What is Ellipal?
Ellipal builds the Titan, a cold-storage device that takes air-gapping to an extreme. It has no USB data port, no Wi-Fi and no Bluetooth for signing; every transaction is exchanged as a QR code between the device and the Ellipal app. The unit is a fully sealed metal body designed to resist physical tampering, with an anti-tamper mechanism intended to wipe keys if the case is breached.
How does it score here?
Ellipal lands in the middle of our hardware-wallet category. We assess maker longevity and companion-service reliability rather than opening the device. Our records give it a multi-year track record, and its companion site responded reasonably (around 243 ms) in our checks. The absence of a dedicated public status page keeps it from scoring higher.
What is distinctive?
- Complete air-gap: no cable, Wi-Fi or Bluetooth is used for signing, only QR codes.
- A sealed metal enclosure with an anti-tamper self-wipe design.
- A colour touchscreen for reviewing transactions before approval.
What are the trade-offs?
The firmware is proprietary, so it cannot be independently audited like open-source alternatives. QR-only signing is slower than a cable for frequent use, and the sealed design means the battery is not user-serviceable. Always review transaction details on the device screen before approving, since the companion app is still part of the flow and a compromised host could present misleading information.
What kind of threat does it address?
Ellipal's design is aimed at users who worry most about physical and network-level attacks: by removing every wired and wireless data path and sealing the case, it narrows the ways an attacker could reach the keys without you noticing. That is a coherent philosophy, and the anti-tamper wipe is a genuine differentiator. The cost is flexibility and openness, since a fully sealed, proprietary device gives you less ability to inspect, repair or extend it, and the QR-only flow trades some speed for that stronger separation.
Who is it for?
Ellipal suits users who prioritise a hard physical air-gap and anti-tamper hardware, and who do not mind proprietary firmware. It is less suited to open-source advocates or those wanting a maker-run status page.