Skip to content
Crypto Almanac Daily
E
Hardware Wallets

Ellipal

Best for documentation-led evaluation

Firmware repository:Not identified at this checkSecurity or spec page:Not identifiedDocumentation:Not identifiedVendor:EllipalRubric:v2.0 · verified 9 Aug 2026
Last verified August 9, 2026
Confidence CRubric v2.0Verified August 9, 2026
2.2
out of 10
Open account
Scorecard

How it rates

Key security & openness · 40%0.0
Purchase transparency · 10%6.0
Product openness · 20%0.0
Vendor transparency · 20%6.0
Public documentation surface · 10%4.0
Pros
  • Tracked and verifiable from public sources at this check
Cons
  • No public firmware repository identified at this check
  • No dedicated security or audit disclosure identified at this check
  • Terms page not found at the conventional address at this check
How this score was built

Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.

Key security & openness · 40% weight0/10 points · 0.0/10
  • Not met
    Firmware source published in a public repository

    No public firmware repository identified at this check.

  • Not met
    Device security or specification page published

    No dedicated security or specification page identified at this check.

  • Not met
    Independent security research or audit programme published

    No published security research or audit programme identified at this check.

  • Not met
    Technical documentation reachable without an account

    No open technical documentation identified at this check.

  • Not met
    Vendor organisation identifiable from the repository

    Not established at this check.

Purchase transparency · 10% weight6/10 points · 6.0/10
  • Met
    Shop or purchase page public

    Reachable without an account at this check.

    www.ellipal.com/
  • Not met
    Model-specific product page public

    Not identified at this check.

  • Not met
    Legal or terms page public

    Not found at the conventional address at this check.

  • Met
    Support or help resource public

    Reachable at this check.

    www.ellipal.com/
  • Met
    Purchase information viewable without an account

    No account required to reach the shop at this check.

    www.ellipal.com/
Product openness · 20% weight0/10 points · 0.0/10
  • Not met
    Public repository organisation

    No public repository organisation identified.

  • Not met
    Firmware repository is the vendor's own

    Not established at this check.

  • Not met
    Model documentation published

    Not identified at this check.

  • Not met
    Documentation site separate from marketing

    Not identified at this check.

  • Not met
    Security posture stated publicly

    Not identified at this check.

Vendor transparency · 20% weight6/10 points · 6.0/10
  • Met
    Vendor site resolves to automated verification

    HTTP 2xx at this check.

    www.ellipal.com/
  • Met
    Vendor entity identifiable

    Vendor organisation identifiable as Ellipal.

    www.ellipal.com/
  • Not met
    Security or disclosure page published

    Not identified at this check.

  • Not met
    Terms or legal documentation published

    Not found at the conventional address at this check.

  • Met
    Product range documented publicly

    Product information published.

    www.ellipal.com/
Public documentation surface · 10% weight4/10 points · 4.0/10
  • Met
    Root site reachable without an account

    HTTP 2xx at this check.

    www.ellipal.com/
  • Not met
    Documentation or support reachable

    Not identified at this check.

  • Not met
    Public code repository reachable

    Not identified at this check.

  • Met
    Shop reachable

    HTTP 2xx at this check.

    www.ellipal.com/
  • Not met
    Legal documentation reachable

    Not found at the conventional address at this check.

A fully air-gapped metal wallet with a large touchscreen and tamper response, running proprietary firmware that cannot be independently audited.

Our assessment

Ellipal Titan 2.0 is a fully air-gapped metal wallet: QR-code signing only, no USB, Bluetooth, Wi-Fi or NFC, an EAL5+ secure element, a 4-inch touchscreen and an anti-tamper mechanism that wipes the device if the case is opened. It also scores lowest in this comparison, and the reason is worth stating precisely.

What the score measures

Seventeen of our twenty-five indicators returned nothing. No public firmware repository, no reachable security or specification page, no model documentation, no separate documentation site, no legal terms — the pages either did not exist at conventional addresses or blocked retrieval. Our rubric scores what a prospective buyer can verify before paying, and the answer here was almost nothing.

Closed firmware is the structural issue

Unlike Trezor or Blockstream Jade, the Titan's firmware is proprietary and cannot be independently audited. For a device whose entire proposition is that it never touches a network, an outsider has no way to confirm what the firmware does when nobody is watching. That is a design choice with a real cost, and it is the one this score is pointing at.

The hardware is not the complaint

Air-gapping, the tamper-response mechanism and the metal casing are genuine engineering, and at around $135 the large screen is competitive. Reviewers consistently note the workflow is slow — two devices, cameras lined up, scan out, scan back — and that the mobile app is the only companion, with no desktop option.

Who it suits

Ellipal fits buyers who value air-gapped hardware and a large touchscreen and are willing to take the firmware on trust. Anyone who wants to verify what they are buying should choose Trezor, BitBox, Foundation Passport, Coldcard or Blockstream Jade.

Alternatives

How rivals compare

ServiceScoreBest for
Trezor9.9verifiable firmware opennessRead →
Reference

Frequently asked

Does this score mean Ellipal is secure?

No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.

Why does firmware openness matter so much here?

It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.

What would raise this score?

Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.