[{"data":1,"prerenderedAt":19},["ShallowReactive",2],{"blog-content-en-nfc-metal-card-security":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9},"nfc-metal-card-security","WATS NFC Metal Card security, explained","What the card is (a tap-to-authenticate companion) and is not (key storage), the NTAG 216 + AES-128 chip, one-device pairing, and what happens if you lose it.","A first-hand technical explanation of WATS NFC Metal Card security: the NTAG 216 + AES-128 chip and contactless handshake, ISO\u002FIEC 14443, physical durability, one-device pairing, and the card-loss scenario.","\u003Cp>\r\n      The WATS NFC Metal Card is one of the most misunderstood objects in the WATS\r\n      ecosystem. It looks like a cold wallet, it feels like a cold wallet, and the\r\n      brushed-steel weight in your hand \u003Cem>wants\u003C\u002Fem> you to believe it is holding your\r\n      private keys. It is not. Understanding precisely what this card does — and, just as\r\n      importantly, what it does not do — is the single most useful thing you can learn\r\n      before you tap it against your phone. This deep-dive walks through the chip, the\r\n      contactless handshake, the physical build, how the card pairs to a single device, and the one scenario everyone worries about: losing it.\r\n    \u003C\u002Fp>\r\n\r\n    \u003Ch2>What the card is — and what it isn't\u003C\u002Fh2>\r\n    \u003Cp>\r\n      The WATS NFC Metal Card is a \u003Cstrong>tap-to-authenticate companion\u003C\u002Fstrong>. Its job\r\n      is to authenticate access to your WATS wallet and to enable NFC tap-to-sign: you bring\r\n      the card to your phone, the app reads it over the contactless interface, and that tap\r\n      becomes a physical confirmation for an action you have already initiated inside the\r\n      app.\r\n    \u003C\u002Fp>\r\n    \u003Cp>\r\n      What the card is \u003Cstrong>not\u003C\u002Fstrong> is equally important. It is\r\n      \u003Cstrong>not key storage\u003C\u002Fstrong>. It is \u003Cstrong>not a standalone cold wallet\u003C\u002Fstrong>.\r\n      There is no private key sitting inside the card waiting to be extracted, and you cannot\r\n      use the card on its own — without the WATS app — to move funds. Your private keys live\r\n      in the non-custodial WATS applications: the WATS mobile app and the WATS Chrome\r\n      extension. The card never becomes the home of your keys, which is exactly why it can be\r\n      thrown in a wallet, dropped in a drawer, or carried through an airport without that\r\n      being the same thing as carrying your seed phrase around.\r\n    \u003C\u002Fp>\r\n    \u003Cblockquote>\r\n      Think of the card as a key to a door, not the vault behind it. Tapping it proves you\r\n      are present and authorised. The vault — your keys — stays in the non-custodial WATS\r\n      apps, under your control, the whole time.\r\n    \u003C\u002Fblockquote>\r\n\r\n    \u003Ch2>The chip and the handshake\u003C\u002Fh2>\r\n    \u003Cp>\r\n      Inside the metal body sits an embedded \u003Cstrong>NTAG 216\u003C\u002Fstrong> chip, an\r\n      \u003Cstrong>NFC Forum Type 4\u003C\u002Fstrong> tag. The contactless interface follows\r\n      \u003Cstrong>ISO\u002FIEC 14443\u003C\u002Fstrong> and operates at \u003Cstrong>13.56 MHz\u003C\u002Fstrong>, the same\r\n      proximity-card frequency used by transit passes and contactless payment cards. When you\r\n      tap, the phone's NFC reader and the card complete a short contactless handshake, and\r\n      that handshake is secured with \u003Cstrong>AES-128\u003C\u002Fstrong> so the exchange between card\r\n      and app cannot be trivially replayed or spoofed by a casual eavesdropper.\r\n    \u003C\u002Fp>\r\n    \u003Cp>\r\n      It is worth being plain about what this hardware is. The NTAG 216 with AES-128 is a\r\n      \u003Cstrong>secured NFC tag\u003C\u002Fstrong>, not a private-key vault. The AES-128 encryption\r\n      protects the \u003Cem>contactless handshake\u003C\u002Fem> — the authentication exchange — rather than\r\n      guarding a secret signing key etched into silicon. We deliberately do not claim the card\r\n      contains a certified secure element, and we do not market it as tamper-proof\r\n      key-storage hardware, because it is neither. It is an honest, well-built authentication\r\n      tag. Conflating \"secured NFC tag\" with \"hardware key vault\" is the most common mistake\r\n      people make about cards like this one, and we would rather you understood the real\r\n      threat model than be reassured by a label that does not apply.