The hardware wallet market is crowded with devices like Ledger and Trezor, but Ellipal aims to stand out with a radical approach: a cold wallet that never touches the internet. The Hong Kong-based company's "The Cold Wallet 2.0" promises the same functionality as its competitors but with an air-gapped design. Instead of connecting via USB or Bluetooth, it uses QR codes to sign transactions through a companion smartphone app.
Unboxing and Build
The packaging is reminiscent of the Ledger Nano S, complete with a tamper-proof seal. Inside, however, the device looks nothing like a USB stick. It resembles a cheap smartphone – plasticky, lightweight, with a thick bezel and a color touchscreen. While it might feel like a child's toy, the build quality is intentionally basic: a Gorilla Glass screen would only add a few hundred dollars to the $149 price tag without improving security or UX. As a cold wallet, it is meant to stay hidden away, not to be flaunted.
Setup and Seed Phrase
After inserting the battery and pressing the side button, users choose a language and create a new wallet for BTC, BCH, ETH, or ERC20 tokens. An account name and a password (capped at 12 characters) are required. Then the device displays a 12-word mnemonic seed for backup. Users must write it down and then verify it by placing the words in the correct order. The reviewer notes that the 12-character password limit seems odd but not a major security concern. A tip is provided: obfuscate the seed slightly by changing one letter or reversing the last two words to thwart physical attackers.
QR Code Transaction Flow
The core innovation of the Ellipal is the QR code bridge. The cold wallet never connects to the internet; instead, it communicates with the Ellipal app on a smartphone. To pair, scan a QR code displayed on the cold wallet with the phone app. To send a transaction: create the transaction in the app – the app generates an unsigned QR code. Scan that with the cold wallet – the cold wallet signs it and displays a signed QR code. Finally, scan the signed code with the phone app, which broadcasts the transaction. Although it involves multiple scans, the process works smoothly in practice. It is a fair trade-off between security and convenience. Users could also opt to store coins directly in the smartphone app, but that undermines the reason for buying the hardware.
Security Assessment
Ellipal's air-gapped approach eliminates most remote attack vectors. However, a theoretical vulnerability exists if the smartphone app is compromised and generates a fraudulent QR code instructing the cold wallet to send funds to an attacker. Such an attack would require a highly sophisticated and targeted operation. Overall, the Ellipal Cold Wallet 2.0 scores well for security, though its user experience is not as refined as market leaders. It is open-source and offers an affiliate program for those with social reach.
Conclusion
The Ellipal Cold Wallet 2.0 is a well-priced addition to the hardware wallet market, distinguished by its original take on cold storage. For users who prioritize maximum security and are willing to accept a slightly less polished UX, it is a compelling option.

