The word wallet is misleading. A crypto wallet does not contain your coins — those are entries on a blockchain and they never move off it. What a wallet holds is the private key that authorises spending them.
Once that clicks, the rest follows. You are not choosing where to store money. You are choosing where to store a key, and how exposed that place is to the internet.
Hot wallets: keys on a connected device
A hot wallet keeps keys on something online — a phone app, a browser extension, an exchange account. Convenient, free, instant, and permanently within reach of anything that compromises the device.
Worth separating two very different things people both call hot wallets:
- Self-custody hot wallet — you hold the keys, on your own device. You control the funds and you carry the risk of malware and phishing.
- Exchange account — the exchange holds the keys. You have a claim on a company, not possession of an asset. Convenient, and a different category of risk entirely: every large exchange failure took customer funds with it.
Cold wallets: keys that never touch the internet
A cold wallet keeps keys on a device that is never online — in practice a hardware wallet. Transactions are signed on the device itself, so the key is never exposed to a computer that might be infected. This removes the largest attack surface there is: remote compromise.
What remains is physical. Lose the device and its recovery phrase and the funds are gone permanently. Buy tampered hardware and you may be using keys someone else generated, which is why devices should only be bought directly from the manufacturer, never from a marketplace listing.
The decision rule
Two variables: how much, and how often you move it.
- Small amount, frequent use — hot wallet. The convenience is worth it and the loss is survivable. Treat it like cash in a pocket.
- Large amount, rare use — cold wallet, without hesitation. This is the case hardware wallets exist for.
- Large amount, frequent use — split it. A cold wallet for the bulk, a hot wallet funded with only what you are actively trading. Almost everyone with meaningful holdings ends up here.
- Small amount, rare use — hot wallet is fine, but write down the recovery phrase properly anyway. Small holdings have a way of becoming large ones.
A useful test: if losing the entire balance overnight would materially change your life, it does not belong in a hot wallet. That threshold is different for everyone and it is the only one that matters.
The recovery phrase is the actual asset
When you set up a self-custody wallet it gives you twelve or twenty-four words. Those words are your funds. They regenerate every key in the wallet, on any compatible device, forever.
Which means:
- Never type them into anything. No legitimate service, support agent or wallet app ever needs them. This request is the single most common theft method in crypto.
- Never store them in cloud notes, photos, email or a password manager that syncs. A phrase in cloud storage is a phrase one account breach away from being someone else’s.
- Write them on paper at minimum; stamped metal if the amount justifies it. Paper burns and fades.
- Store a backup somewhere geographically separate. A single location covers theft and forgetfulness but not fire or flood.
What to do first
If you currently hold crypto on an exchange and have never used a wallet, the useful first step is not buying hardware. It is moving a deliberately small amount to a self-custody hot wallet, sending it back, and confirming you can recover the wallet from the phrase alone on a different device. Practise the recovery before it matters. People discover their backup was wrong at exactly the moment they cannot afford to.
Then, once the amount justifies it, buy a hardware wallet from the manufacturer and repeat the same exercise.