Self-custody reference sheet

SafePal

Doc
WLT-01
Type
Explainer
Lang
en-US

Hardware wallet + free app

SafePal Hardware Wallets and the SafePal App Explained

SafePal is a self-custody crypto wallet brand, founded in 2018, that sells small offline signing devices and gives away the software wallet that drives them. This page explains what SafePal makes, how its air-gapped signing actually works, where the SFP token fits, and how to set a SafePal wallet up without making the mistakes that cost people their coins.

The short version: a SafePal hardware wallet keeps private keys on a chip that never touches the internet, while the SafePal app handles balances, prices, swaps, staking and connections to decentralized applications. A transaction travels between the two either by scanning QR codes off the screens or, on the Bluetooth model, over a short local radio link.

SafePal is not an exchange and does not hold customer funds. That is the whole point of the category, and it is also the part that trips newcomers up, because with SafePal the recovery phrase is the account, and nobody can reset it for you.

A SafePal hardware wallet used alongside the SafePal mobile app for self-custody of crypto assets
Fig. 01 - Device and app work as a pair

What SafePal is

SafePal is a digital asset wallet company founded in 2018 and headquartered in Singapore. It builds two things that are designed to work as one system: small dedicated devices that hold private keys offline, and a free mobile and browser wallet that handles everything a key does not need to touch. The hardware is what most people picture when they hear SafePal, but the software is what they look at every day.

The company drew attention early because Binance Labs, the venture arm of the crypto exchange Binance, invested in it in 2018, which made SafePal the first hardware wallet company in that portfolio. The relationship shaped the product, and SafePal later launched its own token through Binance Launchpad. It is worth being precise about the boundary though: the two are separate companies, and a SafePal wallet is non-custodial, so no exchange holds or can freeze the keys inside it.

Everything SafePal sells rests on one idea. A crypto address is controlled by a private key, and whoever knows that key controls the funds. If the key is generated and stored on a chip that has no radio, no port for data and no operating system to attack, then a compromised phone or laptop cannot quietly take it. SafePal turns that principle into a consumer product that costs less than most people expect and does not require any technical background to run.

The product family has four parts. The hardware wallets sign transactions offline. The SafePal app manages accounts across many blockchains and connects to decentralized applications. A metal recovery-phrase backup product protects the written seed against fire and water. And SFP, the platform token, sits alongside all of it with fee and reward benefits rather than any role in security.

Who is it for? Broadly, anyone whose crypto holdings have grown past the point where losing a phone would be an inconvenience rather than a disaster. SafePal is also popular with people who use many chains at once, because the app covers a wide range of networks in a single interface rather than forcing a separate wallet per ecosystem.

Founded
Base
Singapore
Custody
User-held
Early backer
Binance Labs
Token
SFP
App price
Free

How SafePal protects a private key

When you set up a SafePal hardware wallet, the device generates a master secret on its own, using a hardware random number generator rather than software running on your phone. From that secret it derives the private keys for every address you use, following the industry standards that most modern wallets share. The secret never leaves the device in normal operation, and the SafePal app never asks for it.

The secret lives in a secure element, the same class of tamper-resistant chip used in bank cards and passports. SafePal specifies an independently evaluated secure element for its devices, assessed under the Common Criteria scheme that grades chips by evaluation assurance level. In plain terms, the chip is built to resist someone who has the device in hand and a laboratory bench, not just someone on the network.

The part that makes SafePal distinctive is the connection, or rather the absence of one. The flagship SafePal devices have no Bluetooth, no Wi-Fi and no data connection over USB. They charge, and that is it. All communication with the phone happens optically: the app shows a QR code, the device camera reads it, the device shows a QR code back, and the phone camera reads that. This is a genuine air gap, and it is the reason SafePal is often recommended to people who are nervous about wireless attack surface.

A transfer therefore runs in a loop. The SafePal app builds an unsigned transaction with the destination address, the amount and the network fee, and turns it into a QR code. The device scans it, decodes the details and shows them on its own screen. You confirm on the device, it produces a signature inside the secure element, and it displays that signature as another QR code. The app scans the signature, assembles the final transaction and broadcasts it to the network. The key itself never appears anywhere in that loop.

This is why the small screen on a SafePal device matters more than it looks. The phone is the untrusted part of the system: it is online, it runs dozens of apps, and it is the thing a scammer tries to manipulate. The device screen is the trusted display. Reading the recipient address and amount off the SafePal hardware, not off the phone, is what turns the air gap into real protection instead of a marketing point.

Recovery works through a standard mnemonic recovery phrase written down during setup. Because SafePal follows the common derivation standards, that phrase is not locked to the brand: if a device is lost or destroyed, the same phrase restores the same accounts on a replacement SafePal device or on other standards-compliant wallets. This portability is a feature worth understanding, since it means your money is not hostage to any single company continuing to exist.

