[SEP 56] [Phase 2] Fund Safenet Aegis to Grow SAFE Token Utility and Sustainability

Authors: Safe Ecosystem Foundation (SEF), represented by the Foundation Council

Created: 2026-09-17

Abstract

This proposal requests ~7,400,000 SAFE tokens from the SafeDAO treasury to fund Safenet Aegis - the phase following Safenet Beta - over a limited 12-month period beginning Tuesday, October 13th 2026. Specifically:

  • ~5,000,000 SAFE tokens to be allocated for validator staking rewards for a 12-month period, distributed every 2 weeks.
  • ~2,400,000 SAFE to be allocated as milestone-based grants to 6 genesis Sentinels - 400,000 SAFE per Sentinel - over the same period, distributed every 3 months.

The requested funding is intended to:

  • sustain Validator participation and attestation coverage for a further 12 months
  • extend Safenet and SAFE token utility to a second participant class (Sentinels) via participation based grants
  • bridge the period until fee-based rewards can cover Sentinel and Validator participation

Proposal types

SEP: Governance Proposals
SEP: Constitutional Proposals
SEP: Other SEPs

1. Achievements of Safenet Beta

SEP-55 Goals & Performance, Q1-Q3 2026:

  • Goal 1: validate whether the validator network can reliably process transaction checks at scale
    • Outcome: 779,795 unique transactions attested by Safenet. 0.28% (≈ 2,183) of evaluated Safenet transactions flagged as insecure.
  • Goal 2: validate whether validator participation can be measured and incentivized
    • Outcome: 0.1% downtime in terms of the Beta’s reliability. Downtime measures infrastructure availability.
  • Goal 3: validate whether SAFE staking and delegation can bootstrap economic security
    • Outcome: 76,889,190 SAFE staked across 865 unique stakers

2. What is Safenet Aegis?

Link to Aegis Documentation

Safenet Aegis is the first production release of the decentralized transaction security network for Safe accounts, following a successful Beta release. It introduces the role of Sentinels who independently evaluate dynamic wallet transactions and return a real-time verdict - secure or insecure - with supporting reasoning signals. Eligible secure results decided by Sentinels are then attested by Validators, and can be enforced onchain with the Safenet Guard.

The goal of Safenet Aegis is to:

  • By the end of the year, showcase with real revenue (at least $30k in monthly revenue) that there is a sustainable network revenue model. Whether a share of future fee volume is allocated to DAO-controlled protocol funds (fee switch) remains subject to a separate SafeDAO decision and applicable law(s).

Safenet Aegis intentionally launches with:

Safenet Aegis is governed by SafeDAO. The DAO controls the following parameters via the usual governance process:

  • Sentinel and Validator sets
  • Fees and bond amounts
  • Slashing percentage
  • DAO fee share (fee switch; if applicable) and recipient

Safenet’s core contracts are non-upgradeable, but SafeDAO can vote to replace them.

Governance Implementation: A new SafeDAO-controlled Safe on Gnosis Chain will be introduced and connected to Snapshot, giving SafeDAO governance direct control over the parameters above.

3. Integration in Safe{Wallet}

  1. Safe Labs plans to add opt-in support for Safenet Aegis transaction checks in Safe{Wallet} and Safe Pro by Q4 2026.

  2. Scope is Safe-transactions only on Ethereum mainnet, Arbitrum, and Gnosis Chain and the types of checks are detailed in the Safenet Charter.

  3. Check verdicts are conducted by 6 independent Sentinels while onchain attestation are handled by the Validators.

  4. Checks will be monetised as an opt-in fee within the Safe{Wallet} transaction flow. It will also be available under the Safe Pro subscription model.

