NexFlow › Is SafePal safe
Is SafePal safe? The air-gapped wallet whose lab report came back with asterisks
SafePal is the family's most interesting lab case: a $50 air-gapped hardware wallet backed by Binance — QR-code signing, no radios, an EAL5+ secure element claim — that is also the only mainstream device a major security lab publicly called out for tamper detection 'at best, ineffective.' Both halves are on record, including the part the lab's critics quote correctly: they never got the seed.
What SafePal is
SafePal, founded 2018 by Veronica Wong, occupies a unique market slot: the first hardware wallet Binance Labs invested in, and the cheapest serious air-gapped device at roughly $50 — the S1 signs entirely over QR codes with no Bluetooth, no WiFi, no NFC, no USB data. The product line also includes a software wallet app and browser extension, which are a different custody class this page keeps separate.
The security claims are aggressive for the price: an EAL5+ secure element, a self-destruct/data-erase mechanism described in marketing as wiping keys on attack detection via multiple sensors, and a server-side device-validation step meant to catch counterfeit units. At half the price of a Trezor or Ledger, those claims are exactly what independent labs came to check.
The custody model
The seed generates inside the device; signing happens air-gapped — the companion app builds an unsigned transaction, displays it as animated QR codes, the S1's camera reads them, signs internally, and returns the signed transaction the same way. PIN and passphrase support sit on top. No cable ever carries key material, which genuinely shrinks the classic attack surface (no USB stack to exploit, no radio to hit).
The honest nuance an air-gap buyer should hold: 'air-gapped' describes the transport, not the whole system — QR codes are still a data channel in both directions (a compromised companion app can lie about what you are signing before the bytes ever reach the camera), and the architecture underneath is unusual for this class: rather than the small microcontroller designs Trezor and Ledger use, the S1 runs embedded Linux on an Allwinner-class SoC, a heavier system that expands the amount of code a security audit has to trust. The device also passes a server-side activation/validation check at setup — meaning counterfeit screening and the vendor's own infrastructure sit inside the provisioning path.
The Kraken Security Labs file — and what it did not find
In January 2021 Kraken Security Labs published the most substantive third-party look at the S1. The findings, stated as they reported them: the tamper detection was 'at best, ineffective' — opening the case stops the device booting, but re-attaching a single pin re-enabled it with contents intact; the data-erase fired only when the device was powered on and that pin stayed disconnected for more than ~10 seconds, an unlikely sequence in a real theft. They also demonstrated a firmware downgrade path (flashing an older signed image via external programmer) and flagged GPL-licensed components (U-Boot, Linux kernel) shipped without corresponding source release.
And the counterweight the same report carries: they did not extract the seed and could not steal funds — the ECDH-protected channel between the application processor and the secure element held. SafePal's response contested the framing (the bypassed pin belongs to an EMC shield, not the core security logic; erase mechanisms exist at other layers) and patched the downgrade vector in firmware V1.0.24. A 2022 independent teardown found no visible tamper sensors in the opened section. The honest synthesis: the device's headline anti-tamper marketing outran what a lab could demonstrate, while the actual key confidentiality survived the lab's attempts — neither 'proven safe' nor 'shown broken,' which is itself information at this price.
Transparency: the family's weakest file
This is where SafePal's record is thinnest relative to peers. Firmware is closed; the promised open-source roadmap did not deliver; the secure element is vendor-asserted (EAL5+ claimed, supplier unnamed); and the GPL findings remain a compliance footnote rather than a resolved transparency item. Compare the corpus's poles: Trezor publishes everything including its failings, Ledger closes firmware but ships a certified element with a decade of remote-attack survival, and SafePal closes firmware around a SoC architecture with a contested anti-tamper claim — at the market's lowest price. The correlation between price and demonstrated transparency is the point the page is for.
None of that means the device is unsafe — it means the assurance budget you can verify is smaller than the marketing budget suggests.
Where SafePal stands
Calibration for the family: the S1 is undemonstrated rather than demonstrated — no documented real-world seed extraction, no user-fund loss on record, and also a lab report that its flagship anti-tamper claim didn't survive plus the weakest transparency file among major hardware wallets. Pair it correctly: as an air-gapped signer for moderate balances it's a rational budget choice with honest asterisks; for maximum-assurance cold storage the extra $80 buys either Trezor's open verifiability or Ledger's demonstrated element. And keep the SafePal app/extension in the mental category they belong to — hot software sharing a brand with the air-gapped device, not sharing its properties. The family rule applies unchanged: buy the property (air-gapped signing), not the logo, and not the price point either — cheap is only a virtue when it is not also the audit.
Frequently asked questions
Has SafePal ever been hacked?
No documented real-world loss of user funds or seed extraction from a SafePal device is on record. The closest thing to a breach story is a lab one: Kraken Security Labs' January 2021 report found weak tamper detection and a (since-patched) firmware downgrade path — while explicitly failing to extract the seed or steal funds. Marketing claim dented; key confidentiality intact — both halves matter.
What exactly did Kraken Security Labs find?
Three things: the self-destruct/tamper mechanism could be sidestepped (open the case, re-attach one pin, device works with data intact — erase needs power plus ~10s of disconnection); firmware could be downgraded via external flash (closed in V1.0.24); and GPL-licensed components shipped without source release. They did not get the seed — the ECDH channel between the app processor and secure element held.
Is SafePal open source?
No — firmware is closed, the secure element is vendor-asserted (EAL5+ claimed, supplier not named), and a stated open-source roadmap went undelivered. Kraken additionally flagged GPL components distributed without corresponding source. Among major hardware wallets that's the thinnest transparency file — Trezor's full-open posture is the opposite pole, and it matters because you're trusting claims you cannot check.
Is the SafePal app the same as the S1 device?
No — and conflating them is the brand's safety trap. The S1 is the air-gapped hardware signer; the SafePal app and browser extension are ordinary hot-wallet software where keys live on your phone/computer. 'Air-gapped' applies only to the hardware product. If your SafePal is an app, carry the hot-wallet risk model, not the lab report.
SafePal vs Trezor or Ledger — which is safer?
On demonstrated assurance: Trezor publishes its full stack (auditable, with a documented physical-extraction caveat on old models); Ledger ships a certified element with a decade of no remote extraction; SafePal ships a cheaper air-gapped design whose signature anti-tamper claim a lab found ineffective while never taking the seed. For significant cold storage the assurance gap argues for the extra ~$80; for moderate balances the S1's air gap at $50 is a reasonable buy — with eyes open about what 'undemonstrated' means.
Is SafePal owned by Binance?
Not owned — backed. SafePal is an independent company (founded by Veronica Wong, 2018) and was the first hardware-wallet investment Binance Labs made. The backing matters mainly as a credibility signal and a distribution channel; the custody properties — seed on-device, QR signing — don't run through Binance and don't depend on it.