A user with significant cryptocurrency holdings faces a familiar tension: convenient access to manage assets across multiple chains versus the security principle that private keys should never touch internet-connected hardware. Hardware wallets solve part of this problem by keeping keys offline during signing, but they still depend on a device that connects to the internet to broadcast transactions and monitor balances. AirGap Vault presents a more aggressive alternative. It is a mobile application designed to run on a dedicated, permanently offline device, creating an air-gapped signing system where the private key remains isolated and every transaction must be manually transferred between the offline signer and an online observer.
Rabby Wallet, a browser extension, can integrate with AirGap Vault through a formal connection protocol, turning Rabby into the online transaction builder and broadcast component while AirGap Vault handles the actual signing. This separation is not merely a convenience feature. It reshapes the threat model. An attacker who compromises the browser extension, the operating system running it, or the network connecting to it cannot access the signing keys because they do not exist on that device. The price is friction: every transaction requires an explicit transfer step, and users must understand what they are signing based on information displayed on two separate devices. For security-conscious users managing substantial value, this workflow can be worth the operational overhead.
The air-gapped principle and why Rabby alone is insufficient
A standard Rabby Wallet installation stores private keys or hardware-wallet connection details on the same machine that runs the browser, connects to the internet, and maintains open tabs to external services. This is the normal pattern for web3 wallets, and it is pragmatic for many users. An extension like Rabby isolates keys from websites through sandboxing and encryption, and it avoids the custodial risk of centralized platforms. But isolation at the application level is not isolation from the device. Malware, browser exploits, or platform vulnerabilities can potentially access sensitive material stored locally, and the device’s internet connection remains a vector for external observation or attack.
AirGap Vault operates on a completely different principle. It is installed on a separate mobile device that is never connected to the internet, never paired with Bluetooth devices, never configured for cellular data, and ideally kept powered off when not in use. The device becomes a dedicated signing appliance. All network communication happens through one mechanism: QR codes. The user scans a QR code from the offline device when initiating a transaction, transfers that code to the air-gapped signer, then uses the offline device’s camera to read the result, scan it back to the online device, and broadcast the signed transaction. This creates a strong physical boundary between the key material and any networked system.
The reason users choose this arrangement despite its awkwardness is that it answers a specific question: if every internet-connected system I own were compromised simultaneously, could an attacker steal my keys? With an air-gapped signer, the answer is definitively no. The attacker would need physical access to the offline device itself. That shifts security from a probabilistic problem—”is my browser secure enough?”—to a deterministic one—”can I keep a physical device secured?” For many users, the latter is easier to reason about and easier to defend.
Setting up Rabby Wallet as the online transaction builder
The first step is to establish Rabby on an internet-connected device—a computer or laptop running a modern browser. Install Rabby Wallet from its official source, create or import a watch-only address for each account you intend to manage with AirGap Vault, and verify that Rabby displays balances and token holdings correctly. A watch-only address receives no private key material; it allows the wallet to display your balance and construct transactions, but it cannot sign them. This is the critical difference from a normal wallet setup. Rabby becomes a transaction interface, not a signing device.
When creating a watch-only address in Rabby, you input only the public address of an account controlled by AirGap Vault. If your AirGap Vault device holds an Ethereum private key, you derive its corresponding address, then paste that address into Rabby’s watch-only import. Rabby will then show that address’s balance, recent transactions, and token holdings. Every time you want to send a transaction, Rabby constructs the unsigned transaction details, displays them on screen, and waits for you to transfer them to AirGap Vault for signing. The critical detail is that Rabby never has a private key to sign with, so it cannot broadcast a transaction on its own. It can only prepare and display.
This design also allows you to add multiple watch-only addresses in Rabby—one for your personal Ethereum account, one for your Polygon position, one for your institutional fund controlled by a different AirGap Vault instance. Rabby becomes a unified view of all these offline-controlled addresses. You can monitor every account’s activity, prepare multiple transactions in parallel, and then take them offline for signing in whatever batch makes sense. The extension remains focused on observation and transaction preparation, not signing.
Installing and configuring AirGap Vault for maximum isolation
AirGap Vault runs on Android or iOS. The most security-conscious users purchase a used smartphone from a generation or two past, factory-reset it, and configure it with the strictest possible settings before installing AirGap Vault. Disable all wireless: turn off Wi-Fi, cellular data, Bluetooth, and NFC. Disable location services, cloud backup, and auto-updates. Disable the lock screen timeout so the device does not automatically wake if left unattended. Some users disable notifications entirely or enable airplane mode and then verify that it remains active. The goal is to create a device that has no capability to communicate with any external system except through the camera and QR code scanner that AirGap Vault controls explicitly.
