[ USER MANUAL // PUBLIC TESTNET RELEASE ]

BunkerSAFE Documentation_

A non-custodial multisignature treasury interface built on officially deployed Safe smart-account contracts. No email login. No BunkerSAFE seed phrase. Wallet signatures are requested through an Ethereum browser wallet.

Sepolia-only transaction preview. Mainnet transfers, approvals and owner changes are disabled in BunkerSAFE. A restricted operator console can create standard mainnet Safes, which must then be managed through Safe Global. Public multisig transaction features remain Sepolia-only. Do not transfer real mainnet funds based on this preview's testnet results.

Create or import Propose and approve Batch transactions Security model Owner security Fees Recovery FAQ
01 / GET STARTED

Create or import a Safe

Open the app, connect MetaMask or another compatible injected Ethereum wallet, select Sepolia, and choose Create bunker. Set the owner addresses and the minimum number of approvals required. Your connected wallet should be one of the owners. Review the deployment gas transaction inside your wallet. The wallet pays testnet gas; BunkerSAFE does not hold signing keys.

You can also Import Safe by address, including a watch-only Safe whose owners you don't control. Importing does not transfer or modify assets.

02 / MULTISIG FLOW

Propose → Approve → Execute

An authorized owner prepares an ETH, ERC-20 or ERC-721 transfer and signs the Safe transaction hash through the connected wallet. The proposal is stored by BunkerSAFE's coordination service. Additional owners open the same Safe, review the destination and amount, and individually approve the exact transaction.

Once enough owner signatures are collected, the current on-chain nonce can be executed by a connected wallet. The final transaction pays network gas and cannot be reversed. Etherscan is the source of truth for on-chain execution.

03 / ADVANCED TRANSFERS

Atomic transfers and owner settings

Batch transfers let an owner submit two to eight ETH/ERC-20 transfers as one Safe transaction using official MultiSendCallOnly. The interface blocks unknown nested calls and approvals. Owner changes, threshold changes, and cancellations are themselves multisig transactions requiring the currently enforced approval threshold.

For a mistaken pending proposal, select Cancel nonce. Owners must approve and execute the replacement transaction before the old proposal is invalidated.

04 / TRUST MODEL

Understand what the service can—and cannot—do

Your wallet retains control of private keys. The coordination backend stores public proposal data and signatures, verifies owner status, and checks Safe transaction hashes. The Safe contract independently enforces the signing threshold on-chain. An attacker compromising BunkerSAFE's coordination server should not be able to sign as owners, but a compromised website could present malicious transactions: always read wallet and transaction prompts carefully.

BunkerSAFE is not affiliated with Safe Global, has not completed an independent security assessment, and does not offer insurance, key recovery, or fund reimbursement. Losing enough owner keys can permanently lock a Safe.

05 / OWNER POLICY

Choosing owners and thresholds.

Every Safe has a list of owners and a threshold. In a 2-of-3 Safe, there are three independent owner addresses and any two must sign the exact transaction to authorize it. A 1-of-1 Safe behaves like a single-signature account and does not protect you against compromise of that one key.

For teams, use separately controlled wallets and don't store all recovery phrases in one location. Choose people or hardware devices you can still access years later. If enough owner keys are lost to drop below the threshold, normal owner recovery is not available.

Changing the policy

An existing owner can propose an add, remove or replace operation or a new approval threshold. Other owners approve using the current policy; the new policy applies only once the transaction executes on-chain. Never remove your last accessible key or set a threshold higher than the number of working signers.

06 / NETWORK FEES

Gas, ETH and what you pay.

Creating a Safe requires an on-chain deployment transaction, so the connected deployer wallet needs native ETH on the selected network. There is no separate initial liquidity requirement for an account; it can have zero ETH or tokens until you fund it.

Collecting approvals is typically an off-chain signature and does not itself move crypto. Executing an approved transfer requires Ethereum gas paid by the account that submits the execution. Gas price varies with network demand; always review the actual estimate in MetaMask.

