"Everyone audits the contract. Almost no one audits the charter."

When the news surfaced that Greenfield Capital โ a Berlin-based crypto venture firm and an early backer of Safe โ had formally asked a Swiss regulator to intervene in the internal governance of the Safe Ecosystem Foundation, the reaction across my feeds was instantaneous and, to my eye, almost entirely beside the point. People reached for the familiar vocabulary. They asked whether there had been an exploit. They asked whether user funds were at risk. They asked whether the multisig had been compromised.
No exploit. No drained treasury. No vulnerability in the deployed code. What happened is quieter and, in the long run, far more consequential: an investor who could not get the board composition of a foundation changed through the channels that were supposed to exist, walked those channels for months, and then reached outside the protocol entirely โ to a government supervisor โ to force the question into the open.
I have spent twenty-four years in and around this industry, and I have learned that the loudest failures are rarely the most dangerous. The loud ones leave wreckage you can photograph. The dangerous ones happen in the documents nobody reads: the charter, the board minutes, the shareholder agreement, the foundation deed. The Safe dispute is the second kind. It is a governance event wearing the costume of a news brief, and if you read it only as a corporate squabble between a venture fund and a nonprofit, you will miss the thing it is actually telling you about every protocol you hold.
So let me slow this down. I want to take one thin, almost contentless news item โ three facts and a lot of silence โ and use it as an X-ray of the structure underneath. Because the structure underneath is the same structure underneath almost everything you trust.
What Safe Actually Is, and Why Its Governance Matters More Than Its Code
First, the context, because I have watched too many people argue about this story without knowing what the protagonist does for a living.
Safe is the most widely used smart-contract wallet and multisig standard in the EVM ecosystem. In plain terms: it is the piece of infrastructure that lets a group of people โ a team, a DAO, a protocol's treasury committee, an institution โ hold assets that require multiple signatures to move. No single key can drain it. A quorum of keys has to agree. That property, unglamorous as it is, is the reason Safe has become the de facto custody spine of decentralized finance. When a protocol raises money and parks it in a treasury, the odds are good that the treasury is a Safe. When a DAO pays contributors, the payment often leaves a Safe. When a foundation holds a war chest, it is frequently sitting inside the same primitive.
The scale is the point. Safe has, at various moments in this cycle, been described as securing assets measured in the tens of billions of dollars. I do not need to litigate the exact figure to make the argument; the order of magnitude is enough. What matters is that Safe is not a product in the ordinary sense. It is a dependency. It is load-bearing. Thousands of other systems assume it works, assume it is stable, and assume โ this is the part people forget โ that the entity governing it is stable too.
The stack is layered, and the layering is where the trouble lives. There is Safe{Wallet}, the interface and the deployed contracts. There is Safe{Core}, the account-abstraction toolkit that other developers build on. There is SafeDAO, the token-governed community that ostensibly stewards the protocol and its treasury. There is the SAFE token, which confers governance rights. And then there is the Safe Ecosystem Foundation โ a Swiss legal entity that, by its name and its structure, holds or influences the things a token cannot hold: intellectual property, brand, legal standing, and often the treasury itself.
That last layer is the one nobody puts on a slide. It is the legal wrapper around a decentralized idea. And the dispute we are discussing is happening precisely there, at the seam between the on-chain governance that everyone talks about and the off-chain legal entity that almost nobody examines.
Greenfield Capital is the antagonist in this story, or the protagonist, depending on where you sit. It is a European crypto investment firm, Berlin-rooted, with a reputation as an early and mid-stage backer of serious infrastructure. It is, by all available indications, an early investor in Safe โ which means it helped fund the thing before it was obvious, and it holds whatever rights that early position bought it.
The event itself is disarmingly small. Greenfield sought a change to the composition of the foundation's board. It pursued that change for months. It did not get it. And then, having exhausted โ or concluded it had exhausted โ the internal channels, it escalated: it asked a Swiss regulator to intervene. That is the whole of it. Three facts. A demand, a duration, an escalation.
What is not in dispute is as important as what is. There is no allegation of a code exploit. No claim that user assets were touched. No suggestion that the multisig threshold was bypassed. This is not a security incident. It is a power incident. And power incidents, in an industry that has spent a decade convincing itself that code is the only thing that matters, are the ones we are least equipped to see.
Custody Is Governance: Whoever Controls the Entity Controls the Resources
Here is the first thing I want you to hold onto, and it is the reason I care about this story at all: in a custody protocol, governance is not a meta-layer hovering above the product. Governance is the product's security model. The two are not separable.
