ELLIPAL sells a vault that does not plug in: QR in both directions, metal chassis, battery. The pitch is easy to understand for a non-technician: “it never touches the computer”. That is true for a class of attacks (USB malware, HID, cable impostors).
The firmware does not have the audit culture of Trezor or Coldcard. Multi-coin thickens the code. The battery and touchscreen are physical surfaces. Air-gap is not synonymous with open source, nor with an SE audited like a Safe 7.
Useful if your main threat is an infected PC and you want multi-coin without USB. Insufficient if your main threat is the manufacturer or auditability.
Fits if
Multi-coin air-gap, users who want “no USB” without tinkering.
Keep in mind
Less firmware transparency. Battery. Less “hardcore” community track record.
Related incidents
- 2018– — Clones and marketplaces
The first security ritual is commercial: who sold you the object, and what does attestation say on first plug-in?