Two further protections sit around this. A PIN gates physical access to the device, with wipe behavior after repeated wrong entries, and SafePal builds in anti-tamper measures intended to destroy stored key material if someone tries to open the hardware and probe it. Firmware updates are delivered through the same offline channel as everything else, so the device is not permanently exposed to a data port.

The SafePal device lineup

SafePal sells a small, deliberately uncomplicated range. Rather than one flagship with several accessories, the lineup splits along a single question: do you want the strictest possible isolation, or do you want convenience with a still-offline key?

SafePal S1 is the model that built the brand. It is a card-sized device with a small color screen, a camera, a directional pad and a battery, and it has no wireless or data connectivity at all. Everything moves by QR code. It is the natural choice for long-term holdings that you touch a few times a year, and it is the reference point most reviews use when they discuss SafePal.

SafePal S1 Pro is the refreshed air-gapped model. It keeps the QR-only workflow of the original while upgrading the internals, the screen and the build. If you like the strict air gap and want the current generation of that design, this is the SafePal device to look at.

SafePal X1 takes the other route. It connects to the app over Bluetooth instead of QR codes, which makes frequent signing far quicker, particularly if you interact with decentralized applications regularly. The keys still live in the device and still never leave it, so the trade is not custody but attack surface: a radio link is a link, and the S1 line exists precisely for people who would rather not have one.

SafePal Cypher is not electronic at all. It is a metal backup kit for recording your recovery phrase, built to survive fire, flooding and the slow decay that ruins paper. Since the phrase is the single point of failure in any self-custody setup, this is the accessory that most often deserves the money.

The comparison below summarizes the practical differences. Exact specifications change between production runs, so treat this as a guide to the shape of the range rather than a datasheet.

Product Link to app Holds keys Best suited to
SafePal S1 QR codes only Yes, secure element Long-term storage, maximum isolation
SafePal S1 Pro QR codes only Yes, secure element Current-generation air-gapped setup
SafePal X1 Bluetooth Yes, secure element Frequent signing, on-chain activity
SafePal Cypher None, offline metal Stores the recovery phrase Disaster-proof seed backup

Wherever you buy, buy from an official SafePal channel or an authorized reseller. Hardware wallets are a known target for supply-chain fraud, in which a device is opened, prepared with a phrase the seller already knows, and resealed. A legitimate SafePal unit generates its secret in front of you during setup and never arrives with a phrase already written on a card in the box.

Check the packaging seals before you open anything, and abandon the setup if a device boots into a wallet that already exists. No genuine SafePal product ships pre-initialized, and no support agent will ever need your phrase to help you.

The SafePal app and browser extension

The SafePal app is free, available for iOS and Android, and paired with a browser extension for desktop use. It is the interface layer: portfolio balances, market prices, transaction history, address book, DApp connections. It never has custody of anything, and when it is paired with hardware it never has the keys either.

The app supports a broad multi-chain range, covering the major networks and a long tail of smaller ones, along with the tokens issued on them. In practice this is one of the reasons people pick SafePal: instead of running one wallet for Bitcoin, another for an EVM chain and a third for something newer, most of it lands in a single list.

A built-in swap feature routes trades through decentralized liquidity, including cross-chain routes, so you can move between assets without sending funds to an exchange first. Rates and fees vary by route and by network conditions, and the app shows the quote before you sign, which is the moment to actually read it.

Staking is handled in-app for the networks that support it, letting you delegate assets to validators and track rewards without leaving SafePal. This is convenient, but delegation carries its own risks that have nothing to do with wallet security, including lock-up periods and validator penalties, so it is worth understanding each network's rules before committing.

For decentralized applications, SafePal includes a DApp browser and supports standard connection protocols such as WalletConnect, so you can use lending markets, exchanges, games and NFT platforms while the signature still comes from the hardware. NFTs held on supported chains appear in the app with their images rather than as raw token IDs.

You can also run SafePal purely as a software wallet, with keys generated and encrypted on the phone. This is a reasonable way to start, and it is how many people first meet SafePal, but it is a different security level: a phone is an online, general-purpose computer. Treat a software-only wallet as a spending account and move anything significant behind hardware.

The reverse pairing is also useful. A hardware-backed account can be added to the app in watch-only form, so you can check balances on the move without the device present, and only bring the SafePal hardware out when something actually needs signing.

SFP, the SafePal token

SFP is the platform token issued by SafePal. It launched through Binance Launchpad in February 2021 and trades as a token on BNB Chain. It is listed on a number of exchanges and, like any crypto asset, its price moves independently of anything the company does in a given week.