Think about what Safe actually protects. It protects the ability to move assets only with consent. That is the entire promise. And consent, in a multisig, is enforced by code โ the threshold, the signers, the transaction execution logic. But consent, at the level of the entity that decides what the signers should do, is enforced by something else entirely: a charter, a board, a set of bylaws, a legal jurisdiction. When we say "Safe secures tens of billions," we are usually talking about the first layer. When we should also be talking about the second.
I learned this lesson in a much smaller way, years ago. In 2020, at the height of DeFi Summer, I audited the smart contracts of a high-yield farming protocol and found a reentrancy vulnerability that could have drained roughly five million dollars. The code was the code. It did exactly what it was written to do. But the reason the vulnerability existed was not a coding error in isolation โ it was an economic assumption baked into the design: that incentives would keep liquidity in place long enough for the model to work. The code was sound. The governance of the assumptions was not. That is the same category of failure we are looking at here, scaled up to an institution.
Apply it to Safe. The foundation is the legal person that holds or steers the resources a multisig cannot: the intellectual property, the brand, the legal agreements, the relationships with regulators, and in many foundation structures, the treasury itself or the authority over it. That means board control is resource control. A seat on the board of the foundation is not a ceremonial honor. It is, functionally, a share of sovereignty over the thing the protocol was built to protect.
This is why an investor would bother. Greenfield is not asking for a board seat because it wants a nicer conference badge. It is asking because, in the architecture as it actually exists, the board is where the un-coded power sits. The multisig protects the assets from theft. The board decides what the assets are for. And the people who put money in early have a strong, rational, entirely predictable interest in who gets to make that second decision.
I want to be precise here, because it is easy to slip into cynicism. I am not saying Greenfield is acting in bad faith, nor that the foundation is. I am saying the structure itself guarantees this conflict. When you build a system with two centers of authority โ an on-chain token democracy and an off-chain legal board โ you have not eliminated the question of who rules. You have postponed it. And postponed questions have a way of arriving all at once, usually at the worst possible moment.
The Swiss Foundation as a Legal Technology, and the Supervisor as Its Kernel
The jurisdiction matters, and it matters more than the headline suggests. The Safe Ecosystem Foundation is, by name and by implication, a Swiss foundation. This is not an accident of geography. Switzerland โ and specifically the Zug region, the so-called Crypto Valley โ became the default home for Web3 foundations because its legal system offered something the industry badly needed: a nonprofit vehicle that could hold assets and sign contracts while remaining, at least in theory, aligned with a decentralized mission.
But a Swiss foundation is not a blank check for decentralization. It is a specific legal instrument with specific rules. It has a charter โ a foundation deed โ that defines its purpose. It has a board that governs it. It has beneficiaries, or a defined mission, rather than shareholders. And crucially, it has an overseer: a supervisory authority. In Switzerland, foundations are generally supervised at the cantonal level, and the authority's job is to ensure the foundation is being run in accordance with its charter and the law. Only if the entity engages in regulated financial services does FINMA, the federal financial regulator, typically enter the picture.
This distinction is the load-bearing detail of the whole story, and it is the one most coverage skips. When Greenfield "asks the regulator to intervene," it is most likely not alleging a securities violation or a financial crime. It is invoking the foundation's supervisor to pressure the entity to comply with its own charter and governance rules. That is a different kind of move than it first appears. It is not a securities complaint. It is a governance complaint, filed through a legal channel.
Why would an investor do that? Because a foundation's board cannot simply be reconstituted by fiat. Board changes generally have to conform to the charter and to Swiss foundation law. If an investor believes its legitimate governance claim is being blocked โ not by a vote it lost, but by a process it cannot access โ then the supervisory authority becomes the only remaining arbiter. You do not go to the supervisor because you are winning. You go because the internal mechanism has stopped responding.
And here is where I want to make a broader point about jurisdiction that I think gets lost. I have written before about how jurisdictions compete for crypto business, and how that competition is often dressed up as principle when it is really positioning. Hong Kong's virtual asset licensing regime, for instance, is frequently framed as an embrace of innovation; I have argued it reads more accurately as a bid to reclaim the role of Asia's financial hub from Singapore. Switzerland's Crypto Valley has a similar duality. It genuinely offers a workable legal home for decentralized projects โ and it also has a competitive interest in being the place where those projects incorporate. The supervisory apparatus that makes Swiss foundations trustworthy is the same apparatus that makes them controllable. That is not a bug in the design. It is the design. You cannot have a legal entity without a legal supervisor, and you cannot have a legal supervisor without giving someone the power to call it.
