CRYPTONEA 24
Crypto News 24
Review · Wallets

SafePal in 2026: The Cheapest Air-Gapped Wallet on the Market, and a Breach Its Customers Only Learned About in August

A complete review of the SafePal S1, S1 Pro and X1. Why the $50 device is genuinely good, why the user numbers are unusable, and what the August 2026 data breach means if you ordered between March 2025 and April 2026.

Data as of 19 August 2026

This page contains affiliate links. We may earn a commission at no extra cost to you. It does not change what this review says.

Our partner offer for SafePal.

Take the offer
Contents
  1. The company
  2. The user numbers are unusable, and that itself is worth knowing
  3. The devices
  4. The secure element question
  5. Open source, and how it has changed
  6. What Kraken found in 2021
  7. The August 2026 data breach
  8. The pattern nobody is reporting
  9. App, assets and the SFP token
  10. Credibility
  11. How it compares
  12. The risks, stated plainly
  13. What we could not verify
  14. Frequently asked questions
  15. Sources

SafePal makes the cheapest genuinely air-gapped hardware wallet you can buy. The S1 costs around 50 dollars, has no USB data connection, no Bluetooth and no Wi-Fi, and signs transactions by scanning QR codes. At that price, nothing else in this series comes close on isolation.

On 16 August 2026, SafePal told 39,798 customers that their names, home addresses, phone numbers and order details had been exposed through a flaw in a third-party order-tracking plugin. The stolen data is already advertised for sale on a cybercrime forum. Customers had been reporting SafePal phishing attempts since May, roughly three months before anyone was told.

Three days earlier, Trezor had disclosed a breach of its own through a different third party. In one week, two hardware wallet makers leaked the home addresses of confirmed crypto owners.

This review covers the product honestly, because the product is good. It also covers what happened in August, because that is the part your money actually depends on.


The company

SafePal was founded in early 2018. Veronica Wong is co-founder and CEO. Before crypto she spent roughly a decade at large technology companies including Tencent. [1][2][3]

The founding team was three people, named in Binance Labs' own 2019 profile: Veronica Wong (CEO), Harry Zhang (CPO) and Leaner Zhang (CTO), with backgrounds spanning hardware, software, cyber security and sales at Tencent and Huawei. [4]

The Binance connection is the company's origin story, not a footnote. SafePal was the only wallet selected for the first Binance Labs incubation programme in September 2018, went through a ten-week programme in San Francisco, and received investment at the end of that year, making it the first hardware wallet brand backed by Binance. The first product, the S1, was unveiled at Binance Blockchain Week in January 2019. [4][5][6]

Wong has been explicit about what that backing was worth: Binance's early investment gave brand credibility, lowered the trust barrier for a newcomer, and drove seed users especially in North America, which is why many people assume SafePal is a Western brand. [5]

Later backers include Animoca Brands, Superscrypt and Temasek, with partnerships involving Fiat24 and Mastercard. [2][7][8]

Headquarters are disputed. Tracxn, the company's own materials and most coverage say Singapore. At least one review says Seychelles. The App Store listing shows the developer as "SAFEPAL LTD." Check the legal entity on safepal.com before stating a jurisdiction. [1][9][10]

Tracxn lists 38 employees as of 31 May 2026. The company describes itself as remote-first, shipping updates every four to six weeks. Total funding is not publicly disclosed in dollar terms. [1][7]


The user numbers are unusable, and that itself is worth knowing

This is the least reliable figure in the entire wallet series, and no review flags it.

Figure Source
55,000 to 60,000 users in 80 to 87 countries ICOholder, early listing text
7 million BitDegree
10 million Wong's own conference biographies, 2023 to 2024
13 million Asia Blockchain Summit biography
15 million wallet users, 1 million hardware users Wong interview, October 2024
20 million CryptoNews, January 2026
25 million Google Play listing, 2026
30 million+ practicalcrypto, 2026

[1][2][3][5][7][9][11][12][13]

The only figure with analytical value is Wong's own October 2024 breakdown: roughly 15 million total wallet users but only about 1 million hardware users.

That single line reframes the company. SafePal is primarily a software wallet business that also sells hardware. Every headline user number conflates the two, and the hardware customer base is roughly one fifteenth of what the marketing implies. It also puts the August breach in proportion: 39,798 exposed customers against a hardware base of around a million.


