Two-factor authentication is an old idea with a simple core: to prove who you are, combine something you know, something you are, and something you have. Crypto wallets have been slow to bring real hardware into that mix. Most software wallets lean on a password or a biometric — one factor, living entirely on a phone that is itself online. A hardware second factor changes that equation by adding something physical you must hold and tap. The WATS NFC Metal Card is exactly this kind of factor, and this article explains how hardware 2FA works for a wallet, what it protects against, and — just as importantly — what it does not.
What "hardware 2FA" means for a wallet
In a software wallet, the everyday unlock is usually a biometric: Face ID or a fingerprint, which is the "something you are" factor. That is good, but it all happens on one device. Hardware 2FA introduces a second, independent factor — "something you have" — in the form of a physical object. With WATS, that object is the NFC Metal Card. To authenticate, you tap the card to your phone; the wallet now has evidence of two different things at once: your biometric on the device, and your physical possession of the card. An attacker has to defeat both, together, rather than picking off one.
Why a software wallet benefits from a physical factor
The threats a software wallet faces are mostly remote and digital: phishing pages, malicious approvals, a compromised app, a stolen session. A physical tap is stubbornly resistant to that whole category, because you cannot phish a tap from the other side of the internet. A scammer who tricks you into a fake site still does not have your card, and cannot conjure the contactless handshake from afar. Adding a "something you have" factor narrows the attack surface to scenarios where someone has both your unlocked device and your physical card — a far higher bar than a stolen password.
How the WATS tap card works as a second factor
The card carries an embedded NTAG 216 chip (NFC Forum Type 4). When you tap, the phone and the card complete a short contactless handshake over ISO/IEC 14443 at 13.56 MHz, secured with AES-128 so the exchange cannot be trivially replayed by a casual eavesdropper. That handshake is the second factor in action. It does two jobs: tap-to-authenticate, which gates access to the wallet, and tap-to-sign, which adds a physical confirmation step to a transaction you have already initiated. In the WATS Hot Wallet, which is fully non-custodial — you hold your own keys and your own seed phrase, and WATS never holds a key — this stacks on top of your biometric unlock, so you end up with biometric and physical tap reinforcing one another while signing authority stays entirely yours.
Think in layers. Biometric proves it is you on the device. The card tap proves you are physically present with the companion. Non-custodial control means your keys and seed phrase never leave your hands, so no one but you can settle a transaction. Each layer covers a gap the others leave open.
Hardware 2FA is not cold storage — and that is the point
This is the distinction people most often blur, so let us be blunt. A cold wallet stores your private keys offline and signs transactions inside the device; its whole job is to keep keys away from an online machine. The WATS tap card does something different: it does not store keys at all. Your keys live in the non-custodial WATS apps. The card secures access and authorisation, not key custody. That is not a weakness to apologise for — it is a deliberate design choice with a real upside. Because the card holds nothing, losing it is an inconvenience, not a catastrophe; a found card is inert metal. A device that holds your keys turns loss into disaster. A second factor that holds nothing turns loss into a replacement order.
What it protects against — and what it doesn't
Being honest about the threat model is what makes a security claim worth anything. Here is the plain version.
- It helps against: remote phishing and unauthorised access on a device, because an attacker without the physical card is missing a required factor; and casual transaction approval, because signing now needs a deliberate physical tap.
- It does not help against: giving away your recovery phrase. The card is not your seed and cannot protect a seed you have already exposed. Treat the card as a second lock, never as a substitute for protecting your recovery phrase.
- What it is not: we do not claim the card is a certified secure element or tamper-proof key vault. It is an honestly described secured NFC authentication tag. Conflating "secured NFC tag" with "hardware key vault" is the most common mistake people make about cards like this.
Where to go next
For the security model in depth — the chip, durability and the card-loss scenario — read WATS NFC Metal Card security, explained. To see how a hardware factor fits a broader security routine, our crypto wallet security best practices guide places it alongside seed backups, approval hygiene and phishing defence. And if you are weighing a tap factor against true offline storage, hot wallet vs cold wallet explains where each belongs.
Frequently asked questions
Is the WATS NFC card the same as a cold or hardware wallet?
No. A cold or hardware wallet stores your private keys offline and signs inside the device. The WATS card stores no keys — it is a hardware second factor that authenticates access and adds a physical tap to sign. Your keys stay in the non-custodial WATS apps.
Can a hardware second factor be phished?
Not remotely. A tap requires physical possession of the card and a real contactless handshake with your phone, so a scammer on a fake website cannot reproduce it. The card does not protect a recovery phrase you have already given away, though — it guards access, not your seed.
Does the card replace my biometric unlock?
No, it layers on top of it. Biometric unlock is "something you are" on the device; the card tap is "something you have". Using both means an attacker has to defeat two independent factors at once instead of one.