Sepolia ETH is test cryptocurrency with no market value. Ethereum mainnet ETH is real money. The current public test environment supports Sepolia transactions, while mainnet account deployment is restricted to authenticated operators.

07 / ASSETS

ETH, ERC-20 tokens and NFTs.

To send ETH, supply a valid destination and amount. ERC-20 transfers call a token's standard transfer(address,uint256) function from the Safe. Amounts use the token's published decimals. Verify token addresses independently before interacting; symbol names can be copied by unrelated contracts.

For ERC-721 NFTs, track the collection contract and token ID, confirm that the Safe holds the NFT, and propose safeTransferFrom. Check the recipient and whether the destination contract supports safe NFT reception. Unsupported or unusual NFTs may require a different interface.

Batch mode supports 2–8 standard ETH/ERC-20 sends in one atomic Safe transaction. All operations succeed together or the batch reverts. Unknown arbitrary contract calls, approvals and nested delegatecalls are intentionally blocked by BunkerSAFE's allowlist.

08 / MISTAKES & CANCELLATIONS

What if a proposal is wrong?

A proposal is not executed immediately; an owner can refuse to approve it. If it occupies an upcoming nonce, owners can propose a zero-value cancellation transaction for that same nonce. Once the cancellation receives the required approvals and is executed, the original proposal at that nonce can no longer execute.

A cancellation is itself a real Safe transaction and requires approvals and gas. It does not reverse transactions that have already executed on-chain. If an execution succeeds but BunkerSAFE's local history does not update, check Etherscan before retrying.

09 / KEY LOSS & RECOVERY

Make an emergency plan before funding.

Keep secure independent backups of owner recovery material, and confirm that the owner threshold is achievable if one signer is unreachable. Rehearse a small Sepolia transfer with your real signing devices before working with significant assets.

Store a copy of the Safe contract address, owner addresses, chain ID and expected threshold outside this website. BunkerSAFE stores your local workspace preferences in browser storage, but the Safe contract persists on-chain if you change devices, browsers or websites.

BunkerSAFE cannot restore an owner private key, and the administrator PIN cannot unlock or transfer Safe assets. If too many keys are lost, access may be permanently lost.

10 / CURRENT LIMITATIONS

What this preview does not do.

The public interface has funded Sepolia execution tests but does not have an independent external security audit. Actual MetaMask-extension popup acceptance testing and complete third-party Safe transaction history indexing are not finished. The coordinator shows transactions created through BunkerSAFE and supported recovered executions, not every transaction a Safe ever performed elsewhere.

Contract-based owners (EIP-1271), Safe modules and guards, unrestricted contract interactions, and full Safe Global application parity are not supported. Ethereum mainnet Safe creation is operator-restricted; BunkerSAFE mainnet transaction signing and execution remain disabled.

11 / QUESTIONS

Frequently asked questions

Do I need to deposit initial liquidity?

No. BunkerSAFE is a multisig treasury utility, not a token launchpad or exchange. Safe creation requires blockchain gas only.

Can I use it without connecting a wallet?

Yes. Import an address to view the on-chain ownership policy, balances and transaction records coordinated through BunkerSAFE.

What does Etherscan verification mean?

Safe proxies deploy through the official Safe deployment infrastructure. Contract source and proxy links are verified by Etherscan when it recognizes the exact on-chain code and metadata. A verification check or submission is not a safety audit, nor a guarantee that Etherscan will accept a proxy.

Why is a proposal missing from history?

The built-in coordination service only guarantees entries created through BunkerSAFE. Full import of arbitrary historical external Safe transactions is not yet implemented. Check the chain explorer and use the History Recovery form for executions that originated in BunkerSAFE.

When will Ethereum mainnet transactions be enabled?

Once the actual-wallet acceptance tests and an independent security assessment are complete. Operators can currently deploy standard Safe proxies on mainnet through /deploy; they must use Safe Global to manage those mainnet Safes.

Visual brain mapAPI referenceOpen BunkerSAFESafe Protocol docs