[ NO JARGON // SIX SIMPLE STEPS ]

How does BunkerSAFE work?

Think of a digital vault with three different keys. Any two people must agree before the vault sends money. That's the idea behind a 2-of-3 multisig.

EXAMPLE / 2-OF-3 TREASURY
OWNER AAPPROVED
OWNER BAPPROVED
OWNER CNOT REQUIRED
2 of 3 SIGNATURES
THE SAFE UNLOCKSOnly for the exact transaction both owners approved
01 / WALK THROUGH THE FLOW

Follow one transaction, from idea to blockchain.

Choose a step on the map. The panel below explains what actually happens, in plain English.

01 / 06
[ STEP 01 ]

You open BunkerSAFE and connect MetaMask.

MetaMask proves which Ethereum address you control. You never upload a seed phrase or send us a private key. Importing a Safe does not require its owners to be online.

The connected account pays gas when a transaction is finally broadcast. Merely viewing a Safe or building a proposal does not move ETH.
02 / THE BIG PICTURE

Who controls what? The brain map.

The important difference: the BunkerSAFE website coordinates people, but the Safe smart contract enforces what happens to the money.

YOUR SAFE VAULTOn-chain multisig account
OWNER WALLETSKeep private keys

Sign transaction hashes independently

BUNKERSAFE APPCoordinates proposals

Collects signed requests and displays status

SAFE CONTRACTEnforces approval policy

Checks threshold, signatures and nonce

ETHEREUM CHAINPublic source of truth

Stores balances and executed transactions

03 / SECURITY EXPLAINED

Signing permission is not custody.

Funds live in the smart contract, not on the website.

Your Safe address holds ETH, tokens and NFTs on-chain. BunkerSAFE displays this information through RPC providers and an explorer; closing the site does not move the assets.

This is a Sepolia public preview, not an independently audited mainnet-custody product. Never share a seed phrase. Check owner addresses and transaction details before signing, and keep independent owner-key backups.

04 / COMMON QUESTIONS

Anything still unclear?

Does BunkerSAFE hold my crypto?

No. Funds belong to the Safe smart-contract account. Only its current on-chain owner policy can approve spending. Your wallet holds your signing keys.

What if one owner loses their phone?

If the remaining owners still meet the signature threshold, they can approve removing or replacing the lost owner. If not enough signers remain, funds can be inaccessible. Keep secure backups and choose independent owners.

Is an approval the same as a transfer?

No. An off-chain owner signature approves one transaction hash. A separate on-chain execution is required, and the executing account pays network gas.

Do I have to deploy my own factory?

No. The official Safe ProxyFactory is already deployed. BunkerSAFE creates individual Safe proxies using official Safe contracts. Operator deployment tools are not part of public navigation.

Can BunkerSAFE admin withdraw from my Safe?

No. The admin panel manages project links and explorer settings, not Safe keys or owner permissions. However, a compromised website could try to present deceptive transaction details, so always verify wallet requests.

Can I use mainnet today?

You can view mainnet Safes, and authorized operators may deploy standard Safe proxies through a restricted console. BunkerSAFE mainnet proposal, approval and execution remain disabled pending security review. Manage any deployed mainnet Safe through Safe Global.

Open BunkerSAFE Read full documentationDeveloper API