The Three-Body Problem: Foundation, DAO, and Core Contributors
Now let me get to the structural heart of it, because I think the deepest insight here is not about Greenfield at all. It is about a design flaw that recurs across the entire industry.
A mature Web3 project is not one government. It is at least three, and they do not agree on who is sovereign.
There is the foundation โ the legal entity, with a board, a charter, and a supervisor. There is the DAO โ the token-holder community, with proposals, votes, and a treasury. And there is the core contributor group โ the developers and operators who actually build and run the thing, who often hold enormous informal influence regardless of what any vote says. In theory these three are one coherent organism. In practice they are three bodies orbiting each other, and the question of who has final authority is left deliberately vague โ because vagueness is useful. It lets everyone claim legitimacy when it suits them.
When times are good, the vagueness is invisible. The token pumps, the contributors ship, the foundation signs the paperwork, and nobody asks which of the three actually governs. When a conflict arises โ as it has here โ the vagueness becomes the battlefield. Greenfield's demand for a board change ran into a structure where it was never clear who had the authority to grant it: the board? The DAO? The contributors? The charter? For months, apparently, the answer was "none of the above, or all of them, depending on whom you ask."
This is the governance failure, and it is not unique to Safe. It is the default state of the industry. I have watched DAO after DAO discover that its token vote is advisory when the foundation disagrees, and that its foundation is a rubber stamp when the DAO is loud enough. The industry built token democracy on top of legal autocracy and never reconciled the two. The SAFE token confers governance rights over a DAO that may or may not control the entity that may or may not control the resources. That sentence should make you uneasy, and it should make you uneasy about a lot of other projects, not just this one.
The tell here is the duration. The demand was pursued for months. Months is not a weekend of disagreement; months is a system failing to produce a decision. In a healthy governance structure, a legitimate request either succeeds or is cleanly and quickly rejected, with a record and a rationale. A request that lingers for months, unresolved, is a request that has fallen into a gap between authorities. And the escalation to a regulator is what happens when someone finally gives up on the gap ever closing on its own.
The Regulatory Channel as a Weapon โ and Why Going Outside the Protocol Is Rational
There is a temptation to read the regulatory escalation as an act of betrayal โ as an investor betraying the decentralized ethos by dragging the state into a community matter. I want to push against that reading, because it is emotionally satisfying and analytically lazy.
Think about what options actually existed. If you are an investor with a governance claim and the internal channels will not resolve it, what is your menu? You can vote. You can lobby. You can negotiate privately. You can go public and try to shame the other side. Or you can invoke the legal supervisor of the entity you co-own. That last option is not a betrayal of the system; it is the logical endpoint of a system that was designed with a legal backstop. The foundation chose to be Swiss. Switzerland came with a supervisor. The supervisor exists precisely for moments like this. You cannot build an entity that is legally supervised and then act shocked when someone uses the supervisor.
What the escalation actually tells us is subtler and more useful. When a party goes to the regulator rather than continuing to negotiate, it usually signals two things at once. First, that private resolution has collapsed โ the parties are no longer on speaking terms, or the talks have become theater. Second, and more importantly, that the escalating party believes the internal mechanism is either broken or being gamed. You do not spend months inside a process and then exit it unless you have concluded the process cannot deliver. The very fact of the escalation is a verdict on the governance, independent of who is right about the board seat.
I have a rule I use in audits and in life, and it applies here: trust the protocol, not the pitch. The pitch, in this case, is the story each side will tell about why the other is being unreasonable. The protocol โ the actual, observable behavior โ is this: a legitimate-seeming request went unresolved for months, and the resolution mechanism that was invoked was external to the project's own governance. That behavior is the fact. Everything else is narrative.
And there is a deeper, more uncomfortable implication. If invoking a state supervisor becomes a normal tool in the Web3 governance toolkit โ if investors learn that the fastest way to win an internal fight is to escalate to a cantonal authority โ then the decentralization of these projects becomes conditional. The state becomes the ultimate oracle of last resort. The community governs until it doesn't, and then a regulator in Zug decides. That is not a hypothetical. It is the shape of the precedent this case could set, and precedents in foundation law are unusually sticky, because foundations are unusually hard to restructure once a supervisor has taken an interest.
The Transmission Chain: From a Board Seat to a Treasury Committee
The reason this matters beyond Safe's own walls is that Safe is not an island. It is a node in a network, and shocks at a node propagate. Let me trace the transmission, because the second-order effects are where the real risk lives.
