[{"data":1,"prerenderedAt":41},["ShallowReactive",2],{"blog-content-en-secure-web3-accounts-with-nfc-cards":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9,"howToSteps":22},"secure-web3-accounts-with-nfc-cards","How to Secure Your Web3 Accounts Using NFC Cards: The Complete Guide","An NFC card turns 'something you know' into 'something you hold.' Here's how tap-to-authenticate hardens your Web3 accounts, step by step — and what it does and doesn't protect.","How to secure your Web3 accounts using NFC cards: how tap-to-authenticate adds a hardware factor, a step-by-step setup, and what an NFC card does and doesn't protect.","\u003Cp>To secure your Web3 accounts with an NFC card, use the card as a physical \u003Cem>something you hold\u003C\u002Fem> factor that your wallet must tap before it unlocks or signs. That way a stolen password, a leaked seed, or a compromised device acting alone is no longer enough to move your funds, because the attacker also needs the physical card in hand. In short: choose the right card type for your goal, pair it to your wallet, turn on tap-to-authenticate, set up a backup plan, and always verify a transaction before you tap.\u003C\u002Fp>\n\u003Cp>This guide first clears up a common confusion between two very different kinds of NFC card, then focuses on using a card as a hardware factor. We use the \u003Ca href=\"\u002Fnfc-card\">WATS NFC Metal Card\u003C\u002Fa> as the worked example throughout, but the principles apply to any tap-to-authenticate companion.\u003C\u002Fp>\n\u003Ch2>First, know which kind of NFC card you have\u003C\u002Fh2>\n\u003Cp>\"NFC card\" describes the connection method, not the security model. Two categories share the same tap gesture but do completely different jobs, and mixing them up leads to bad security decisions.\u003C\u002Fp>\n\u003Ch3>Cold key-storage cards\u003C\u002Fh3>\n\u003Cp>A cold NFC card, such as a Tangem card, actually stores your private keys on a secure element inside the card and signs transactions offline. The keys never leave the card, there is often no seed phrase, and the card itself is the wallet. If you lose every copy of that card and have no backup card, you can lose access to the funds it controls. These cards are a form of cold storage.\u003C\u002Fp>\n\u003Ch3>Tap-to-authenticate companion cards\u003C\u002Fh3>\n\u003Cp>A companion card, such as the \u003Ca href=\"\u002Fnfc-card\">WATS NFC Metal Card\u003C\u002Fa>, does \u003Cstrong>not\u003C\u002Fstrong> store your private keys and is \u003Cstrong>not\u003C\u002Fstrong> a cold wallet. Your keys stay inside your non-custodial WATS apps. The card is a physical factor: when your wallet asks you to tap, the card proves you physically possess it, which authorizes the unlock or the signature. Think of it like a hardware key for your accounts rather than the vault where your coins live.\u003C\u002Fp>\n\u003Cp>This guide is about the second use: \u003Cstrong>using an NFC card as a hardware factor\u003C\u002Fstrong> to harden accounts you already control in a software wallet. If your goal is offline cold storage instead, a cold key-storage card or a dedicated hardware device like Ledger is the right tool, and our overview of \u003Ca href=\"\u002Fblog\u002Fare-metal-crypto-wallets-worth-it\">whether metal crypto wallets are worth it\u003C\u002Fa> is a better starting point.\u003C\u002Fp>\n\u003Ch2>Why a hardware factor actually helps\u003C\u002Fh2>\n\u003Cp>Most Web3 accounts are protected by a single secret: a password, a PIN, or a seed phrase. Anything a determined attacker can copy remotely is a single point of failure. Add a physical card and you split authentication across two categories that are hard to compromise at once: \u003Cem>something you know\u003C\u002Fem> (your unlock method) and \u003Cem>something you hold\u003C\u002Fem> (the card). This is the same logic behind \u003Ca href=\"\u002Fblog\u002Fhardware-2fa-crypto-wallet\">hardware two-factor authentication for a crypto wallet\u003C\u002Fa>, applied with a tap instead of a plugged-in dongle.\u003C\u002Fp>\n\u003Cp>The practical effect is that an attacker who phishes your password, clones your SIM, or gets a few minutes alone with your unlocked-looking phone still cannot approve a high-value action, because the card is not in their possession. That is a meaningful upgrade over a password-only account.\u003C\u002Fp>\n\u003Ch2>What an NFC card protects (and what it does not)\u003C\u002Fh2>\n\u003Cp>Being honest about the threat model matters. A hardware factor is powerful against some attacks and largely irrelevant to others. Do not let a card give you false confidence.\u003C\u002Fp>\n\u003Ch3>Threats a tap-to-authenticate card mitigates\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Remote malware acting alone.\u003C\u002Fstrong> Software that lands on your device cannot tap a card it does not physically have, so it cannot complete an action that requires the tap.