Approving a transaction on a device that never connects to a network, passing the unsigned request in and the signature out by QR code, camera or removable media.
Why it matters
It removes the network as a path to the key. What it does not remove is the possibility that the request carried across the gap is not the one the user believes they are approving — which is why what the offline device displays still matters more than what sent it.
What you can check
The meaningful property is whether the offline device can decode and display the transaction in human-readable terms, or whether it can only show an opaque payload. An air gap around a device that cannot tell you what it is signing narrows one risk and leaves another intact.
Where it showed up
Records in the Incident Tracker that turn on this: Bybit cold wallet compromise.
Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.