There are many attacks to consider. The most obvious is to obtain the private key. If you did so, you could give the note to someone else in an environment lacking network access. This would enable double-spending - the main problem Bitcoin solves.
The attack can range in complexity from breaking into the secure element to physically separating the element from the note. The latter approach was used way back to pull private keys from Casascius coins by dissolving the adhesive on the security sticker.
I suspect not all of these kinds of attacks have been considered by the creators.
If it becomes necessary to verify Kong with a network connection, the main value proposition disappears. That can be done already without a physical note.