Why an old iPhone works as a cold wallet
- No supply-chain PII record. A Trezor / Ledger / Cypherock ships to your name and address, and that record lives in the vendor's fulfillment stack (and now, on the black market). A used iPhone bought in cash from a stranger is a device that no vendor associates with a crypto holder.
- Plausibly-deniable. A hardware wallet in your drawer screams "wallet." An old iPhone in a drawer is a phone. A thief with your address doesn't know to demand it, and if they take it they see a phone, not a stack.
- Secure Enclave. iPhones from the iPhone 6s onward carry a Secure Enclave — hardened key storage that is architecturally comparable to what dedicated hardware wallets ship. The seed can live behind a passcode + Face ID / Touch ID inside the enclave.
- Ubiquity + parts availability. If the device dies or the battery swells, replacement is at any repair shop, in cash, without a customs record.
- Air-gap is trivial. Airplane mode + disabled Wi-Fi + disabled Bluetooth + SIM removed = a device that cannot exfiltrate a seed until you deliberately re-enable networking.
Sourcing the device — the cash + secondhand rule
- Buy in cash, in person, from a private seller. Craigslist / Kleinanzeigen / Facebook Marketplace / a corner-store repair shop — the goal is a device that has never touched your identity or a credit-card record.
- Any model from iPhone 6s / SE (1st gen) upward works — Secure Enclave present, still receives security updates for several more years for the newer ones. iPhone SE (2nd/3rd gen) is the sweet spot: cheap, small, still supported.
- Factory-reset before use. Settings → General → Transfer or Reset iPhone → Erase All Content and Settings. Trust nothing the previous owner left.
- Skip the Apple ID setup. When Setup Assistant asks to sign in, use the "Set up as new iPhone" flow and then decline the Apple ID prompt (tap "Forgot password or don't have an Apple ID?" → "Don't have an Apple ID?" → "Set up later in Settings"). Your cold wallet must not be tied to your legal Apple ID.
- If you must install a wallet via the App Store, create a burner Apple ID with a masked email (SimpleLogin, addy.io) and no payment method. Install the wallet, then sign out of the burner Apple ID before generating the seed.
The airgap setup
- Airplane mode ON — Control Center or Settings.
- Wi-Fi OFF — separately, in Settings → Wi-Fi (Airplane mode alone can auto-re-enable Wi-Fi on some iOS versions).
- Bluetooth OFF — Settings → Bluetooth, separately.
- SIM removed. No cellular attack surface.
- Auto-updates OFF. Settings → General → Software Update → Automatic Updates → OFF. You will manually update the OS on a schedule you control, on your own trusted Wi-Fi, before returning to airgap.
- Screen time / privacy hardening. Disable Siri, disable analytics, disable location, disable Handoff.
- Store the device offline when not signing. Faraday pouch is overkill for most threat models — a drawer is fine. Battery care: charge to ~60% and store in a cool dry place; check twice a year to avoid swelling.
Wallet options for iOS + air-gap
- Cake Wallet (recommended). iOS-native, supports Monero directly, generates the seed on-device inside the Secure Enclave, works fully offline once installed. Pair with a view-only copy of the same wallet on a separate online device for receive tracking.
- Monero GUI on a paired offline laptop — if you'd rather sign on a laptop than a phone, use the iPhone as your online view-only companion and keep a hardened offline Mac / Linux box as the signer. Same air-gap principle, different form factor.
- Feather (paired desktop). Best-in-class UX for the view-only + offline-signing workflow. Same pattern as above; iPhone as the online view side, Feather on an offline laptop as the signer.
- What NOT to use: browser-extension wallets, custodial mobile wallets, anything that requires a cloud backup step during setup.
The canonical flow: view-only + air-gap signing
- Generate the seed on the air-gapped iPhone (Cake Wallet → new wallet → write the seed to metal offline). Never a photo, never iCloud, never AirDrop.
- Export the view-only key from the offline wallet (Cake → Wallet → View-Only Details).
- Transfer the view-only key to your online device via QR code (offline iPhone displays the QR, online device's camera scans it). USB / AirDrop are optional; QR is the airgap-cleanest.
- Online device now sees balance + builds unsigned transactions — but cannot spend.