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SIM-swap and password theft.\u003C\u002Fstrong> Taking over your phone number or guessing your password no longer grants access on its own, because the missing factor is a physical object an attacker cannot copy over the air.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Casual device access.\u003C\u002Fstrong> Someone who grabs your phone for a moment, or a snooping housemate, cannot sign without also holding the card that lives separately from the device.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Credential reuse.\u003C\u002Fstrong> If a password you reused leaks in an unrelated breach, it is still not enough to move funds by itself.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>What it does NOT fully stop\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Blind-signing a malicious transaction.\u003C\u002Fstrong> If a scam dApp tricks you into approving a harmful transaction and you tap to confirm it, the card faithfully authorizes exactly what you approved. The card verifies \u003Cem>you\u003C\u002Fem>, not the honesty of the request. You still have to read what you sign.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Losing your only card copy.\u003C\u002Fstrong> A physical factor you cannot replace becomes a physical point of failure. Without a recovery plan or a second card, a lost card can lock you out of the factor.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Coercion or theft of both factors together.\u003C\u002Fstrong> If someone takes your device and your card at the same time, or forces you to tap, the second factor no longer helps. Physical separation is part of the protection.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Compromise of the underlying keys.\u003C\u002Fstrong> If your seed phrase is already exposed elsewhere, an attacker may be able to import it into their own wallet entirely outside your card. A companion card guards access to \u003Cem>your\u003C\u002Fem> app; it cannot un-leak a secret that has already left it.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The takeaway: a tap-to-authenticate card is excellent at blocking remote and casual attackers, and it is not a substitute for careful signing or good seed hygiene. It raises the floor; it does not remove your responsibility.\u003C\u002Fp>\n\u003Ch2>How to secure your Web3 accounts with an NFC card: the step-by-step\u003C\u002Fh2>\n\u003Cp>Follow these six steps in order. They mirror how you would set up the \u003Ca href=\"\u002Fnfc-card\">WATS NFC Metal Card\u003C\u002Fa>, and the same shape applies to most companion cards.\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Choose a card type for your goal.\u003C\u002Fstrong> Decide first whether you want a hardware factor for an existing software wallet or true offline cold storage. For hardening day-to-day accounts you actively use, a tap-to-authenticate companion like the WATS card fits; for deep cold storage of funds you rarely touch, choose a key-storing cold card or hardware device instead. Getting this decision right up front prevents the wrong-tool frustration later.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Install the wallet app.\u003C\u002Fstrong> Install the non-custodial wallet the card works with. For the WATS card, that is the \u003Ca href=\"\u002Fdownload\">WATS Mobile App\u003C\u002Fa> on iOS 15+ or Android 9+, which supports biometric unlock and NFC tap-to-sign. Create or import your wallet and confirm you have securely recorded any recovery material before you attach a hardware factor on top.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Pair the card (tap).\u003C\u002Fstrong> Open the card or security section of the app and follow the pairing flow, holding the card to the back of your phone when prompted so the NFC chip is read. Pairing links this specific physical card to your wallet so future taps are recognized. If the tap does not register, reposition the card over the phone's NFC antenna and try again.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enable tap-to-authenticate \u002F tap-to-sign.\u003C\u002Fstrong> Turn on the setting that requires a card tap to unlock the wallet or to confirm signing. From now on, sensitive actions ask for the physical card in addition to your biometric or PIN, which is exactly the two-factor upgrade you are after. Decide which actions must require a tap based on how strict you want to be.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Set up a backup and recovery plan.\u003C\u002Fstrong> Because the card is a physical factor, plan for losing it before it happens. Keep your wallet's recovery method safe and offline, and if the product is sold as a set, store the second card in a separate secure location so a single loss does not lock you out. The WATS card is sold in a multi-card set from the store precisely so you have a spare.