In June 2019, at the Breaking Bitcoin conference in Amsterdam, Ledger's security research team stood up and explained how it had extracted the seed phrase from an ELLIPAL hardware wallet. The device marketed as air-gapped turned out, under analysis, to be an Android phone whose interfaces were locked only by software.
What happened next is the reason ELLIPAL is still worth writing about seven years later. The company did not dispute the findings, did not question the researchers' motives, and did not go quiet. It paid them a bounty, credited them publicly, created a bug bounty programme it had not previously had, pulled a marketing image after admitting it was inaccurate, and redesigned the hardware around a chipset that physically cannot connect to a network.
In October 2025, a retired man in North Carolina lost 1.2 million XRP, worth about 3.05 million dollars, from an ELLIPAL wallet. ELLIPAL said he had imported his seed phrase into its mobile app, turning a cold wallet into a hot one. Independent analysis agreed there was no evidence the hardware had failed. Three weeks later, ELLIPAL shut down its entire hot wallet business.
Both of those stories are true, and an honest review has to hold them together.
The company
ELLIPAL Limited is based in Hong Kong. The name is a contraction of "Elliptic Curve Cryptography" and "Pal", meaning partner or friend. [1][2][3]
The founding year is genuinely unclear. Tracxn, Crunchbase and the company's own LinkedIn page say 2017. ELLIPAL's own five-year recap, its 2026 press materials and Gate's company profile say 2018. The most likely reading is incorporation in 2017 with the first product reaching customers in 2018, and that is how this review states it. [1][3][4][5][6][7]
The founders are consistently identified as David Tian and Tong Chen, and ELLIPAL's own anniversary post credits "David and Tong". Databases disagree on which of the two currently holds the chief executive role, so this review does not name one. [1][2][4][6][8][9]
The first product was funded on Indiegogo in autumn 2018, raising roughly 55,168 dollars against a 10,000 dollar goal. [2][3]
This is a small company, and the article should not pretend otherwise. Total funding raised is reported as anywhere between 1.46 and 2.46 million dollars, with a further seed round recorded in May 2026. Headcount is given as 14 by PitchBook, 26 by Tracxn and 11 to 50 on LinkedIn. For comparison, that is a fraction of the scale of Ledger or Trezor. [1][8][10][11]
ELLIPAL states it serves over one million users across more than 140 countries. That figure is self-reported. [7][12]
The product line
| Product | Type | Secure element | Price |
|---|---|---|---|
| Titan 2.0 | Air-gapped QR, 4-inch touchscreen, sealed metal body | CC EAL5+ | 149 dollars on the official store, 169 in most reviews |
| Titan Mini | Smaller, runs without the Android layer | CC EAL5+ | Lower |
| X Card | NFC card, tap to phone | CC EAL6+ | About 69 dollars |
| Joy | Open-source seed phrase generator | - | - |
| Mnemonic Metal | Steel seed backup | - | - |
[13][14][15][16][17][18]
The Titan 2.0 measures roughly 118 by 66 by 9.7 mm and weighs about 135 to 140 grams. It has a 4-inch IPS colour touchscreen, a fully sealed aluminium alloy unibody, and no ports whatsoever. Charging works through a magnetic contact and a separate "Security Adapter" that also holds the microSD slot used for offline firmware updates. It carries IP65 dust and water resistance and launched on 6 November 2023. [16][19][20]
Two details in that table deserve attention.
