Cap Money Multisig - 03/10/2026 15:44 - MEDIUM
- Protocol: CAP
- Contract: Cap Money Multisig —
0xb8FC49402dF3ee4f8587268FB89fda4d621a8793 - Chain: Mainnet (chain id 1)
- Risk: MEDIUM
Summary
Records one owner’s hash approval on Cap Money Multisig, which can count toward later Safe execution. No transaction is executed or funds moved by this call. The approved payload is not provided, leaving its scope and eventual impact unknown.
Analysis
Call behavior and purpose
The single call invokes approveHash(bytes32) on Cap Money Multisig:
0xFBF18B80569b29C897C6a857456b5adEA720B984(SafeProxy)
It records the calling owner’s approval of the supplied hash. This provides an on-chain approval that can be used toward the Safe’s authorization requirements during a later execution. It does not execute the transaction represented by that hash.
The approved hash is:
0xceeaf03bee90198fb795396734d1b15c72f543264d6f6d12399387d1acc66881
This is a 32-byte digest, not an amount or destination. The underlying payload is not supplied, so the hash alone does not disclose the intended recipient, native-asset value, function calls, or execution operation.
State changes and simulation
The call marks the supplied hash as approved for the approving owner. It does not, by itself, change the Safe’s owners, signature threshold, implementation, or module configuration.
The simulation reports:
- Result: SUCCESS.
- Gas used: 52,753.
- Events: One
ApproveHashevent, containing the supplied hash and the approving owner.
The event supports the conclusion that the simulated call successfully records an owner’s approval. It does not demonstrate execution of the approved payload.
No previous approval state, owner count, or signature threshold is provided. Consequently, it is not possible to determine whether this is the owner’s first approval of this hash, whether sufficient approvals already exist, or how many additional approvals a later execution would require. Simulation success is also not evidence that the transaction has been finalized on-chain.
Asset and token flows
No funds are moved by this call. It neither transfers ETH or tokens nor executes an underlying transaction that could move them.
Any subsequent asset movement or administrative action would depend on the undisclosed payload and a separate Safe execution satisfying the applicable authorization requirements. There is therefore no supported transfer amount, recipient, or downstream asset exposure to quantify here.
Risk assessment and monitoring concerns
Risk level: MEDIUM.
The immediate effect is limited to recording one owner’s approval; the call itself does not move assets or alter Safe configuration. Nevertheless, the approval can contribute to authorization of a later execution, making it consequential rather than merely informational.
The principal concern is payload opacity. Without the transaction preimage, the monitoring team cannot establish whether the approval supports a transfer, allowance, configuration change, or another action. This uncertainty warrants medium risk, but it does not establish malicious intent or justify assuming a specific financial impact.
Before treating the approval as routine, obtain the intended Safe transaction payload and verify that its computed hash matches the approved digest. Review its destination, value, operation, calldata, and nonce, then assess the existing approvals and required threshold. Monitor any subsequent execution associated with this hash separately, since that is where the underlying action and any asset movement would occur.
Call Flow
From: 0xb8FC49402dF3ee4f8587268FB89fda4d621a8793
approveHash(bytes32)on0xFBF18B80569b29C897C6a857456b5adEA720B984(SafeProxy)bytes32:0xceeaf03bee90198fb795396734d1b15c72f543264d6f6d12399387d1acc66881- Simulation: SUCCESS, gas 52,753
Reference
| Address | Label | Role | Description |
|---|---|---|---|
0xb8FC49402dF3ee4f8587268FB89fda4d621a8793 |
Cap Money Multisig | Executor | Executor: Execution authority for the governance transaction |
0xFBF18B80569b29C897C6a857456b5adEA720B984 |
SafeProxy | Call target | Call target: Receives approveHash(bytes32) |