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Practice safe signing (verify the transaction before you tap).\u003C\u002Fstrong> The tap is your final confirmation, so treat it as one. Before tapping, read the transaction details: the destination, the amount, the network, and any token approvals. If anything looks wrong or unexpected, do not tap. A hardware factor only helps if you refuse to authorize bad requests.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>For a product-specific walkthrough with screenshots, follow our guide on \u003Ca href=\"\u002Fblog\u002Fhow-to-set-up-nfc-metal-card\">how to set up the NFC Metal Card\u003C\u002Fa>, and for a deeper look at the card's construction and chip security, see \u003Ca href=\"\u002Fblog\u002Fnfc-metal-card-security\">NFC Metal Card security\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>What makes a companion card trustworthy\u003C\u002Fh2>\n\u003Cp>Not all NFC cards are equally serious. When you evaluate one as a hardware factor, look at both the chip and the build.\u003C\u002Fp>\n\u003Cp>On the chip side, the WATS NFC Metal Card uses an NTAG 216 chip (NFC Forum Type 4) with AES-128 and operates over ISO\u002FIEC 14443 at 13.56 MHz. Those are established, standards-based NFC specifications, and AES-128 backs the authentication rather than leaving the tap easy to clone. Crucially, the chip authenticates; it does not hold your private keys, which remain in the non-custodial WATS apps.\u003C\u002Fp>\n\u003Cp>On the build side, a hardware factor is only useful if it survives daily life. The WATS card is CR-80 credit-card size in steel (around 22 g) or polycarbonate (around 5 g), rated IP68 waterproof, MIL-STD-810 durable across a wide temperature range, and EMI-shielded. A card you can carry in a wallet without babying it is a card you will actually keep with you, which is the whole point of a physical factor.\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\u003Cth>Card type\u003C\u002Fth>\u003Cth>Where keys live\u003C\u002Fth>\u003Cth>Primary job\u003C\u002Fth>\u003Cth>If you lose it\u003C\u002Fth>\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\u003Ctd>Tap-to-authenticate companion (e.g. WATS NFC Metal Card)\u003C\u002Ftd>\u003Ctd>In your non-custodial app, not on the card\u003C\u002Ftd>\u003Ctd>Physical factor to unlock and sign\u003C\u002Ftd>\u003Ctd>Recover via your wallet's recovery method or a spare card\u003C\u002Ftd>\u003C\u002Ftr>\n\u003Ctr>\u003Ctd>Cold key-storage card (e.g. Tangem)\u003C\u002Ftd>\u003Ctd>On the card's secure element\u003C\u002Ftd>\u003Ctd>Store keys and sign offline\u003C\u002Ftd>\u003Ctd>Restore from a backup card; the card is the wallet\u003C\u002Ftd>\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003Ch2>Where a companion card fits alongside other WATS security\u003C\u002Fh2>\n\u003Cp>A tap-to-authenticate card is one layer, and it pairs naturally with others. In the WATS Mobile App it sits on top of biometric unlock and push notifications so you both authorize actions physically and get alerted to them. It is worth being clear about how the card relates to WATS's other products. Every WATS product is self-custody: the Chrome extension, the mobile app, and the \u003Ca href=\"\u002Fhot-wallet\">WATS Hot Wallet\u003C\u002Fa> all keep your keys with you, and WATS never holds a key. The Hot Wallet's own distinguishing feature is its single ATS fee token, which lets every action be paid in one token instead of juggling native gas on each network. The NFC card is a different kind of layer: a physical possession factor that pairs with one device and works only with that phone as tap-to-authenticate 2FA. You can benefit from all of them, and they solve different problems. If you want the full picture of how these pieces combine, our \u003Ca href=\"\u002Fsecurity\">security overview\u003C\u002Fa> lays them out.\u003C\u002Fp>\n\u003Ch2>Common mistakes to avoid\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Treating a companion card as cold storage.\u003C\u002Fstrong> It authenticates; it does not hold keys. If you need offline key storage, that is a different product.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Storing your only card with your phone.\u003C\u002Fstrong> Two factors kept in the same pocket are effectively one factor. Separate them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Skipping the recovery plan.\u003C\u002Fstrong> A physical factor with no backup is a lockout waiting to happen. Sort recovery before you rely on the card.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Tapping without reading.\u003C\u002Fstrong> The card confirms your intent. If you tap on autopilot, you can still authorize a malicious transaction.