Crypto Wallets: Hot Wallets vs Cold Wallets — How to Store Crypto Safely

Not your keys, not your coins. If your crypto is on an exchange and that exchange gets hacked or freezes withdrawals, your crypto is gone. Here's how to store your crypto safely.

A crypto wallet does not actually store your coins — your crypto lives on the blockchain. What a wallet stores is your private keys, which are the cryptographic passwords that prove you own your coins and authorize transactions. If you lose your private keys, you lose your crypto forever. If someone else gets them, they can steal everything. Choosing the right wallet is the most important security decision you will make as a crypto investor. This guide covers the different types of wallets, their security tradeoffs, and the best practices for keeping your crypto safe.

Real-world example: In November 2022, FTX — one of the largest crypto exchanges — was hacked for over $600 million shortly after filing for bankruptcy. Users who kept their crypto on the exchange lost everything. Users who had withdrawn their coins to a hardware wallet were completely unaffected because their private keys were stored offline and never touched the compromised exchange servers. This single event reinforced why self-custody matters: if you do not control your private keys, you do not truly own your crypto. Learn the fundamentals of Bitcoin →

Hot Wallets vs Cold Wallets

The fundamental distinction in crypto wallets is between hot wallets (connected to the internet) and cold wallets (offline storage). Hot wallets include software wallets like Exodus and Electrum, browser extension wallets like MetaMask, mobile wallets like Trust Wallet, and exchange wallets like Coinbase and Kraken. They are free, convenient for frequent transactions, and good for small amounts. The trade-off is lower security — hot wallets are connected to the internet and are vulnerable to hacking, phishing, and malware. Cold wallets include hardware wallets like Ledger Nano X and Trezor Model T, as well as paper wallets. Hardware wallets keep your private keys completely offline, making them immune to remote attacks. They cost $50 to $200 and are best for long-term storage of significant amounts. Paper wallets (public and private keys printed on paper) are free but fragile and largely obsolete — hardware wallets are superior in every way for cold storage.

Custodial vs Non-Custodial Wallets

Custodial wallets are wallets where a third party — usually an exchange — holds your private keys for you. Coinbase, Binance, and Kraken all provide custodial wallets when you deposit crypto on their platform. The advantage is convenience: if you forget your password, the exchange can help you recover access. The disadvantage is that you do not truly own your crypto. If the exchange is hacked (Mt. Gox, FTX, Celsius), freezes withdrawals, or goes bankrupt, your funds are at risk. Non-custodial wallets are wallets where you control your own private keys. Examples include MetaMask, Trust Wallet, Ledger, and Trezor. No one else can access your crypto — but there is also no customer support if you lose your seed phrase. For any amount over $1,000, a non-custodial wallet should be your default choice. For amounts over $10,000, a hardware wallet is strongly recommended. Understand Ethereum and smart contract wallets →

How Crypto Wallets Work: Seed Phrases and Private Keys

All non-custodial wallets generate a seed phrase using the BIP39 standard — a sequence of 12 or 24 random words (for example, "abandon amount ability able about above absent absorb abstract absurd accident account"). This seed phrase is the master key to your wallet. From this seed phrase, all of your private keys are derived deterministically, meaning the same seed phrase always generates the same wallet addresses on any compatible wallet software. This is why your seed phrase is the single most important thing to protect. If you lose it, you lose access to your crypto forever. If someone else obtains it, they can steal everything. Best practice: write your seed phrase on paper (never store it digitally, take a screenshot, or type it into any website), store it in a fireproof safe, and consider a second backup in a separate secure location. Never share your seed phrase with anyone — no legitimate service will ever ask for it. Learn how blockchain technology works →

Best Practices for Crypto Storage

The optimal storage strategy uses multiple wallets for different purposes. Use a hardware wallet (Ledger or Trezor) for long-term holdings that represent the majority of your portfolio value. Use a software or mobile wallet (MetaMask, Trust Wallet) for smaller amounts you use for daily transactions and interacting with decentralized applications. Keep only a small amount on exchange wallets for active trading. Never keep significant crypto on an exchange. When setting up any wallet: always download software from the official source, verify the authenticity of hardware wallets by checking packaging seals and using manufacturer verification tools, start with a small test transaction before sending large amounts, and never enter your seed phrase into any website or digital device. For your hardware wallet, purchase directly from the manufacturer — never from third-party marketplaces where tampered devices have been reported. Start with our crypto beginner's guide →

What is the safest crypto wallet?

Hardware wallets (cold wallets) are the safest option for storing cryptocurrency. Devices like Ledger Nano X and Trezor Model T keep your private keys completely offline, making them immune to remote hacks, phishing attacks, and malware. The trade-off is that you must physically connect the device to sign transactions, which is less convenient for frequent trading. For maximum security, use a hardware wallet for long-term holdings and a hot wallet for small, actively traded amounts. No wallet is completely risk-free — you must also protect your seed phrase from physical threats like fire, water damage, and loss.

What happens if I lose my hardware wallet?

If you lose your hardware wallet, you can buy a new device and recover your funds using your seed phrase (also called recovery phrase). The seed phrase is the true key to your crypto — the hardware device is just a convenient way to store and use it. This is why writing down your seed phrase on paper and storing it securely is absolutely critical. If you lose both your device and your seed phrase, your crypto is gone forever. There is no central authority, no password reset, and no customer support that can recover it. Multiple backups stored in separate secure locations are strongly recommended.

Can I recover a wallet without the seed phrase?

No. Without the seed phrase, it is impossible to recover a non-custodial wallet. The seed phrase is the master key from which all private keys are derived. There is no backdoor, no password reset, and no company you can contact to restore access. This is the fundamental trade-off of self-custody: you have full control, but also full responsibility. If you lose your seed phrase, your crypto is permanently inaccessible. This is why writing it down on paper, making multiple copies, and storing them in secure locations is absolutely critical. Never store your seed phrase in a digital format such as a screenshot, cloud storage, email draft, or password manager.

Should I keep crypto on an exchange?

Only keep crypto on an exchange if you are actively trading it and the amount is small enough that you would be comfortable losing it. Exchange wallets are custodial, meaning the exchange holds your private keys. History has shown that even major exchanges can be hacked (Mt. Gox, $460 million lost), freeze withdrawals (FTX, Celsius), or become insolvent. For long-term holdings, always withdraw your crypto to a non-custodial wallet where you control the private keys. A good rule of thumb: keep no more than 5% to 10% of your crypto portfolio on any exchange. Move the rest to a hardware wallet for secure self-custody.

Related Resources