Quick answer: The Safe wallet scam is a paid Google ad that sat at the top of search results on Oct. 11, 2026, and sent users to a lookalike site at wallet-safe.global. Gnosis co-founder Martin Koeppelmann flagged it on X at 08:02 UTC. RDAP records show the domain was registered on Oct. 8, 2026.
A Safe wallet scam is sitting where people trust results most: the very top of Google. On Sunday, the first result for a Safe search was a paid ad that opened a polished clone of the multisig app. Safe secures treasuries for DAOs, funds and power users, so a single bad signature there can be very costly.
Gnosis co-founder Martin Koeppelmann raised the alarm on X at 08:02 UTC on Oct. 11, 2026. He wrote that “the top Google result (an ad) leads to a well-made scam version” of Safe. By 14:50 UTC his post had about 26,800 views and 467 likes.

What happened with the fake Safe wallet ad?
The first public report came hours earlier. At 03:47 UTC, X user @atshelchin wrote that a sponsored result for “safe wallet” looked like Safe’s official site but opened wallet-safe.global instead. The clone looked almost identical to the real one. Other users said the same ad appeared for the search “gnosis safe.”
CryptoVank checked the public RDAP record for wallet-safe.global. It shows the domain was registered on Oct. 8, 2026, at 23:29 UTC through OwnRegistrar, Inc. That is less than three days before the warnings. A brand-new domain dressed up as a long-running wallet is a classic phishing sign.
Curve Finance founder Michael Egorov backed the warning at 11:01 UTC. “If you are in crypto – always block ads in your browsers,” he wrote. He called ads “outright malicious.”
Does Google allow ads that impersonate crypto wallets?
No. Google’s Misrepresentation policy bans ads that impersonate other brands or imply ties they do not have. Google calls these violations “egregious” and says it suspends such accounts without warning. The trouble is speed. A scam ad only needs a few hours at the top of the page to catch victims.
Koeppelmann also pointed at a double standard. Legitimate crypto projects often get suspended from ad programs, he wrote, while Google “still happily sells its top spot to scammers.” He has raised this before. In April 2026, after a compromised CowSwap interface, he listed malicious Google ads among the main ways users land on fake front-ends.
How does a fake wallet site steal funds?
A cloned wallet app does not need your keys. It needs you to connect a real wallet and approve a transaction. The page shows one action, but the request you sign can move tokens or hand over control to the attacker. With a multisig like Safe, a single tricked signer can be enough to push a bad transaction toward its threshold.
That risk is not abstract for Safe users. In February 2025, attackers tampered with the Safe interface used by Bybit, and the exchange lost about $1.5 billion. Koeppelmann explained at the time that the hacked front-end showed one transaction while sending another. Safe now offers a protection layer called Safe Shield that warns about risky transactions, but it only works inside the real app.
How can you stay safe from wallet ads?
Use these habits for any wallet, not only Safe:
- Type safe.global or app.safe.global yourself, or use a saved bookmark.
- Never open a wallet, exchange or DeFi app from a search ad.
- Check the full domain before you connect. One added word, like “wallet-“, is enough to fake a brand.
- Read every signing request on your hardware wallet screen. Stop if it does not match what you meant to do.
- Use an ad blocker in the browser you use for crypto.
Our guide on how to spot crypto scams covers more warning signs. For a full setup, see the self-custody wallet setup guide.
What does this mean for the market?
Prices shrugged it off. Ether traded near $2,505 and the SAFE token near $0.119 on CoinGecko at 14:50 UTC, both flat on the day. You can follow the live Ethereum price on CryptoVank. The bigger story is trust. This is the third wallet trap in three days, after the Ledger CryptoBilis thefts and the Coldcard phishing post. Each one hit users through a channel they had good reason to trust.
Safe Wallet Scam FAQ
What is the official Safe wallet website?
Safe’s official site is safe.global, and its web app runs at app.safe.global. The lookalike domain wallet-safe.global, promoted through a Google ad on Oct. 11, 2026, is not run by Safe.
Is Safe itself hacked?
No hack of Safe’s smart contracts or official app has been reported. The Oct. 11, 2026, scam is an impersonation: a paid ad sent people to a copy of the app on a different domain.
What should I do if I connected my wallet to wallet-safe.global?
Connecting alone does not move funds, but any transaction or approval you signed there could. Revoke token approvals from that session with a trusted tool, and move assets to a fresh wallet if you signed anything you do not recognize.
When was wallet-safe.global registered?
The public RDAP record shows wallet-safe.global was registered on Oct. 8, 2026, at 23:29 UTC through OwnRegistrar, Inc. The first public warning about the ad came at 03:47 UTC on Oct. 11, 2026.
Not financial advice. This article is for information only. Always do your own research (DYOR) before making any decision about your crypto.
Sources
- Martin Koeppelmann on X, Oct. 11, 2026
- @atshelchin report on X, Oct. 11, 2026
- Michael Egorov on X, Oct. 11, 2026
- RDAP record for wallet-safe.global
- Google Ads: Misrepresentation policy
- AiCoin: Koeppelmann on the CowSwap interface compromise, April 2026
- The Coinomist: Koeppelmann explains the Safe breach behind the Bybit hack
- Safe official website
- CoinGecko: Safe price