First, the Titan Mini runs without the Android layer, and at least one security-focused review treats that as a genuine advantage rather than a downgrade. A smaller firmware surface means a smaller attack surface. Buyers who assume the bigger device is automatically the safer one have it backwards on that specific axis. [3]
Second, the 69 dollar X Card carries a higher-grade secure element than the flagship. EAL6+ against the Titan's EAL5+. The X Card generates its seed offline on a Starter device, gates every signature behind a PIN, and follows the BIP39 standard. Compactness does not imply weaker silicon here. [14][15][21]
Security architecture
The Titan is air-gapped in the strictest sense available on the consumer market. There is no USB data connection, no Bluetooth, no Wi-Fi, no NFC and no cellular capability. Every transaction moves by QR code between the device's camera and the phone app, and firmware updates arrive by microSD card in one direction only. [13][16][19][22]
The physical defences are the strongest in the category. The metal unibody cannot be opened without permanent damage, and internal sensors trigger a full wipe of keys and seed data if a breach is detected. That is the defence against the "evil maid" scenario, where someone has brief physical access to your device while you are elsewhere. [16][17][19]
The 2.0 generation introduced a CC EAL5+ certified secure element in the Titan and Titan Mini. Keys are generated and stored inside the chip and cryptographic operations run internally. ELLIPAL states seed generation uses a hardware true random number generator with no software fallback. [12][16][17][19]
Access control combines a numeric password with a gesture pattern lock, with the device wiping itself after repeated failures. Passphrase support creates hidden accounts, and the device holds up to five seeds plus five passphrase accounts. [17][20][23]
Recovery follows BIP39 with 12 or 24 words, so your seed restores on any compatible wallet and your funds do not depend on ELLIPAL continuing to exist. The device also supports private key import and offline sweeping of paper wallets, which is uncommon and can rescue assets sent to a wrong but compatible address format. [16][22]
Three real limitations belong here rather than buried at the end. You cannot export your own extended public key. Multisignature is not supported. And the wallet does not generate a fresh address for every Bitcoin transaction, which is a meaningful privacy weakness for anyone who cares about chain analysis. Swapping, buying and staking cover a smaller subset of assets than the total the device supports. [17]
Open source, and what you are being asked to trust
ELLIPAL is largely closed source. What is published on GitHub amounts to the QR code data format and the firmware update mechanism, both of which the company argues can therefore be independently checked to confirm the device is not signing transactions other than the ones you approve. The device firmware, the secure element implementation and most of the app are closed. [12][22][23]
No public third-party security audit of the Titan 2.0 could be found. One review states this directly. Another notes ELLIPAL has expressed interest in commissioning an audit from a firm such as CertiK or SolidProof, but no such report has been published. [12][23]
ELLIPAL has argued publicly against full open source on the grounds that publishing code helps attackers as much as defenders. That is a defensible position, held by Ledger too, and it deserves to be presented as a position rather than a failing. But the consequence is concrete: the key-generation firmware, the chip's single most sensitive job, cannot be independently audited by anyone outside the company. [22][24]
Placed against its direct rivals, that puts ELLIPAL roughly level with NGRAVE and Tangem on transparency, clearly behind Keystone and Trezor, and marginally behind SafePal, which at least opened the firmware on its X1 model. Combined with the absence of a published audit, the Titan asks for more trust than any open competitor at the same price.
2019: what Ledger Donjon found, and what ELLIPAL did about it
This episode is documented from both sides, which is rare enough to be worth reporting in detail.
Ledger's Donjon team evaluated the original ELLIPAL EC01 and presented its findings at Breaking Bitcoin in Amsterdam in June 2019, alongside vulnerabilities in the Trezor One, Trezor T, KeepKey and the HTC Exodus phone. [25][26]
Donjon's own account of what it found:
- The analysis revealed the device was in fact an Android phone, with its interfaces locked only by the Android software stack
- Several vulnerabilities allowed an attacker to re-activate the communication interfaces and backdoor the device, enabling supply chain or evil maid attacks
- One vulnerability was critical: it allowed an attacker with physical access to extract the seed [25]
French coverage of the same presentation adds a detail worth stating plainly. For ELLIPAL, Trezor One, Trezor T and KeepKey alike, key extraction required physical access but was relatively fast and needed only around 100 dollars of equipment. This was not a laboratory curiosity requiring a quarter of a million dollars in lasers. [26]
ELLIPAL's response is the part that stands out. Donjon's own write-up records that ELLIPAL took the findings very seriously, that the exchanges between the two teams were productive, that the report triggered the creation of ELLIPAL's bug bounty programme, that ELLIPAL issued an upgrade, credited Donjon publicly and paid a bounty. ELLIPAL also removed a marketing image after acknowledging it was inaccurate. [25][24]
ELLIPAL then published its own account of the study and used it to justify a hardware redesign: a new Allwinner A64 chipset with no 4G, Bluetooth or Wi-Fi capability at all, and removal of the USB port in favour of a contact charging port, so the device physically cannot connect to another machine. [24]