  5. Safenet checks can also be used without enabling the Guard

  6. Ultimately, the Guard cannot block a transaction and can always be overridden by the user.

4. Reward design - Validators

Ask

  • ~5,000,000 SAFE for Validator staking rewards over 12 months from Tuesday, October 13th distributed every two weeks on the same cadence and methodology as SEP-55.
  • Rationale: For Safenet Aegis, there is no direct connection between the protocol fees and the validator rewards. Under Aegis’ current fee model, 100% of income flows to Sentinels who perform checks. Subsidies incentivise Validators to continue participating in Safenet (as they play a crucial role in the attestation process).

Run-rate comparison against SEP-55

SEP-55 SEP-56
Validator reward pool 4,500,000 SAFE ~5,000,000 SAFE
Duration 6 months
(Apr-Oct 2026)
12 months
(Oct 2026-Oct 2027)
Per-period pool ~346,000 SAFE ~192,000 SAFE

Staking Design & Scope

  • Design broadly follows SEP-55 (see Rewards - Safe Docs ). However:
    • the minimum reward payout threshold will be removed
  • With the introduction of Sentinels, validators no longer perform transaction checks and only need to provide attestations.

5. Reward Design - Sentinels

Ask

  • 2,400,000 SAFE, distributed by SafeDAO, granted to six genesis Sentinels, subject to achieving agreed tx participation of 75% over 12 months. Evaluated and distributed every 2 weeks.
  • This implies 400,000 SAFE per Sentinel over 12 months
  • Rationale: Cover the cold-start problem of lower initial user volumes while Sentinel discovery, integration, and product iteration are still ongoing - bridging the period until fee volumes can sustain Sentinel participation.

Participation milestone

  • Eligibility is tied to a Sentinel participation rate of ~75% per distribution period
  • Sentinels operating a narrower check scope who fail to reach the 75% continue to earn Wallet user fee split but do not qualify for the SAFE grant.
  • Sentinels are required to run the full reference coverage (in the Charter). Sentinel specialisation can only open when the set expands and Aegis’ logic is updated.
  • Unclaimed or forfeited amounts are not redistributed to other Sentinels, whether due to fewer than 6 genesis Sentinels being active or a Sentinel falling below the participation threshold.

Fees & Bonds

  • Fees are explicitly decided by Safe{DAO} Governance through SEPs.
  • Initially proposed Safenet fee is set at 0.40 USDC per check, paid entirely to Sentinels; the SafeDAO protocol share is 0% to support bootstrapping the network. The split remains governance-controlled and may change in a future proposal (and subject to applicable laws).
  • Each participating Sentinel posts a bond for the check. At launch, the bond is 800 USDC per Sentinel per check, derived from the configured transaction fee. The bond creates economic accountability for Sentinel decisions.
  • The launch configuration provides for a bond-slashing-free dry run through the end of 2026. During this period Sentinels risk only their earned per-check fee (see above); no bonds are slashed. Long-term participation terms, including slashing, will be revisited in Q1 2027 once real system data is available. Any update to Safenet require a successful SafeDAO proposal.

6. Alternative solutions

No rewards subsidy - Considered but not pursued.

Without subsidies, Safenet Aegis risks no Validator participation and a difficult pitch to Sentinels who face a cold start funding problem.

SEF-only funding - Considered but not pursued

While SEF may support ecosystem initiatives, Safenet is a SafeDAO-level token utility initiative and should be validated through SafeDAO governance.

7. Implementation

Timeline

  • Aegis testnet integration with Sentinels running: live now on Sepolia
  • Aegis network live on mainnet and Safe{Wallet}: targeted for Q4, 2026
  • Safenet Aegis staking UI
    • Beta Validators will be asked to transition by October 13th
    • New Validator and Sentinel rewards start: from October 13th
  • Reward distribution: begins after Snapshot ratification. Validator and Sentinel rewards calculated retroactively from October 13th and distributed every 2 weeks, on the same cadence as SEP-55.

