WATS Wallet logoWATS Wallet
Technical8 min read

Hardware 2FA for Crypto: How a Tap Card Secures a Software Wallet

Software wallets are fast, but they live online. The WATS NFC Metal Card adds a hardware second factor — something you physically hold and tap — on top of your biometric unlock. Here is how hardware 2FA works for a wallet, and why a card that stores no keys is not the same thing as cold storage.

Hardware 2FA for a crypto wallet means requiring a second, physical factor — something you have — on top of the unlock already on your device, so that compromising one factor is not enough to get in. In practice that means pairing a biometric unlock (something you are) with an object you must physically hold and tap, so an attacker needs both at the same time. The WATS NFC Metal Card is exactly this kind of factor: you tap it to your phone to authenticate, and it stores no private keys — it authenticates to keys that stay inside the non-custodial WATS apps, where only you hold them and WATS never holds a key. Each card carries a unique card ID and pairs to exactly one device, which makes it closer to a physical security key than to a cold-storage vault.

Two-factor authentication is an old idea with a simple core: instead of trusting a single secret, combine factors from two different categories — something you know, something you have, something you are — so that stealing one of them is not enough. Crypto wallets have been slow to bring real hardware into that mix. Most software wallets lean on a password or a biometric — one factor, living entirely on a phone that is itself online. A hardware second factor changes that equation by adding something physical you must hold and tap. The WATS NFC Metal Card is exactly this kind of factor, and this article explains how hardware 2FA works for a wallet, what it protects against, and — just as importantly — what it does not.

What "hardware 2FA" means for a wallet

In a software wallet, the everyday unlock is usually a biometric: Face ID or a fingerprint, which is the "something you are" factor. That is good, but it all happens on one device. Hardware 2FA introduces a second, independent factor — "something you have" — in the form of a physical object. With WATS, that object is the NFC Metal Card. To authenticate, you tap the card to your phone, and the wallet now has evidence of two different things at once: your biometric on the device, and your physical possession of the card. An attacker has to defeat both together, rather than picking off one.

Why a software wallet benefits from a physical factor

The threats a software wallet faces are mostly remote and digital: phishing pages, malicious approvals, a compromised app, a stolen session. A physical tap is stubbornly resistant to that whole category, because you cannot phish a tap from the other side of the internet. A scammer who tricks you into a fake site still does not have your card, and cannot conjure the contactless handshake from afar. Adding a "something you have" factor narrows the attack surface to scenarios where someone has both your unlocked device and your physical card — a far higher bar than a stolen password.

How the WATS tap card works as a second factor

The card carries an embedded NTAG 216 chip and is specified with AES-128. When you tap, the phone and the card complete a short contactless handshake over ISO/IEC 14443 Type A at 13.56 MHz — a range of a few centimetres, which is itself part of the security story, since the card has to be in your hand at the phone. That handshake is tap-to-authenticate — the second factor in action, gating access to the wallet. Every card has a unique card ID and pairs to exactly one device, so a card only means anything next to the phone it was paired with. The body is military-grade metal rated IP68 and built to MIL-STD-810, because a factor you carry every day has to survive being carried. In the WATS Hot Wallet, which is fully non-custodial — you hold your own keys and your own recovery phrase, and WATS never holds a key — the tap stacks on top of your biometric unlock across every chain WATS supports: Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON. One physical factor, the same in front of all of them.

Think of it in layers:

  • Something you are. The biometric unlock proves it is you at the device.
  • Something you have. The card tap proves you are physically present with the paired card, which is the part remote attackers cannot fake.
  • Sole custody underneath both. Keys and recovery phrase live with you in the WATS apps. WATS never holds a key, so there is no company account to socially engineer and no back door that routes around the two factors.

Hardware 2FA is not cold storage — and that is the point

This is the distinction people most often blur, so here it is bluntly. A cold wallet stores your private keys offline and signs transactions inside the device; its whole job is to keep keys away from an online machine. The WATS NFC Metal Card does something different: it does not store keys at all. Your keys live in the non-custodial WATS apps, and the card secures access, not key custody — which makes it closer to a physical security key than to a cold-storage vault. That is not a weakness to apologise for; it is a deliberate design choice with a real upside. Because the card holds nothing, losing it is an inconvenience rather than a catastrophe, and a found card is inert metal in a stranger's hand. A device that holds your keys turns loss into disaster. A second factor that holds nothing does not.

What it protects against — and what it doesn't

Being honest about the threat model is what makes a security claim worth anything. Here is the plain version.

  • It helps against: remote phishing and unauthorised access on a device, because an attacker without the physical card is missing a required factor — including the everyday case of a phone left unlocked on a desk.
  • It does not help against: giving away your recovery phrase. The card is not your seed and cannot protect a seed you have already exposed. Treat the card as a second lock, never as a substitute for protecting your recovery phrase.
  • What it is not: WATS does not claim the card is a certified secure element or a tamper-proof key vault. It is an honestly described secured NFC authentication card. Conflating "secured NFC card" with "hardware key vault" is the most common mistake people make about cards like this.

Where to go next

For the security model in depth — the chip, the durability ratings and the card-loss scenario — read WATS NFC Metal Card security, explained. To see how a hardware factor fits a broader security routine, the WATS crypto wallet security best practices guide places it alongside seed backups, approval hygiene and phishing defence. And if you are weighing a tap factor against true offline storage, hot wallet vs cold wallet explains where each belongs.

If you want a hardware factor without moving your keys onto a separate signing device, the concrete setup that follows from all of the above is the WATS Hot Wallet on your phone with a WATS NFC Metal Card paired to it: a biometric for something you are, a tap for something you have, and private keys that never leave your own hands.

Frequently asked questions

Is the WATS NFC card the same as a cold or hardware wallet?

No. WATS is explicit about this: the NFC Metal Card stores no private keys at all. A cold or hardware wallet keeps keys offline and signs inside the device, whereas the WATS card is a hardware second factor that authenticates you to keys held in the non-custodial WATS apps — closer to a physical security key than to a cold-storage vault.

Can a hardware second factor be phished?

Not remotely. Tapping the WATS NFC Metal Card requires physical possession of the card and a real contactless handshake with the one device it is paired to, so a scammer on a fake website cannot reproduce it. The card does not protect a recovery phrase you have already given away, though — it guards access, not your seed.

Does the card replace my biometric unlock?

No, it layers on top of it. Biometric unlock is "something you are" on the device; the card tap is "something you have". Using both means an attacker has to defeat two independent factors at once instead of one.

What happens if I lose the WATS NFC card?

Losing the WATS NFC Metal Card does not put your funds at risk, because the card holds no private keys — to anyone who finds it, it is inert metal, and it carries a unique card ID paired to exactly one device. Your keys and recovery phrase stay where they always were: in the non-custodial WATS apps, under your control.