The necessary caveat comes from Donjon in one parenthesis: "They emitted an upgrade (we didn't check the upgrade)." No independent verification of the fixes has ever been published, and a 2025 security review makes the same point. The redesign is plausible and well documented. It has simply never been re-tested by the people who broke the original. [25][3]
October 2025: three million dollars, and a colour scheme
On 12 October 2025, 1.2 million XRP worth roughly 3.05 million dollars was drained from an ELLIPAL wallet belonging to Brandon LaRoque, a 54-year-old retiree from North Carolina. He discovered it on 15 October. The pattern was two 10-XRP test transfers followed by a sweep of about 1,209,990 XRP to a newly created address, then fan-out across dozens and eventually hundreds of wallets. He said it represented almost his entire retirement savings, accumulated since 2017. [27][28][29]
The blockchain investigator ZachXBT traced the funds. The attacker executed over 120 Ripple-to-Tron swaps through Bridgers, formerly SWFT, consolidated the proceeds on Tron, and by 15 October the entire amount had been laundered through over-the-counter desks linked to Huione, a Southeast Asian marketplace under United States sanctions. Elliptic has reported that Huione Guarantee and its merchant network received over 27 billion dollars in crypto since 2021. [27][30][31]
ELLIPAL's explanation, published on 18 October, was that its review indicated the user had imported the hardware wallet's seed phrase into the ELLIPAL mobile app. Doing that recreates the wallet on an internet-connected device and turns it into a hot wallet. LaRoque said his iPhone app displayed a blue background and his iPad an orange one, and that ELLIPAL told him blue denotes a cold wallet connection while orange indicates a hot wallet. ELLIPAL stated its hardware devices are air-gapped and that it has not seen thefts originating from the hardware itself. [28][29][32]
ZachXBT agreed there was no evidence of a technical failure in the ELLIPAL hardware, describing it as a user configuration error. He used the case to make a broader point: the victim believed he was using a cold wallet when he was operating a hot one, and that confusion between product types is an industry-wide problem that enables large thefts. He added that he believes self-custody is not the right answer for the vast majority of people. [27][30]
CoinDesk noted that it had not independently verified the investor's identity, balances or the complete on-chain path, and that ELLIPAL's account points to user error but does not by itself prove it. [29]
Then came the part that complicates the clean explanation. Within roughly two weeks, ELLIPAL announced it was shutting down all hot wallet services, with 31 October 2025 as the final date, and redirecting all engineering and support resources to cold storage. Users were told to withdraw funds from the ELLIPAL mobile wallet before the deadline. [33][34]
And Trustpilot reviews from the same period describe other losses. One reviewer reports 1,009 XRP stolen on 23 October 2025, says ELLIPAL support told them to report it to the police, and notes the hot wallet shutdown was announced days later. Others report discovering the shutdown late and hitting network errors while trying to migrate to a cold wallet before the deadline. ELLIPAL responded publicly that blockchain transactions are irreversible and that as a decentralised wallet it cannot retrieve assets, but would cooperate with police. [35]
The fair conclusion is narrower than either side's framing. There is no evidence the Titan's silicon was compromised, and the person who traced the money says so explicitly. But a product design that placed a hot wallet and a cold wallet behind the same app, distinguished largely by a background colour, produced user confusion; more than one user reported losses; and the company discontinued the entire hot wallet product within three weeks. That is a design and communication failure even when the hardware holds.
Assets, app and everyday use
ELLIPAL supports over 10,000 tokens across roughly 40 to 50 blockchains, with 2026 firmware adding Near and Filecoin. The app handles buying, selling, swapping, staking on a subset of assets, and dApp access through WalletConnect. A MetaMask partnership was announced in 2023. [17][18][20][22]
The ecosystem is mobile-first and proprietary. There is no meaningful desktop workflow, and third-party wallet integration is thin compared with Keystone, which pairs with MetaMask, Sparrow, Rabby, BlueWallet and dozens more. One reviewer names the practical consequence: if ELLIPAL disappeared tomorrow, interacting with your funds through Electrum or MetaMask would be harder than with a more standardised wallet, though the BIP39 seed itself remains portable. [13][23]
The recurring day-to-day complaints are consistent across reviews and user reports: the dual QR scanning workflow is slow, firmware updates by microSD are cumbersome, the device is large and heavy at around 140 grams, and multiple users report camera focus and QR scanning failures. Older packages did not include the microSD card needed for updates. [3][20][23][36]
Buying one in Greece
ELLIPAL ships worldwide from Hong Kong. [2][6]
That matters more than the sticker price suggests. Because shipments originate outside the European Union, import VAT and customs handling apply, unlike Trezor shipping from the Czech Republic or NGRAVE from Belgium. A 2019 reviewer documented his device being opened by customs, with the tamper seals intact but the packaging disturbed. For a security product where the unopened seal is part of the trust model, knowing that in advance matters. Check the landed cost at checkout, not the advertised price. [2]
ELLIPAL was advertising discounts of up to 50 percent in a summer promotion at the time of research, which explains part of the price spread across sources. [12]
Buy from the official store or an authorised reseller. Never from a general marketplace listing or a second-hand seller.