When you first launch AirGap Vault, it generates a recovery phrase or allows you to import an existing one. If you are generating a new key, AirGap Vault displays the recovery phrase on screen, and you should write it down, encrypt it, and store it offline in multiple secure locations—separate from the device itself. Losing this recovery phrase means losing access to any funds signed by this key. If you import a phrase you generated elsewhere, confirm that you are importing the exact phrase, character by character, using a separate verification document. Do not copy and paste recovery phrases between devices; type them manually or use a QR code if the software supports it.
After the key is stored, you can select which blockchains to activate. AirGap Vault supports Ethereum, Bitcoin, Polkadot, Cosmos, Tezos, Avalanche, and others. For each chain, the app derives the appropriate keys and displays your public address. Write down or take a photograph of each public address—you will need them to create the corresponding watch-only accounts in Rabby. Then power off the device. It should remain off except during the moments when you are actually signing a transaction.
The transaction signing ritual: QR code transfer and verification
When you are ready to send a transaction using funds controlled by AirGap Vault, the process follows a specific sequence. First, in Rabby Wallet on your internet-connected device, navigate to the watch-only address you want to send from, construct the transaction (recipient, amount, gas settings, nonce), and preview it. Do not sign anything yet. Instead, look for an option to export the unsigned transaction or display it as a QR code. Rabby should present a large, scannable QR code that encodes all the transaction details: the recipient address, the amount, the gas parameters, the network, everything.
Power on the AirGap Vault device, unlock it, and open the application. Select the appropriate blockchain and account. Then use the device’s camera to scan the QR code displayed by Rabby. AirGap Vault will decode the transaction, display every parameter on the offline device’s screen, and ask you to verify it. Read carefully. Confirm the recipient address character by character if possible, verify the amount in both the base unit and any conversion you have calculated, and check the network identifier. This is the moment where a phishing attack on the online device means nothing. You are reading the transaction data from an offline device that has no connection to any compromised internet service. If the address looks wrong, or if the amount is different from what you intended, reject it and restart from Rabby.
If everything is correct, approve the transaction on the AirGap Vault device. It will sign the transaction using the private key stored locally and display the result as a new QR code. Photograph this QR code or display it on the offline device while scanning it with your Rabby device. The Rabby extension will decode the signed transaction, verify the signature, and display the final transaction data. Check once more that the signing was successful, then broadcast the transaction to the blockchain. At this point, the transaction is public, and there is no further opportunity to modify it.
Handling multiple blockchains and derivation paths
One advantage of AirGap Vault is that a single recovery phrase can generate keys for multiple blockchains. If you back up one phrase, you have simultaneously backed up your Ethereum key, your Bitcoin key, your Cosmos key, and your Avalanche key. This reduces the number of recovery phrases you must secure, but it also means you must organize Rabby watch-only accounts to match. Create a separate watch-only account in Rabby for each blockchain you use. For instance, one watch-only address for your Ethereum position, another for your Bitcoin position, and so on. Rabby should display each as a separate asset with its own balance and transaction history.
The blockchain and derivation path matter for the public address. Two different blockchains will produce two different addresses from the same recovery phrase. If you accidentally paste an Ethereum address into an AirGap Vault Cosmos import, the keys will not match. To prevent this, write down the blockchain name and the corresponding address next to each watch-only import in Rabby. Some users create Rabby contact notes or labels for each address, documenting which AirGap Vault instance and blockchain it belongs to. This simple step prevents a critical mistake: sending a transaction intended for Ethereum to the Bitcoin account instead, or vice versa.
AirGap Vault also supports custom derivation paths if you have created keys with non-standard paths on another device. Advanced users can manually enter a path, but the default paths are standardized. Unless you have a specific reason to deviate, use the application’s defaults and verify that the address displayed in AirGap Vault matches the address you configured in Rabby.
Device security, backup, and recovery under duress
The AirGap Vault device should be stored in a secure location when not in use. A safe, lockbox, or safe deposit box are common choices. Some users store it separately from the recovery phrase backup, reasoning that an attacker who finds one will not find the other. The device itself should be powered off to reduce wear and avoid any potential remote attack surface, however theoretical. When it is off, it is simply inert hardware.
The recovery phrase backup is the actual point of risk. If someone obtains your recovery phrase, they can import it into AirGap Vault on any device and sign transactions without your knowledge or consent. Store the phrase in a secure, encrypted, and redundant format. Some users engrave it on a metal plate, store it in a hardware-backed safety deposit box, or encrypt it under a strong passphrase and back it up to multiple secure locations. Do not store the phrase in a cloud service, even encrypted, if you believe the cloud service itself might be compromised. Do not take a photograph of the phrase on an internet-connected device. The goal is to make recovering the phrase require actions you can detect and prevent, not merely finding it on a compromised device.
If you suspect compromise of the AirGap Vault device—for instance, if it is lost, stolen, or you believe someone accessed it without your knowledge—move funds immediately. Import the recovery phrase into a new AirGap Vault setup or into a different hardware wallet, then broadcast transactions from the new setup to transfer all assets to fresh addresses. The time window for an attacker to act is limited. Once you move the funds, the old key becomes worthless. In a high-stress scenario where you cannot access your backup or recovery tools, you may need to pay a transaction fee to transfer funds to a temporarily accessible wallet. This is a reasonable loss compared to losing the entire balance.