The devices

Model Connection Price Notes
SafePal S1 Air-gapped, QR only ~$49.99 1.3-inch colour screen, D-pad, camera, 400 mAh battery
SafePal S1 Pro Air-gapped, QR only ~$89.99 Aluminium alloy and tempered glass, improved camera placement, larger battery
SafePal X1 Bluetooth ~$69.99 Open-source firmware, keypad, not air-gapped
SafePal App Software Free Mobile, browser extension, Telegram integration
Cypher seed board Metal backup varies

[9][12][14][15][16]

The S1 and S1 Pro are genuinely air-gapped: no USB data, no Bluetooth, no Wi-Fi, no NFC. The USB-C port carries power only. Signing works by scanning an unsigned transaction QR from the phone, confirming on the device screen, then displaying a signed QR back to the phone. [14][15][17]

One correction that matters, because reviews get it wrong constantly. The X1 is not air-gapped. It uses Bluetooth, has no NFC or QR signing, and offline signing is not available. Several published reviews describe SafePal's whole line as air-gapped. If you want the air gap, buy the S1 or S1 Pro. [16][18]

Security features across the line: a secure element, a true random number generator, mandatory PIN, passphrase support, and an anti-tamper self-destruct mechanism that wipes wallet data including the private key if intrusion is detected. Recovery uses standard BIP39 and BIP44 seed phrases, so the wallet is portable to any compatible device and your funds do not depend on SafePal surviving. [15][19][20]


The secure element question

SafePal's certification level is genuinely unclear across sources, and the article should say so rather than pick a number.

EAL5+ is stated by SafePal's older Amazon listing, the S1 product materials, 99bitcoins, walletinsights for the X1, and several 2026 reviews. EAL6+ is stated by SafePal's newer Amazon listing, Coin Bureau's May 2026 review, and others. CryptoNews says the X1 is EAL5+ while the S1 and S1 Pro are EAL6+. Webopedia says devices "previously offered EAL5+ chips" and "have been upgraded to EAL6+." [9][15][16][19][20][21][22][23][24]

The most likely explanation is a hardware revision that raised the S1 line from EAL5+ to EAL6+ while the X1 stayed at the lower tier. Do not state a single figure. Check the spec sheet for the exact unit you are buying.

And SafePal does not publicly disclose which secure element it uses. Trezor names its chips. NGRAVE names its chips. Ledger Donjon was able to identify Tangem's chip by inspection. SafePal names nothing, which one reviewer correctly identifies as a transparency gap. [16]

For context: EAL5+ sits below the EAL6+ found in Trezor's Safe 3 and Safe 5 and in Tangem's Samsung element.


Open source, and how it has changed

SafePal's position has shifted over time, and current descriptions conflict.

In 2021, responding to Kraken, SafePal stated plainly that it was "not open-sourced yet." Its reasoning: most users cannot audit code anyway, open source makes exploitation easier, and users cannot verify that the shipped binary matches the published source. It compared its approach to Apple and Microsoft. [25]

In September 2023 SafePal announced a transition to open source alongside the X1 launch, with the X1 audited by Keylabs before release and parts of its code progressively opened. [26]

The current position is partial. WalletScrutiny's assessment of the SafePal S1 repository is that the published code is primarily user interface and workflow logic, not the security core. Webopedia notes that some researchers indicate certain aspects remain unavailable. And a review of the X1 states that reproducible builds are not supported, which means you cannot verify that the firmware on your device matches the published source. [16][24][27]

The honest summary: SafePal has moved from closed to partially open, the X1 is the most open product, and no SafePal device supports reproducible builds. That places it above Ledger, NGRAVE, Tangem and ELLIPAL on transparency, and clearly below Trezor and Keystone.


What Kraken found in 2021

Kraken Security Labs disclosed findings to SafePal on 18 November 2020 and published in February 2021. Kraken stated at the outset that it was not able to steal cryptocurrency from the wallet, but demonstrated weaknesses that could enable future compromise. [28]

The findings:

  1. Tamper detection was ineffective. Kraken bypassed the self-destruct mechanism by removing the RF shield and re-attaching a single pin. Testing showed the wallet erases data only when powered on and only when that pin is disconnected for more than ten seconds. Kraken judged that a motivated attacker in a theft scenario would be unlikely to trigger the alarm.
  2. Firmware downgrade attack. Using a flash programmer, Kraken flashed an earlier firmware version back onto the device, and the device did not detect it.
  3. GPL licensing violation. The wallet contains GPLv2-licensed U-Boot and Linux kernel code. Kraken requested the source and SafePal refused, which Kraken stated puts SafePal in violation of GPL licensing, noting that such violations have led to litigation.
  4. Kraken also found the U-Boot bootloader heavily modified, encrypted and obfuscated, and time-limited its review as a result. [27][28]

SafePal fixed the downgrade issue in firmware V1.0.24. On tamper detection, it argued the RF shield design is unrelated to the core security logic. On open source, it gave the response quoted above. It also stated that no user funds were stolen and that Kraken made no substantial progress penetrating the core security architecture, which it framed as evidence of the design's strength. [22][25]

No public exploit of a SafePal device resulting in stolen user funds has ever been documented. [22][28]

Whether the GPL source-code issue was ever resolved could not be established.


