# @safe: Investigation Updates and Community Call to Action Source: https://x.com/safe/status/1897663514975649938?s=46 Safe{Wallet}’s forensic investigation is being conducted in collaboration with Mandiant, a leading cybersecurity firm that is now part of Google Cloud. This investigation has reached a critical checkpoint, allowing us to share an update on the progress and insights gathered so far from the security incident that occurred on February 21, 2025. Evidence suggests that this was a highly sophisticated, state-sponsored attack. We present these findings in the spirit of transparency and to highlight key lessons learned, along with calls to action for the broader community to learn from this incident and strengthen defenses. We wish to stress that despite hundreds of hours of analysis already conducted, there is more work to be done. Certain gaps in fully recovering certain aspects of the attack remain because the attacker removed their malware and cleared Bash history in an effort to thwart investigative efforts. While the analysis is ongoing, we are sharing Mandiant’s preliminary findings thus far. Finally, the Safe{Wallet} team continues to advance diligently in order to bring all networks and services back online for users. There is more information on the specific steps taken in this preliminary report below, as we continue our unrelenting efforts to restore and enhance all networks. Summary The FBI has attributed the February 21 heist to TraderTraitor, a threat group linked to the Democratic People’s Republic of Korea (DPRK). Mandiant tracks TraderTraitor as UNC4899 and notes that they are responsible for numerous crypto heists. The preliminary Mandiant report confirms this attribution. The attack involved the compromise of a Safe{Wallet} developer’s laptop (“Developer1”) and the hijacking of AWS session tokens to bypass multi-factor authentication (“MFA”) controls. This developer was one of the very few personnel that had higher access in order to perform their duties. The investigation is still ongoing to understand attacker activity following the compromise of the workstation that was used to obtain commit access to Safe{Wallet} servers. The Safe{Wallet} team has implemented security enhancements to reinforce infrastructure far beyond pre-incident levels. Safe’s Smart Contracts remain unaffected by this incident. Timeline Key findings from Mandiant’s investigation The adversary was able to bypass Safe{Wallet}'s security program, despite having many layers: The security program included, but was not limited to, Limiting privileged access to the infrastructure, including S3, only to the strictly necessary amount of developers, maintaining a clear separation of access between development source code and infrastructure management Requiring multiple peer reviews before introducing changes to production Having monitoring systems in place to detect external threats Conducting continuous security audits with independent third parties Using third-party service providers to detect malicious transactions About Safe{Wallet}’s Architecture Safe{Wallet} operates a backend primarily to enhance the user experience for accounts with multiple signers. It stores signatures and performs checks before a transaction is fully executed, ensuring that all required approvals are met before submission to the blockchain. This enables smoother coordination and provides a better UX around pending transactions. The ultimate verification happens on chain and triggers the resulting transactions. Users have the option to use the Safe smart contracts without using Safe services, or to set up these services on their own infrastructure. For more information, please refer to our documentation. Systems Were Restored with Enhanced Security Measures The Safe{Wallet} team continues to advance diligently in order to bring all networks back online for users. Below are some of the actions the team has taken to eradicate the identified threats and further strengthen the security posture: Full infrastructure reset – Including rotation of all credentials, resetting clusters, rotating keys & secrets, provisioning new developer machines, updating builds, and redeploying container images. External access lockdown – Temporarily restricted external access to the Transaction Service, allowing only internal communication. Additionally, we implemented more firewall rules for externally facing services. Enhanced malicious transaction detection – Collaborated with Blockaid to upgrade our malicious transaction detection systems, including flagging master copy upgrades for Safe accounts. Comprehensive monitoring – Increased logging and real-time threat detection across all layers of our stack for better visibility and faster response times. Pending transactions reset – We cleared all pending queued transactions from our databases to eliminate potential human errors. Temporary disablement of native hardware wallet signing – Temporarily disabled native hardware wallet support due to their reliance on eth_sign and many third party dependencies. However, support for these hardwares remains accessible via WalletConnect. UI Enhancements – Safe{Wallet} now also provides another 3rd party verification tool “Safe Utils”, developed by the community in order to independently verify Transaction hashes. We are also working towards providing an option for users to use Safe{Wallet} that is fully hosted on IPFS as well. In addition to the above, the Safe{Wallet} team is closely working with Mandiant to significantly invest and upgrade our security. While we cannot disclose all low-level details of the security enhancements to avoid overexposing our internal infrastructure to malicious actors, you can review the relevant changelogs for our open source code: Safe Wallet Safe Client Gateway Safe Transaction Service A Call to Action The recent attack underscores the evolving sophistication of threat actors and highlights critical vulnerabilities in Web3 security. Please refer to the IOCs in the appendix. In addition, see Mandiant’s recent guidance for securing Web3 organizations. Verifying that the transaction you are signing will result in the intended outcome remains one of the biggest security challenges in Web3, and this is not just a user and education problem — it is an industry-wide issue that demands collective action. While self-custody comes with individual responsibility, in order to drive broad adoption platforms must play a critical role by providing better tooling to detect and prevent malicious interference. We need significant UX improvements that simplify secure transaction management. Ultimately, the act of signing the transaction itself currently is the last line of defense, and it can only be effective if the user can understand what they are signing. To support users in securing their transactions, Safe{Wallet} has published a comprehensive guide on how to verify transactions before signing and will take further steps to make this process a frictionless part of using the Safe{Wallet} in the near term. Appendix ## Comments **0xeD0D...87F5**: Given Safe is the leading open source multi-sig provider and widely adopted (100B in assets stored?), shouldnt they consider to implement something akin to Aave's Safety module? Besides of ongoing bug bounties, etc. **timdaub.eth**: Are they going to be on the hook for the stolen money?