your Safe multisig, admin keys and contracts. Every queued transaction is decoded from raw calldata, its hashes are recomputed for your hardware wallet, and risky actions land in your team's Telegram — usually while only the proposer has signed.
Most watchers forward what the Safe service says. Hashvard does not trust the UI or the service: it recomputes safeTxHash, domain and message hashes from the raw fields and decodes calldata itself.
Inputs read from chain: tx 0x46de…7882, block 21,895,238. The recomputed safeTxHash matches the ExecutionSuccess event of the Bybit Safe exactly.
The biggest incidents of 2025–2026 were not code bugs. People approved something other than what they were shown.
Signers were shown a routine transfer. The Safe actually delegatecalled into an attacker contract.
On-chain transaction ↗Security-council signers were socially engineered into pre-signing an admin transfer.
TRM Labs ↗ · BlockSec ↗Spoofed transfers passed the normal approval flow. Keys were not stolen.
CoinDesk ↗The same transaction, three views. Hashvard reads the third one.
A routine transfer from the cold wallet, presented by a compromised web interface.
operation = 1 (DELEGATECALL) to 0x9622…7242, an unknown contract, calling transfer(0xbDd0…9516, 0). Executed with delegatecall, that call runs inside the Safe and rewrites its storage.
CRITICAL — DELEGATECALL to non-standard contract. Only the official MultiSend, SignMessageLib and CreateCall libraries are expected here. Plus the exact hashes the hardware wallet displays.
Two independent watches over the same team: the signing queue and the on-chain admin surface.
Anything other than the official Safe libraries gets full control of your Safe. Flagged at the top level and inside batches.
Owners, threshold, modules, guard, fallback handler, singleton — queued or already executed.
We recompute safeTxHash, domain and message hashes ourselves. If the service disagrees, you hear about it.
Proxy implementation, ProxyAdmin owner, beacon, owner(), roles granted or revoked, timelock delay.
ERC-20 approvals, Permit2 allowances and setApprovalForAll from your treasury, decoded per call.
Everything else that changes who controls the protocol, explained in plain words.
No contracts to deploy, no keys to share. Read-only from day one.
Send your Safe, proxy, timelock or token contract to @Hashvard_bot — or use the form below.
Signers, threshold, modules, guard, proxy admin, owner, roles, pause state, timelock delay.
Every new queued transaction and every change to the baseline. Add the bot to your signers' group so everyone sees it.
Timing, honestly. The Safe queue is read from the Safe Transaction Service every minute; contract state is re-checked every 5 minutes. A new transaction is flagged when it is proposed — with a 2-of-3 or 3-of-5 threshold that is normally while only the proposer has signed, so the other signers compare the hashes before adding theirs.
Hashvard alerts; it does not block. It does not replace your hardware wallet or a careful signing process — it gives every signer an independent second view.
Our hash recomputation is regression-tested against live Safes before every release.
What you need to know before giving us a treasury address.
/remove <id> in the bot. Ask in the bot to delete everything for your chat.Small protocols, DAOs and treasuries. Alerts start the same day.
ethereum 0x….