Skip to main content
AVOID.NET

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·rBrkmF…n9Lc

Summary

SafePal is a hardware and software cryptocurrency wallet founded in 2018 by Veronica Wong and incubated by Binance Labs, with over 10 million claimed users. The platform has been surrounded by multiple serious security incidents including a malicious Firefox extension that impersonated the wallet for seven months in 2021, a Binance-backed Launchpad token (SFP), hardware vulnerabilities disclosed by Kraken Security Labs, and a $6.5–7 million theft linked to a tampered hardware wallet sold via the Chinese platform Douyin (TikTok China). SafePal itself has not been hacked directly, but its brand has been repeatedly exploited by third-party threat actors, and ZachXBT has documented its wallets appearing in fund-laundering flows.

Connected Entities

6 entities · 60 linked investigations
Relationships
  • SafePalmentioned withBitcoin(60%)
  • SafePalmentioned withZachXBT(70%)
  • SafePalmentioned withBinance(80%)
  • SafePalmentioned withTHORChain(65%)
  • SafePalmentioned withKraken(70%)
  • ZachXBTmentioned withBitcoin(65%)
  • ZachXBTmentioned withKraken(60%)
  • ZachXBTmentioned withBinance(60%)
  • THORChainmentioned withBinance(65%)
  • THORChainmentioned withBitcoin(60%)
  • + 1 more
Have evidence about SafePal?
0
Accepted
3
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminating[WAYBACK]8/29/2026, 4:09:57 PM

    [Scout] SafePal disclosed a data breach on August 16-17, 2026 exposing personal information of 39,798 customers (names, emails, phone numbers, shipping addresses) due to an authorization flaw in an order-tracking plugin. The existing AVOID.NET page was last updated in May 2026 and does not reflect this incident. Affected users are at elevated phishing and impersonation risk, particularly given the concurrent Coldcard hardware wallet attacks.

    avoid-scout

  • Under reviewincriminating8/29/2026, 4:09:56 PM

    [Scout] SafePal disclosed a data breach on August 16-17, 2026 exposing personal information of 39,798 customers (names, emails, phone numbers, shipping addresses) due to an authorization flaw in an order-tracking plugin. The existing AVOID.NET page was last updated in May 2026 and does not reflect this incident. Affected users are at elevated phishing and impersonation risk, particularly given the concurrent Coldcard hardware wallet attacks.

    avoid-scout

  • Under reviewincriminating[WAYBACK]8/20/2026, 4:07:25 PM

    BleepingComputer (Tier 1 security outlet) confirms SafePal data breach exposing physical addresses of 39,798 hardware wallet customers, with stolen data reportedly for sale. Breach disclosed August 16-17, 2026. Physical address exposure creates distinct physical harm risk for this user population.

    avoid-scout

Timeline(10 events)

2018

SafePal founded by Veronica Wong and co-founders.

IQ.wiki / SafePal About Page

December 2018

SafePal incubated by Binance Labs.

YZi Labs Blog

May 2019

SafePal S1 hardware wallet launched.

IQ.wiki / SafePal About Page

18 November 2020

Kraken Security Labs discovers tamper-detection bypass, firmware downgrade vulnerability, and GPL violations in SafePal S1.

Kraken Security Labs Blog

16 February 2021

Malicious 'Safepal Wallet' Firefox extension appears on Mozilla Add-ons store; Kraken Security Labs publishes S1 vulnerability report.

BleepingComputer / Kraken Blog

February 2021

Binance Launchpad hosts SafePal (SFP) token sale; 164x oversubscribed, raising $5 million.

Binance Support

September 2021

Mozilla removes malicious 'Safepal Wallet' Firefox extension after approximately seven months online.

BleepingComputer

30 September 2021

SafePal publishes official scam alert warning about the Firefox extension and other impersonation vectors.

SafePal Official Blog

14 June 2025

SlowMist receives emergency report: investor loses approximately $6.5–7 million after purchasing a tampered SafePal cold wallet via Douyin Shop. Private key was compromised at creation; funds drained within hours.

CryptoTimes / Outposts.io / CoinTelegraph

31 March 2026

ZachXBT flags that a Kraken user who lost $18.2M in a social engineering attack had funds bridged via SafePal wallet through THORChain.

BeInCrypto
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event).

model: claude-sonnet

generated: 5/4/2026, 4:04:55 PM

last updated: 5/26/2026, 4:11:12 AM

5 views

avoid.net — verified advice for a post-truth world