The August 2026 data breach

On Sunday 16 August 2026, SafePal disclosed that an authorization flaw in a third-party order-tracking plugin allowed unauthorised parties to view other customers' order information. In practice, altering an order number could reveal another customer's details. [29][30][31]

Scope: approximately 39,798 customers who placed orders between 2 March 2025 and 11 April 2026. Exposed data: names, email addresses, shipping addresses, phone numbers and purchase details. [29][30][32]

SafePal states the breach did not involve seed phrases, private keys, wallet passwords or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers, adding that it never requests or stores such information. It says no evidence has been found that wallets or funds were compromised. [30][32][33]

Three details make this worse than the disclosure implies.

First, a second failure widened the damage. During its investigation SafePal discovered a separate configuration error that caused a data-cleanup process to stop functioning correctly between September 2025 and April 2026, which expanded the volume of retained data available to be stolen. [32]

Second, the data is already for sale. A threat actor is advertising the stolen SafePal customer data on a cybercrime forum, referencing the same order period and the same figure of approximately 39,798 customers, and offering to share order IDs and shipping countries that can be confirmed against SafePal's own order-verification tool as proof of legitimacy. [32]

Third, and most seriously, customers reported SafePal phishing emails and phone calls as early as May 2026, roughly three months before disclosure. That timeline suggests the flaw was being exploited long before anyone was told. [32]

SafePal's response was fast once the problem was known: the flaw has been fixed, additional security controls added, all affected customers emailed on 16 August with a subject line beginning "[Important] Your SafePal Order Information Has Been Affected", more than 30 fraudulent websites and phishing links identified and removed, ongoing domain monitoring, and an independent cybersecurity firm engaged to verify the remediation. [31][33][34]

What SafePal has not disclosed: when the vulnerable code was introduced, or how many parties accessed the records before the flaw was found. [31]

SafePal's own warning to users is the important part, and it should be repeated in plain language: anyone who has already shared or entered a seed phrase or private key in response to a suspicious message, website, phone call or letter should treat that wallet as compromised and move the assets immediately. [30][35]


The pattern nobody is reporting

Trezor disclosed a customer data breach on 13 August 2026 through its fulfilment partner ShipMonk. SafePal disclosed on 16 August 2026 through an order-tracking plugin. Both exposed names, addresses and phone numbers. Neither touched a private key.

Ledger has now had two such breaches, in 2020 and January 2026, and the 2020 list has produced six years of phishing, extortion, tampered devices sent by post and threats of physical violence.

The pattern is unmistakable and it is structural. Hardware wallet makers have hardened their devices to the point where remote key extraction has essentially never happened. Their order databases, fulfilment partners, analytics plugins and payment processors have not been hardened to anything like the same standard. And a list of confirmed hardware wallet owners with home addresses is one of the most valuable customer datasets in existence for a criminal.

If you own any hardware wallet, assume your purchase details have leaked or will leak, and behave accordingly.


App, assets and the SFP token

The SafePal App supports 16 languages, 200+ blockchains, and 200,000+ tokens and NFTs, with a custom RPC feature covering 400+ EVM networks. On-ramp covers 35+ cryptocurrencies via MoonPay, Simplex and Binance Connect, with off-ramp to USD, EUR and GBP. Asset counts vary wildly across sources, so cite the app store listings with a date. [13]

Features: in-app swaps through DEX aggregators, a Web3 browser for dApps, WalletConnect, staking through providers including Chorus One and P2P.org with typical returns of 5% to 10%, NFT support, a browser extension and a Telegram bot. [24][36]

Two limitations worth knowing before you buy. The desktop browser extension does not support the full asset list, with Cardano, Stellar, VeChain, NEO and USDC among reported omissions. And there is no native desktop application for Windows, macOS or Linux. [9][20]

SFP is the native token, launched in 2021 as the first IEO on Binance Launchpad. Total supply 500 million, split 300 million on BNB Chain and 200 million on Ethereum. Utilities include discounts on SafePal hardware, listing and promotion fees inside the app, staking rewards and airdrops. It is not required to use the wallets. [36][37]