When Rabby Wallet for hardware wallets becomes practical for non-AirGap setups
Many users do not need full air-gapping. If you have a standard hardware wallet such as Ledger or Trezor, Rabby Wallet for hardware wallets integrates directly, allowing you to connect the device via USB, confirm transactions on the hardware wallet’s screen, and broadcast the signed result without Rabby ever touching the private key. This provides most of the security benefits of hardware signing without the operational friction of QR codes. Rabby detects the connected hardware wallet, displays it in the accounts list, and prompts you to approve on the device whenever a transaction is initiated.
The tradeoff is that a hardware wallet still requires the device to be plugged into a computer to sign. That computer could be compromised. AirGap Vault’s air-gapped design eliminates this entire category of risk. But it also requires discipline and procedural rigor. If you are just beginning to think about hardware security, a traditional hardware wallet paired with Rabby is a reasonable starting point. As your holdings grow and your security concerns deepen, air-gapping becomes more attractive.
Common mistakes and how to avoid them
One frequent error is confusing the watch-only address in Rabby with a receiving address for that account. When you send funds to a watch-only address in Rabby, those funds are actually controlled by the AirGap Vault key, not by Rabby. Rabby simply displays them. This is correct behavior, but users sometimes create a new Rabby address thinking they can receive funds that Rabby will control. They cannot. All funds received by a watch-only address remain under the control of whatever system generated the original key—in this case, AirGap Vault.
Another common mistake is losing track of which recovery phrase is stored where. If you maintain multiple AirGap Vault devices—perhaps one for long-term cold storage and one for periodic transactions—keep clear documentation of which recovery phrase is on which device, and store the backup phrases separately. If a phrase becomes associated with the wrong device after a factory reset, you may inadvertently sign transactions with a key you did not intend to use. Use labels, dates, and cryptographic fingerprints of the keys to disambiguate.
Finally, users sometimes bypass the QR code transfer for convenience, taking a screenshot of the transaction details or copying and pasting the address between devices. Do not do this. The entire security model depends on the offline device confirming what the online device proposes. If you shortcut this step, you reintroduce the attack surface you were trying to eliminate. The QR code process is deliberately cumbersome because that cumberousness is what makes it secure.
The psychological and operational sustainability of air-gapping
Air-gapping only works if you actually use it consistently. If the friction becomes unbearable, you may be tempted to import the AirGap Vault key into a regular wallet just for one transaction, or to set up a second online wallet for convenience. That defeat of your security system is understandable but defeats the entire purpose. Before committing to an air-gapped setup, honestly assess whether you can tolerate the workflow for months or years. If you regularly need rapid, frequent transactions, air-gapping is not appropriate. If you hold assets for long periods and transact occasionally, it is viable.
Many users find it helpful to commit to explicit procedures. Write down the steps: which device you power on first, in what order you scan QR codes, how you verify addresses. Then practice with small amounts before using the setup for significant funds. Performing the workflow a few times with low stakes will make you comfortable with the rhythm and more likely to catch errors when they matter.
The security benefit of air-gapping is substantial, but it requires understanding what you are and are not protected against. An offline device cannot be hacked remotely. It can be stolen, physically examined, or compromised if someone obtains the recovery phrase. The recovery phrase backup is therefore your actual point of maximum risk. If you can protect that, the offline device becomes a practical cold storage system that is dramatically harder to compromise than keeping keys on an internet-connected computer.
Frequently asked questions
Can I use Rabby Wallet directly with AirGap Vault, or do I need another app?
Rabby Wallet integrates with AirGap Vault through QR code scanning. Rabby runs on your internet-connected device and prepares transactions; AirGap Vault runs on a separate offline device and signs them. You do not need a separate app beyond these two, though you should document which address on AirGap Vault corresponds to which watch-only account in Rabby.
What happens if the QR code is too small or I cannot scan it between devices?
Ensure the screen brightness on the device displaying the QR code is set to maximum. Hold the scanning device steady and allow it to focus. If the QR code is very complex (encoding a large transaction), it may be too dense for casual scanning. In that case, try reducing zoom or moving the devices farther apart. As a last resort, some air-gapped setups support a SD card transfer method, though QR codes are the standard and most secure approach.
If I lose the AirGap Vault device, can I recover my funds?
Yes, if you have a backup of the recovery phrase. Import the phrase into a new AirGap Vault device or into any compatible wallet (hardware wallet, another software wallet, etc.), derive the public addresses, and move the funds to a new address controlled by a key you trust. This process should happen as soon as you realize the device is lost, to prevent an attacker from accessing the funds. The recovery phrase itself is what matters; the device is just hardware.