\r\n    \u003C\u002Fp>\r\n\r\n    \u003Ch2>Physical durability\u003C\u002Fh2>\r\n    \u003Cp>\r\n      Where the card genuinely earns its \"metal\" name is the physical build. The steel\r\n      variant is engineered to survive far more than a paper backup or a printed plastic card\r\n      ever could. It is rated \u003Cstrong>IP68\u003C\u002Fstrong>, meaning it can sit submerged at\r\n      \u003Cstrong>1.5 m for 30 minutes\u003C\u002Fstrong> without water ingress, and it is built to\r\n      \u003Cstrong>MIL-STD-810\u003C\u002Fstrong> tolerances across an operating range of\r\n      \u003Cstrong>-40&nbsp;&deg;C to +85&nbsp;&deg;C\u003C\u002Fstrong>. It also carries\r\n      \u003Cstrong>EMI and radiation shielding\u003C\u002Fstrong>, which matters for a contactless device you\r\n      want to behave predictably and resist stray interference.\r\n    \u003C\u002Fp>\r\n    \u003Ctable>\r\n      \u003Cthead>\r\n        \u003Ctr>\r\n          \u003Cth>Property\u003C\u002Fth>\r\n          \u003Cth>Specification\u003C\u002Fth>\r\n        \u003C\u002Ftr>\r\n      \u003C\u002Fthead>\r\n      \u003Ctbody>\r\n        \u003Ctr>\r\n          \u003Ctd>Water resistance\u003C\u002Ftd>\r\n          \u003Ctd>IP68 (submersible 1.5 m \u002F 30 min)\u003C\u002Ftd>\r\n        \u003C\u002Ftr>\r\n        \u003Ctr>\r\n          \u003Ctd>Durability standard\u003C\u002Ftd>\r\n          \u003Ctd>MIL-STD-810, -40&nbsp;&deg;C to +85&nbsp;&deg;C\u003C\u002Ftd>\r\n        \u003C\u002Ftr>\r\n        \u003Ctr>\r\n          \u003Ctd>Shielding\u003C\u002Ftd>\r\n          \u003Ctd>EMI \u002F radiation shielding\u003C\u002Ftd>\r\n        \u003C\u002Ftr>\r\n        \u003Ctr>\r\n          \u003Ctd>NFC chip\u003C\u002Ftd>\r\n          \u003Ctd>NTAG 216, NFC Forum Type 4\u003C\u002Ftd>\r\n        \u003C\u002Ftr>\r\n        \u003Ctr>\r\n          \u003Ctd>Standard \u002F frequency\u003C\u002Ftd>\r\n          \u003Ctd>ISO\u002FIEC 14443, 13.56 MHz\u003C\u002Ftd>\r\n        \u003C\u002Ftr>\r\n        \u003Ctr>\r\n          \u003Ctd>Handshake encryption\u003C\u002Ftd>\r\n          \u003Ctd>AES-128\u003C\u002Ftd>\r\n        \u003C\u002Ftr>\r\n        \u003Ctr>\r\n          \u003Ctd>Weight\u003C\u002Ftd>\r\n          \u003Ctd>Steel ~22 g \u002F polycarbonate ~5 g\u003C\u002Ftd>\r\n        \u003C\u002Ftr>\r\n      \u003C\u002Ftbody>\r\n    \u003C\u002Ftable>\r\n    \u003Cp>\r\n      The card ships in two materials: a brushed stainless-steel version that weighs around\r\n      \u003Cstrong>22 g\u003C\u002Fstrong> and feels like a premium object, and a lighter polycarbonate\r\n      version at around \u003Cstrong>5 g\u003C\u002Fstrong> for people who would rather carry something\r\n      barely-there. Both run the same NTAG 216 chip and the same contactless behaviour — the\r\n      choice is about weight and feel, not about how the authentication works.\r\n    \u003C\u002Fp>\r\n\r\n    \u003Ch2>Self-custody and one-device card pairing\u003C\u002Fh2>\r\n    \u003Cp>\r\n      Here is the part most people conflate, so let's separate it cleanly. Every WATS product — the Chrome extension, the mobile app and the Hot Wallet — is \u003Cstrong>self-custody\u003C\u002Fstrong>: you hold your own keys, and WATS never holds a key. The NFC card is a different kind of security mechanism that lives in the same ecosystem, and it is worth understanding on its own terms.\r\n    \u003C\u002Fp>\r\n    \u003Cp>\r\n      What actually makes the card a distinct security layer is \u003Cstrong>one-device pairing\u003C\u002Fstrong>. Each WATS NFC Metal Card carries a unique ID, and the first time you tap it to your phone in the WATS mobile app, the card pairs with that specific device. From then on it works only with that paired phone — a lost or found card is useless against any other device. That is what turns the tap into a genuine \u003Cstrong>physical tap-to-authenticate second factor\u003C\u002Fstrong> (hardware 2FA); it proves physical presence, and it says nothing about where your keys are stored.