Directory · Hardware wallets

ELLIPAL

You hold the keys Founded 2018

How we make money from this listing. We may earn a commission if you sign up through our link. That buys position on a list — nothing else. It does not change a word of what follows, and we do not publish scores that could be bought. Our rules, in writing.

ELLIPAL is air-gapped in the strict sense of the word, which is rarer than the marketing use of it suggests. There is no USB data connection, no Bluetooth and no network radio. The device has its own screen and camera, and everything moves in and out of it by displaying and scanning QR codes with a phone. Whatever is wrong with your computer, and whatever is wrong with the cable, none of it reaches the keys — because there is no path for it to travel down. The body is sealed metal with anti-tamper protection that wipes the device if it is opened, and the current Titan carries a CC EAL5+ secure element.

The main criticism is straightforward and it is not about any of that: the firmware is closed source. You cannot read it, and neither can an independent researcher with no stake in the answer. That is a real difference from Trezor or Blockstream Jade, where the code is public and has been picked over by people who would gain from finding a flaw. ELLIPAL's position is that isolation matters more than auditability, and it is not a stupid argument — an attack has to reach the device before code quality is relevant, and the air gap is a genuinely strong barrier. It is still their argument, about their own product, and independent review exists precisely so that you do not have to weigh a manufacturer's self-assessment. Weigh it how you like, but weigh it knowingly.

What substantially reduces the risk of that is the one detail worth understanding about any wallet: it uses standard BIP39. The recovery phrase is not proprietary and the device is not the asset. If ELLIPAL stopped existing tomorrow, or the app broke, or you simply wanted to leave, those words restore into any compatible wallet from any manufacturer. That is what makes the closed-source question a matter of degree rather than a trap — you are trusting the firmware while the coins sit there, but you are not trusting the company with your ability to ever get them back. Not every device in this category is so clean about it, and it is the first thing to check about any of them.

A note from actually owning one, since it is the reason this site exists at all. The wallet I use is an ELLIPAL, and I have been through a recovery — not because the device failed, but because a phrase written down once by hand, calmly, with no sense of occasion, turned out months later not to be quite what I believed it was. Word order that had shifted. A letter that could honestly be read two ways. A passphrase remembered almost correctly. Any one of those is enough to lock you out completely, and not one of them is the wallet's fault. It took purpose-built software and a great deal of patience to get back in, and not all of it came back.

So the practical advice here is not about ELLIPAL, and it applies to every device on this page. Write the phrase in block capitals and number the words, because word order is the failure nobody expects. Restore it onto the device before you put anything meaningful on it, so you find out that the backup works while it still does not matter. If you use a passphrase, record it with exactly the same rigour as the seed rather than trusting yourself to remember it — the passphrase is where confidence outruns memory. And consider steel rather than paper, because the phrase has to survive not just a fire but a decade of you being certain you would recognise your own handwriting. The five ways people actually lose crypto covers the rest of the list, and what to do when you have lost access covers the part I had to find out the hard way.

Buy it from the manufacturer, never a marketplace. An air-gapped device bought second-hand or from a reseller can arrive pre-initialised with a phrase somebody else already has, and the air gap does nothing about that whatsoever. It is generic advice, it applies to every hardware wallet, and it is skipped often enough to be worth the sentence.

Who it suits. Someone who wants the strongest practical isolation available and is comfortable trusting a manufacturer's own account of code they cannot read. Someone whose priority is independently verifiable security should look at an open-source device instead — that is a real trade-off rather than a ranking, and the honest answer is that the two camps are optimising for different threats.

Good for

  • Genuinely air-gapped — no cable, no radio
  • Sealed body with anti-tamper protection
  • Standard BIP39, so you are not locked in
  • A big screen makes address checks easy

Watch out for

  • The firmware is closed source
  • You trust the company, not an audit
  • The companion app is proprietary too
  • Air-gapped does not mean un-loseable

Visit ELLIPAL → Commercial link

This listing is our own opinion. We are not affiliated with ELLIPAL beyond any commercial relationship disclosed above, we never take custody of your assets, and nothing here is financial advice. Verify anything that matters against the company's own site before acting on it.