The Ngrave Zero ($398, 2021) is a fully air-gapped multi-coin wallet: it has no data USB, Bluetooth, NFC or WiFi and signs only by scanning QR codes with its built-in camera. Its operating system is built on the Common Criteria EAL7-certified ProvenCore TEE (the secure element itself is an EAL5+ STSAFE-A100), and it adds a fingerprint sensor used in its proprietary "Perfect Key" seed generation plus the steel GRAPHENE backup. The main caveat is that the firmware is closed-source and fails WalletScrutiny’s reproducibility checks. It suits security-maximalist cold storage; users who prize open-source verifiability or fast everyday signing should look elsewhere.
The Zero’s headline is its operating system: the Common CriteriaEAL7-certified ProvenCoreTEE, the highest assurance level for a consumer device OS. Note the distinction — EAL7 applies to the operating system, while the discrete secure element is a customized STSAFE-A100 (EAL5+) on an STM32MP157C MPU with secure boot and non-extractable keys.
Being 100% air-gapped removes the remote attack surface entirely, and tamper-detection sensors wipe the device if it is opened. The significant caveat: the firmware is closed-source and does not provide reproducible builds, so its security must largely be taken on trust and certification rather than public verification.
SecurityKey Factor
The Zero generates a proprietary "Perfect Key" that combines device entropy with the biometric sensor, producing a standard 24-word BIP-39 seed under the hood. A BIP-39 passphrase and hidden wallets are supported; there is no Shamir Secret Sharing.
For physical backup, Ngrave sells GRAPHENE, a stainless-steel two-plate system (around $148, or bundled in a Combo Pack). The seed can also be written down as a normal 24-word phrase.
Recovery & backups
A large 4-inch color touchscreen and a fingerprint sensor make on-device verification and unlocking straightforward, and the IP55 metal body is durable. Initial setup takes around 20 minutes.
The trade-off is speed: every transaction is exchanged as QR codes between the device and the Ngrave Liquid app, which is slower and more deliberate than a USB or Bluetooth connection.
Usability / UX
The Zero is multi-coin, with native support for roughly 15 base networks (Bitcoin, Ethereum and ERC-20 tokens, Litecoin, Bitcoin Cash, Dogecoin, Dash) and 3,500+ assets in total. EVM dApp and smart-contract access is provided through MetaMask and Rabby integration rather than a built-in WalletConnect.
It pairs with the Ngrave Liquid app on mobile and desktop. Multisig support is basic and coordinated manually, which suits storage more than active multisig setups.
Ecosystem & integrations
The air-gapped design gives the Zero the strongest wireless posture of any wallet here: with no Bluetooth, NFC, WiFi or data USB, there is effectively no wireless attack or fingerprinting surface. No account registration is required and the device works fully offline.
The limit is verifiability: because the firmware is closed-source, its privacy and data-handling behavior cannot be independently audited the way an open-source wallet’s can.
Privacy
At $398 (more with the GRAPHENE backup) the Zero is among the most expensive consumer wallets. You are paying for the security posture, not openness:
Foundation Passport Prime ($349) — audited and open-source, but Bitcoin-first and not fully air-gapped.
Cypherock X1 ($159) — open-source and seedless, far cheaper, but USB-tethered.
Trezor Safe 7 ($249) — open-source with reproducible builds and a touchscreen.
The Zero is justified only if an EAL7 OS, biometrics and a total air-gap are your priorities.
Price & value
The Ngrave Zero is one of the most security-forward consumer wallets available: a fully air-gapped, biometric device with an EAL7-certified operating system and a steel backup. That posture comes at the cost of openness, price and convenience.
Buy this wallet if:
You want maximum-security cold storage with no wireless attack surface — QR-only signing, no USB data, Bluetooth, NFC or WiFi.
You value a biometric factor and a tamper-resistant, IP55 metal device, and want the steel GRAPHENE backup ecosystem.
You hold a long-term, multi-coin portfolio and rarely transact.
Look elsewhere if:
You require open-source, reproducible firmware you can independently verify.
You transact often and want fast signing, built-in WalletConnect or USB convenience.
You want a low-cost or pocket-portable device — the Zero is premium and bulkier than a USB key.
✓ Our Verdict
The Ngrave Zero is one of the most security-forward consumer wallets available: a fully air-gapped, biometric device with an EAL7-certified operating system and a steel backup. That posture comes at the cost of openness, price and convenience.
Buy this wallet if:
You want maximum-security cold storage with no wireless attack surface — QR-only signing, no USB data, Bluetooth, NFC or WiFi.
You value a biometric factor and a tamper-resistant, IP55 metal device, and want the steel GRAPHENE backup ecosystem.
You hold a long-term, multi-coin portfolio and rarely transact.
Look elsewhere if:
You require open-source, reproducible firmware you can independently verify.
You transact often and want fast signing, built-in WalletConnect or USB convenience.
You want a low-cost or pocket-portable device — the Zero is premium and bulkier than a USB key.
Ready to buyNgrave Zero?
We may earn a commission if you purchase through our links. This doesn't affect our editorial independence.
Impermanent loss happens when asset prices in a liquidity pool diverge from external markets, reducing the value of liquidity providers' holdings compared to simply holding the assets.
EAL Certification (Evaluation Assurance Level) from Common Criteria rates the security of hardware components, like secure chips in crypto hardware wallets. Higher levels, such as EAL5+ or EAL6+, indicate stronger resistance to attacks.
Secure Boot is a security feature that ensures only trusted software runs on a device by verifying its integrity during startup, preventing unauthorized code execution in crypto systems.
Non-extractable keys are private keys generated and stored within a hardware wallet that users cannot export or remove, protecting them from malware or physical attacks.
Reproducible Builds refer to the process where the same source code consistently produces identical binary outputs, ensuring verifiable and trustworthy software in blockchain and crypto projects.
BIP39 is a standard for generating mnemonic seed phrases that are used to create deterministic wallets and securely back up cryptocurrency private keys.
A passphrase is an additional security layer for cryptocurrency wallets, acting as a 25th word in the BIP39 seed phrase, protecting access to hidden wallets.
Shamir Secret Sharing (SSS) divides a secret, like a crypto wallet seed, into multiple shares. A threshold number of shares reconstructs it, enhancing security as in SLIP-39 backups.
A backup in cryptocurrency is a secure copy of a wallet's seed phrase or private keys. It enables recovery of funds if the original wallet is lost or damaged.
Firmware Attestation is the process of verifying the authenticity of a device's firmware to ensure it has not been tampered with, commonly used in hardware wallets for security.
UTXO (Unspent Transaction Output) is a unit of cryptocurrency from a previous transaction that remains unspent and serves as input for new transactions in blockchains like Bitcoin.
Bitcoin (BTC) is the first decentralized cryptocurrency, launched in 2009. It uses blockchain technology for secure, peer-to-peer digital transactions without intermediaries.
Ethereum is a decentralized blockchain platform that enables smart contracts and decentralized applications (dApps). Its native cryptocurrency is Ether (ETH).
Litecoin (LTC) is a peer-to-peer cryptocurrency forked from Bitcoin in 2011, offering faster block times (2.5 minutes) and using the Scrypt hashing algorithm.
WalletConnect is a protocol that enables secure communication between decentralized applications (dApps) and mobile wallets through QR code scanning or deep linking.
Multisig (multi-signature) is a security feature that requires multiple private keys to authorize a transaction, enhancing protection against unauthorized access in blockchain networks.
A metal backup is a durable metal plate or device engraved with a cryptocurrency wallet's seed phrase, providing fireproof and waterproof protection for offline key storage.
HODL is cryptocurrency slang for holding assets long-term despite price volatility, rather than selling. It originated from a 2013 forum post misspelling 'hold' as 'I AM HODLING.'
Ngrave Zero uses a certified Secure Element chip to store private keys in tamper-resistant hardware. Even if the device's software were compromised, the Secure Element isolates your keys from extraction. The device has been independently security audited.
What if Ngrave goes out of business?
Your seed phrase follows the BIP39 standard, meaning you can recover your funds using any compatible wallet — you are not locked into Ngrave's ecosystem.
What if I lose my Ngrave Zero?
Your cryptocurrency is stored on the blockchain, not on the device. If you lose your Ngrave Zero, you can recover full access using your seed phrase on any compatible wallet.
How long will Ngrave Zero receive security updates?
Check Ngrave's website for the latest firmware update schedule.
Is the Ngrave Zero open source?
No. The Zero’s firmware is closed-source and does not offer reproducible builds — it fails WalletScrutiny’s verification. Ngrave instead emphasizes the EAL7 certification of its ProvenCore operating system.
Is the secure element EAL7-certified?
No — the EAL7 certification applies to the ProvenCore operating system (TEE), not the chip. The discrete secure element is a customized STSAFE-A100, which is Common Criteria EAL5+.
What is the GRAPHENE backup?
GRAPHENE is Ngrave’s stainless-steel, two-plate cryptographic backup for the recovery seed, sold separately (around $148) or bundled with the Zero in a Combo Pack.
Some links on this page are affiliate links. If you purchase through them, I may earn a commission at no additional cost to you. This helps support the site and allows me to continue creating detailed, independent reviews.
Our testing methodology is evolving. Ratings and assessments will be refined as we improve our scoring framework to reflect the most accurate results.
Ready to get Ngrave Zero?
Official website • Secure Element • Security audited