
Custody mechanics
When the Box Owns the Key, the Air Gap Stops Helping
Updated 10 October 2026
That is a signer whose box is the device. It is not a wallet that earns its safety from the gap between the seed and the screen.
A closed box used to live behind a wire
The old picture was tidy. A hardware wallet kept the private key inside a small sealed device, and a host computer built the transaction. The host could see the addresses, the amounts, the fees, the dust. The host could not see the key. The line between what spends and what watches ran along the USB socket, and the side that held the key stayed dark.
That line is now drawn in a different place. A growing family of signing devices, often sold as air gapped, hold the key, the policy engine, the address generator, the change detector, and the transaction parser inside the same case. The case is the box, and the box owns the key. The host is reduced to a dumb terminal that prints bytes. People call this an air gap because there is no cable, but the radio is inside the box, and the box is the thing you are trying to keep closed.

The threat model that the marketing copy imports
Air gap, in the original sense, was a refusal. No packets, no frames, no electrons carrying user data cross the boundary. The device had to be carried to a clean machine, or the clean machine had to be carried to the device. The implicit promise was that the only way a key left the box was through a physical button press, with a human watching what was being signed.
Self-contained signers do not keep that promise. They take a QR code, decode it, and rebuild a transaction from a set of inputs they parse themselves. They listen for Bluetooth Low Energy advertisements so a phone can push a partially signed transaction. They wake on NFC from a tap. Each of these is a side channel. The question is no longer can the host see the key, but can anything in the room steer the box into signing the wrong transaction, and the answer depends on inputs that the marketing brochure does not enumerate.
What changes when the box parses the spend
A host that builds a transaction can be wrong in obvious ways. It can lie about a fee, it can lie about a change amount, it can pull a malicious address from a hijacked DNS cache. The user notices because the user reads the screen. When the box parses the spend, the user is reading a screen that the box controls. The box can show you one transaction and sign another. The defence is to verify the output on a second device, and a second device is something most buyers of an air-gapped product do not own.
This is the uncomfortable geometry of the new shape. The closed box, the one CatBitcoin keeps returning to, has moved from being a passive vessel for a key to being an active computer that decides what the key signs. The single point of failure is now inside the closed box, and the closed box is also the part that the customer is told to trust by feel.
Side channels that the radio drags in
Bluetooth Low Energy is the easiest case to talk about, because the spec is public. A BLE peripheral exposes a GATT table. A phone pairs, writes a characteristic, reads a characteristic. The peripheral can ask the phone to confirm a spend. The peripheral can also be told, by a sufficiently motivated attacker, to advertise a different name, a different service UUID, or a different transaction template than the one the user believes is in front of them. The radio is a wire, even when the wire is invisible.
QR is harder to attack at range, but easier to attack at the lens. A camera that takes a picture of a printed square can be aimed by a passerby with a sticker. NFC is range bound. None of this is exotic. It is the ordinary cost of giving a closed box the ability to talk, and it is the cost the air gap was invented to refuse.
What a buyer can actually verify
Three things, before money changes hands. First, the firmware is reproducible from a public source tree, and the binary on the device matches. Second, the signing flow requires a physical confirmation on a screen that is not the host's screen, and that screen shows every output address in full. Third, the device has a documented, mechanical way to refuse a transaction that does not match what the user saw, including a way to refuse a transaction that the user cannot see because the screen failed.
If a product does not pass all three, the box is not closed. It is a computer that happens to be small, and the threat model is the same as the threat model for any other computer you carry in your pocket, which is to say, the threat model for a phone.
The shape of the cat, in this case
CatBitcoin is fond of a particular distinction. The closed box is the thing that holds the key. The device is the thing you hold in your hand. When the device and the box are the same object, every promise about the box has to be tested through the device, and every promise about the device has to be tested through the box. A hardware wallet used to be two things pretending to be one. The new air-gapped signer is one thing that has to do both jobs, and the air gap is a marketing word for the cable that nobody wants to call a cable.
What to do this week
Treat the device as a small computer. Update the firmware, verify the binary, read the release notes, and keep the device away from radios you did not invite. Do not paste a seed into a watch-only field on a host that the device has ever talked to. The closed box is a discipline, not a product feature, and the discipline has to outlive the cable that used to enforce it.
Quick answers
- Does air gapped still mean anything in 2026?
- It means the device has no persistent wired connection to a host. It does not mean the device is silent, and a signer with a radio is not air gapped in the original sense.
- Is a phone wallet the same threat?
- Worse, because the key and the radio and the network stack are in the same process. A self-contained signer is at least a separate device, but the separation is only as good as the verification on its own screen.
- What is the single most useful habit?
- Verify every output address on the device's own screen, every time, and refuse to sign if the screen is dim, flickering, or showing a QR code you cannot read in full.