Cointelegraph
DOGE$0.08577 5.17%
TRX$0.3399 0.28%
LINK$11.85 5.75%
ZEC$1,232.24 0.25%
ADA$0.2138 3.09%
XRP$1.38 3.21%
ETH$2,479.39 0.85%
BTC$78,389.88 0.98%
XMR$515.09 2.57%
BNB$720.65 4.43%
XLM$0.1808 4.75%
SOL$101.92 2.53%
HYPE$83.95 3.16%
Written by Erhan KahramanCommissioned Content

Open QR protocols make cold-wallet data independently verifiable

CommissionedPublishedSep 8, 2026

Structured QR data gives offline signers an inspectable communication layer that lets users independently verify transaction payloads across multichain self-custody.

Commissioned byNgrave

Cold storage keeps private keys offline, yet signing still depends on data that moves between the hardware device and a watch-only wallet. With USB or Bluetooth, users cannot see what crosses the channel; firmware decides what leaves one endpoint and reaches the other. 

Recent security incidents have kept hardware-wallet and signing workflows under scrutiny. The 2025 Bybit attack, for example, exploited Safe’s frontend during a cold-wallet transaction. As decentralized finance (DeFi) activity stretches across more chains and contract types, observable transport increasingly forms part of the security model for users managing complex self-custody setups.

The isolated silos and risks of blind signing

Air-gapped wallets inherit another source of friction because blockchain ecosystems use different native transaction and communication standards. Bitcoin transactions may arrive as Partially Signed Bitcoin Transactions (PSBTs), while Ethereum and other networks use their own formats. Universal QR places those native structures inside a common envelope that identifies the intent, curve, coin, chain subtype and asset before the signer processes the underlying transaction.

Fragmentation leaves multichain devices with incompatible ways to describe curves, networks and asset metadata. When a signer lacks enough structure to identify a token or chain, it may reject the request, display an unsupported state, expose only partial metadata or permit blind signing. 

The last case carries the highest risk: a device can authorize transaction data that it cannot explain in human terms. Self-custody loses much of its informational value when the holder controls the private key yet cannot verify the asset name, decimals or network attached to the instruction. Unsupported contracts can still require blind signing under Universal QR. The protocol exposes and standardizes the data surrounding the signing request so the payload can be independently inspected.

How open QR architecture makes signing data verifiable

Crypto wallet Ngrave is moving wallet synchronization and transaction signing onto its Universal QR Protocol, an open multiblockchain format built on Blockchain Commons’ Uniform Resources (UR), with its ZERO firmware 1.8 update. Because the protocol stack is open, the payload exchanged between ZERO and its watch-only wallet can also be decoded by independent tools, giving users and developers a way to inspect the same data before authorization.

Ngrave publishes the specifications, libraries and type registry under the MIT license, making the protocol available for third-party implementation and inspection. The QR frames carry the transaction data themselves, so the visible scan serves as the transport channel.

Blockchain identity enters the protocol as structured parameters instead of spawning a separate top-level format for every network. Recognition follows a graduated hierarchy:


Each layer carries an explicit identity, which lets the device state the boundary of its knowledge and leave missing metadata visible.

ZERO maps the hierarchy to graduated support states. Fully recognized assets can sync and sign with the metadata expected by the device. With a partly known asset, ZERO may understand the curve, coin and chain while lacking token metadata such as its name, logo or decimals. The device can expose that knowledge gap before approval; depending on the underlying transaction and contract support, some requests may still require blind signing.

Open sign requests add an external verification path to the middle state. Under the What-You-See-Is-What-You-Sign (WYSIWYS) model, an independent decoder can inspect the exact public transaction request before approval because verification never requires access to private keys. 


Ngrave ZERO physical wallet. Source: Ngrave

Any independent tool that implements the open protocol can decode the same request, even when ZERO does not yet recognize the contract locally. A contract developer could publish its own verification tool, while public decoders or compatible wallets can expose the payload without receiving the user’s private keys. The protocol makes the signer’s knowledge boundary visible, while independent tools provide another route for inspecting requests that exceed ZERO’s local contract metadata.

Polygon ERC-20 support ships with firmware 1.8, which gives the curve-to-chain taxonomy a direct production use case on ZERO. 

When UR payloads are transmitted through animated QR codes, fountain coding reduces a persistent usability cost of air-gapped signing. Each frame carries a computed blend of the wider payload, which allows the decoder to begin collecting data from any point in the sequence and reconstruct the message once it has received enough independent fragments. 

Users therefore do not need to wait for the animation to return to its opening frame. Ngrave says this shortens both synchronization and transaction-signing scans while preserving the same open, inspectable payload format.

Moving toward informed self-custody infrastructure 

Air-gapped self-custody will increasingly depend on the semantics of the data that crosses the physical gap. Open message types and shared registries give hardware signers a common grammar for multichain activity, and public specifications allow independent wallets or verification tools to interpret the same requests over time.

Vendor-specific protocols can preserve strong key isolation while still creating interoperability friction when each device speaks its own transaction dialect. Structured taxonomies make the signer’s support boundary explicit, while an open transport layer lets external tools inspect the payload even when the hardware wallet lacks the metadata to interpret it fully. Blind signing may still be required for unsupported contracts, but the communication surrounding that request no longer has to remain opaque.

As self-custody expands into contract-heavy, multichain workflows, offline key storage solves only part of the security problem. Open communication standards add another layer of control by making the data presented to a signer inspectable beyond the hardware wallet itself.

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
This content is part of a paid partnership. The text below is a commissioned article that is not part of Cointelegraph editorial content. The material is written by our advertorial team and has undergone editorial review to ensure clarity and relevance, it may not reflect the views and opinions of Cointelegraph.com. Readers are encouraged to conduct their own research before taking any actions related to the company. Disclosure.

More on the subject