Definition
Cold signing separates the creation of a transaction signature from the internet-connected process that prepares or broadcasts the transaction. It is used to reduce direct exposure of private keys to online systems. The term describes an operational arrangement rather than a single standard; some workflows use an air-gapped device, while others rely on a hardware signer with carefully constrained communication.
How It Works
An online wallet prepares the transaction data, and the signer receives enough information to verify and authorize the intended action. The signed result returns to a network-connected device for broadcast. Private keys should remain inside the protected signing environment. A watch-only wallet can assist with balances and preparation, but it cannot replace the required signing authority. The exact transport and file format depend on the chain and tools.
Key Considerations
Review the destination, amount, fees, and contract effects on a trusted display where possible. An offline signer can still approve malicious data if the user does not understand the request or the device cannot display it accurately. Recovery phrases, firmware, and any transferred media need protection too. Cold signing does not make transaction details private or guarantee successful execution. It also does not automatically mean that keys have never been exposed online; the security of key generation, import, backup, and device lifecycle remains part of the overall assessment.