Resourcing

Own implementation possible
Own implementation but with funding
Request for technical support through Safe matter experts

8. Effects and impact analysis

Effects of this Proposal

  • ~7,400,000 SAFE tokens will be transferred from the SafeDAO treasury to a dedicated, DAO-controlled Safe for Rewards Distribution for distribution over 12 months period.
  • A live, integration to Safe{Wallet} with fees distributed to Sentinels in Q4, 2026, whilst the fee switch remains available to the DAO.
  • Authorization for SEF to transfer ownership of the existing Beta rewards-distribution contract to the new Reward Distribution Safe upon proposal approval.

Pros

  • Continues the SEP-21 and SEP-23 mandates on staking and security abstraction that SafeDAO has already voted for.

  • SAFE token utility extends as fees have been implemented via the introduction of Sentinels and a fee switch may, subject to applicable law and a separate SafeDAO decision, be enabled by the DAO.

Cons

  • Treasury cost for a second consecutive phase.

  • Validator set remains permissioned throughout, extending the Beta

    centralisation trust assumption by a further 12 months.

Risks

  • Validators falling below the 75% threshold and Sentinels dropping out of operation due economic/technical challenges.

9. Governance process and compliance

This proposal is submitted on behalf of the Safe Ecosystem Foundation represented by the Foundation Council, and is intended to comply with SafeDAO governance requirements, including:

  • forum discussion period
  • snapshot vote
  • SEF compliance requirements for treasury execution
  • Basic sanctions screening of reward recipient addresses against the UN, EU, UK, Swiss SECO, and US OFAC lists published by sanctions-address-lists.
  • Extended sanctions screening for rewards recipients above CHF 10,000 per rewards period.

This proposal follows the standard SEP-7 governance process as amended by SEP-53, which removed sprint-type restrictions and allows any proposal to be submitted in any sprint. Given that no active governance season calendar has been in effect during the SEP-54 pause period, this proposal is submitted independently of a specific sprint cycle. It will go through the full SEP-7 process: forum discussion, maturity signaling by three delegates or Guardians holding a combined minimum of 60,000 SAFE, and a Snapshot vote including a “Make no changes” option. The Foundation Council members named in the disclaimers section will abstain from both signaling and voting.

10. Disclaimers

The Validators were determined based on technical expertise, pro-active outreach, as well as ability to show sufficient token holdings in order to provide the minimum stake of 3.5M tokens. SafeDAO can update the Validator set via the usual governance process.

Safe Labs GmbH, Berlin, is a wholly owned subsidiary of SEF and the operator of Safe Wallet by Safe Labs interface, which creates a potential conflict of interest. The Foundation and its foundation council members will abstain from voting on this proposal.

Stefan George is a member of the SEF foundation council and founder of Gnosis who is running a Safenet Beta validator which creates a potential conflict of interest. GnosisDAO as largest Safe token holders is considered as legitimized to be a running one of the initial Validators. Stefan will abstain from voting on this proposal.

Richard Meißner is a member of the SEF foundation council and shareholder of Core Contributors GmbH, Berlin, which creates a potential conflict of interest. Core Contributors worked on Safenet Beta based on a grant agreement and is therefore considered to be invaluable in gaining first-hand experience in operating a validator. Richard will abstain from voting on this proposal.

The minimum validator stake amount of 3.5M SAFE applies to all Validators alike.

The Sentinels were determined based on technical expertise, pro-active outreach, and the ability to partake in earlier testnets. SafeDAO can update the Sentinel set via the usual governance process.

11. Open questions

None

12. Copyright

Copyright and related rights waived via CC0.

5 Likes

Great work on this proposal @rimeissner and team! It will be exciting and important to see onchain fee revenue power Safenet.

Aegis goals

The measurable and specific targets outlined above are good, E.g. 30,000 USD in monthly revenue.

  • Is 30k USD/month the breakeven point for a “sustainable network revenue model”?
  • Is there an estimate for the total cost of operation/month to run the network based on the data so far?

Validators and Sentinels

From my knowledge of Safe history the validators and sentinels make up a good starting diversity of small and large teams, many with significant past contributions to Safe I’m aware of.

I had to remind myself of the difference between validators and sentinels.