Within the ecosystem, SFP is positioned as a benefits and incentive token: discounts and preferential treatment on certain SafePal services, participation in campaigns and rewards, and a way for the company to align long-term users with the platform. The specifics have changed over time, so check current program terms rather than relying on any summary.

The important clarification is that SFP is not part of the security model. You do not need to hold it to use a SafePal wallet, to set up a device, to sign transactions or to recover a phrase. Nothing about your custody depends on it, and the wallet works identically whether your SFP balance is zero or large.

Anyone considering the token should treat it as a speculative asset and not as a required accessory to the hardware. Buying a SafePal device and buying SFP are two separate decisions with completely different risk profiles.

How SafePal developed

SafePal was founded in 2018 and secured backing from Binance Labs that same year, which gave a young hardware startup both capital and immediate distribution in a market where trust is otherwise very slow to build.

The first SafePal S1 reached customers in 2019 and set the pattern that still defines the brand: air-gapped signing by QR code, a certified secure element, and a price point well below what the category had trained people to expect.

February 2021 brought the SFP token sale on Binance Launchpad, which widened the audience considerably. Over the following years the company extended the software side, adding the browser extension for desktop users, broadening chain support in the app, and shipping the Cypher metal backup product.

More recently SafePal has run two hardware tracks in parallel, continuing the air-gapped S1 line while adding the Bluetooth-connected X1 for people who sign often. That split, rather than a single flagship, is the clearest signal of how SafePal reads its own user base.

Security model and real-world threats

It helps to be specific about which threats a SafePal wallet actually removes and which it merely reduces. The device is very good at one job: keeping the private key out of reach of software. Everything else it does is about giving you a trustworthy place to check what you are about to authorize.

Against malware, the protection is close to complete. An infected phone or laptop can watch your balances and try to substitute a recipient address, but it cannot extract a key that has never been on it. This is the scenario that empties software wallets, and it is the main reason to move holdings onto SafePal hardware.

Against phishing, protection is partial and depends on you. A convincing fake site can produce a legitimate-looking transaction that drains a token allowance rather than sending coins directly. SafePal will show you what you are signing, but the device cannot know that the contract is hostile. Slowing down at the confirmation screen is the defense here, not the hardware itself.

Against physical theft, the PIN and the secure element buy you time and, in most realistic cases, complete safety, since a thief with a locked SafePal device and no recovery phrase has an expensive paperweight. The exposure is not the device but the phrase: if both are in the same drawer, the hardware has bought you nothing.

Against supply-chain tampering, the defense is procedural. Buy through official SafePal channels, inspect the packaging, and refuse any unit that arrives already initialized. Generating the phrase yourself on first boot is the step that makes the device yours.

Against social engineering, no wallet can help. Every large theft category eventually reduces to someone typing their twelve or twenty-four words into a screen because a persuasive stranger asked. SafePal support does not need those words, no legitimate service ever does, and any request for them is a theft in progress. Reporting from mainstream outlets such as Reuters on crypto fraud losses is a useful reminder of how routine these scripts have become.

SafePal compared with other ways to hold crypto

The honest comparison is not SafePal against other wallet brands, which mostly differ at the margins, but SafePal against the alternatives people are actually choosing between: leaving assets on an exchange, using a phone wallet, or going offline.

An exchange account is the easiest option and the only one with a password reset, but the exchange holds the keys, which means its solvency, its policies and its own security become yours. A phone wallet gives you the keys but stores them on an online device. Both SafePal configurations put the keys on dedicated hardware; they differ only in how that hardware talks to the app.

Approach Who holds keys Online exposure If you lose access Speed of use
Exchange account The exchange High Account recovery possible Instant
Phone-only wallet You, on the phone Moderate to high Recovery phrase only Instant
SafePal app + S1 or S1 Pro You, on the device None for the key Recovery phrase only Slower, QR scans
SafePal app + X1 You, on the device Local Bluetooth link Recovery phrase only Fast

Plenty of people run two of these at once, and that is usually the sensible answer: a small working balance where it is convenient, and the bulk behind SafePal hardware where a bad click cannot reach it.

Getting started with SafePal

Setting up takes about twenty minutes if you do it properly, and the only part that requires care is the recovery phrase. Do it somewhere private, without a camera pointed at your desk, and without anyone on a call with you.

The sequence below assumes a hardware device paired with the app. If you are starting with the software wallet alone, steps three and four still apply in the same form.

  1. 01

    Buy from an official channel

    Order the SafePal device from the company or an authorized reseller, never from an anonymous marketplace listing. Inspect the seals on arrival.

  2. 02

    Install the app

    Get the SafePal app from the official app store listing or the browser extension store, and check the publisher name before installing. Fake wallet apps are a persistent problem across the whole category.

