XColdPro Security Architecture

How XColdPro isolates keys, what its encryption does and does not cover, and the operating assumptions the design depends on.

Encryption

Wallet material is stored under AES-256-GCM, an authenticated cipher, so tampering with the stored data is detected rather than silently accepted.

Air-gap isolation

Severing network paths — WiFi, Bluetooth, Ethernet — removes the remote attack surface. Keys are generated and used only inside that isolated environment; only unsigned and signed transaction data crosses the boundary.

What this cannot protect against

Software-first cold storage protects key material through software controls on hardware you supply. It does not defend a device that is already compromised before the wallet is created, and anyone holding the seed can spend outside XColdPro. Cold storage is a set of controls, not an absolute.