Crypto's New Defense Protocol

View in Browser
Sponsor: MegaETH β Crypto has new apps, finally.

- ποΈ Coinbase Receives Conditional National Trust Bank Charter from OCC. The crypto exchange will not engage in fractional reserve lending but plans to operate payment products under federal supervision, a move that drew criticism from several banking industry lobby groups.
- π² Hyperliquid Launches MVP Mobile Trading App on Google Play Store. The Android-only release is limited to order fill notifications for now, but comes as third-party mobile interfaces already account for roughly 10% of platform trading volume.
- π¬ Circle Faces Backlash Over Slow Response to $280M Drift Hack. Attackers bridged stolen funds through Circle's CCTP infrastructure over multiple hours without intervention, and onchain sleuth ZachXBT estimates the issuer has failed to freeze over $420M in illicit USDC transfers since 2022.
| Prices as of 5:30pm ET | 24hr | 7d |
|
Crypto $2.39T | β 0.3% | β 1.7% |
|
BTC $66,900 | β 0.1% | β 1.4% |
|
ETH $2,057 | β 0.1% | β 3.7% |

EthCC[9] returned to Cannes with an institutional lean, side events that charged β¬700 a ticket, and five days of panels.
While there were numerous announcements that came out of the event β Aave V4 and the Ethereum Economic Zone, for example β if I had to pick one announcement from the entire week that carries the most weight for the Ethereum ecosystem, it's the Safe Foundation launching Safenet.
Here's why.

The Problem Safenet Solves
Crypto theft hit $3.4 billion in 2025, according to Chainalysis.
The single largest incident was the $1.5 billion Bybit hack in February, attributed to North Korea's Lazarus Group. The method was simple. Attackers compromised a Safe{Wallet} developer's machine, injected malicious JavaScript into the wallet's front-end, and waited. When Bybit's signers went to approve what looked like a routine cold-wallet transfer, the UI showed them a legitimate transaction while the underlying call data redirected 401,000 ETH to attacker-controlled addresses. Three of six multisig signers approved it and the money was gone.
This incident exposed a gap the industry has been papering over, that between what users sign and what they intend. Warning banners and simulation tools help, but they operate outside the execution path. When the UI itself is compromised, those warnings are worthless.
Safe co-founder Richard Meissner put it plainly: "crypto has spent years building better warnings. That is not enough."
And the problem is accelerating. Q1 2026 saw $168 million stolen across 34 DeFi protocols, the largest of which came from private key compromises. Chainalysis reported a 1,400% surge in impersonation scams year over year, with AI-enabled scams 4.5 times more profitable than traditional scams. As the Immunefi CEO noted earlier this year, onchain security is actually improving. The main attack surface in 2026 is people.
Which is exactly the surface Safenet is designed to protect.
What Safenet Actually Does
Safenet is a decentralized transaction security network for Safe accounts.
Rather than merely flagging suspicious transactions, the network's validators actually evaluate every proposed transaction against a set of security rules before it can go through. If the transaction passes, the validators collectively sign off on it. That approval is then verified onchain as part of the execution process itself. A transaction without that approval simply can't execute.

At launch, the beta enforces five checks on every proposed Safe transaction: 1. blocking unauthorized delegate calls, 2. restricting upgrades to trusted contracts, 3. preventing the installation of untrusted modules, 4. restricting which fallback handlers can be set, and 5. restricting which guards can be set.
Every one of those checks maps to the categories of exploit that enabled the Bybit hack. That attack succeeded because the malicious transaction looked correct in the UI. Under Safenet, what the UI showed wouldn't matter, because the transaction would still need to pass the validators' independent security checks before any funds could move.
The beta launches with six genesis validators (Greenfield, Gnosis, Safe Labs, Rockaway, Blockchain Capital, and Core Contributors GmbH), each staking a minimum of 3.5 million SAFE tokens. The network is Byzantine Fault Tolerant, meaning it can withstand up to a third of its validators acting dishonestly and still function correctly. All validator activity is publicly auditable.
Users retain full self-custody throughout. If a transaction fails the security check but you still want to proceed, you can, with explicit additional owner approval after a time delay.
SAFE the Token Gets a Real Job
The launch of Safenet gives the SAFE token its first live economic function.
Validators stake SAFE to participate in the network. Token holders can delegate to validators and earn staking rewards for helping secure it. The staking UI went live April 2. The long-term reward mechanism is a proposal pending SafeDAO approval. During Beta, rewards are subsidized. Right now, rewards are subsidized. Long-term, they're intended to be funded by transaction fees from users and integrators. Slashing is not active during beta, so staked tokens aren't at risk of being penalized.

What Safenet Doesn't Solve
Safenet doesn't touch privacy leaks through RPC nodes or IP-level network analysis, problems Vitalik flagged in his EthCC keynote when he framed security as hygiene, not a feature.
But Safenet addresses something the rest of the stack can't compensate for: the integrity of the transaction itself. Every other security measure, audits, simulations, multisig ceremonies, depends on the assumption that what a signer sees is what they're signing. Safenet moves that check out of the interface and into the execution path, where a decentralized validator network enforces it before a single dollar moves.
For a protocol that secures over $1 trillion in cumulative transfers, used by nearly every major institution onchain, that's a meaningful answer to a problem that just cost someone $1.5 billion.
Not financial or tax advice. This newsletter is strictly educational and is not investment advice or a solicitation to buy or sell any assets or to make any financial decisions. This newsletter is not tax advice. Talk to your accountant. Do your own research.
Disclosure. From time-to-time I may add links in this newsletter to products I use. I may receive commission if you make a purchase through one of these links. Additionally, the Bankless writers hold crypto assets. See our investment disclosures here.
