Private balances for Safe accounts.

A privacy add-on for Safe, now in testnet beta. Shield balances and payments for specific workflows while your signers keep threshold control.

The Bermuda app for a Safe treasury account: total, private and public balance, top assets, Morpho vault positions and pending transactions waiting for signatures

Problem

Some workflows shouldn't be public.

Run your Safe workflows privately. Work the way you always have, just without everyone watching.

Frontrunning

Bots trade before you do.

Tracking

Anyone can see who you pay.

Balances

Counterparties see what you hold.

Signers

Anyone can see who signed.

Solution

Everyone sees exactly what they should.

Architecture

Threshold control over private balances.

Bermuda threshold signing

3 of 5

  • 0x3f5C…f0bEConfirmedWaiting
  • 0x8ba1…BA72ConfirmedWaiting
  • 0xde0B…7BAeConfirmedWaiting
  • 0xAb58…eC9BConfirmedWaiting
  • 0x71C7…976FConfirmedWaiting

Same chain

Shielded balances stay on your Safe's chain, in the Bermuda protocol.

Familiar flow

Propose, review, confirm.

Threshold control

Private transfers require your signers' threshold.

Same people, new key shares

Each Safe signer receives a threshold key share for private balances.

For builders

An add-on for your Safe.

One SDK adds private balances, proposals and policy-checked transfers to a Safe.

Details

How it works with your Safe.

What happens to my existing Safe?

Privacy is an add-on that works alongside your existing Safe. Nothing is installed on your Safe: its address, signers, threshold, public balance and history don't change. Funds you shield move from your Safe into the Bermuda protocol through a normal Safe transaction approved by your signers, and are controlled there by threshold key shares held by your signers. To stop using Bermuda, withdraw your shielded funds back to your Safe.

How do the other signers experience it?

A Safe-style proposal queue. Propose, review, confirm, with the details visible only inside the quorum.

How are key shares managed?

Each signer holds an independent threshold share; the full key never exists anywhere. Key share recovery is separate from your Safe's recovery setup. Key-lifecycle documentation, including recovery, will be published before mainnet. Adding or removing a signer on your Safe does not automatically update key shares. Rotate key shares whenever your Safe's signers change; until then, private transactions are paused. If so many signers are removed that the old threshold can't be met, the private balance is locked, and the app warns before that happens.

Is this on mainnet?

Not yet. The program runs as a testnet beta on Base Sepolia. It is not yet audited, and the contracts and circuits are not yet public. Mainnet will be announced soon.

Who submits transactions, and what does it cost?

In the beta, Bermuda operates the relayer, which broadcasts transactions so they don't link back to your Safe or its signers. It can't read recipients or amounts. The beta is free.

The beta

Private treasury operations, on the Safe you run.

For teams evaluating private treasury workflows on testnet.