Safe sits at the center of a hub-and-spoke structure. Upstream, it depends on the L1 and L2 chains it runs on, on the EVM compatibility layer, and on the auditors who have blessed its contracts. Downstream โ and this is the important direction โ it is depended upon by an enormous set of actors: DeFi protocols that keep treasury reserves in a Safe, DAOs that hold their war chests in a Safe, NFT and gaming projects that custody assets in a Safe, and institutions and funds that manage capital through the same primitive. All of these parties made an implicit bet, and the bet was not just "the code is sound." The bet was "this thing is stable enough to entrust with the money I cannot afford to lose."
Governance instability attacks that second bet directly. It does not touch the first. Your multisig will still execute. Your keys will still work. But the confidence that underpins the decision to use the primitive โ the quiet assumption that the institution behind it is not in the middle of an existential fight โ takes a hit. And in a custody product, confidence is not a soft variable. It is the product.
Here is where I would watch most carefully. The downstream parties most exposed are the ones holding treasuries. A protocol's treasury committee, looking at a governance dispute at the foundation level, faces a question it did not want to have to answer: is the entity that governs my custody provider stable enough that I can leave my reserves where they are? Most will do nothing, because migration is expensive and the code still works. But some will begin to watch, and watching is the first step toward leaving. If the dispute drags, you get a slow bleed of confidence rather than a sudden run โ which is harder to see and, in some ways, harder to stop.
There is a parallel to the DeFi problem I have been arguing about for years. Liquidity mining incentives are, in essence, a project subsidizing its own TVL โ a number that evaporates the moment the subsidy stops, because the users were never there for the product. Governance stability functions the same way. A project can subsidize the appearance of legitimacy with marketing, with token emissions, with a slick narrative about decentralization. But strip away the subsidy and ask whether the underlying governance can actually resolve a conflict, and you find out what you really have. Safe just ran that test on itself, in public, and the answer is still pending.
The Information Vacuum: Silence Is the Loudest Audit
There is one more feature of this story I cannot let pass, and it is the feature that makes the whole thing feel like a warning rather than an incident.
Almost nothing is public. We do not know the specifics of the board change Greenfield sought. We do not know Greenfield's ownership stake or what governance rights attach to it. We do not know the current composition of the board, or who appointed its members, or what the charter says about how they can be replaced. We do not know whether the dispute has already touched the SAFE token's economics โ its unlock schedule, its treasury flows, its emissions. A governance conflict has been running for months, has escalated to a national regulator, and the public record is close to empty.
That emptiness is itself the finding. Silence is the loudest audit. When a project that markets itself on transparency and decentralization cannot or will not explain a months-long governance fight, the silence is data. It tells you where the transparency actually lives โ in the marketing, not in the governance. It tells you that the disclosure norms of these foundations are closer to those of a private club than a public institution. And it tells you that the people holding the token โ the ones who supposedly govern โ are, in this fight, spectators.
I have a personal stake in caring about this, and I should name it. In 2022, in the depths of the FTX collapse and the winter that followed, I withdrew from public life for six months. I did not speak, I did not post, I processed. And what I concluded, sitting with the wreckage, was that the industry's biggest failure was never purely technical. It was a failure of honesty โ of structures that looked transparent and were not, of institutions that claimed to be accountable and were not, of a gap between the pitch and the protocol that nobody was willing to name. The Safe dispute is a smaller version of that same gap. The protocol says "decentralized governance." The structure says "a board and a supervisor." The distance between those two sentences is where trust dies.
The Contrarian Read: This Is Not the Failure โ This Is the First Honest Moment
Now let me do what I always try to do with a story like this, which is to turn it over and look at the underside, because the consensus read โ "Web3 governance is broken, another example" โ is correct and also incomplete.
Here is the contrarian angle. This dispute is not evidence that Safe's governance failed. It is evidence that Safe's governance, until now, never existed in a form that could fail. A mechanism that has never been tested is not a working mechanism; it is an untested assumption. For years, Safe's governance sat in the comfortable zone where nobody had a reason to fight โ the token was distributed, the foundation signed things, the contributors shipped, and the three-body system never had to answer the question of who was actually in charge. The conflict with Greenfield forced that question into the open for the first time. In a strange way, that is a service. You cannot fix a structure you have never stress-tested, and this dispute is the stress test.
