Accounts your users own. Mostly just announcements and releases here.

Ethereum
tether.wallet runs on Candide. We operate the bundler and paymaster inside Tether's self-custodial wallet. Users pay fees in USD₮, XAU₮, and USA₮. No native gas token. Built on @Safe smart accounts and ERC-4337. Tether can switch wallet infra anytime, no migration.
2
4
19
7,659
Candide retweeted
🗳️ New Proposal for Safenet Aegis is now live on the Safe{DAO} forum. Here is a breakdown ↓ It asks to fund the first production-ready protocol version built to secure @safe Multisig and the wider ecosystem in Q4. Threats to self-custody are only increasing, and most defences today are still just warnings, not enforcement. Safenet Aegis is changing that paradigm. 🔰 Safenet is a decentralized network of independent Sentinels and Validators 📜 Sentinels check every transaction against a public, DAO-owned charter using their own proprietary threat detection systems 🧾 Sentinels pass verdicts. Verdicts are attested by validators onchain making security enforceable 🛡️ Enforcement happens at the account level via Safenet Guards Proposed Independent Sentinels checking transactions: @OpenCover, @IntentGuard , @hackenclub, @hexens, @BlockSecTeam and @candidelabs Proposed Validators: @gnosisdao, Core Contributors, @greenfield_cap, @SafeLabs_, @RockawayX and @bcap Safe{DAO} through this proposal, owns every fee parameter on the Safenet protocol. Safenet Aegis will ship inside @SafeLabs_ multisigs in Q4 2026. Read More ↓
Draft Proposal for Safenet is live on the Safe{DAO} forum for discussion: It asks to fund Safenet Aegis: The first production-ready protocol release to secure the @safe ecosystem and the first, with onchain fees paid to participants in the network. Read More: forum.safefoundation.org/t/d…
8
8
31
8,020
Your gold. Your control. Candide handles the gas.
Sending gold-backed XAU₮ doesn’t require holding a separate token just to cover the fee. One asset. One send. Nothing extra to figure out. Tether Wallet. The People’s Wallet. Send gold, simply → tether.me
2
117
Years ago we watched new users give up on sending stables because apps told them to signup on an exchange to buy a second token to pay the fee. Hold gold, send gold, the fee comes out in gold. No gas token. Gold from your pocket only works if the pocket doesn't need a manual.
Gold used to mean vaults and paperwork. Now it means opening an app. Meet XAU₮, gold-backed tokens, fully in your control. Tether Wallet. The People’s Wallet. Hold gold from your pocket → wallet.tether.io
5
221
One Forwarding Address, seven chains to deposit stables from, funds land in the user's main account on Arbitrum. Instant, non-custodial deposits where users need them the most. ¡Felicitaciones, El Dorado!
⛓️ Now live at El Dorado: More networks for USDT deposits. USDC now available across 7 networks.
1
2
8
698
tether.wallet runs on Candide. We operate the bundler and paymaster inside Tether's self-custodial wallet. Users pay fees in USD₮, XAU₮, and USA₮. No native gas token. Built on @Safe smart accounts and ERC-4337. Tether can switch wallet infra anytime, no migration.
2
4
19
7,659
Candide retweeted
Banks don't move at the speed you do. Today we're launching El Dorado Business: The Multisig Account for Internet Businesses. One account to move money across the globe, with or without a US entity. Built on @tempo
10
27
89
26,261
Candide retweeted
Multisig signers should be able to verify the transaction, not just trust the interface. Safe OpenSig by @candidelabs helps Safe signers avoid blind signing with on-device transaction simulation, independent state verification, and clearer checks before hardware wallet approval. Learn more: piped.video/watch?v=hQI88j44… Support: qf.giveth.io/project/safe-op…
2
5
672
0/ Clear signing is now live. An open standard to end blind signing, making human-readable transactions default. This effort brings a major UX and Security upgrade to transaction signing on Ethereum.
161
431
2,177
356,305
Ethereum Foundation. $ 187M Safe multisig. 2 signers pending on a 10,000 ETH transfer. This is what verifying before signing with Ledger looks like, without blind signing.
4
3
36
9,330
We simulated and verified this tx locally 2 hours ago, and showed the signer exactly what they'd see on their Ledger. Now it's been executed.
0/ Today, the Ethereum Foundation finalized the terms of a 10,000 ETH sale at an average price of $2,387 via OTC. For this sale, our OTC counterparts was @BitMNR.
1
458
Approving a Safe multisig transaction means trusting the RPC node and infra behind the UI. $290M was stolen last week through compromised nodes. Safe OpenSig verifies onchain state across multiple independent nodes before you sign with your Ledger.
3
3
22
2,764
You can stop blind trusting RPCs. Before showing you what a transaction does, Safe OpenSig requests a Merkle proof from multiple independent nodes. They have to agree on the state. One compromised RPC can't pass it. Verified state. Then simulate.
2
5
30
2,306
Impressive! I am going to start incorporating this into my airgapped signing setup.
Frax Finance. $35M Safe multisig. 3 out of 5 threshold. 1 signer pending on a 17k frxUSD transfer. This is what verifying that tx looks like, without blind signing.
1
1
16
2,696
Frax Finance. $35M Safe multisig. 3 out of 5 threshold. 1 signer pending on a 17k frxUSD transfer. This is what verifying that tx looks like, without blind signing.
10
6
86
19,469
Candide retweeted
A few days ago we launched Safe OpenSig. The thing that surprised me most was how misunderstood blind signing is. Even among people who think seriously about this. So let me explain what it actually means, step by step. Step 1: You open Safe. A transaction was proposed. You review it. You see decoded details. A transfer, a contract call, an ownership change. Looks right. But three things can compromise what you see before you ever touch your hardware wallet. The interface can be compromised through: a tampered frontend, a poisoned backend, a malicious browser extension, a hijacked DNS record, or a compromised dependency deep in the frontend's supply chain. You wouldn't know which one. Step 2. You try to verify. Smart move. You copy the calldata and paste it into an external tool to decode it. But where did you get that calldata? You copied it from the same interface that may be compromised. The verification is tainted from the start. The only review that means anything is one where you constructed the calldata yourself, offline, from scratch. Without touching the UI at all. That's not a realistic workflow for a n-m multisig signing transactions every week. Step 3. You connect your Ledger. This is where people assume the hardware takes over as the trusted layer. It doesn't. For anything beyond a simple ETH transfer, your Ledger can't decode the transaction. It shows two hashes. Domain hash. Message hash. nitter.net/heymarcopolox/status/2… Step 4. You approve the hash. You always do. This is the attack surface. There is no moment in this workflow where you can verify that what the interface showed you matches what the hardware is actually committing to. The security layer you thought existed doesn't. What Safe OpenSig does Before you touch your Ledger, Safe OpenSig simulates your Safe transaction locally on your mobile phone, away from your desktop. Two devices means two independent verification layers. It verifies state against multiple independent nodes, and shows you a pixel perfect mirror of what your Ledger screen will display. The hash gets a face. You know what you're signing before you sign it. candide.dev/opensig
I have no idea what I just signed
1
6
25
2,873