As of a mid-2025 capture, SFP traded around $0.45 with a market cap near $227 million, roughly 90% below its peak of $4.39. Check the current price before publishing, and treat it as a volatile asset rather than a discount coupon. [20]

One review reports that the built-in swap feature can trigger unexpected KYC restrictions or freeze transactions during high-traffic market events. Worth verifying, but worth a sentence if it holds. [38]


Credibility

Trustpilot gives SafePal 3.9 out of 5 from over 350 reviews in one March 2026 capture, with the live profile showing 388 reviews more recently. Note that the profile carries a merge notice, meaning reviews from another profile were combined into it, which affects how the score should be read. [12][39]

The mobile app is broadly well reviewed, with users citing the interface, network coverage and the hardware-software pairing. Negative app reviews frequently reflect user error and gas fee confusion rather than product failure. [40]

Recurring complaints: delayed orders or orders that never arrived, support available only through online tickets with no phone or live channel, no desktop application, and the swap KYC friction above. Recurring positives: price, air-gapped design, and support responsiveness once a ticket is opened. [9][39][41]

Brand impersonation is a live and elevated risk. SafePal has previously warned that a Chrome web store extension impersonating it was a scam, and the August breach has since produced more than 30 additional fraudulent domains. [34][40]


How it compares

Wallet Air-gapped Secure element Firmware open Reproducible builds Price
SafePal S1 Yes, QR EAL5+ or EAL6+ Partial No ~$49.99
SafePal S1 Pro Yes, QR EAL5+ or EAL6+ Partial No ~$89.99
SafePal X1 No, Bluetooth EAL5+ Yes No ~$69.99
Trezor Safe 3 No, USB EAL6+ Yes Yes ~$79
Trezor Safe 5 No, USB EAL6+ Yes Yes ~$129
Tangem No, NFC EAL6+ No No ~$55
Keystone 3 Pro Yes, QR Three chips Yes, MCU blob excepted Yes ~$129
NGRAVE ZERO Yes, QR EAL5+, EAL7 OS No No ~$398
ELLIPAL Titan 2.0 Yes, QR EAL5+ No No ~$149
Blockstream Jade Plus Optional QR varies Fully open Yes ~$65
Ledger Nano S Plus No, USB EAL6+, closed Partly No ~$79

[14][15][16]

The S1 is the cheapest genuinely air-gapped hardware wallet on the market. At the same price the Trezor Model One has open hardware but connects by USB, and the Ledger Nano S Plus costs more with no battery.

The comparison that should worry SafePal is the Blockstream Jade Plus at around 65 dollars, which one reviewer judges the stronger device overall for Bitcoin-focused users because of fully open firmware and hardware. And at 129 dollars the Keystone 3 Pro offers the same air gap plus published audits, three secure elements and reproducible builds.


The risks, stated plainly

  1. Your order data may already be exposed. If you ordered between 2 March 2025 and 11 April 2026, assume your name, address, phone and email are circulating and for sale. Expect targeted phishing.
  2. No legitimate party will ever ask for your seed phrase. Not SafePal support, not by email, not by phone, not by letter.
  3. If you have already entered a seed phrase anywhere in response to a message, move your funds now. This is SafePal's own advice.
  4. The X1 is not air-gapped. Buy the S1 or S1 Pro if that is what you want.
  5. Certification is inconsistent across models and revisions, and SafePal does not name its chips.
  6. No reproducible builds means you cannot verify the firmware on your device matches published code.
  7. Support is ticket-only, and order fulfilment complaints are a recurring theme.
  8. SFP is a volatile token, not a loyalty scheme.
  9. Buy only from safepal.com or an authorised reseller. The counterfeit and impersonation risk is elevated right now.

What we could not verify

Deliberately absent above: the registered legal entity and jurisdiction; total funding raised, revenue, profitability and valuation; the real hardware user count as distinct from app users; the exact secure element model in any SafePal device; which models and production runs carry EAL5+ versus EAL6+; when the breached order-tracking code was introduced and how many parties accessed the data; whether SafePal operates a public bug bounty; whether the GPL source-code issue Kraken raised in 2021 was ever resolved; and Greek-language interface, VAT-inclusive euro pricing, shipping times and warranty handling for Greece.


Frequently asked questions

Was I affected by the August 2026 breach? Only if you received a notification email on 16 August. The affected group is approximately 39,798 customers who placed orders between 2 March 2025 and 11 April 2026. No seed phrases, private keys or payment card numbers were involved.

Is my crypto at risk because of the breach? Not directly. Nothing that controls your funds was exposed. The risk is targeted phishing, because criminals now know you own a hardware wallet and where you live. If you have already entered your seed phrase somewhere in response to a message, treat that wallet as compromised and move the assets.