Credibility
Trustpilot captures give 3.9 out of 5 from 196 reviews at one point and a 4-star rating from 251 reviews at another. The rating period matters enormously here, because the hot wallet shutdown and the reported thefts fall inside it. [23][35]
Positive themes are consistent: build quality, the sealed metal body, the large screen, the air-gapped design, and support responsiveness. Negative themes are equally consistent: delivery delays, defective SD cards included in the box, the hot wallet shutdown and migration difficulties, camera and scanning problems, and losses from the discontinued hot wallet product. [3][35][36]
To ELLIPAL's credit, the company replies publicly to negative Trustpilot reviews, including hostile ones. [35]
How it compares
| Wallet | Air-gapped | Secure element | Firmware open | Public audit | Price |
|---|---|---|---|---|---|
| ELLIPAL Titan 2.0 | Yes, QR | EAL5+ | No, QR logic only | None found | 149 to 169 dollars |
| ELLIPAL X Card | NFC tap | EAL6+ | No | None found | About 69 dollars |
| Keystone 3 Pro | Yes, QR and microSD | Three chips | Yes, MCU blob excepted | Yes, published | 129 to 169 dollars |
| SafePal S1 | Yes, QR | One | Partial | Kraken, 2021 | About 50 dollars |
| NGRAVE ZERO | Yes, QR | EAL5+ with EAL7 OS | No | Donjon, 2026 | About 398 dollars |
| Trezor Safe 5 | No, USB | EAL6+ | Yes | Yes | About 129 dollars |
| Tangem | No, NFC | EAL6+ | No | Donjon, three times | About 55 dollars |
| Foundation Passport | Yes, QR | Yes | Yes | Yes | About 199 dollars |
[3][13][14][23]
ELLIPAL has the most physically hardened body in the category and one of the strictest air gaps available. At the same price, however, the Keystone 3 Pro offers the same air gap plus published audit reports, partially open firmware, three secure elements, a fingerprint sensor and far broader third-party wallet support. Multiple independent reviews reach the same verdict, that the Trezor Safe 5 or the Keystone is the better overall value at the Titan's price point.
ELLIPAL's genuine niche is narrow but real: the buyer who ranks physical attack resistance above every other consideration and touches the device a few times a month.
The risks, stated plainly
- Import VAT and customs. Shipping from Hong Kong, not from inside the EU. Budget for the landed cost.
- No published third-party audit of the current device, and closed key-generation firmware.
- The 2019 fixes were never independently verified. Donjon said so in its own write-up.
- The hot wallet history. The product that caused the losses is gone, but it shows how the company handled a design that confused its own users.
- Never import your seed phrase into any phone app. ELLIPAL's own case is the proof. This applies to every wallet, not just this one.
- No extended public key export, no multisignature, no Bitcoin address rotation.
- Proprietary mobile ecosystem with thin desktop and third-party support.
- Small company, somewhere between 14 and 26 employees, with modest funding.
- QR workflow friction makes this a storage device rather than a trading device.
What we could not verify
Deliberately absent from the above, because public sources did not support it: the exact founding year, which founder currently holds the chief executive role, total funding raised, current headcount, revenue and profitability, the "Top 3 Cold Wallet" ranking ELLIPAL cites, whether the bug bounty programme is still active, whether any third-party audit of the Titan 2.0 exists, how many users in total lost funds through the discontinued hot wallet, and Greek pricing, delivery times, warranty length and RMA handling.
Frequently asked questions
Has ELLIPAL ever been hacked? A competitor's security lab extracted the seed from the original 2018 device with physical access, and ELLIPAL redesigned the hardware in response. No remote compromise of ELLIPAL hardware has been documented. The 2025 loss of 3.05 million dollars was attributed to a seed imported into the mobile app, not to the hardware, and the investigator who traced the funds agreed.
Is the Titan 2.0 or the X Card more secure? The X Card actually carries the higher-grade secure element, EAL6+ against the Titan's EAL5+. The Titan wins on physical hardening and screen size for verifying transactions. They serve different purposes: the Titan as a vault, the X Card for daily carry.
