← All posts

Tutorial Security Advisory August 4, 2026

DIY Air-Gapped Hardware Wallet: Turn an Old Phone into an Offline Signing Device (Cupcake + Cake Wallet)

Need to move your Bitcoin off a vulnerable Coldcard immediately, but don't have a spare hardware wallet on hand? In this complete step-by-step guide, learn how to turn an unused smartphone into a zero-cost, air-gapped offline signing device using Cupcake Wallet and Cake Wallet.

The Coldcard Triage Dilemma

Following the widespread random number generator (RNG) entropy vulnerability affecting Coldcard devices (MK4, MK5, Q, and MK3), Bitcoins generated on these devices must be moved to fresh, secure entropy. But what if you don't have a second hardware wallet ready and can't wait days for shipping?

Moving funds to an online hot wallet or centralized exchange introduces unnecessary network and counterparty risks. Converting an old spare phone into an offline, air-gapped signing device using QR codes serves as an ideal intermediate triage solution.

Comparing Emergency Migration Options

Option Air-Gapped / Offline? Private Key Storage Security Level
Dedicated Hardware Wallet (Passport, Keystone, SeedSigner) Yes (100% Offline) Secure Element / Offline Chip Gold Standard (Highest)
DIY Phone (Cupcake + Cake Wallet) Yes (Airplane Mode / Offline) Offline Encrypted App Storage High (Excellent Emergency Stopgap)
Online Hot Wallet (Mobile/Desktop App) No (Connected to Internet) Internet-Connected Storage Moderate / Compromised Surface
Centralized Exchange No (Custodial) Held by Third Party Low (Counterparty / KYC Risk)

Step-by-Step Setup Guide: Building Your DIY Air-Gapped Wallet

To follow this tutorial, you will need an old Android or iOS smartphone (e.g., an old Pixel or iPhone sitting in a drawer) and your primary daily smartphone.

1

Download & Install Cupcake Wallet on Old Phone

Visit cupcakewallet.com on your old phone. You have two installation options:

  • Option A (Google Play Store / Apple App Store): Search for Cupcake Wallet and install directly via the official store.
  • Option B (GitHub APK Sideloading for Android): Scroll to the bottom of cupcakewallet.com, click GitHub → Releases → Download the latest APK file. Open your phone's Files / Downloads app, allow installation from unknown sources, and complete installation.
2

Sever All Connections (Turn 100% Offline)

CRITICAL STEP: Once Cupcake is installed, immediately disable Wi-Fi, turn off Bluetooth, turn off Location services, and turn ON Airplane Mode.

Your old smartphone is now a dedicated, air-gapped signing computer. It will never connect to the internet again while holding private keys.

3

Generate Your Seed Phrase & Passphrase in Cupcake

  1. Open Cupcake Wallet on the offline phone → Press Continue → Select Bitcoin.
  2. Set a secure device PIN or password (do not use a trivial 4-digit sequence).
  3. Name your wallet (e.g., Temp From Coldcard).
  4. Add a Custom Passphrase: Enter a long, complex passphrase. This adds human-supplied entropy and creates an encrypted hidden wallet layer.
  5. Press Show Me Seed → Write down the 12-word seed phrase on paper in exact order. Store this backup safely.
  6. Complete the quick seed verification check.
4

Pair Watch-Only Companion (Cake Wallet on Daily Phone)

On your regular, internet-connected smartphone, download Cake Wallet.

  1. In Cupcake (offline phone), tap the top menu → Select Link to Cake Wallet to display a QR code.
  2. In Cake Wallet (daily phone), go to WalletsRestore Wallet → Select Cupcake App.
  3. Scan the linking QR code from Cupcake's screen.
  4. Cake Wallet is now configured as a watch-only wallet. It can display your balance, generate receive addresses, and construct unsigned transactions, but it holds zero private keys!
5

Migrate Funds off Coldcard (Using Sparrow Wallet)

  1. In Cake Wallet (watch-only), tap Receive and copy your native SegWit receive address (starts with bc1q...).
  2. Open Sparrow Wallet (connected to your Coldcard). Paste the Cake Wallet receive address.
  3. Run a Test Transaction First: Send a small test amount (e.g. 10,000 SATs) before migrating your full balance.
  4. Save the PSBT (Partially Signed Bitcoin Transaction) to a MicroSD card (or display QR code on Coldcard Q).
  5. Insert MicroSD into Coldcard → Enter PIN → Select Ready to Sign.
  6. Verify Address on Coldcard Screen: Confirm that the output address displayed on Coldcard matches your Cake Wallet receive address exactly.
  7. Sign PSBT on Coldcard → Move MicroSD back to computer → Load signed PSBT in Sparrow → Broadcast transaction.
6

How Air-Gapped QR Spending Works

When you eventually want to spend Bitcoin out of your DIY Cupcake hardware wallet, the transaction remains completely air-gapped:

  1. In Cake Wallet (daily online phone), initiate a Send transaction → Cake displays an Unsigned Transaction QR Code.
  2. In Cupcake Wallet (offline phone), tap the center Scan button → Scan the QR code from Cake Wallet.
  3. Cupcake displays transaction details (fees, recipient address, amount). Verify everything → Swipe to sign.
  4. Cupcake generates a Signed Transaction QR Code.
  5. In Cake Wallet, tap Scan QR Code → Scan the signed QR code from Cupcake's screen → Cake broadcasts the signed transaction to the Bitcoin network!

Important Security Takeaways

"Slow is Smooth, Smooth is Fast"
  • Always Start with a Test Transaction: Move 10,000 SATs first. Verify that you can receive, view, and successfully spend out of your new setup before transferring your main balance.
  • This is a Triage Intermediate Solution: While Cupcake on an offline phone is significantly safer than an online hot wallet or exchange, a dedicated hardware wallet (with physical dice rolling) remains the gold standard for long-term treasury storage.
  • Verify Addresses on Every Screen: Never rely on copy-paste alone. Compare the first and last 6 characters of target addresses on both devices.

Need Guidance Navigating Your Emergency Migration?

If you are affected by the Coldcard vulnerability and need one-on-one help setting up an emergency signing device, auditing your passphrase, or moving UTXOs safely: