How to Set Up an Offline Wallet for On-Chain Transactions Signing Without the Internet

An offline wallet — also called an air-gapped wallet — never connects to the internet. The private keys that control a Bitcoin address are generated and stored on a device that has no network interface, no WiFi hardware, and no cellular radio. The device signs transactions locally, produces a signed transaction file, and passes that file to an internet-connected device through a QR code, USB, or SD card. The internet-connected device broadcasts the signed transaction without ever seeing the private key. The private key never leaves the offline environment. An attacker who compromises the connected device gains nothing useful. Bitok Arena Research documented the air-gapped signing setup that separates key control from network exposure entirely.

Bitok Arena Says
Bitok Arena's read: air-gapped signing separates two functions that most wallets combine on one device — signing (requires the private key) and broadcasting (requires the internet). The online attack surface — everything a connected device is exposed to — cannot reach the private key because the private key is never on a connected device. That separation is the entire security model.

Setting up offline Bitcoin signing follows the same principle whether the offline device is a dedicated hardware wallet or a software wallet installed on a permanently air-gapped computer. Key generation happens offline. The Bitcoin address is exported to the online device as a watch-only wallet. The online wallet sees the balance and prepares unsigned transactions. The unsigned transaction passes to the offline device, is signed, and returns. The signed transaction is broadcast. This air-gapped signing workflow applies to any Bitcoin transaction — on-chain competition entries, regular transfers, or any output from a self-custody address that needs to stay fully air-gapped throughout the signing process.

The Two-Device Setup in Practice

Air-gapped signing starts with the offline device configuration. The most accessible approach uses a hardware wallet designed specifically for air-gapped operation: the ColdCard Mk4 generates keys offline, exports public key data through a MicroSD card, and receives unsigned transactions through the same card. The Ellipal Titan uses QR codes exclusively — no USB, no SD card, and no wireless connection of any kind. The Foundation Passport operates similarly. All three produce the same result: the private key never exists in a network-connected environment. Bitok Arena Research reviewed setup documentation for all three to verify the air-gap integrity at each step.

Bitok Arena Research

Bitok Arena documented the four-step air-gapped signing workflow for on-chain Bitcoin transactions:

Offline device setup — hardware wallet (ColdCard, Ellipal, Foundation Passport) or permanently air-gapped computer running open-source Bitcoin wallet software; private keys generated and stored exclusively on this device.

Watch-only wallet import — the public key (xpub) from the offline device is imported into a watch-only wallet on an internet-connected device (Sparrow Wallet or Electrum in watch-only mode); this wallet displays balances and prepares unsigned transactions but cannot sign them.

Transaction transfer — unsigned transactions pass from the online device to the offline device via MicroSD card (ColdCard), QR code scan (Ellipal, Passport), or USB PSBT file; signed transactions return by the same method.

Broadcast — the signed transaction file is imported into the watch-only wallet and broadcast to the Bitcoin network; confirmation follows standard Bitcoin network timing.

QR code transaction signing is the approach used by Ellipal Titan and Foundation Passport. The online wallet displays an unsigned transaction as a QR code. The offline device scans the QR with its camera, signs the transaction internally, and displays the signed result as a new QR code. The online device scans the signed QR and broadcasts it. No cable connects the two devices at any point. No data transfers through any network. The QR codes carry only the transaction data — not the private key, not any credential that could be used to spend from the address independently.

What the Air Gap Actually Removes

Software wallet users face a specific security exposure: their signing environment — the phone or laptop where transactions are created and signed — is also an internet-connected device exposed to malware, phishing, and network interception. Malware that can steal a Bitcoin private key targets exactly this environment. A compromised device can intercept the private key during signing operations or alter the destination address in the clipboard before broadcast. Both attacks require that the private key be present on a connected device at some point during the transaction process. The air-gapped setup removes that requirement entirely.

Bitok Arena Research

Bitok Arena identified three attack categories that the air-gapped signing workflow removes from the threat model:

Network-based key theft — an attacker who compromises the online broadcasting device cannot access the private key because it resides on the offline device, which is unreachable over any network.

Clipboard address substitution — malware that replaces clipboard addresses targets the destination address entered on a connected device; in the air-gapped workflow, the transaction destination is set on the offline device before the QR or PSBT is generated, removing clipboard substitution from the attack surface.

Remote access attacks — remote access tools that give attackers control of an online device provide no benefit when the device they control holds no private keys; the signing authority is in an environment with no remote access surface by design.

A watch-only wallet on the connected device complements the air-gapped signing setup. It imports the public key from the offline device and displays the balance and full transaction history of the controlled address without holding any private key. The watch-only wallet is the view: it shows current balance, pending confirmations, and confirmed transactions — all readable without any signing authority. The offline device is the vault: it holds the key that proves ownership of everything the watch-only wallet displays. Neither can function as the other.

The Practical Trade-Off at Different BTC Levels

Whether a software wallet is safe enough for regular on-chain Bitcoin use is a question about risk tolerance proportional to the BTC amount involved. For small amounts or infrequent transactions, a reputable software wallet on a dedicated phone that is not used for other activity represents a reasonable balance of security and convenience. For users who hold meaningful BTC in self-custody addresses used for on-chain competition entries and prize receipts, the air-gapped setup removes an entire category of risk that the software wallet cannot address. The additional setup time — roughly one hour for initial configuration — amortises across every subsequent transaction, which takes no longer than a standard software wallet send once the workflow is familiar.

Bitok Arena Says
Bitok Arena's position: the air-gapped signing setup costs one hour of configuration and removes network-based attacks from the signing process entirely. Every on-chain Bitcoin transaction after that follows the same workflow: prepare unsigned transaction on the watch-only device, sign on the offline device, broadcast from the watch-only device. The private key never leaves the offline environment.

The configuration is completed once. Set up the watch-only wallet on the connected device and the signing environment on the offline device. From that point forward, every on-chain Bitcoin transaction — competition entries, transfers, prize receipts — follows the same two-device workflow. The address controlled by the offline device receives BTC and commits BTC to on-chain rounds from a signing environment that has never touched the internet. That is the practical result of the air-gap: the key controlling the address is in a place no remote attacker can reach.

Bitok Arena Bottom Line

Bitok Arena's review of air-gapped signing hardware confirms that ColdCard Mk4, Ellipal Titan, and Foundation Passport all achieve full private key isolation from connected devices throughout the signing process. The workflow adds one transfer step per transaction; what it removes is the entire network-based attack surface that software wallets on connected devices are permanently exposed to.

⚡ READ MORE ⚡

Bitcoin competition insights, on-chain strategy, and crypto leaderboard analysis.

BITÓK ARENA
JOIN NOW