Can I still use the ELLIPAL app as a hot wallet? No. ELLIPAL shut down all hot wallet services on 31 October 2025 and now focuses exclusively on cold storage.
Is my money safe if ELLIPAL goes out of business? Your seed follows the BIP39 standard, so it restores on any compatible wallet. You would lose the convenience of the ELLIPAL app, not the funds.
Should I buy it in Greece? It ships to Greece, but from Hong Kong, so expect import VAT and possible customs inspection. At the same price a Keystone 3 Pro or Trezor Safe 5 gives you published audits and open firmware, which is why most independent reviews prefer them.
What is the single most important thing to remember? Never type your hardware wallet seed phrase into a phone or computer. Not into the manufacturer's own app, not anywhere. That one act converts cold storage into a hot wallet, and it is what cost one retiree his life savings.
Sources
All accessed 19 August 2026.
- Tracxn, ELLIPAL company profile, Aug 2026
- Dan Okopnyi via Medium, "Ellipal Wallet review", 2019
- Bytwork, "Ellipal Wallets: A Critical Security Review", Nov 2025
- Moj Kripto, "Ellipal Titan, The Coldest Crypto Wallet"
- Gate Learn, "What Is Ellipal Wallet?", Apr 2026
- ELLIPAL, "ELLIPAL Five Year Recap"
- MEXC News, "ELLIPAL Joins Hong Kong Web3 Festival 2026", Jan 2026
- RocketReach, ELLIPAL company information
- ZoomInfo, Ellipal overview
- PitchBook, Ellipal company profile
- The Company Check, ELLIPAL profile
- ELLIPAL official store, ellipal.com
- bitcoins.tools, "ELLIPAL Titan 2.0 Review 2026"
- Webopedia, "ELLIPAL Wallet Review 2026", Mar 2026
- ELLIPAL, "ELLIPAL X Card Review 2026" (vendor-published)
- Coin Bureau, "ELLIPAL Titan 2.0 Review", Apr 2026
- ICOBench, "Ellipal Wallet Review"
- Cryptoscobra, "Ellipal Titan 2.0 Review 2026", Apr 2026
- hardware-wallets.net, "ELLIPAL Titan 2.0 Review"
- Aldaron Crypto, "Ellipal Titan 2.0 Review", Nov 2025
- ExchangeSelector, "ELLIPAL X Card Review", Jun 2026
- Coinspot.io, "ELLIPAL Titan 2.0 Review", Nov 2025
- CryptoSlate, "Ellipal Titan 2.0 Review 2026: Fully Air-Gapped, Partly Closed", updated Jul 2026
- ELLIPAL, "Ledger-Donjon Vulnerability Study and The Development of The ELLIPAL Titan", Dec 2019
- Ledger Donjon, "Extracting seed from Ellipal wallet", ledger.com/blog/ellipal-security
- Bitcoin.fr, "Ledger Donjon révèle des vulnérabilités critiques sur plusieurs hardware wallets", Jun 2019
- CryptoNews, "Ellipal Hardware Wallet Hacked, User Loses $3M in XRP to Sanctioned Launderers", 20 Oct 2025
- FinanceFeeds, "U.S. Retiree Loses $3M in XRP After Ellipal Wallet Hack", Oct 2025
- CoinDesk, "XRP Investor Says $3M in XRP Was Stolen; Cold Wallet Maker Says Seed Import Made Wallet Hot", 19 Oct 2025
- ZachXBT, X thread, 19 Oct 2025
- CryptoTimes, "U.S. Investor Loses $3M in XRP Hack Through Huione Laundering", Oct 2025
- CoinCentral, "XRP Theft Claims Spark Online Investigation", Oct 2025
- Analytics Insight, "Ellipal Shuts Hot Wallets After $3M XRP Breach", Oct 2025
- CryptoNews.net, "A Cryptocurrency Wallet is Ceasing Operations", Oct 2025
- Trustpilot, ellipal.com reviews, page 2
- hardwarewallets.net, "My ELLIPAL Titan 2.0 Review", Aug 2026
Πληροφοριακό υλικό μόνο. Δεν αποτελεί επενδυτική συμβουλή. Η αγορά κρυπτονομισμάτων ενέχει υψηλό κίνδυνο.
Information only. Not investment advice. Cryptocurrency markets carry substantial risk.