Shopping Cart

No products in the cart.

Blog
/
/
/
/
/
Wasabi Wallet on Air-Gapped Machines: Building a Two-Computer Privacy Setup with Hardware Wallets

Wasabi Wallet on Air-Gapped Machines: Building a Two-Computer Privacy Setup with Hardware Wallets

A Bitcoin holder concerned with state-level surveillance, advanced persistent threats, or the compounding risk of holding significant value in a single digital location faces a practical problem: even a non-custodial wallet on an internet-connected computer can be vulnerable to malware, supply-chain attacks, or remote exploitation. An air-gapped machine—a computer with no network connectivity—eliminates that vector entirely. The challenge is integrating such an isolated environment with a hardware wallet and transaction broadcasting in a way that remains usable without introducing new attack surfaces through USB transfers, QR codes, or manual data entry.

Wasabi Wallet’s architecture, hardware wallet integration, and support for offline transaction construction make it possible to build a legitimate two-computer setup. One machine running Wasabi stays completely isolated, holding no private keys but preparing and signing transactions offline. A second internet-connected machine broadcasts those signed transactions to the Bitcoin network. A hardware wallet such as a Ledger or Trezor acts as the actual key holder, never exposing secrets to either computer. This approach trades convenience for a meaningful reduction in attack surface, but only if the setup is implemented carefully and the user understands what each component actually protects.

A two-computer Bitcoin setup showing an air-gapped offline machine with Wasabi Wallet signing transactions and a networked machine broadcasting to the Bitcoin network

Why air-gapping matters and what it actually prevents

An air-gapped machine cannot receive inbound network connections or send outbound traffic without explicit intervention. A computer that has never been connected to the internet, or one that has been disconnected and its network interfaces disabled at the BIOS level, cannot be remotely exploited by worms, botnets, or attackers who have compromised a service the user normally visits. It also cannot receive malware through automatic updates, drive-by downloads, or watering-hole attacks targeting specific websites. This is a genuine reduction in risk for a user who holds enough Bitcoin to justify the operational friction.

The protection is narrower than it might first appear. An air-gapped machine can still be compromised by physical access, supply-chain tampering, or an attacker with pre-existing code already on the device. Malware installed before air-gapping takes effect is not retroactively removed. A USB stick or external drive introduced into the offline machine can carry infection. A hardware wallet connected to an air-gapped machine can still be exposed if the device itself is malicious or if the Wasabi installation on the offline machine has been tampered with. Air-gapping is a powerful control, but it is only as strong as the weakest component it protects.

For Bitcoin stored in a hardware wallet, the isolation serves a specific function: it makes remote key compromise far more difficult. A Ledger or Trezor keeps private keys on a secure element and requires physical confirmation (a button press or display verification) for each transaction. If that hardware device is connected only to an air-gapped Wasabi instance, an attacker would need to breach the air-gapped machine first, then exploit the hardware device itself or compromise the user’s physical environment. The operational complexity is substantial enough that casual theft or remote exploitation becomes significantly less viable.

The counterbalancing risk is usability under pressure. If a user must urgently access funds, the requirement to physically move data between machines via USB drives or to reconnect equipment may introduce hurried mistakes. Recovery from loss of the air-gapped machine is also more complicated because the hardware wallet seed must be available elsewhere (another hardware device, a paper backup, or a split key-sharing scheme). The setup makes sense only for long-term holdings, not for frequently moving or exchanging Bitcoin.

Choosing and preparing the offline machine

The air-gapped computer should be purchased secondhand or new, with no prior network connection if possible. An old laptop or desktop without wireless capability is preferable to a newer device with integrated WiFi and Bluetooth that must be disabled at multiple levels. Before bringing it into use, disable the BIOS battery if the device is several years old—this prevents clock-reset attacks and ensures that the machine cannot be time-tricked into accepting expired certificates. Document the BIOS configuration and consider writing it down or storing it safely, as reconfiguring a completely isolated machine can require restoration from notes.