  • Validators: Confirm consensus of the sentinels evaluations
  • Sentinels: Evaluate the business logic of transactions

Sentinels is a cool name and I didn’t realize the formal definition, “a person or thing that watches or stands as if watching”. My first thought is The Matrix. I wonder if it’s better to have a clearer name for this role such as watchers, auditors, evaluators, etc.

:headphone: For those that want to listen to the proposal I uploaded an audiocast on X.

1 Like

Thanks for the read and the audiocast Adam! Good questions.

Breakeven: No, $30k/month isn’t a calculated breakeven figure - it’s a target we chose to demonstrate the network can generate meaningful, non-trivial revenue.

  • Annualizing the $30k/month target gives ~$360k/year in check revenue, against the ~7.4M SAFE ($ ~$700k at today’s spot price) requested for the year. So here, the target revenue covers roughly half (~51%) the dollar value of the yearly funding ask.

  • Note that the revenue doesn’t actually offset the SAFE being spent unless/until a DAO fee switch is turned on. Ultimately, it’s evidence the network can sustain itself, but not that it currently is funding itself. We would need a fee switch for this.

On the naming side, “Sentinel” was locked in before Aegis’s Charter work started and it’s now baked into the docs, contract naming, and UI, so a rename at this stage touches more surface area than it looks like from outside. We evaluated watcher/auditor/evaluator but thought Sentinel has a “distinct/uniqueness” quality over them and the term “sentinels” infer that they are keeping watch for something that is coming i.e. hacks/threats/sophisticated attacks.

2 Likes

I think the overall approach makes sense, especially the separation between Sentinels doing the transaction evaluation and Validators providing the attestation layer. The proposed 12-month bootstrap period also seems reasonable given the cold-start problem and the need to establish real fee-generating usage.

One point I would strongly suggest adding to the economic design is a cap on the total Sentinel compensation.

The proposal sets a target of at least $30k/month in revenue by year-end, while the initial fee model sends 100% of check fees to Sentinels. I think it would be healthier for the long-term sustainability of the network if total Sentinel rewards were capped at a maximum of $30k USD per month across the entire Sentinel set.

Once monthly Sentinel compensation reaches $30k:

  • Sentinels continue to receive compensation up to the $30k/month aggregate cap.

  • Any fees/revenue above that amount should flow either to the SafeDAO treasury / DAO-controlled protocol fund or to SAFE stakers, according to a future DAO-approved fee allocation.

  • The cap should apply to the aggregate Sentinel set, rather than being a $30k cap per Sentinel.

This would preserve the economic incentive for Sentinels to participate and solve the initial cold-start problem, while also ensuring that increasing Safenet adoption creates increasing economic value for the broader Safe ecosystem rather than allowing Sentinel compensation to scale indefinitely with transaction volume.

It also gives the $30k/month target a clearer meaning: once the network reaches that level of recurring revenue, additional growth starts building protocol/tokenholder value rather than simply increasing operating payouts.

I would therefore suggest making the long-term fee flow something along the lines of:

Revenue → Sentinel compensation (capped at $30k/month) → excess revenue to DAO / SAFE stakers

The exact split of the excess can remain a separate governance decision, but establishing the aggregate Sentinel cap now would provide a useful economic boundary for Aegis.

Overall, I like the direction of using Aegis to turn Safenet into a real fee-generating piece of infrastructure. I think adding this cap would make the transition from DAO-subsidized bootstrapping to a sustainable, value-accretive network much clearer.

1 Like

As a Safe delegate, I support this proposal to keep progress on the development of Safenet.

2 Likes

Thank you for sharing more info on the notes above @klotzketten!

As a Safe Guardian I recommend this draft is ready to move forward to the voting process.

1 Like

Will users see a plain-language explanation of why a transaction was flagged and what they should check next? That would make the warning much easier to act on than a simple “insecure” label.

2 Likes

Sentinels must state a reason for any insecure verdicts and the reasons must be taken from the Charter here - safenet-charter/Safenet_Arbitration_Charter.md at main · safe-research/safenet-charter · GitHub

The plain text reason will be shown to the user as a result.

