What is air-gapped signing, and do I need it?
Confirmed Published 5 min read
Short answer
Air-gapped signing means approving transactions on a device kept off the internet, so the secret key never goes online. XRPL.org calls any setup that lets outside sources reach a secret key dangerous. Keeping the key offline closes that route, but it does not catch a wrong address, destination tag or fee unless someone reads them on the device.
The full answer
What does keeping the key offline protect against?
XRPL.org, the XRP Ledger’s documentation site, says any configuration in which outside sources may gain access to a secret key is dangerous, and is likely to result in a malicious user stealing all the XRP at that address [1]. It also says anyone who knows an address’s private key has effectively full control over it, and that no privileged administrator can undo or reverse a transaction once it has applied [2].
The documented response is to keep the key away from the internet. XRPL.org says a key pair and its address can be generated entirely offline, without contacting the ledger or any other party [3]. Writing about master keys, it says that a key kept enabled but offline cannot reasonably be reached over the internet, yet can still be fetched for an emergency [2]. FINRA’s investor guidance describes cold wallets as paper or hardware that generally aren’t connected to the internet, and says they tend to be harder for malicious actors to hack because of that [4]. In a September 3, 2024 public service announcement, the FBI told holders not to store seed phrases, private keys, passwords or wallet logins on internet-connected devices [5].
Hardware wallets follow a related model. D’CENT, a hardware wallet maker, says in its app FAQ that the app serves only as the interface for display and operation, and that the private key remains within the device’s secure chip [6].
What does air-gapped signing not stop?
The protection covers the key. It does not cover the content of what the key signs. None of these sources says an offline device checks whether a transaction matches what its owner intended; that check sits with the person looking at the screen.
Address poisoning shows the gap. FBI Denver said on April 26, 2024 that criminals send tokens from addresses that closely resemble ones a victim has used before. Because wallet software truncates addresses, the first and last characters can match a familiar address while the middle characters differ [7]. A payment to that look-alike address would be signed offline as readily as online. The same applies to a malicious signing request that dresses a harmful transaction up as a routine one. That is covered on its own page and in what to do about address poisoning.
Offline signing also cannot repair a key that was weak or exposed before it went offline. XRPL.org says a private key should be chosen using a strong source of randomness, and that holders should only use key pairs generated with devices and software they trust, because compromised applications can expose the secret [2]. D’CENT says that if a hardware wallet’s recovery phrase was ever entered into an app wallet or any other software wallet, the two share the same private keys and the hardware wallet should not be treated as isolated [6]. Questions about weak seed generation and fake or tampered devices are taken up in whether a hardware wallet can be hacked.
What should I check on the device screen before approving?
The address comes first. FBI Denver’s advice is to check the entire address to make sure it fully matches the one you mean to pay [7]. Comparing only the opening and closing characters is the habit the April 2024 warning describes attackers exploiting.
When the destination is an exchange, the destination tag matters too. XRPL.org says a payment to an exchange address can use a destination tag to tell the business which customer to credit, and that a payment to a shared address with no tag can require manual intervention and a discussion with the sender to work out who should receive it [8]. More on this is in what a destination tag is and what happens if you forget it.
The fee is the third field worth reading. XRPL.org says every transaction destroys the exact amount of XRP in its Fee field, even if that amount is much more than the current minimum, and gives the current minimum for a standard transaction as 10 drops [9]. A device screen that shows a fee far above that figure is showing something the holder did not ask for.
Which XRP-compatible devices support air-gapped signing?
XRPL.org documents offline key generation and offline storage of a master key [2][3], but it does not list devices. This page names no device and recommends none.
Does an ordinary holder need it?
No regulator, and no XRPL.org page cited here, says that individual holders need fully offline signing. What the sources agree on is narrower: keep secret keys and recovery phrases off internet-connected devices [1][5]. How much of a holding to keep in a fully offline setup is a question of amounts and convenience, set out in how much to keep in a hot wallet versus cold storage. Controls built into the ledger itself, such as keeping the master key offline and using a separate key day to day, are explained in the XRP Ledger’s account security features.
What is the strongest case against relying on it?
The strongest objection is that an offline setup moves risk from thieves to the holder. NIST said in February 2021 that both paper and digital backups of seed phrases can be lost, stolen or destroyed [10]. FINRA says hardware wallets can break down, suffer defects, or be lost or stolen, and aren’t totally immune from sophisticated hacking [4]. XRPL.org says there is no one who can restore access to an XRP Ledger account if something goes wrong [11]. The FTC says that if you lose the password to your digital wallet, you are likely to find that no one can step in to help recover your funds [12]. Those cases are gathered in how people lose XRP without being hacked.
