Buy now

The ELLIPAL wallet makes the strictest version of a promise that every cold storage device makes in some form. Where most hardware wallets remove some connections and keep others, ELLIPAL removes all of them: no Bluetooth, no Wi-Fi, no NFC, and a USB port wired for charging with the data lines disabled. The device talks to your phone by showing a QR code on its screen and reading one back through its camera.

It is a clean idea, and it closes off an entire category of attack. Understanding what it leaves open is the harder and more useful half of the question.

What ELLIPAL is

The current flagship is the Titan 2.0, a touchscreen device in a sealed metal body. ELLIPAL lists a CC EAL5+ secure chip, an anti-tamper mechanism that wipes the device if someone opens or physically interferes with it, and support for a very wide asset list running into the thousands. Firmware updates arrive by SD card rather than over a cable, which keeps the air gap intact through the one process that would otherwise need a connection.

The signing flow follows from the design. Your phone builds an unsigned transaction and renders it as a QR code, the device reads that code with its camera, you approve on the device screen, and the signed result goes back to the phone as another QR code. Your private key never travels over a radio, because the device has no radio to travel over.

The research that complicated the picture

In 2019, the Donjon, Ledger's in-house security research team, published a teardown of an ELLIPAL device and reported several vulnerabilities. Some of them let an attacker re-activate the communication interfaces the air-gap depends on being absent, which opens the door to supply chain tampering or an evil maid attack on a device left unattended. One finding was more severe: with hands-on access to the hardware, a researcher could extract the seed from the device.

The specifics are worth knowing because they are architectural rather than incidental. Underneath the enclosure sat a MediaTek MT6580, a system-on-chip designed for low-cost smartphones, with an active debug interface on the board's underside that printed boot information and accepted commands. Firmware archives were encrypted in ECB mode with a 64-bit block cipher, weak enough that the team started a brute-force run against it.

Two pieces of context belong alongside that. Ledger sells competing products, so the research has an interested author, though the technique is documented in enough detail that anyone with the equipment can check it. More importantly, the work was disclosed responsibly, ELLIPAL shipped an update in response, and the exchange between the two companies is recorded in the post with an amendment dated 11 July 2019. The hardware on sale now is a later generation with a certified secure chip that the teardown device did not have.

So the fair reading is that a specific set of flaws was found and fixed some years ago, and that the episode is evidence about how the product was engineered at the time rather than proof of a current hole.

What air-gapping covers

Cutting every radio removes remote attack as a category. Nobody pairs with the device over Bluetooth, nobody reaches it through a compromised driver on your laptop, and a drainer in your browser cannot negotiate with hardware that has no channel to your browser. For anyone whose mental model of theft is a stranger on the internet, that is most of the threat handled.

It also makes the trust boundary easy to describe, which matters more than it sounds. You can explain a QR code to a person who does not work in security, and they can see with their own eyes that nothing is transmitting.

What it doesn't cover

Air-gapping says nothing about what you approve. A QR code carries a transaction the same way a cable would, and if the request encoded in it sends your balance to an address you did not intend, a device with no radios will sign it as obediently as a device with three. The defence there is the screen: reading the destination and the amount on the device before you confirm, every time, including the times you are in a hurry.

It also says nothing about someone holding the device. The anti-tamper wipe exists precisely because a sealed box in a stranger's hands is a different problem from a sealed box on your shelf, and the Donjon work is a demonstration that hands-on attacks belong in the threat model rather than outside it.

Nor does it cover the failure that empties more wallets than any hardware flaw. If you are tricked into typing your recovery words into a convincing screen, every property of the device becomes irrelevant, because the attacker no longer needs the device at all.

Backup is where the model stops helping

Whatever the signing architecture, ELLIPAL hands you a recovery phrase and the rest is yours to solve. That is true of nearly every hardware wallet on the market, and it is the part of the design that has barely moved in a decade.

Writing the words on paper leaves one sheet that has to stay secret and intact for as long as you hold crypto, and a house move or a helpful relative tidying a drawer is enough to end it. Stamping them into steel is the usual next step, which fixes durability and leaves the secrecy problem exactly where it was, since a plate that someone finds is a wallet that someone drains. ELLIPAL sells a steel plate of its own, and it inherits the same limit every plate has.

We built TapSafe Recovery to change the shape of that arrangement rather than the material it is made from. Access is split across pieces: your Recovery Tag carries half, your paired phone carries the other half encrypted into your own iCloud or Google Drive rather than sitting on the handset, and optional Recovery Contacts hold a quarter each while learning nothing about your holdings. Because no single piece opens anything alone, no single piece has to survive everything. Your seed phrase remains available on the device as a last resort and meets the BIP-39 standard, so you are never tied to our hardware.

How Ryder One compares

We should be precise rather than flattering here. The Ryder One is not air-gapped in ELLIPAL's sense, because it communicates over NFC. That is a deliberate trade: NFC works at a range of a few centimetres and requires you to physically tap the device against your phone, which we think buys most of the isolation benefit while keeping the experience close to tapping a bank card.

On the parts that are comparable, keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave the chip, the firmware was independently audited by Halborn with the full report public, and every transaction is shown in readable detail on the 1.6-inch screen before you approve it. The button that signs is wired directly to the secure element, so no software path can approve a transaction without a press. At 149 USD for the Starter Combo it also sits below the air-gapped devices it competes with, though price is the least interesting thing on this list.

If you are weighing ELLIPAL, weigh it on the right axis. The QR-only design is a legitimate answer to remote attack and it works. What it does not answer is what happens to your backup, and that is the question that decides whether a bad week costs you an afternoon or costs you everything. Get your Ryder One.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More