The operating system should be a fresh installation from verified media. Linux (Ubuntu, Debian, or Fedora) is often preferred for air-gapped Bitcoin work because the installation process is more transparent and the OS is less likely to have built-in telemetry or automatic connectivity features. Download the official ISO file on a different machine, verify the checksum against the published hash, burn it to a USB stick using a utility such as Balena Etcher or GNOME Disks, and then install it on the offline machine without connecting to the internet during or after setup. If the offline machine is very old, ensure the CPU supports the operating system version you intend to use—older processors may not run modern Linux distributions.

Do not connect the machine to the internet even temporarily to update packages or download software. Instead, transfer all required files via USB stick from a separate machine. This requires downloading Wasabi and any dependencies on your networked computer, verifying signatures, copying them to a USB drive, disconnecting that drive from the internet-connected machine, and then plugging it into the offline system. It is slower, but it ensures that no automatic update mechanism, DNS query, or metadata leak reveals anything about the offline environment to an external observer.

Physical security of the air-gapped machine matters as much as its network isolation. The device should be stored in a locked location when not in use, ideally in a safe or secure cabinet. USB ports should be covered or disabled through BIOS settings unless actively in use. Keyboard and mouse should be dedicated to that machine to prevent cross-contamination if the same peripherals are used on an internet-connected device. Document these practices as part of your setup procedure; consistency over time prevents lapses that defeat the entire exercise.

Installing Wasabi on the offline machine

Wasabi is an open-source secure Bitcoin wallet that runs on Windows, macOS, and Linux. For an air-gapped setup, Linux is the most straightforward because the application and all dependencies can be obtained and verified without relying on automatic update channels. Download the latest Wasabi release from the official repository on a networked machine, verify the GPG signature against the maintainers’ published keys, and transfer the signed installer or binary to a USB stick. Never trust an installer obtained from a third-party download site or mirror.

On the offline machine, extract the Wasabi installer and verify its integrity again using the same GPG keys. Install the application to a standard location such as `/opt/wasabi` and do not grant it root privileges or automatic update permissions. Wasabi can run as a regular user, and this principle of least privilege is important: if the application is compromised, it cannot easily escalate to system-level access. Create a dedicated user account for Wasabi if the offline machine will be used for other purposes.

Launch Wasabi and allow it to generate a new wallet file, but do not yet import any private keys or connect a hardware device. This first run establishes the local database structure, creates the Tor configuration, and initializes the application state. Exit Wasabi, then disconnect the machine’s USB stick and physically verify that it is no longer attached to the network-connected computer. At this point, the offline machine is ready to accept a hardware wallet connection but has not yet been exposed to any live Bitcoin addresses or transaction data.

Document the Wasabi version number, installation date, and checksum of the binary you used. This record will help you verify that the installation has not been modified and will guide any future updates or recovery. Store this documentation in a secure location separate from the offline machine itself, such as a paper file or an encrypted USB drive stored in a different building.

Integrating a hardware wallet while staying offline

A Ledger or Trezor hardware wallet acts as the actual Bitcoin private-key holder. When connected to the air-gapped Wasabi machine, it will be prompted to confirm each transaction, but it will never expose the private keys themselves to the computer. Wasabi can recognize and communicate with the hardware device through USB, retrieve the public keys and address information, and construct unsigned transactions. The hardware device signs the transaction internally and returns only the signature and signed transaction data—never the private key.

Before connecting the hardware wallet to the offline machine for the first time, initialize it on a separate, internet-connected device and write down the seed phrase on paper. Store this recovery information in a secure location such as a safe deposit box or home safe, not in any digital format. The hardware device should already be set up with a PIN code and, if desired, a passphrase. Verify that you can successfully recover from the seed phrase before relying on the hardware wallet for actual Bitcoin holdings.

Connect the hardware device to the offline machine via USB. Launch Wasabi and select the option to add a hardware wallet. The application will detect the connected device, retrieve the extended public key (which does not include the private key), and create wallet files that reference that extended public key. Multiple accounts or different derivation paths can be configured, each generating a separate set of receiving addresses but all controlled by the same hardware device. Document which derivation path you have chosen, as you will need this information to recover funds if the Wasabi wallet files are lost.