Which leads to the second contrarian point, and it is the one that should genuinely unsettle the decentralization maximalists: an investor going to a regulator is not a betrayal of trustless systems. It is the correct behavior inside a system that was never actually trustless. The foundation is a legal entity. Legal entities have supervisors. If you wanted pure on-chain governance, you would not have created a Swiss foundation โ you would have put the treasury under a DAO with no legal wrapper, and accepted the legal exposure that comes with it. The industry chose the wrapper for good reasons: legal standing, tax treatment, the ability to sign contracts and hold IP. But the wrapper came with a price, and the price is that a regulator is always in the room. The dispute did not introduce the state into Safe's governance. The state was always there, in the foundation deed, waiting.
So the pragmatic test โ the one I always apply โ is this: does the foundation structure actually protect the users, or does it protect the insiders? A well-designed foundation structure should make the project more accountable to its community and more resilient to capture. A badly designed one becomes a legal shell that insiders use to hold power that the token holders believe they own. Which of these Safe has is not something we can determine from the outside, precisely because of the information vacuum. But the fact that we cannot determine it โ that a governance fight can run for months with the public locked out โ is itself a signal that the structure leans toward the second.
There is an analogy I keep returning to, from the work I have done at the intersection of institutions and decentralization. In 2024 I advised a family office in Abu Dhabi that wanted to enter this space. My job was to bridge the rigidity of traditional finance and the flexibility of crypto without letting either side pretend the other's rules did not exist. The lesson I took from that work is that institutions do not invest in narratives. They invest in structures. They want to know who controls what, how decisions are made, and what happens when the decision-makers disagree. And when they cannot get a clean answer โ when the answer is "it's decentralized, mostly, except for the foundation, except for the board" โ they either walk away or they price in a discount. Governance ambiguity is not a philosophical problem. It is a line item. It shows up in the valuation, whether or not anyone writes it down.
What I Am Watching, and What It Means for the People Holding the Bag
The most useful thing I can offer, beyond the diagnosis, is a set of signals โ the things that will actually tell us how this resolves, and which way the risk is tilting. Because the outcome is genuinely undetermined, and the market will price the ambiguity before it prices the resolution.
Watch the regulator's response. If the Swiss supervisory authority formally engages โ requesting documents, opening a review โ the dispute enters a slow, semi-public process that will stretch the uncertainty window and force disclosures the foundation has so far avoided. If it declines to engage, the escalation has failed, and the pressure returns to the internal channels, which have already proven they cannot deliver.
Watch the foundation's own communications. Silence has been the pattern so far. A substantive response to Greenfield's claim would be the first real transparency event of this whole affair, and it would tell us whether the foundation is capable of explaining itself. The inability to explain is a finding in its own right.
Watch the other investors. Greenfield is, by all appearances, acting alone for now. If other early backers take sides โ publicly or through their own governance actions โ the conflict stops being a two-party dispute and becomes a factional one, which is far harder to resolve and far more damaging to confidence.
Watch the token. If SAFE's price or unlock behavior shifts around this window, it will confirm what many already suspect: that the governance fight and the economic interests of the token holders are not aligned, and that the insiders' timetable is not the community's timetable. I would treat any large unlock that coincides with this dispute as a signal worth interrogating, not a coincidence to shrug at.
And watch the downstream. If DAOs and protocols begin quietly moving treasuries out of Safe โ or even just announcing reviews of their custody arrangements โ that is the ecosystem's own verdict on the governance risk, delivered in the only language that ultimately matters: where the money goes.
The Takeaway
So here is where I land. A venture fund and a Swiss foundation are locked in a governance dispute over a board seat. On its face, it is the smallest possible story. But the reason it should occupy your attention is that it is a stress test of a structure that the entire industry relies on and almost nobody examines: the legal entity that sits beneath the decentralized promise, holding the things a token cannot hold, answering to a supervisor that a community cannot fire.
The code held. The code always holds, until it doesn't, and this time it wasn't the code that failed โ it was the thing we never audited. We have spent a decade learning to read smart contracts line by line, and almost none of us have learned to read a charter. That asymmetry is the real vulnerability. Not a reentrancy bug, not a bridge exploit, not a key leak โ a board seat, in a jurisdiction most users could not name, deciding who controls the resources that a multisig was built to protect.
Which raises the question I cannot answer for you, and which I suspect no one in this industry can yet answer honestly: if you cannot say who governs the entity that governs your custody provider, in what sense is your custody actually yours? The protocol is not the pitch. And when the two disagree, the pitch is where the money goes to disappear. I will be watching the charter. I would suggest you start watching yours.