Shared wallets

A shared wallet
is not a shared password

Give every member of the team their own signer and their own role, on a Safe that no single one of them can empty.

Your Safe, your owners. We are not one of them.

The usual setup

One seed phrase, four people, no way back

The common way to share a company wallet is to share its recovery phrase. It works until the first time it does not.

Everyone is the owner

A seed phrase cannot be handed over partially. Whoever holds it can move everything, at any hour, without asking — and can never be un-given it afterwards.

Leaving is a migration

When someone who knows the phrase leaves, the only real remedy is a new wallet and moving every asset across. Most teams postpone that, and the phrase stays out there.

No signature to point at

Every transaction is signed by 'the wallet'. Which person actually sent it is recorded nowhere, so nothing can be attributed and nothing can be disputed.

The alternative

Separate identity from authority

Nobody shares a key, because nobody needs to hold the same key as anybody else.

  1. 1

    Each person keeps their own key

    Signers are individual wallets your people already own. Nothing is shared, so nothing has to be re-shared when the team changes shape.

  2. 2

    The Safe sets the threshold

    An M-of-N Safe requires several owners to agree. A single compromised key becomes a problem to fix rather than a treasury that is already gone.

  3. 3

    Roles below the signers

    Most of the team never signs at all. Requesters, approvers, reviewers and auditors get exactly the access their job needs, and no key whatsoever.

  4. 4

    Turnover is a role change

    When someone leaves you remove their role and remove their address as a Safe owner. No migration, no new wallet, no assets to move under time pressure.

Questions about shared wallets

We already share a seed phrase. Can we move?

Yes, and it is a one-way move: create a Safe with the individual signers as owners, then transfer the assets across once. After that the old phrase controls nothing.

What if a signer loses their key?

That is what the threshold is for. The remaining owners keep control and can replace the lost owner's address, so the treasury never depends on one person's device.

Does everyone have to understand multisig?

No. Only signers interact with the Safe. Requesters and approvers work in an ordinary web app and never touch a key or a seed phrase.

Can we see who did what?

Yes. Each approval and signature is attributed to a person and an address in an append-only log — precisely what a shared seed phrase makes impossible.

Move your team's money
transparently, starting today

Start free without a credit card. Setup takes five minutes, and your funds stay inside your team's Safe.