Test the wallet by asking Wasabi to display one of the generated addresses on the hardware device’s screen. The address should match exactly what Wasabi shows; this confirmation step prevents a malicious Wasabi installation from generating different addresses than the hardware device is actually protecting. Once verified, Wasabi now knows the public key structure but cannot create valid transactions without the hardware device to sign them.

Creating and transferring signed transactions between machines

The workflow for spending Bitcoin involves three steps across two computers. First, on the offline machine, Wasabi prepares an unsigned transaction containing all the details: input UTXOs, output addresses, amounts, and fees. Second, the hardware wallet signs this transaction after you physically confirm it on the device’s screen. Third, the signed transaction must be transferred to a networked machine and broadcast to the Bitcoin network.

The transfer mechanism is the critical chokepoint. USB cables should be used only to connect the hardware wallet, never to transfer data files between the two computers. Instead, use a dedicated USB stick that serves only as the transport medium between offline and online machines. On the offline Wasabi instance, export the signed transaction as a file (often named with a `.txn` extension or containing the raw transaction hex). Copy this file to the USB stick without copying any other data, metadata, or configuration files. Physically disconnect the USB stick, walk it to the networked machine, and import the signed transaction into a networked Wasabi instance or any Bitcoin broadcast tool.

The networked machine does not need Wasabi installed; it needs only a tool capable of broadcasting raw transactions to the Bitcoin network. Wasabi itself can serve this purpose if you install it on the internet-connected computer as well, but use a separate wallet file configured to only broadcast transactions and never store or manage private keys. Alternatively, use a command-line tool such as Bitcoin Core’s `sendrawtransaction` RPC call or a web-based tool such as blockchair.com’s transaction broadcast feature. The specific tool matters less than ensuring it accepts only the signed transaction hex and broadcasts it without modification.

Wait for the transaction to appear on the blockchain, which typically takes 10 minutes to an hour depending on network congestion and fees. Monitor the transaction using a block explorer such as Mempool.space or Blockchair on the networked machine, but verify the transaction ID on the offline machine as well by reviewing Wasabi’s transaction history. This cross-verification ensures that the correct transaction was broadcast and that no attacker intercepted the USB stick to modify the hex.

Protecting recovery and backup procedures

The recovery process is where many air-gapped setups fail. If the offline machine is lost, stolen, or damaged, you must be able to restore your Bitcoin using only the hardware wallet’s seed phrase and your documentation. Before moving significant value into this setup, perform a full recovery test: reset the hardware wallet to factory defaults, restore it from the seed phrase, and verify that Wasabi can recognize the same addresses and transaction history. Do this test using a small amount of Bitcoin, not your entire holdings.

Store the hardware wallet seed phrase on paper using a standard metal seed storage device (such as a Coldplate or SeedVault) rather than writing on regular paper, which can degrade. Keep this backup in a secure location entirely separate from both computers. Consider using a multi-signature setup where multiple hardware devices, each with different seed phrases, must all approve a transaction. This approach distributes key compromise risk: even if one device is stolen, an attacker cannot move the Bitcoin without also compromising the others.

Document the Wasabi wallet derivation path, the account index, and the extended public key in a secure format such as a laminated card or encrypted USB drive. This information allows recovery without the offline machine: if Wasabi itself becomes unavailable, you can use the extended public key to reconstruct the wallet in any compatible Bitcoin application. Never store this documentation with the seed phrase in the same location; if an attacker finds one, they should not automatically find both.

Update your recovery documentation whenever you make significant changes to the setup, such as upgrading Wasabi, connecting additional hardware wallets, or moving funds to a different derivation path. Every six months, review the documentation to ensure it remains accurate and that you have not forgotten the password or PIN protecting any of the devices. A recovery plan that nobody remembers how to execute is not a recovery plan.

Operational discipline and common mistakes

The two-computer setup creates friction by design. When that friction leads to shortcuts, the security benefit evaporates. Users often attempt to connect the offline machine to the internet “just once” to update Wasabi, or to skip the verification step for an address because they are in a hurry. Document your procedures in writing and follow them consistently, even when the motivation to cut corners is high. This is true whether you learn how to download and install Wasabi or set up any other security-critical system.

