Kraken Security Labs examined latest hyped hardware wallet
Safepal S1 and found some serious vulnerabilities and weaknesses in
this detailed report.
The thing that had most impact on me after reading their report is the fact that Safepal used GPL open source licenses and claimed them as their own making Safepal closed source, and they made licensing violations without giving credits to original creators!
Kraken team asked for source code from Safepal but they refused to provide it confirming GPL licensing violations and risking potential lawsuit.
There is also possibility that they used firmware check used in Trezor wallet with trezor-license, but this could not be proven at the time of report.
Safepal Tamper Detection is ineffective and Kraken team managed to open wallet easy and without any issue, but Safepal later confirmed this in their reply claiming it doesn’t impact the wallet security.
Interesting thing when they opened the wallet is that they could not identity Secure Element chip that Safepal claims it's EAL5+ but it's obvious from unknown manufacturer.
Downgrade Attack is a big flaw for Safepal as Kraken security team managed to change it's firmware that could be used in some potential attack.
Safepal later confirmed this, made a patch and claimed it's non-exploitable.
Safepal team made a quick public reply to Kraken in
this blog post claiming that funds are
SAFU... and that Kraken team failed to extract the seed from device, but their lame reply to license violations is that they will open source Safepal in 2021, let's wait and see.
You can read detailed Kraken report
here and Safepal reply in
this post.
My conclusion is that Safepal wallet can not be trusted, as they stole someone else work and claim it as their own and we call that a plagiarism (unless they claim the origianl source)
The fact that Kraken didn't manage to extract keys doesn't mean that it will not happen soon and who knows what kind of crap is running inside their toy and their Secure Element is unknown and can not be trusted with holding anything.
I would stay away from Safepal and advice anyone not to waste their money and risk your privacy ordering it.