Physical coercion is the other limit. Chainalysis defines a wrench attack as one in which violence or its threat bypasses encryption however strong it is, and reported on August 6, 2026 that 46 violent crypto-related incidents had been documented globally through late June 2026 [13]. A key that never touches the internet can still be handed over under threat.
What we know
- XRPL.org (undated, checked September 2026) says any configuration in which outside sources may gain access to a secret key is dangerous and likely to result in theft of all the XRP at that address.
- XRPL.org (undated, checked September 2026) says a key pair and its address can be generated entirely offline, and that a master key kept enabled but offline cannot reasonably be reached over the internet but can still be used in an emergency.
- XRPL.org (undated, page last updated about June 2026) says no privileged administrator can undo or reverse a transaction once it has applied.
- FINRA’s investor guidance (undated) says cold wallets generally aren’t connected to the internet and tend to be harder to hack for that reason, but that hardware wallets can break, be lost or stolen, and aren’t totally immune from sophisticated hacking.
- The FBI (public service announcement, September 3, 2024) says not to store seed phrases, private keys, passwords or wallet logins on internet-connected devices.
- D’CENT, a hardware wallet maker, says in its app FAQ (undated) that the key is generated inside the device’s secure chip and never leaves it, that every transfer must be approved on the device, and that a hardware wallet whose recovery phrase was entered into any software wallet should not be treated as isolated.
- FBI Denver (April 26, 2024) says look-alike addresses can match a familiar address in their first and last characters, and advises checking the entire address before sending.
- XRPL.org (undated, checked September 2026) says every transaction destroys the exact XRP amount in its Fee field, and that the current minimum for a standard transaction is 10 drops.
- NIST (NISTIR 8301, February 2021) says paper and digital backups of seed phrases can be lost, stolen or destroyed.
- Chainalysis reported on August 6, 2026 that 46 violent crypto-related incidents had been documented globally through late June 2026.
What we reason Analysis
- An offline key protects the key, not the decision. XRPL.org’s secure signing warning and D’CENT’s description of on-device approval both place the protection at the point where the key is reached; neither says the device judges whether a transaction is the one its owner meant to send. That judgement rests on what the holder reads on the device screen.
- Address poisoning, as FBI Denver described it in April 2024, works on the holder’s eyes rather than on the key, so a payment to a look-alike address would be signed offline just as readily as online.
- Offline signing cannot repair a key that was weak or exposed before it went offline. XRPL.org asks for keys made with strong randomness on trusted devices and software, and D’CENT says a hardware wallet whose phrase was typed into an app is no longer isolated.
- For an individual, the trade is between remote theft and self-inflicted loss. The FBI and XRPL.org favour keeping secrets off connected devices; NIST, FINRA, the FTC and XRPL.org’s own warning that no one can restore access describe the losses that an offline setup leaves with the holder alone.
What's still open
- As of October 1, 2026, no independent public source establishes which consumer devices can sign XRP Ledger transactions with no cable or wireless connection at all.
- As of October 1, 2026, no regulator, standards body or peer-reviewed study has compared losses among individuals using fully offline signing with those using connected hardware wallets or software wallets.
In plain English
Your XRP is controlled by a secret key, and anyone who gets that key can move the coins. Air-gapped signing keeps the key on a device that never goes online, so thieves on the internet cannot reasonably reach it. The device still signs whatever it is shown, so you have to read the address, tag and fee on its screen before you approve. Keeping everything offline also means that if you lose the device and its backup, nobody can give you access back.
Key terms
Sources
- Secure Signing — XRPL.org, undated Primary
- Cryptographic Keys — XRPL.org, undated Primary
- Addresses — XRPL.org, undated Primary
- Cryptocurrency Storage — FINRA, undated Primary
- North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Techniques (PSA) — FBI Internet Crime Complaint Center, September 3, 2024 Primary
- FAQ: DCENT App — D'CENT (IoTrust), undated Company-reported
- FBI Warns of Cryptocurrency Token Impersonation Scam — FBI Denver, April 26, 2024 Primary
- Source and Destination Tags — XRPL.org, undated Primary
- Transaction Cost — XRPL.org, undated Primary
- NISTIR 8301: Blockchain Networks: Token Design and Management Overview — National Institute of Standards and Technology, 2021-02 Primary
- Disable Master Key Pair — XRPL.org, undated Primary
- What To Know About Cryptocurrency and Scams — Federal Trade Commission, undated Primary
- Violent crypto wrench attacks in 2026 — Chainalysis, August 6, 2026 Company-reported
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