- To send: build unsigned tx on the online device → generate QR of the unsigned tx → offline iPhone scans and signs → offline iPhone generates QR of the signed tx → online device scans and broadcasts.
- Verify the destination address on the offline iPhone before signing. Malware on the online device can swap an address between "you paste" and "you sign." The offline device is your last line of defense.
Why this beats a Trezor for shipping-address opsec
Two-column reframe. A hardware wallet in your drawer today gives an attacker:
- A shipping record tying your name + phone + address to "owns crypto."
- A visible device that identifies exactly which wallet software / seed format to demand under duress.
- A brand-name attack surface — every firmware CVE, every customer-database leak, every phishing campaign is pre-targeted at you.
An air-gapped, cash-sourced iPhone in the same drawer gives an attacker:
- Nothing. No shipping record, no brand association, no visible signal that this specific device holds anything.
The iPhone approach does not beat a Trezor on cryptographic security — both are strong. It beats a Trezor on threat-model surface, which is where hardware wallets have quietly stopped being the safest option.
Prior art — this isn't a new take
The pattern predates the 2026-08-13 Trezor breach. On-chain investigator ZachXBT — the reference for stolen-crypto forensics in the space — publicly recommended it on his Telegram channel (88.3K views on the post), verbatim:
"Hot take: All hardware wallets are complete garbage and I do not advise using them for important tasks like signing transactions or storing funds. Much better to have a separate iPhone with its only purpose being to use as your hardware wallet. Ledger is the worst and Ledger Live has regular updates for UI / apps for no good reason that break simple actions."
What the Trezor breach did was harden the argument: the case for the separate-iPhone pattern used to be about firmware trust and vendor UX; now the same pattern also closes the shipping-address surface. If the investigator most active in tracing stolen crypto has been on this for months, and the breach data now backs him up on grounds he wasn't even making at the time, the pattern is worth taking seriously.
Pitfalls
- iOS forced updates when the version reaches end-of-support. Apple drops security updates after ~5–7 years per model. Plan the update cadence on trusted Wi-Fi, then return to airgap. Do not let the device linger unpatched for a year past its EOL date.
- App Store account entanglement. If you signed into a real Apple ID during setup, the device is linked to your identity in Apple's fulfillment records. Factory reset and start over with a burner or no-Apple-ID setup.
- Battery swelling for long-storage devices. Lithium batteries don't like sitting at 100% or 0% for years. Charge to ~60% for storage; check twice a year.
- The "which app has the real seed" trap. If you install multiple wallet apps to test, seed confusion is real. Wipe the device between tests, then run the real setup once cleanly.
- Screenshot in the wrong app. A screenshot of Cake's seed screen lives in Photos, syncs to iCloud if enabled, and undoes the whole setup. If you must document, use the physical screen photographed by another air-gapped camera device, printed once, then metal-stamped.
- Face ID on the seed-view screen. Convenient. Also convenient for an attacker holding the device to your face while you sleep. Use a passcode-only unlock for the signer device, not Face ID.
When this is NOT the right pattern
- Small balances / active spending. A hot wallet on your daily phone is fine for < 1 XMR. Air-gap friction is not worth it for lunch money.
- Users who won't maintain the process. Air-gap discipline is the security property. If you'll re-enable Wi-Fi "just for a minute," the whole model collapses. A hardware wallet with a real threat-model that matches your actual behavior beats an air-gap in theory.
- Team / multisig setups. Multisig with hardware wallets from different vendors, in different jurisdictions, held by different people is a stronger construction than a single-device iPhone airgap. Pick the appropriate tool.
- If you're already deep in a Ledger / Trezor workflow that works. Don't switch for switching's sake. Add a mailing-address rotation (PO box, drop shipper, mail-forwarding) before your next order and you've closed most of the shipping-address gap without changing wallets.
Curator's cross-refs
- Parent guide: /guides/monero-cold-storage — the full cold-storage spectrum, hardware-wallet specifics, multisig.
- Verify-your-wallet: /guides/verify-wallet-binary — before you trust a wallet installer, check the signature.
- Inheritance: /guides/monero-inheritance-plan — how to make sure the seed survives you without doxing your heirs.