The contracts are the standard
Safe secures more on-chain value than any other contract wallet, with modules, spending policies, role separation and a full audit trail for every proposal and signature. For a treasury, a DAO or any arrangement where no single person should be able to move funds, it is the default and deservedly so.
February 2025 was not a contract failure
A compromised Safe{Wallet} developer machine was used to serve tampered JavaScript that showed Bybit's signers a routine transfer while altering what they were actually approving. Roughly $1.5bn left. Investigators found no flaw in the contracts — and that is precisely the lesson: a multisig protects against a rogue signer, not against every signer being shown the same lie.
What that means in practice
Signers on a serious treasury should verify calldata on a hardware device rather than trusting the interface, and large transfers deserve an out-of-band confirmation. The threshold protects you only if the people meeting it are seeing the truth.
Not for individuals
Gas costs and signer coordination make it overkill for personal use, and the contracts are open source and deployed across major EVM chains with several usable interfaces.
Threshold and signer distribution, then the modules and spending limits that constrain routine transactions. A three-of-five spread across people and devices is worth more than any additional software control.