Multisig Inspector

See what your Safe multisig actually does before you sign.

Multisig Inspector is a free, read-only scanner for Safe multisigs. It reads your Safe's owners, threshold, modules, and guard straight from the chain, decodes any queued transaction, and recomputes the SafeTxHash so you can compare it with your hardware wallet. No wallet connection. No keys. Nothing stored on our servers.

No sign-up. Runs in your browser. 8 mainnets supported.

Safe Inspector report view showing a security score and findings for a scanned Safe
Trusted by the Top Names in Web3
the problem

$2.06B was lost through multisigs that were "secure."

Signers approved what the interface showed them. In Bybit, a compromised UI masked a delegatecall that swapped the Safe's masterCopy. In Radiant, infected devices displayed a benign transaction while pool ownership moved. In StablR, minting sat behind a 1-of-3 threshold. None of these were smart contract bugs. All of them were visible on-chain to anyone who looked at the raw configuration or the raw transaction instead of the screen.

$2.06Blost across 10 documented multisig incidents
3 of 10would have been caught by independent decoding or config scanning
5 of 10partially preventable with the same checks
See the full incident timeline →

Two tools. One question: is this what we agreed to?

Safe Inspector

Paste a Safe address. Get the on-chain truth about who controls it.

  • Owners and threshold, read directly from public RPC
  • Enabled modules (which can execute without the owner threshold)
  • Guard, fallback handler, implementation, version, nonce
  • Checks the implementation is the canonical Safe singleton for that network
  • Findings graded Critical to Info
  • Configuration drift: every rescan is compared with your last saved baseline
  • Export the report as Markdown or JSON

Transaction Inspector

Load a queued transaction. See what the calldata really does, then match the hash on your hardware wallet.

  • Import from a Safe address, Safe transaction URL, Transaction Builder JSON, or manual entry
  • Decodes calldata, expands nested MultiSend batches and Safe admin actions
  • Flags every delegatecall
  • Recomputes the EIP-712 domain hash, message hash, and SafeTxHash
  • Tells you whether the imported hash matches the recomputed one
  • Checks involved addresses against versioned threat-intelligence data
  • Optional simulation on Ethereum, BNB Smart Chain, and Base

The hash on your wallet is the only thing you can trust. Check it.

The SafeTxHash binds the destination, value, calldata, operation, nonce, and chain into one fingerprint. Your hardware wallet shows that fingerprint when you sign. Multisig Inspector recomputes it from the raw transaction fields, independently of the Safe interface, so you have a second source to compare against.

If the two match, the transaction you reviewed is the transaction you are signing. If they differ, stop. A mismatch is a stop condition, not something to work around.

Step 01

Load the transaction in Transaction Inspector

Step 02

Review every decoded action: recipient, asset, amount, function, operation

Step 03

Read the recomputed SafeTxHash

Step 04

Open the same transaction in your signing wallet

Step 05

Compare character by character: beginning, middle, and end

Step 06

Sign only when the full hash matches and every action is approved

A matching hash confirms the fingerprint, not the intent. You still have to approve what the decoded actions do.

Read-only by design.

Multisig Inspector is deliberately separated from signing. It cannot move your funds even if it wanted to.

No wallet connection
No private keys or seed phrases requested
No Safe SDK or API dependency
No transaction creation, signing, queuing, or broadcast
No backend database of scanned Safes
Snapshots stay in your browser's IndexedDB

Some features send data outside the browser only when you use them: RPC reads to public endpoints, queued transaction imports via a read-only proxy to the Safe Transaction Service, optional GoPlus simulation, and optional contract signature resolution. Details in the networks & privacy and security model docs.

Built for the people who hold the keys.

Signers

Verify the hash and the decoded actions before every signature, on every Safe you sit on.

Treasury and ops teams

Scan production Safes weekly or monthly. Catch owner, threshold, or module drift before it becomes an incident.

Auditors and incident responders

Get a point-in-time configuration report with a block number, exportable as Markdown or JSON.

DeFi users and DAO members

Check that a protocol's Safe is configured the way its governance says it is.

When to run it.

Every transactionDecode, review, verify the hash before signing
Weekly or monthlyScan every production Safe from the same baseline browser and review drift
Before and after config changesBaseline, execute, rescan, confirm only the intended fields changed
After signer changesRescan immediately and compare owners against the access roster
During an incidentAny unexplained drift is the first thing to investigate

Full operating routine in the docs →

The scanner shows you the state. The audit tests the system.

Free Tool

Multisig Inspector (free)

  • On-chain Safe configuration and findings
  • Transaction decoding and SafeTxHash verification
  • Local drift tracking and exportable reports
  • Self-serve, instant, no engagement needed
Professional Service

OPSEC & Multisig Audit

  • Signer device, key storage, and channel security review
  • Admin function inventory and k-signers-compromised threat model
  • Social engineering and blind-signing red team
  • Timelock, governance, and incident-response readiness
  • Severity-classified report with remediation roadmap

A clean scan does not prove your Safe is secure. It cannot know whether the owners are the right people, whether their keys are stored safely, or whether governance is being followed. That is what the OPSEC & Multisig Audit is for.

95% of the incidents we respond to were entirely preventable with basic operational security.

QuillAudits
pcaversaccioCo-Founder, SEAL 911 Emergency Response

Frequently asked questions

Check your Safe now. It takes one address.

Scan a Safe (free)
cta-bg

WE SECURE EVERYTHING YOU BUILD.

From day-zero risk mapping to exchange-ready audits — QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance — secured end-to-end.

QuillAudits Logo


ISO 27001Circle Alliance Program
Uniswap FoundationAethiropt-collectivePolygon SPNBNB Chain Kickstart

All Rights Reserved. © 2026. QuillAudits - LLC