A hot wallet keeps the key to your crypto on something connected to the internet, usually your phone or a browser extension on your laptop. A cold wallet keeps it on a device that never goes online. Hot is free and quick. Cold costs $79 to $399 for the common models and adds a minute to every transaction, and for that the key sits out of reach of anything that gets into your computer. Most people holding crypto for longer than a few weeks need both. A hot wallet for spending money, a cold one for the rest.
Hot or cold? A quick check
Two questions. Tap an answer to each.
About how much crypto do you hold?
What's it for?
A rule of thumb, not financial advice.
What a crypto wallet actually holds
Your coins sit on the blockchain. The wallet holds the private key that lets you move them. That key is backed up as a seed phrase: 12 or 24 ordinary words from a fixed list of 2,048. Type those words into any compatible wallet, anywhere, and the coins are yours to move. Anyone else who types them in can move them too. They don't need your phone or your password.
An exchange account is something else again. Coinbase and Kraken hold the keys, and you hold a balance on their books. That works until the company stops paying out.
When I bought my first bitcoin in 2011, nobody sold a hardware wallet. Mostly your coins sat in a file on your own computer, or you left them on an exchange. In February 2014 Mt. Gox, once the biggest Bitcoin exchange in the world, went offline with about 850,000 bitcoins missing. The first Trezor hardware wallet went on sale that July. Eight years later FTX froze withdrawals. Its customers waited more than two years for their first payouts, and those came in dollars, at what their coins had been worth in November 2022, plus some interest.
| Exchange account | Hot wallet | Cold wallet | |
|---|---|---|---|
| Who holds the key | The exchange | You, on a device that's online | You, on a device that never goes online |
| Cost | Free to hold | Free | About $79 to $399 for the device |
| Speed | Instant | Seconds | A minute or two: plug in, read the screen, press the button |
| How people lose money | The company fails or freezes withdrawals | Signing a drainer's request, or malware | Losing the seed words, a fake device, or signing blind |
| Good for | Active trading | Spending, DeFi apps, NFT mints | Anything you're keeping |
Hot wallets, and how they get emptied
A hot wallet is an app. MetaMask, Phantom and Trust Wallet are the familiar names. They're free, they take a couple of minutes to set up, and you need one for almost anything in DeFi or to mint an NFT.
The weak spot is where the key lives. The same laptop runs your email and every browser extension you ever clicked yes on. Malware that swaps a copied wallet address for the thief's is cheap and common.
Still, the usual way a wallet gets drained is that its owner signs something. It tends to start with a fake mint page or a fake airdrop claim, reached from a reply on X or a direct message. You connect, the site asks you to sign, and what you're signing is a token approval or a Permit. Either one is written permission for another address to move your tokens later, with no further click from you. Scam Sniffer, which tracks crypto phishing, counted $494 million taken by these "drainers" in 2024 and about $84 million in 2025. The biggest single theft of 2025, $6.5 million that September, came from one Permit signature.
Two habits cut the damage. Keep only spending money in a hot wallet. And look at what you've already approved: revoke.cash and Etherscan's token approval checker list every live permission, and canceling one costs a network fee. An approval you gave a yield farm years ago still works if that farm's contract is ever exploited.
Do this now: check what your wallet has already approved
- Go to revoke.cash. Never follow a link to it from a DM or an email, because scammers run lookalike copies. Paste in your wallet's public address. Looking costs nothing and connects nothing.
- Read the list. Cancel anything you don't recognize, and any "Unlimited" approval for a site you no longer use.
- To cancel one, connect your wallet and press Revoke. Each one costs a small network fee.
Fake tokens are the other bait. Our guide to spotting a rug pull covers those, and the five checks are on one free printable page, Check a Token in 10 Minutes, at the bottom of this article.
Cold wallets: what they protect, and what they don't
A hardware wallet makes the key inside itself and never lets it out. When you send crypto, your phone or computer builds the transaction and passes it across, the device puts the details on its own small screen, and nothing happens until you check them and press its button. It signs inside. Only the signed transaction comes back out. Malware on your laptop can watch every step and never sees the key.
Ledger and Trezor are the best-known makers. Their entry models, the Ledger Nano S Plus and the Trezor Safe 3, list at $79. Ledger's touchscreen Stax is $399. Most of the extra money buys a bigger screen. That matters more than it sounds, because a cold wallet signs whatever you approve.
In February 2025 the exchange Bybit lost about $1.5 billion in ether from a cold wallet that needed several of its staff to approve every transaction. Attackers had tampered with the web page the signers used. Their screens showed a routine transfer. Underneath, the transaction handed control of the wallet to the attackers, and the signers approved it. The FBI blamed North Korea.
