The S1 Pro drops Bluetooth and USB signing in favor of QR codes alone, wrapped in an aluminum body with a CC EAL6+ chip. We checked whether that tradeoff holds up against Ledger and Trezor for a buyer who actually wants to self-custody savings.
The pitch for the S1 Pro is narrow and specific: keep the full air gap of the original S1, then fix the two things buyers complained about. SafePal swapped the plastic shell for aluminum and tempered glass, and it doubled down on QR-only signing instead of adding Bluetooth for convenience. We funded a small test wallet on it, moved assets across three chains, and read through the 2021 Kraken Security Labs report that still follows this product line around.
Why no cable and no Bluetooth is the whole design
Most rival wallets plug into a phone or a laptop, or pair over Bluetooth the way Ledger's Nano X does. The S1 Pro does neither. It signs a transaction by displaying a QR code on its own 1.3-inch, 320x320 screen, which the SafePal app on a separate phone camera reads back. Nothing about the private key ever crosses a wire or a radio signal, because there is no wire or radio to cross. SafePal states plainly that the device carries no Bluetooth, WiFi or NFC hardware at all, which closes off an entire category of remote exploit that has hit other wallets in the past.
That tradeoff has a cost. Setup takes longer than tapping a Ledger over Bluetooth, and every signature means holding two devices up to each other and waiting for a scan. Frequent traders will feel that friction daily. Someone parking savings for months at a time will not notice it as much.
The chip and the certification behind the marketing
Underneath the aluminum body sits a secure element rated CC EAL6+, the same certification tier SafePal has used across its hardware line, paired with what the company calls an anti-tampering self-destruct mechanism. That rating sits above the EAL5+ chips found in some budget wallets, though it is not independently verified per unit the way a bank card chip audit would be. The company also keeps parts of its firmware open for review, though not the whole stack the way Trezor does.




