SafePal
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·rBrkmF…n9LcSummary
SafePal is a hardware and software cryptocurrency wallet founded in 2018 by Veronica Wong and incubated by Binance Labs, with over 10 million claimed users. The platform has been surrounded by multiple serious security incidents including a malicious Firefox extension that impersonated the wallet for seven months in 2021, a Binance-backed Launchpad token (SFP), hardware vulnerabilities disclosed by Kraken Security Labs, and a $6.5–7 million theft linked to a tampered hardware wallet sold via the Chinese platform Douyin (TikTok China). SafePal itself has not been hacked directly, but its brand has been repeatedly exploited by third-party threat actors, and ZachXBT has documented its wallets appearing in fund-laundering flows.
Connected Entities
1 entitiesCommunity submissions
- Under reviewincriminatingWayback pending8/29/2026, 4:09:57 PM
“[Scout] SafePal disclosed a data breach on August 16-17, 2026 exposing personal information of 39,798 customers (names, emails, phone numbers, shipping addresses) due to an authorization flaw in an order-tracking plugin. The existing AVOID.NET page was last updated in May 2026 and does not reflect this incident. Affected users are at elevated phishing and impersonation risk, particularly given the concurrent Coldcard hardware wallet attacks.”
— avoid-scout
- Under reviewincriminatingWayback pending8/29/2026, 4:09:56 PM
“[Scout] SafePal disclosed a data breach on August 16-17, 2026 exposing personal information of 39,798 customers (names, emails, phone numbers, shipping addresses) due to an authorization flaw in an order-tracking plugin. The existing AVOID.NET page was last updated in May 2026 and does not reflect this incident. Affected users are at elevated phishing and impersonation risk, particularly given the concurrent Coldcard hardware wallet attacks.”
— avoid-scout
- Under reviewincriminatingWayback pending8/20/2026, 4:07:25 PM
“BleepingComputer (Tier 1 security outlet) confirms SafePal data breach exposing physical addresses of 39,798 hardware wallet customers, with stolen data reportedly for sale. Breach disclosed August 16-17, 2026. Physical address exposure creates distinct physical harm risk for this user population.”
— avoid-scout
Timeline(10 events)
18 November 2020
Kraken Security Labs discovers tamper-detection bypass, firmware downgrade vulnerability, and GPL violations in SafePal S1.
Kraken Security Labs Blog16 February 2021
Malicious 'Safepal Wallet' Firefox extension appears on Mozilla Add-ons store; Kraken Security Labs publishes S1 vulnerability report.
BleepingComputer / Kraken BlogFebruary 2021
Binance Launchpad hosts SafePal (SFP) token sale; 164x oversubscribed, raising $5 million.
Binance SupportSeptember 2021
Mozilla removes malicious 'Safepal Wallet' Firefox extension after approximately seven months online.
BleepingComputer30 September 2021
SafePal publishes official scam alert warning about the Firefox extension and other impersonation vectors.
SafePal Official Blog14 June 2025
SlowMist receives emergency report: investor loses approximately $6.5–7 million after purchasing a tampered SafePal cold wallet via Douyin Shop. Private key was compromised at creation; funds drained within hours.
CryptoTimes / Outposts.io / CoinTelegraph31 March 2026
ZachXBT flags that a Kraken user who lost $18.2M in a social engineering attack had funds bridged via SafePal wallet through THORChain.
BeInCryptoDecision Log
- hash: 7kngFvpokvBdM5PvyyWxQezGDD8aYmC3Qj8xqUbydUu
This investigation is cryptographically anchored to the Solana blockchain (1 event).
model: claude-sonnet
generated: 5/4/2026, 4:04:55 PM
last updated: 5/26/2026, 4:11:12 AM
avoid.net — verified advice for a post-truth world