On your own device the warning is a screen of hex code, or a message saying it can't show the details. That's called blind signing. Ledger devices, for one, keep it switched off until you turn it on in settings. Leave it off. If a DeFi app insists on it, you're being asked to sign a contract you can't read.
The other cold wallet risk comes in the mail. In December 2020 hackers published Ledger customer data that included about 270,000 home addresses. The following year some of those customers received a "replacement" Nano X in a shrink-wrapped box, with a letter. It was a fake with a flash drive wired inside, and it asked for their 24 words.
Buy the device from the maker's own store. A genuine one never comes with words already printed on a card in the box. You create the words on the device yourself, and no real company, the maker included, will ever ask you to type them into a website or an app.
Losing it, and passing it on
If the device dies or goes missing, you're out $79. Buy another, enter your words, and the coins are back. Losing the words is worse. While the device still works you're on a clock: move everything to a new wallet with new words, today. Lose both and it's over. Chainalysis estimated in 2020 that about 3.7 million bitcoins, close to a fifth of all mined by then, were probably gone for good. A lot of those went in the early years, on wiped laptops and dead hard drives.
Write the words on paper and keep copies in two places that won't burn or flood together. Paper doesn't survive a house fire. Steel plates made for the job do, and you stamp the words in yourself.
Then decide who finds them if you die. If your family doesn't know the words exist, they can't get the money. Write a letter for your family: what you hold, which wallet, where the words are, and who they can trust to help them move it. Keep the words themselves out of your will. In most US states a will becomes a public record once it's filed for probate. Tell one person you trust that the letter exists.
Hot or cold: a simple rule
Use the cash test. If you'd walk around with it in your back pocket as cash, a hot wallet is fine. If you wouldn't, it goes cold. In dollars: once you're holding more than a few hundred that you mean to keep for months, a $79 device is cheap next to what it guards.
| What the money is for | Where to keep it |
|---|---|
| Spending, minting, trying a new app | A hot wallet with a small balance. A second one for mints if you do a lot of them |
| Trading on an exchange this week | On the exchange while you trade, then off it |
| Holding for months or years | A cold wallet, plugged in only when you move money |
| Family money, or more than you could replace | A cold wallet, the words in two places, and the letter. Some people add a multisig wallet that needs two of three devices to sign |
Then keep the two apart. Refill the hot wallet from the cold one when you need to. New sites and anything you reached from a direct message get the hot wallet, holding only what you're prepared to lose. The cold wallet connects to apps you've used before and checked, and nothing else.
Common mistakes
- Typing the seed phrase into anything online. A "wallet validation" page, or a "support agent" who messaged you first. Both are thieves.
- Keeping a photo of it. In February 2025 Kaspersky found malware in apps on both Google Play and Apple's App Store that read people's photo galleries looking for screenshots of seed phrases.
- Copying an address from your transaction history. Scammers send tiny amounts from lookalike addresses so the fake turns up in your list. They match the first and last few characters, which are the bits people check. Compare the whole address, on the device screen if you have one.
- Never testing the backup. Ledger and Trezor both have a built-in check of the recovery words. Run it once, before serious money goes on.
Questions people ask
Do I need a cold wallet for crypto?
Not for small amounts you use often. If you hold more than a few hundred dollars you plan to keep for months, a hardware wallet at about $79 is worth buying. If you buy on an exchange and leave it there, the exchange holds your keys and you carry its risks.
Is a hot wallet safer than an exchange?
They fail in different ways. On an exchange the company holds your keys, so you're exposed if it collapses or freezes withdrawals. In a hot wallet you hold the keys and nobody can freeze you, but one bad signature can empty it and there's no one to call. For small amounts you use often, either will do. Keep savings on a cold wallet.
Can a cold wallet be hacked?
Researchers have pulled keys off some hardware wallets in a lab, with the device in their hands and specialist equipment. Over the internet, against a genuine device, nobody has a practical way in. People who lose money from a cold wallet usually bought a fake device or typed their seed words into a phishing site. The rest signed something the screen didn't explain.
What happens if I lose my cold wallet?
If you still have the seed phrase, not much. Buy a new device, or any wallet that supports the same coins, enter the words and your crypto is back. Whoever finds the old one needs your PIN, and most devices wipe themselves after a run of wrong guesses. If you think someone has it and the time to work on it, move the coins to a new wallet with new words. If you've lost the seed phrase as well, the crypto is gone.

