Crypto Wallets Explained: Hot vs Cold, Custodial vs Self-Custody
A wallet does not store your coins β it stores the key that moves them. Here is what actually differs between wallet types, and how to pick one without losing everything to the wrong choice.
Key takeaways
- A wallet doesn't store your coins β it stores the private key that authorises moving them; the coins live on the blockchain.
- The real split is custodial vs self-custodial (who holds the key) and hot vs cold (online vs offline), not the brand.
- Your wallet is only ever a backup of its seed phrase β that phrase, not the app or device, is what you actually protect.
- Match the wallet to the job: a hot wallet for spending, a cold wallet for savings.
The single most useful thing to understand about crypto is that your coins are never in your wallet. They are entries on a public ledger. A wallet holds the private key that authorises changes to those entries. Lose the key and the coins still exist β they are simply unreachable, forever, by anyone. Almost every wallet decision follows from that one fact.
Keys, seed phrases and addresses
Three things get confused constantly. Your address is public β it is safe to share and is how people send you funds. Your private key signs transactions and must never leave your control. Your seed phrase (12 or 24 words) is a human-readable master secret from which every private key in the wallet is derived. Anyone with the seed phrase has every key, on every chain that wallet supports, forever.
No legitimate wallet, exchange, support agent or airdrop will ever need your seed phrase. There is no exception to this rule. Every single request for it is a theft attempt, without exception, no matter how convincing the context.
Custodial vs self-custody
This is the more important split, and the one beginners get wrong. In a custodial wallet β Binance, Coinbase, Kraken, any exchange account β the platform holds the keys. What you own is a claim on the company, much like a bank balance. In a self-custody wallet you hold the keys yourself.
- β’Custodial: password resets, 2FA recovery and a support line if you make a mistake. In exchange, you carry the platform's insolvency and freeze risk β the lesson of Mt. Gox, Celsius and FTX is that a balance on a screen is not the same as coins you control.
- β’Self-custody: nobody can freeze, seize or lend out your funds, and no company failure touches them. In exchange, there is no reset button. A lost seed phrase or a signed malicious transaction is permanent and uninsured.
- β’The practical answer for most people is both: trading balance on an exchange, long-term holdings in self-custody. Match the split to what you could stand to lose.
Hot vs cold
The second split is about whether the key ever touches an internet-connected device. A hot wallet β MetaMask, Phantom, Trust Wallet, a mobile app β keeps keys on a phone or browser. That makes it fast, free and convenient, and it means any malware, malicious extension or phished signature on that device can reach your keys. A cold wallet keeps the key on a device that never goes online; transactions are signed on the device itself and only the signed result crosses over.
Cold storage does not make you invulnerable. It removes remote key extraction from the threat model, which is the biggest single category of loss. It does not protect you from approving a draining transaction on the device's own screen, and it does not protect a seed phrase you photographed.
The four types in practice
- β’Exchange account (custodial, hot) β fine for funds you are actively trading, or amounts you would shrug off. Enable withdrawal allowlists and hardware-key 2FA, not SMS.
- β’Mobile / browser wallet (self-custody, hot) β the everyday wallet for DeFi, NFTs and small balances. Treat it as the cash in your pocket, not your savings.
- β’Hardware wallet (self-custody, cold) β a Ledger, Trezor or Coldcard. The default for meaningful long-term holdings; see our hardware wallet guide for choosing one.
- β’Paper / metal backup β not a wallet, a backup of the seed phrase. Metal survives fire and flood; paper does not.
Choosing by balance, not by preference
A useful heuristic: if losing the balance would materially change your year, it belongs in self-custody on cold storage. If it would merely annoy you, a hot wallet is a reasonable trade for the convenience. The cost of a hardware wallet is fixed at roughly the price of a nice dinner; the cost of not having one scales with your balance, which is why people who bought one late almost always say they should have bought it earlier.
The mistakes that actually cause losses
- β’Storing the seed phrase digitally β a photo, a password manager note, a cloud document. Device compromise then means total loss.
- β’One backup in one place. Fire, flood and moving house all destroy seed phrases. Two or three geographically separate copies.
- β’Not testing recovery. Restore the wallet from the phrase onto a spare device before you fund it seriously. An untested backup is a guess.
- β’Blind-signing. Read what the transaction actually does. Most self-custody losses are not broken cryptography β they are users approving a token allowance to a contract that drains it.
- β’Stale approvals. Old unlimited token allowances stay live for years. Revoke ones you no longer use.
- β’Buying hardware secondhand or from a marketplace listing. Buy direct from the manufacturer; a pre-seeded device is a known scam.
A reasonable setup
Long-term holdings on a hardware wallet, its seed phrase stamped in metal and stored in two separate physical locations, never photographed. A separate hot wallet with a small float for day-to-day on-chain activity, so a bad signature there cannot touch the main stack. An exchange account holding only what you are actively trading, secured with a hardware 2FA key. That structure survives essentially every common failure except forgetting where you put the backup β which, by then, is the risk worth having.
Where to store it safely
Keep your keys off the internet with a hardware wallet
Get a Ledger βPartner links β we may earn a commission at no extra cost to you. See our affiliate disclosure.
Frequently asked questions
- What happens if my hardware wallet breaks or is lost?
- Nothing, provided you have the seed phrase. The device is just a secure keypad β the keys are derived from the phrase, so you restore onto a replacement device from any manufacturer that supports the same standard.
- Is a hot wallet safe for small amounts?
- Reasonably, if the device is clean, the wallet came from the official source and you do not store a seed phrase on it. Treat it like cash in a pocket: a good place for spending money, a bad place for savings.
- Can someone steal my crypto if they know my wallet address?
- No. The address is public by design β it is visible on the blockchain to everyone. Funds move only with a signature from the private key.
- Do I need a different wallet for each blockchain?
- Often not. Most modern wallets derive keys for many chains from one seed phrase. You do need a wallet that supports the specific chain, and sending an asset to an address on the wrong network is a common and usually unrecoverable mistake.
- Are custodial wallets ever the right choice?
- Yes β for active trading balances, for people genuinely unlikely to keep a backup safe, and for small amounts where the convenience outweighs the counterparty risk. The mistake is holding life-changing sums there by default.
Related tools
Self-custody means you are the bank β and the whole job is not losing or leaking your keys. A start-to-finish path through choosing a wallet, protecting the seed phrase, and avoiding the ways people actually lose crypto.