\r\n    \u003C\u002Fp>\r\n    \u003Cp>\r\n      The card relates to your wallet as an \u003Cem>additional\u003C\u002Fem> layer rather than a replacement for self-custody. When you use it, the tap adds a \u003Cstrong>physical hardware confirmation step on top of your biometric unlock\u003C\u002Fstrong> — Face ID or fingerprint gets you into the app, and the card tap is a second, tangible \"yes, I am here and I authorise this\" gesture before an action goes through. So the layers stack like this: biometric unlock proves it is you on the device, and the card tap proves you physically hold the companion paired to that phone. Throughout, your keys stay with you — the card strengthens the front door without ever becoming the vault. They complement each other; they are not the same thing.\r\n    \u003C\u002Fp>\r\n\r\n    \u003Ch2>The card-loss scenario\u003C\u002Fh2>\r\n    \u003Cp>\r\n      The honest version of the threat model is reassuring precisely because the card was\r\n      never your keys. If you lose the card, you have not lost your wallet, and nobody who\r\n      finds it can drain your funds with it. Here is what actually happens, in order:\r\n    \u003C\u002Fp>\r\n    \u003Col>\r\n      \u003Cli>\r\n        \u003Cstrong>The card is not your only key, so losing it does not move funds.\u003C\u002Fstrong>\r\n        It cannot sign a transaction on its own — your keys remain in the non-custodial WATS\r\n        apps, and the card only ever works with the phone it was paired to. A found card, in isolation, is an inert piece of metal.\r\n      \u003C\u002Fli>\r\n      \u003Cli>\r\n        \u003Cstrong>Keep using the WATS mobile app or Chrome extension.\u003C\u002Fstrong> Your access does\r\n        not depend on the physical card. You can continue to send, receive, swap and manage\r\n        your wallet through the apps exactly as before while you sort out a replacement.\r\n      \u003C\u002Fli>\r\n      \u003Cli>\r\n        \u003Cstrong>Order a replacement card from the WATS store.\u003C\u002Fstrong> A new card is a\r\n        new authentication companion you can pair to your existing wallet; it restores the\r\n        tap-to-authenticate and tap-to-sign convenience you lost.\r\n      \u003C\u002Fli>\r\n      \u003Cli>\r\n        \u003Cstrong>Follow the WATS docs for the exact recovery steps.\u003C\u002Fstrong> The precise\r\n        flow for re-pairing a replacement and revoking the old card is documented and may be\r\n        updated over time, so treat the official WATS documentation — not this article — as\r\n        the authoritative, step-by-step source.\r\n      \u003C\u002Fli>\r\n    \u003C\u002Fol>\r\n    \u003Cp>\r\n      The reason we can frame card loss so calmly is the same reason we refuse to call the\r\n      card a cold wallet: it was designed to \u003Cem>not\u003C\u002Fem> be a single point of failure. A\r\n      device that holds your keys turns loss into catastrophe. An authentication companion\r\n      turns loss into an inconvenience.\r\n    \u003C\u002Fp>\r\n\r\n    \u003Ch2>Where to go next\u003C\u002Fh2>\r\n    \u003Cp>\r\n      If you want the product-level overview of the card — materials, finishes and how to get\r\n      one — start at the \u003Ca href=\"\u002Fnfc-card\">WATS NFC Metal Card page\u003C\u002Fa>. If you are weighing\r\n      this tap-to-authenticate approach against key-storage cold cards from other vendors and\r\n      trying to decide which philosophy fits your own threat model, read our companion guide,\r\n      \u003Ca href=\"\u002Fblog\u002Fbest-web3-wallets-nfc-metal-card\">Best Web3 wallets with an NFC metal\r\n      card\u003C\u002Fa>, which lays the two designs side by side without pretending one is universally\r\n      better than the other.\r\n    \u003C\u002Fp>",[10,13,16],{"q":11,"a":12},"Does the WATS NFC Metal Card store my private keys?","No. The card is a tap-to-authenticate companion and a secured NFC tag — it does not hold\r\n      your private keys. Your keys live in the non-custodial WATS mobile app and Chrome\r\n      extension, and the card simply authenticates access and enables NFC tap-to-sign.",{"q":14,"a":15},"If someone finds my card, can they steal my funds?","No. The card cannot move funds on its own. It is not a standalone cold wallet, your keys stay in the non-custodial WATS apps, and the card only works with the phone it was paired to on first tap. A lost card, by itself, cannot drain a wallet.",{"q":17,"a":18},"Is the card a hardware secure element or a certified cold wallet?","No. It is an embedded NTAG 216 (NFC Forum Type 4) tag whose contactless handshake is\r\n      secured with AES-128 over ISO\u002FIEC 14443 at 13.56 MHz. We describe it accurately as a\r\n      secured NFC authentication card, not as a certified secure-element key vault.",1784634270845]