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Bottom line\u003C\u002Fh2>\n\u003Cp>An NFC card secures your Web3 accounts by adding a physical \u003Cem>something you hold\u003C\u002Fem> factor, so a stolen password, a swapped SIM, or a lone piece of malware can no longer sign for you. First make sure you have the right kind of card: a tap-to-authenticate companion like the \u003Ca href=\"\u002Fnfc-card\">WATS NFC Metal Card\u003C\u002Fa> hardens a software wallet whose keys stay in your non-custodial apps, while a cold key-storage card is for offline storage instead. Choose the right type, install the wallet, pair the card, enable tap-to-sign, plan your recovery, and always verify a transaction before you tap. Do that, and a card meaningfully raises your security floor, as long as you remember it protects access, not the honesty of what you approve.\u003C\u002Fp>",[10,13,16,19],{"q":11,"a":12},"Does an NFC card store my private keys or my crypto?","It depends on the card type. A cold key-storage card such as Tangem stores your keys on the card and signs offline. A tap-to-authenticate companion like the WATS NFC Metal Card does not store keys or hold crypto; your keys stay in your non-custodial WATS apps, and the card only acts as a physical factor that authorizes unlocking and signing.",{"q":14,"a":15},"What happens if I lose my NFC card?","With a companion card, losing it removes your physical factor but not your funds, because the keys live in your wallet app and you recover access through your wallet's recovery method. This is why the WATS card is sold as a set, so you can keep a spare in a separate location. With a cold key-storage card, the card is the wallet, so you must restore from a backup card to regain access.",{"q":17,"a":18},"Can an NFC card stop me from getting phished or signing a scam transaction?","No, and it is important not to assume otherwise. If you approve a malicious transaction, the card faithfully authorizes exactly what you confirmed, because it verifies that you are present rather than whether the request is safe. The card blocks remote and casual attackers, but you still have to read the destination, amount, and approvals before you tap.",{"q":20,"a":21},"How is tapping an NFC card different from a normal password or seed phrase?","A password or seed phrase is something you know, which a determined attacker can copy remotely through phishing or a breach. An NFC card is something you hold, a physical object that cannot be copied over the air. Requiring both means an attacker needs your knowledge and your physical card at once, which is far harder than compromising a single secret.",[23,26,29,32,35,38],{"title":24,"body":25},"Choose a card type for your goal","Decide whether you want a hardware factor for an existing software wallet or true offline cold storage. A tap-to-authenticate companion like the WATS NFC Metal Card fits day-to-day accounts you actively use, while a key-storing cold card suits deep cold storage. Getting this decision right first avoids wrong-tool frustration later.",{"title":27,"body":28},"Install the wallet app","Install the non-custodial wallet the card works with; for the WATS card that is the WATS Mobile App on iOS 15+ or Android 9+, with biometric unlock and NFC tap-to-sign. Create or import your wallet and confirm you have securely recorded any recovery material before adding a hardware factor on top.",{"title":30,"body":31},"Pair the card (tap)","Open the card or security section of the app and follow the pairing flow, holding the card to the back of your phone when prompted so the NFC chip is read. Pairing links this specific card to your wallet so future taps are recognized. If the tap does not register, reposition the card over the phone's NFC antenna and try again.",{"title":33,"body":34},"Enable tap-to-authenticate \u002F tap-to-sign","Turn on the setting that requires a card tap to unlock the wallet or confirm signing. Sensitive actions now ask for the physical card in addition to your biometric or PIN, delivering the two-factor upgrade. Choose which actions must require a tap based on how strict you want your security to be.",{"title":36,"body":37},"Set up a backup and recovery plan","Because the card is a physical factor, plan for losing it before it happens. Keep your wallet's recovery method safe and offline, and if the product ships as a set, store the second card in a separate secure location. The WATS card comes in a multi-card set precisely so you have a spare.",{"title":39,"body":40},"Practice safe signing (verify the transaction before you tap)","Treat the tap as your final confirmation. Before tapping, read the destination, amount, network, and any token approvals, and if anything looks wrong or unexpected, do not tap. A hardware factor only protects you if you refuse to authorize bad requests.",1784634269540]