Has a SafePal device ever been hacked? No public exploit resulting in stolen user funds has been documented. Kraken Security Labs found weaknesses in 2021 in tamper detection and firmware downgrade protection but was explicitly unable to steal cryptocurrency from the device.

Which SafePal should I buy? The S1 at around 50 dollars if you want air-gapped security on a budget, or the S1 Pro at 90 dollars for better build quality. Avoid the X1 if the air gap is why you are buying, since it uses Bluetooth.

Is SafePal owned by Binance? No. Binance Labs invested in 2018 and SafePal was the first hardware wallet brand it backed, but SafePal is an independent company with several other investors since.

What is the single most important thing? Write your recovery phrase on paper or metal, store it offline, and never type it into anything. That includes any website, app, phone call or letter claiming to be SafePal.


Sources

All accessed 19 August 2026.

  1. Tracxn, SafePal company profile, Aug 2026
  2. CryptoSlate, Veronica Wong profile
  3. WebX Asia 2024, Veronica Wong speaker biography
  4. Binance Labs via Medium, "#BUIDLers Season 1: Project 3 of 8 (SafePal)", Feb 2019
  5. AiCoin, "Dialogue with SafePal Co-founder Veronica Wong", Oct 2024
  6. IQ.wiki, Veronica Wong
  7. practicalcrypto.net, "SafePal 2026, Wallets, App and Extension Review"
  8. Asia Blockchain Summit, Veronica Wong speaker biography
  9. CryptoNews, "SafePal Wallet Review 2026: How Reliable Is It?", Jan 2026
  10. Apple App Store, SafePal listing
  11. ICOholder, SafePal profile
  12. crypto-insite, "Safepal Wallet in 2026", Mar 2026
  13. Google Play, SafePal listing, 2026
  14. bitcoins.tools, "SafePal S1 Review 2026"
  15. Coin Bureau, "SafePal S1 Review 2026", updated 27 May 2026
  16. walletinsights.io, "SafePal X1 Review", Apr 2026
  17. snout0x, "SafePal S1 Review 2026", Apr 2026
  18. CryptoAdventure, "SafePal Wallet Review 2026", Feb 2026
  19. Amazon listing, SafePal S1 (EAL5+ product text)
  20. 99bitcoins, "SafePal Review 2026"
  21. Traders Union, "SafePal Wallet Review", Jul 2026
  22. Amazon listing, SafePal S1 (EAL6+ product text, newer ASIN)
  23. RankFi, "SafePal S1 Wallet Review", Oct 2025
  24. Webopedia, "Safepal Wallet Review 2026", Apr 2026
  25. SafePal, "Our Response To The Security Findings From Kraken Security Labs", Feb 2021
  26. Benzinga, "SafePal Breaks New Ground With Open-source Wallet Suite And X1 Bluetooth Hardware"
  27. WalletScrutiny, SafePal S1 assessment
  28. Kraken Security Labs, "Kraken Security Labs Finds Flaws in Safepal S1 Hardware Wallet", Feb 2021
  29. CoinDesk, "Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order info", 16 Aug 2026
  30. Cryptopolitan, "SafePal reveals security breach affecting 39,798 users as phishing risks mount", Aug 2026
  31. Cryptonomist, "SafePal Data Breach: Insights and Security Response", 17 Aug 2026
  32. BleepingComputer, "SafePal data breach impacts 39,798 customers, stolen info for sale", Aug 2026
  33. SecurityWeek, "40,000 Impacted by SafePal Data Breach", Aug 2026
  34. Undercode News, "SafePal Data Breach Exposes Nearly 40,000 Customers", Aug 2026
  35. Bitcoin World, "SafePal Data Breach: 39,798 Customers' Personal Information Exposed", Aug 2026
  36. ICOBench, "SafePal Wallet Review"
  37. BitDegree, "SafePal Wallet Review"
  38. ComparEdge, SafePal review, May 2026
  39. Trustpilot, safepal.com reviews
  40. Apple App Store, SafePal reviews
  41. UpgradedReviews, SafePal aggregated reviews

Πληροφοριακό υλικό μόνο. Δεν αποτελεί επενδυτική συμβουλή. Η αγορά κρυπτονομισμάτων ενέχει υψηλό κίνδυνο.

Information only. Not investment advice. Cryptocurrency markets carry substantial risk.

Our partner offer for SafePal.

Take the offer

This review was written by our editorial team from public sources, which are listed at the foot of the article. Prices, fees and terms change: verify them on the provider's own site before you buy or deposit. This is not financial advice.