# SafePal

分類: wallets
等級: C
亮點: INCIDENT-2026-08, MULTI-CHAIN, MONERO-CAPABLE
功能: multi_chain, monero_support
手續費: Hardware wallet purchase price varies by model (S1 / X1 / X1 Pro / Cypher). Free companion app. Fee schedule for on-app swaps varies by integration; verify at purchase time.
網站: https://safepal.com/

## 事件 (2026-08-16, severity: high)
SafePal disclosed on 2026-08-16 (blog: "Unauthorized Access To A Subset Of Customer Order Information") that a flaw in their order-tracking plug-in led to unauthorized access to customer information for approximately 39,798 customers who placed orders between 2025-03-02 and 2026-04-11 — a 13-month window. Exposed data: full names, email addresses, shipping addresses, phone numbers, and purchase details. Wallets, seed phrases, private keys, and wallet passwords are not affected — the exposure is entirely on the fulfillment / order-tracking supply chain. The reader-facing risk is not phishing (SafePal's own framing) — it is physical: confirmed crypto-holder home addresses in the hands of any buyer of the leaked data is home-invasion / stalking / $5-wrench-attack territory. Affected customers notified individually by email; verification available at safepal.com/scam-protection using order ID + shipping country. This is the second major hardware-wallet supply-chain PII exposure in 5 days (Trezor 2026-08-13 exposed 11,742 customers over a 90-day window). See /guides/old-iphone-cold-storage for the shipping-address opsec response.

> 多鏈硬體錢包，透過 Monero GUI 支援 Monero。Grade C。上架同時開啟事件：2026-08-16 訂單追蹤外掛被利用，約 39,798 名客戶完整個資（姓名 + 郵件 + 收件地址 + 電話 + 購買明細）在 2025-03-02 至 2026-04-11 之 13 個月區間內被存取。實體安全風險，非釣魚風險。請閱讀事件區塊再下單。

## 評測

**上架同時開啟事件（2026-08-16）。** SafePal 自家揭露（[`safepal.com/scam-protection`](https://safepal.com/scam-protection)）：**訂單追蹤外掛**存在漏洞，導致大約 **39,798 名客戶** 在 **2025-03-02 至 2026-04-11**（**13 個月區間**）下單的訂單資訊遭未授權存取。曝光資料：完整姓名、電子郵件、收件地址、電話號碼、購買明細。錢包、種子片語、私鑰、錢包密碼未受影響 — 曝光完全發生在物流／訂單追蹤供應鏈。SafePal 公開說明以「錢包安全」／釣魚風險為主 — 技術上為真，但沒抓到重點。讀者層面的風險不是釣魚，是實體：39,798 名已確認加密幣持有人的住址進入黑市，那是入室搶劫／跟蹤／五塊美金扳手攻擊的領域。見 [`/guides/old-iphone-cold-storage`](/zh/guides/old-iphone-cold-storage) 關於寄送地址 opsec 的重新框架，以及能完全關掉此類曝光的一步步替代方案。

**在類別脈絡下這代表什麼。** SafePal 是 **5 天內第二個**因供應鏈外洩而曝光客戶個資的重大硬體錢包供應商。Trezor（2026-08-13）在 90 天區間內曝光 11,742 名客戶；SafePal（2026-08-16）在 13 個月區間內曝光約 39,798 名客戶 — 合計 **5 天內 51,540 筆硬體錢包客戶的完整住址個資進入黑市**。再加上 Coldcard 2026-07-30 韌體 RNG 事件（潛伏 5 年的弱熵 bug 讓 ~594 BTC 從 ~500 個錢包被抽走 — 見 [`/guides/hardware-wallets-for-monero-after-coldcard`](/zh/guides/hardware-wallets-for-monero-after-coldcard)），硬體錢包信任面在 18 天內捱了三種不同型別的打擊：裝置韌體信任、供應鏈個資（Trezor）、以及再一次供應鏈個資但規模 3.4 倍、時間 13 倍（SafePal）。這是類別級的模式，而非廠商專屬。

**SafePal 是什麼。** 多鏈硬體錢包家族（S1、X1、X1 Pro、Cypher），支援 Bitcoin、Ethereum、Solana，以及（部分機型透過 Monero GUI 整合）Monero。供應商：SafePal Inc.（新加坡）。

**你信任什麼。** 裝置本身（Secure Element 架構；各機型韌體模型不同）。錢包密碼學與簽章路徑在多鏈 HW 類別中為標準。

**你不信任什麼。** SafePal 的物流供應鏈 — 具體來說是那個在 13 個月區間內被外洩、直到 5 月客戶開始收到釣魚郵件才被察覺的訂單追蹤外掛（據 SafePal 的 FAQ：*「我 5 月就收到釣魚郵件了。為什麼到 8 月才確認原因？」*）。緩解方式：PO box、轉運商、郵政轉寄，或使用連結指南中的獨立 iPhone 模式。

**替代方案。** 隔離網路使用案例專用：**Cupcake Wallet**（Cake Wallet 團隊所出），在舊 iPhone／Android 上執行 — 為隔離網路籤章方角色量身打造，完全避開寄送地址那面。要維持硬體錢包路線的話：下次下單前先匯入寄件地址輪換（PO box、轉運商、郵政轉寄）。

**交叉引用。** 父指南：[`/guides/monero-cold-storage`](/zh/guides/monero-cold-storage)。替代模式：[`/guides/old-iphone-cold-storage`](/zh/guides/old-iphone-cold-storage)。Coldcard 之後的信任模型：[`/guides/hardware-wallets-for-monero-after-coldcard`](/zh/guides/hardware-wallets-for-monero-after-coldcard)。二進位檔驗證：[`/guides/verify-wallet-binary`](/zh/guides/verify-wallet-binary)。

來源: https://xmr.club/zh/wallets/safepal