A common mistake is using the same USB stick for multiple purposes. A stick that transfers transaction data should not also be used to transfer music, documents, or files from the internet-connected machine. The risk of accidentally moving a malware-infected file is low but non-zero, and the operational cost of having a dedicated USB stick is minimal. Label the stick clearly and store it with the offline machine or in a secure location. Never leave USB sticks in public areas or plugged into shared computers.

Another frequent error is failing to physically disconnect peripherals between machines. If the same keyboard or mouse is used on both the offline and online computers without thorough disinfection, it theoretically could carry keystroke-logging malware from the networked machine to the offline one. This risk is small compared to direct network compromise, but using dedicated input devices for the offline machine is a low-cost control. Similarly, do not allow anyone else to use either machine, and do not use either machine for general-purpose tasks such as browsing or email.

Clock synchronization can cause subtle problems. If the offline machine’s system clock drifts significantly, Bitcoin transactions may be rejected by the network as too old, or hardware wallet PIN codes may expire. Synchronize the offline machine’s clock manually before creating transactions by noting the time from an external source (your phone, a wristwatch, or a wall clock) and adjusting the system time accordingly. This does not require internet connectivity; the clock only needs to be approximately accurate, within a few minutes.

When air-gapping is worth the effort

This level of complexity is appropriate for Bitcoin holdings that are meaningful enough to justify the operational overhead and significant enough to attract targeted attacks. A typical threshold might be holdings worth more than several hundred thousand dollars, or Bitcoin that you intend to hold for years without frequent transactions. For smaller amounts or frequent trading, the friction of the two-computer setup will eventually lead to shortcuts that undermine its security benefit.

The setup is also more valuable if you have reason to believe that your primary internet-connected computers may be targeted. If you work in a politically sensitive field, manage cryptocurrency professionally, or live in a jurisdiction where asset seizure is a realistic concern, the additional isolation provides meaningful protection. Conversely, if your primary threat model is casual theft or local compromise, a single hardware wallet stored in a safe is likely sufficient and far more practical.

An air-gapped machine is not a substitute for secure password management, two-factor authentication, or basic operational security on your internet-connected devices. It is a specialized control that reduces specific attack vectors while introducing new constraints. The decision to implement it should be made deliberately, based on your actual risk profile and your willingness to follow procedures consistently. A properly maintained setup can provide years of security; a half-implemented one may provide a false sense of security while adding little real protection.

The ultimate question is whether the benefit—reduced remote attack surface and elimination of network-based key compromise—justifies the cost in inconvenience, increased recovery complexity, and the ongoing discipline required to maintain operational security. For users who hold significant Bitcoin holdings and have the technical competence to manage an offline environment, the answer is often yes. For most users, a single hardware wallet stored securely and used with careful address verification provides adequate protection with far less friction.

Frequently asked questions

Can I connect my air-gapped machine to the internet just once to download Wasabi updates?

No. Any network connection defeats the air-gapping by design. Instead, download updates on a separate internet-connected computer, verify the GPG signature, transfer the file via USB stick, and manually update the offline installation. If you cannot commit to this procedure, air-gapping will not provide meaningful security because you will eventually cut corners.

What happens if I lose the air-gapped machine or it is stolen?

Your Bitcoin remains secure because the private keys are stored on the hardware wallet, not on the machine. Recover the funds by initializing a new hardware wallet from your seed phrase backup and restoring it in any compatible Bitcoin wallet application. This is why storing the seed phrase in a secure, separate location is essential. The Wasabi wallet files on the offline machine have no value to an attacker because they contain no private keys.

Is a two-computer setup more secure than a hardware wallet alone?

It provides different protections. A hardware wallet already keeps private keys isolated from any computer. An air-gapped Wasabi machine adds isolation at the transaction construction layer, reducing the risk that malware could intercept or modify unsigned transactions before the hardware wallet signs them. For most users, a hardware wallet is sufficient. Air-gapping is appropriate when holdings are large enough and your threat model specific enough to justify the operational complexity.

Leave a Reply

Artist

Jenny Wilson

recent post

instagram

follow us