1 Like

Thanks for clarifying—that should make the warning much easier to understand.

1 Like

Broadly supportive, a few things

  1. What does it cost to run an attestation node? Validators now do less than in Beta (no checks, only attestations) but the pool is up from 4.5M to 5M SAFE. Would be good to see the numbers behind the ask.
  2. The validator set stays permissioned for another 12 months. If the DAO is subsidising a hand-picked set, the proposal should include a roadmap or criteria for opening it. Otherwise this is a trust assumption renewed by default.
  3. There are no Beta adoption stats (opt-in rate, true-positive rate on flags) and the Safe{Wallet} integration doesn’t land until Q4. Rather than a lump 12-month allocation, could the payout be released quarterly against milestones, e.g. Q1 2027 checkpoint on wallet opt-in and progress toward the $30k/month target?

Great proposal @rimeissner and team.
As a SafeGuardian, Angel Investor, and power user, I support this proposal to keep Safenet development and PMF exploration moving forward. Keep building. Keep pushing. Safe is one of the greatest products I’ve seen. However, users take for granted that it’s free. I hope Safe Pro changes that, and we can match the quality and value to a fair revenue.

One comment: next time, it would be nice to see real data to back up your numbers. Eg: # of checks: current vs expected to hit the goal ($30k/month @ $0.4/check).

1 Like

The clarifications covered most of my questions. I do agree that Beta adoption stats would be very helpful, but I support this overall direction.

As a Safe Guardian, I support this proposal going to vote.

Proposal has been moved to Phase 2 and is ready for voting! :ballot_box:

As treasury manager at kpk, I support SEP-56

Building on earlier points:

  1. Validator pool: @Denham noted the pool grows from 4.5M to 5M SAFE. Spread over 12 months instead of 6, though, the per-period pool falls about 45%
  2. Spend vs. revenue: following @klotzketten and @enel : until a fee switch exists, it would help to report SAFE distributed (in SAFE and USD) alongside fee revenue
  3. Check volume: following @Manu and Denham: the $30k/month target means about 75,000 paid checks a month at 0.40 USDC, a useful figure to track toward Q1 2027

One addition:

  1. Unused SAFE: the proposal says forfeited Sentinel amounts aren’t redistributed, but not where they go. Could the team clarify? Returning any unspent balance in the Rewards Safe to the treasury after 12 months would close that loop
  1. We don’t have a published cost breakdown for running attestation-only infra to show you. The 5M SAFE ask is framed in the proposal as a participation subsidy, since the opportunity cost for stakers is other staking opportunities for their capital and we need to be competitive here. It’s not a reimbursement tied to actual infra spend. Per-period, the pool is actually falling, not rising — ~346k SAFE every two weeks under SEP-55 (6 months) vs. ~192k under SEP-56 (12 months), about a 45% drop. So the higher total (4.5M→5M) isn’t validators getting paid more per period for doing less.
  2. We do want to open the validator set but your point is valid, we don’t have a criteria for opening it up yet in the proposal. Would be open to your thoughts here so the trust assumption isn’t open ended. But we wanted to make the core goal of generating revenue explicit so we can fund an open set.
  3. We will post quarterly updates on the progress of the SEP, e.g. a Q1 2027 checkpoint on wallet opt-in and progress toward the $30k/month target will be reported.

Addressing Daniel and Manu’s point here. .

Daniel and Manu’s point (2) - yes we will include this in a quarterly report to the DAO to track volumes and fees, next update will be in Q1, 2027.
Daniel’s point (3) - Yes, the $30k/month target means about 75,000 paid checks a month at 0.40 USDC. However, we want to make it clear that this is an initial start to fees, and we do plan to adjust fees dynamically once we start seeing what adoption looks like in terms of throughput, $ volumes and user profiles. So the 0.40 USDC fee isn’t fixed for 2027. This can be adjusted to reach our revenue goal.