xmr.club
EN 中文 ES RU
★ FRONT-PAGECDexsport— Web3 crypto sportsbook + casino since 2021, No-KYC, accepts XMR (+38 coins). Read first: documented cancelled-winnings /→
/wallets · unverified

SafePal

C

Multi-chain hardware wallet with Monero support via Monero GUI. Grade C. Live incident: 2026-08-16 order-tracking plug-in breach exposed ~39,798 customers' full PII (name + email + shipping address + phone + purchase details) across a 13-month window (2025-03-02 → 2026-04-11). Physical-safety risk, not phishing risk. Read the incident block before ordering.

Incident timeline

  1. 2026-08-20auto SafePal posted an 18 August follow-up on its 16 August incident blog acknowledging unverified claims that the ~39,798-record order dataset is being offered for sale, while restating that seed phrases, keys, and wallet credentials were not in scope. A cybercrime-forum listing matching the disclosed order window and c…
  2. 2026-08-28auto SafePal posted an official X progress note on 2026-08-23: still finalizing 4 anti-phishing vendors and 3 independent auditors, still monitoring dark-web sale/publication claims, and reviewing order/shipping data held. The official blog is unchanged since its 2026-08-18 addendum; victim count (~39,798), data types, a…

At a glance

Grade
C
Fees
Hardware wallet purchase price varies by model (S1 / X1 / X1 Pro / Cypher). Free companion app. Fee schedule for on-app swaps varies by integration; verify at purchase time.
Incident
⚠ Active since 2026-08-16 — /incidents
C Why grade C?

Acceptable with reservations. Posture intact but evidence is older, lighter, or the provider sits on a known weakness (custody risk, history of customer-fund freezes resolved, etc.).

Full rubric + 7-step verification walkthrough at /methodology.

curator verdict · bottom line

Curator Verdict & OpSec Breakdown

THE BOTTOM LINE

SafePal remains listed for comparative coverage, but carries notable custodial, verification, or track-record caveats that warrant extra user caution.

✓

Proven Strengths

  • ▸ Established listing actively reviewed in the xmr.club Monero wallet directory.
⚠

OpSec Trade-offs & Caveats

  • ▸ ACTIVE INCIDENT (2026-08-16): SafePal disclosed on 2026-08-16 (blog: "Unauthorized Access To A Subset Of Customer Order Information") that a flaw in their order-tracking plug-in led to unauthorized access to customer information for approximately 39,798 customers who placed orders between 2025-03-02 and 2026-04-11 — a 13-month window. Exposed data: full names, email addresses, shipping addresses, phone numbers, and purchase details. Wallets, seed phrases, private keys, and wallet passwords are not affected — the exposure is entirely on the fulfillment / order-tracking supply chain. The reader-facing risk is not phishing (SafePal's own framing) — it is physical: confirmed crypto-holder home addresses in the hands of any buyer of the leaked data is home-invasion / stalking / $5-wrench-attack territory. Affected customers notified individually by email; verification available at safepal.com/scam-protection using order ID + shipping country. This is the second major hardware-wallet supply-chain PII exposure in 5 days (Trezor 2026-08-13 exposed 11,742 customers over a 90-day window). See /guides/old-iphone-cold-storage for the shipping-address opsec response.
  • ▸ Clearnet-only footprint: lacks an official .onion hidden service mirror; exposes visitor network IP unless routed through VPN/Tor.

Review

Live incident (2026-08-16). SafePal's own disclosure (`safepal.com/scam-protection`): a flaw in their order-tracking plug-in led to unauthorized access to customer order information for approximately 39,798 customers who placed orders between 2025-03-02 and 2026-04-11 — a 13-month window. Exposed data: full names, email addresses, shipping addresses, phone numbers, purchase details. Wallets, seed phrases, private keys, wallet passwords are unaffected — the breach is entirely on the fulfillment / order-tracking supply chain. SafePal's public framing leads with the standard *"wallets are secure"* / phishing-risk warning — technically true and beside the point. The reader-facing risk is not phishing; it is physical: 39,798 confirmed crypto-holder home addresses on the black market is home-invasion / stalking / $5-wrench-attack territory. See `/guides/old-iphone-cold-storage` for the shipping-address-opsec reframe + a step-by-step alternative that closes this class of exposure entirely.

What this is in category context. SafePal is the second major hardware-wallet vendor to expose customer PII via supply-chain breach in 5 days. Trezor (2026-08-13) exposed 11,742 customers over a 90-day window; SafePal (2026-08-16) exposes ~39,798 customers over a 13-month window — combined 51,540 hardware-wallet customer records with full home-address PII on the black market in five days. Add Coldcard's 2026-07-30 firmware-RNG incident (~594 BTC drained across ~500 wallets from a 5-year-latent weak-entropy bug — see `/guides/hardware-wallets-for-monero-after-coldcard`) and the hardware-wallet trust surface has taken three distinct hits in 18 days: device firmware trust, supply-chain PII (Trezor), and supply-chain PII again with 3.4× the count and 13× the window (SafePal). The pattern is category-wide, not vendor-specific.

What SafePal is. Multi-chain hardware wallet family (S1, X1, X1 Pro, Cypher) with support for Bitcoin, Ethereum, Solana, and (via Monero GUI integration for select models) Monero. Vendor: SafePal Inc. (Singapore, founded 2018 per public record; verify on their /about surface).

What you trust. The device itself (Secure Element architecture; firmware model per model varies). Wallet cryptography and signing paths appear standard for the multi-chain HW category.

What you don't. SafePal's fulfillment supply chain — specifically the order-tracking plug-in that was breached over a 13-month window and only detected after phishing emails started reaching customers in May 2026 (per SafePal's FAQ: *"I received phishing emails in May. Why did it take until August to confirm the cause?"*). Mitigations: PO box, drop shipper, mail-forwarding service, or the separate-iPhone pattern in the linked guide.

Alternatives. For the airgap use case specifically: Cupcake Wallet (by the Cake Wallet team) on an old iPhone / Android — purpose-built for the airgap-signer role, avoids the shipping-address surface entirely. For a hardware wallet without changing the pattern: rotate through a shipping-privacy layer before your next order.

Cross-refs. Parent guide: `/guides/monero-cold-storage`. Alternative pattern: `/guides/old-iphone-cold-storage`. After-Coldcard trust model: `/guides/hardware-wallets-for-monero-after-coldcard`. Verify-your-binary: `/guides/verify-wallet-binary`.

Fees

Hardware wallet purchase price varies by model (S1 / X1 / X1 Pro / Cypher). Free companion app. Fee schedule for on-app swaps varies by integration; verify at purchase time.

Links

Audit trail — receipts for the editorial claim

  • ● UPSTREAM Up · HTTP 200 · 188ms · checked 9h ago
  • ○ ONION No .onion mirror listed
  • ⚠ MANUAL No last_verified stamp — see /freshness

Reviews — moderated · rules

No community reviews yet. Be the first below.

Add a review

Honest, brand-neutral feedback welcome. A curator approves before it appears here. No JS required.

Required: review body. Honest, descriptive reviews get approved within a day. Marketing copy, slurs, or invective get rejected. Per-day cap of 5 submissions per IP.