XMR/USD
$324.18
0% 1 HR
24HR Change
-1.2%
Price
$324.18
Market Cap
$5.979B

Cold Signing a Monero Transaction: Spend From Cold Storage Without Keys Ever Going Online

> 47 > Cold Signing a Monero Transaction: Spend From Cold Storage Without Keys Ever Going Online

A wallet that has never touched the internet is a wallet nobody can drain remotely. Cold signing is how you spend from one. The private spend key lives on a machine that stays offline permanently, a second online machine does all the talking to the network, and the only thing that crosses between them is a small file moved by USB stick. The online machine never sees your keys. The offline machine never sees the internet. Here is how the whole flow works, where people get it wrong, and what the trade-offs really are.

The two wallets you need

Cold signing rests on a Monero feature called a watch-only wallet. From your cold wallet’s private view key and address, you create a second wallet file that can see incoming payments, check balances, and even see when payments have been spent, but cannot sign anything on its own. That watch-only wallet runs on your everyday computer, the one connected to a node and the internet. Your actual keys sit on the offline machine.

The setup step people skip and later regret is writing down the seed phrase for the cold wallet and storing it separately. Hardware fails, USB sticks die, and a cold wallet whose seed was never recorded is a single point of failure no matter how air-gapped it is. If you are starting from a seed you already have, read what actually gets recovered when restoring a Monero wallet from seed first, because the same rules apply to recreating a cold wallet later.

Step by step: spending from cold storage

First, on the online machine, open the watch-only wallet and make sure it has synced up to the current chain. Select the amount to send and the destination address, set the priority, and choose the option to save an unsigned transaction to file. The official GUI labels this clearly; the CLI calls it transfer_unsigned style output via make_multisig-free tooling, but the concept is the same: the wallet writes a small file that describes the intended spend without being able to execute it. A hardware wallet does this for you at the press of a button; with a software cold wallet you do it by hand.

Second, copy that unsigned file to a USB stick and carry it to the offline machine. There is no requirement that the transfer medium be exotic. The unsigned file contains the destination, the amount, and the set of candidate outputs the wallet wants to use, but no secret key material. The risk at this step is not that the file leaks your keys, it is that a compromised online machine has already prepared a transaction that sends somewhere you did not intend. That is why the third step exists.

Verify before you sign

Third, open the cold wallet on the offline machine and load the unsigned transaction. The wallet will show you the destination address and the amount. Check them character by character, or at minimum the first several and last several characters of the address, against what you intended. This is the moment where malware on your online machine would do its damage, and this screen is your only defense. If the amount or address does not match what the watch-only wallet showed, stop, assume the online machine is compromised, and investigate before signing anything. The offline machine then produces a signed transaction file, which contains the ring signature but still no spend key.

Fourth, carry the signed file back to the online machine, import it into the watch-only wallet, and click relay or submit. The transaction broadcasts like any other. The cold wallet’s balance updates once the transaction is visible on chain.

The costs of running cold

Cold signing is not free in convenience, and pretending otherwise does nobody a favor.

Every spend needs the physical ceremony: create, carry, verify, sign, carry back, relay. For a savings wallet you touch twice a year, that is nothing. For a wallet you spend from weekly, it gets old fast, and bored users take shortcuts. The right pattern for most people is a small hot wallet for day-to-day spending, funded occasionally from the cold wallet, with the bulk of funds in cold storage. Decide the split based on how much you could afford to lose from the hot wallet, not on any formula.

Second, change outputs from cold spends return to the cold wallet by default, which means every cold spend re-entangles your ceremony timing: the change cannot be spent again until the transaction confirms, and it consolidates into a new output in the cold wallet. If you repeatedly spend from cold storage, plan a consolidation pass once in a while so your cold wallet does not accumulate a mess of small outputs that each need to be signed for individually. The mechanics behind change addresses and why sweeping exists are worth understanding before your first spend, because they affect how many outputs your wallet selects and how large the fee will be.

Common mistakes

The most common cold-signing failure is not a hack, it is a lockout. People build a cold wallet, move funds in, then lose the seed phrase, the password, or the machine, in that order of frequency. The second most common is doing the verification step lazily: glancing at the address on the offline screen without comparing it to the intended destination, which defeats the entire point of the exercise. The third is letting the offline machine quietly become an online machine, by plugging in a network card, connecting it to a hotspot out of convenience, or using a laptop whose Wi-Fi cannot truly be disabled.

If you ever share control of funds with another party instead of holding keys solo, the related tooling is Monero multisig: 2-of-3 setups, escrow and shared funds, which solves a different problem with a similar philosophy.

Who cold signing is for

If you hold an amount of Monero whose loss would genuinely hurt you, and you interact with it rarely, cold signing is the correct default and the ceremony is a feature, not a bug. If you spend often, keep cold funds for storage and a hot wallet for spending, and accept that the two-tier structure is what the threat model demands. What cold signing buys you is a hard boundary: no key material on any networked machine, ever, so no remote attacker, no keylogger, no malicious update on your daily driver can ever reach the keys that matter.


Categories:

Leave a Reply

Your email address will not be published. Required fields are marked *