  3. 03

    Initialize the device and set a PIN

    Charge the unit, create a new wallet on it, and choose a PIN you will remember without writing it next to the device. SafePal generates the secret on the hardware at this point, not on your phone.

  4. 04

    Write down the recovery phrase, offline

    Copy the words in order onto paper or a metal backup. Never photograph them, never type them into a phone, never store them in a password manager or cloud note. Verify the phrase when SafePal asks you to confirm it.

  5. 05

    Pair, test small, then move the rest

    Pair the device with the SafePal app, send a small amount to one of your new addresses, confirm it arrives, then send a small amount back out so you have practiced the signing flow before it matters. Only then transfer the main balance.

Day-to-day practices that actually matter

Store the recovery phrase somewhere separate from the device. Two locations you control, ideally in different buildings, protects against both theft and fire without introducing a third party who knows anything.

Read the full destination address on the SafePal screen, not just the first and last few characters. Address-swapping malware is specifically written to produce lookalikes that match at the ends, which is exactly the part most people check.

Keep the firmware current, but install updates only through the SafePal app and only when you have your recovery phrase to hand. Updates fix real issues; doing one without a backup available is an avoidable risk.

Review token approvals periodically. When you use a decentralized exchange, you grant contracts permission to move specific tokens, and those permissions persist after you close the tab. Revoking old approvals limits what a compromised protocol can take later, even from a SafePal-secured account.

Separate your accounts by purpose. Many people run one SafePal account for long-term holdings that never interacts with a DApp, and another for on-chain activity. If something goes wrong in the active account, the isolated one is untouched.

Test recovery once, deliberately. Restoring your phrase onto a spare SafePal device or wiping and restoring the same one is the only way to know your backup is correct. Discovering a transcription error two years from now, in an emergency, is not a plan.

Finally, keep your setup boring and private. Do not discuss holdings publicly, do not accept help from strangers in support chats, and remember that anyone contacting you first about a SafePal problem you did not report is almost certainly not from SafePal.

What SafePal does not do

SafePal cannot recover your wallet. There is no password reset, no support ticket that restores access, and no company-held copy of your key. That is not a limitation to complain about, it is the definition of self-custody, and it is why the phrase backup deserves more attention than the device itself.

SafePal cannot reverse a transaction. Once a signed transfer is broadcast and confirmed, it is final. Nothing in the app or the hardware can claw it back, which is why the test transfer in the setup routine is worth the extra two minutes.

SafePal cannot judge a smart contract for you. If you approve a malicious contract, the signature is valid and the device did its job correctly. Protection at that layer comes from research and caution, not from firmware.

SafePal does not insure your assets or offer the protections attached to a bank account. Nor does it change the tax or reporting obligations that apply where you live. Holding your own keys shifts responsibility onto you across the board.

And SafePal cannot save a phrase you have shown to someone. Once the words are out, the attacker has a copy of the wallet, and no PIN, secure element or air gap makes any difference. Every layer of the system funnels down to keeping twelve or twenty-four words private.

Frequently asked questions

Is the SafePal app free to use?

Yes. The SafePal app and browser extension are free to download and use as a software wallet. You pay only for hardware, and for the ordinary network fees that any blockchain transaction incurs, plus whatever spread applies if you use the in-app swap.

Is SafePal owned by Binance?

No. Binance Labs invested in SafePal in 2018 and the two ecosystems are closely integrated, but SafePal operates as its own company and its wallets are non-custodial. No exchange holds the keys inside a SafePal device.

What happens if my SafePal device breaks or is stolen?

Your funds live on the blockchain, not in the device. Restore your recovery phrase onto a new SafePal device, or onto another wallet that follows the same standards, and the accounts reappear. A thief without the phrase faces a PIN-locked secure element.

Do I need the SFP token to use a SafePal wallet?

No. SFP offers benefits inside the ecosystem, but the wallet functions identically without it. Setting up a SafePal device, signing transactions and recovering a phrase never require holding the token.

Which is better, the air-gapped S1 line or the Bluetooth X1?

It depends on how often you sign. For holdings you touch rarely, the QR-only SafePal S1 or S1 Pro removes the wireless link entirely. For regular DApp use, the SafePal X1 is considerably faster while still keeping keys on dedicated hardware.

Can I use my SafePal recovery phrase with a different wallet?

Generally yes, because SafePal follows the widely adopted mnemonic and derivation standards. Some chains use different derivation paths between wallets, so if an address does not appear immediately, the funds are usually still there under an alternative path rather than lost.

Will SafePal support ever ask for my recovery phrase?

Never. No legitimate SafePal staff member, and no genuine support channel for any wallet, needs those words. A request for your phrase, in any wording and through any channel, is a theft attempt and should end the conversation.