Private balances for Safe accounts.
A privacy add-on for Safe, now in testnet beta. Shield balances and payments for specific workflows while your signers keep threshold control.
Problem
Some workflows shouldn't be public.
Run your Safe workflows privately. Work the way you always have, just without everyone watching.
Frontrunning
Bots trade before you do.
Tracking
Anyone can see who you pay.
Balances
Counterparties see what you hold.
Signers
Anyone can see who signed.
Solution
Everyone sees exactly what they should.
Your Safe→12 payees84,200 USDCPayroll · March
Your Safe→12 payees84,200 USDCPayroll · March
Your Safe→12 payees84,200 USDCPayroll · March
Architecture
Threshold control over private balances.
Bermuda threshold signing
3 of 5
- 0x3f5C…f0bEConfirmedWaiting
- 0x8ba1…BA72ConfirmedWaiting
- 0xde0B…7BAeConfirmedWaiting
- 0xAb58…eC9BConfirmedWaiting
- 0x71C7…976FConfirmedWaiting
Same chain
Shielded balances stay on your Safe's chain, in the Bermuda protocol.
Familiar flow
Propose, review, confirm.
Threshold control
Private transfers require your signers' threshold.
Same people, new key shares
Each Safe signer receives a threshold key share for private balances.
For builders
An add-on for your Safe.
One SDK adds private balances, proposals and policy-checked transfers to a Safe.
Your Safe
Privacy add-on
Details
How it works with your Safe.
What happens to my existing Safe?
Privacy is an add-on that works alongside your existing Safe. Nothing is installed on your Safe: its address, signers, threshold, public balance and history don't change. Funds you shield move from your Safe into the Bermuda protocol through a normal Safe transaction approved by your signers, and are controlled there by threshold key shares held by your signers. To stop using Bermuda, withdraw your shielded funds back to your Safe.
How do the other signers experience it?
A Safe-style proposal queue. Propose, review, confirm, with the details visible only inside the quorum.
How are key shares managed?
Each signer holds an independent threshold share; the full key never exists anywhere. Key share recovery is separate from your Safe's recovery setup. Key-lifecycle documentation, including recovery, will be published before mainnet. Adding or removing a signer on your Safe does not automatically update key shares. Rotate key shares whenever your Safe's signers change; until then, private transactions are paused. If so many signers are removed that the old threshold can't be met, the private balance is locked, and the app warns before that happens.
Is this on mainnet?
Not yet. The program runs as a testnet beta on Base Sepolia. It is not yet audited, and the contracts and circuits are not yet public. Mainnet will be announced soon.
Who submits transactions, and what does it cost?
In the beta, Bermuda operates the relayer, which broadcasts transactions so they don't link back to your Safe or its signers. It can't read recipients or amounts. The beta is free.
The beta
Private treasury operations, on the Safe you run.
For teams evaluating private treasury workflows on testnet.