What is a crypto wallet? A plain guide to hot and cold storage
A crypto wallet does not hold your coins. It holds the private keys that prove the coins are yours, and whoever holds the keys controls the money. Here is how custodial, hardware and mobile wallets differ, and how people lose everything by losing a few words.
Published · 7 min read
A crypto wallet is the tool you use to hold and move cryptocurrency. It does not store coins. It stores the private keys that prove the coins on a blockchain belong to you, and anyone who holds those keys can spend the funds. Choose the wrong type, or lose your backup, and the money is usually gone for good.
That single idea trips up almost every newcomer. Coins never leave the blockchain. Your wallet is closer to a keyring than a purse. Lose the keys and you lose access, even though the balance still sits on a public ledger that anyone can read. Get the keys right and everything else is detail.
What a crypto wallet actually holds
Every wallet holds cryptographic keys, not money. Each account has two keys that work as a pair. A public key creates an address you can share, much like an email address people use to send you funds. A private key stays secret and signs each transaction, which proves the request came from you and nobody else. The address is meant to be seen. The private key is never meant to leave your control.
Bitcoin's own documentation puts it plainly. A wallet keeps a secret piece of data called a private key, bitcoin.org says, used to sign transactions and give mathematical proof that they came from the owner. Ethereum's documentation makes the same point from the other direction. Wallet software does not have custody of your funds. It just gives you a window to see assets that live on the chain.
One wallet can hold many different coins and tokens, and most support more than one address at once. Your balance is not a file stored inside the app. It is a set of entries on the blockchain that your keys can unlock. Move to a new phone, enter the same recovery words, and the same balance appears, because the coins were never on the old phone to begin with.
This is why key safety matters more than almost anything else in crypto. Most big losses are not clever attacks on the math behind a blockchain. They start with stolen or mislaid keys, a pattern BTC Newz has written about in why stolen keys, not broken code, are crypto's real threat.
Custodial or non-custodial wallets
Wallets fall into two camps, and the camp decides who is really in control. A custodial wallet means a company holds your keys for you. Most exchange accounts work this way. You sign in with a username and password, and if you forget the password, support can reset it. For many beginners that feels familiar and safe.
Non-custodial wallets hand you the keys and the full weight that comes with them. No reset. No hotline. Ethereum's documentation says it flatly: there is no customer support in crypto, and you are responsible for keeping your keys safe. The convenience of a custodial account comes with a catch. You are trusting the company to stay solvent and honest, and exchanges have failed before, freezing or losing customer money. A non-custodial wallet removes that middleman and puts every decision, and every mistake, on you.
Hot wallets versus cold wallets
Another split comes down to one thing. Internet connection. A hot wallet stays online. A cold wallet stays offline, and that gap changes the whole risk picture.
Hot wallets run on your phone, in your browser, or on a website. They suit daily spending and quick trades, because the keys are right there when you need them. Being online also gives an attacker a door to try, from fake websites to malicious approvals that drain a wallet in one click. Cold wallets keep the keys on a device that never connects to the internet, so remote theft becomes far harder. A common habit among longtime holders is dull but sound. Keep a little in a hot wallet for spending. Keep the rest in cold storage.
Main wallet types, in plain terms
Beyond the hot and cold labels, wallets come in a handful of everyday forms. Ethereum's documentation lists five main kinds, and the same shapes apply across most chains. Each one sits somewhere on the line between easy to use and hard to steal from.
Hardware wallets are small physical devices that store keys offline and sign transactions only when you plug them in and approve. They cost money and feel fiddly the first few times. For larger balances, most security-minded users treat them as the default choice.
Mobile and desktop apps install on a phone or computer and keep your keys on that device, which is convenient and only as safe as the machine itself. Browser wallets and browser extensions live in a tab or an add-on, and connect quickly to web apps. That makes them popular for using decentralized finance, and a little riskier, because they touch the open web every day. Each form trades some safety for some convenience. None is the single right answer for everyone.
Most people start on a custodial exchange because buying is simple there, then move coins to a non-custodial wallet as the amount grows. There is nothing wrong with that path. The mistake is leaving a life-changing sum on an account whose keys you do not hold, and forgetting that an exchange is a company that can be hacked, frozen by a court, or shut down.
How to keep a wallet safe
Safety in crypto rests on one habit above all. Protect the recovery phrase. When you set up a non-custodial wallet, it shows you a list of words, often 12 or 24, called a seed phrase. Those words can rebuild the wallet on any device in the world. Anyone who reads them can empty it in minutes.
Write them on paper and keep them offline. Never type them into a website, a chat box or a photo on your phone. We explain the mechanics, and the common ways people slip up, in how seed phrases work. A seed phrase works like the master key to a safe. Lose it, and the safe stays shut forever. A few more habits help: turn on two-factor security where you can, check the address before you send, and review what you are approving before you sign.
Make more than one backup and keep the copies in separate safe places, so a fire or a flood cannot wipe out the only record. Some people stamp the words into metal for exactly that reason. Do not store the phrase in cloud notes, email or a password manager that syncs online, because a breach of that account then hands over everything you own.
Regulators keep repeating the same warning. The US Federal Trade Commission tells consumers that cryptocurrency sits in a digital wallet, and that if the wallet is lost, stolen or compromised, you are likely to find that no one can step in to help you recover your funds. No honest company will ever ask for your seed phrase or private key. Anyone who does is trying to rob you.
How to pick a wallet without getting scammed
Fake wallet apps are a known trap. Scammers publish lookalike apps and browser extensions that quietly send your seed phrase to them the moment you enter it. Download only from the official website or the maker's verified listing, and check the developer name and reviews. When an app or a stranger asks you to import an existing seed phrase into a brand new tool, stop. That request is the oldest drainer trick there is.
What to watch before you pick a wallet
No wallet removes risk. It moves the risk somewhere else, and you decide which trade you can live with. A custodial account spares you the key management but exposes you if the platform fails. A hardware wallet protects your keys, yet it is not magic. It guards the keys, not your judgment. Approve a bad transaction and the device signs it without complaint.
Lost access is not a rare edge case. A June 2020 report from blockchain analysis firm Chainalysis estimated that about 3.7 million bitcoin (BTC) had not moved in at least five years, much of it likely gone for good after owners lost their keys. So start small. Send a tiny amount first. Make sure you can restore the wallet from your backup before you trust it with money you cannot afford to lose.
Frequently asked
Does a crypto wallet actually store my coins?
No. Your coins stay recorded on the blockchain, not inside the wallet. A wallet stores the private keys that prove the coins are yours and let you spend them. Think of it as a keyring rather than a purse. If you lose the keys, the balance still exists on the ledger, but you can no longer move it.
What is the difference between a custodial and a non-custodial wallet?
A custodial wallet means a company, usually an exchange, holds your keys and can reset your password if you forget it. A non-custodial wallet puts the keys entirely in your hands, with no password reset and no support line. Custodial is easier but depends on trusting the firm. Non-custodial gives you full control and full responsibility.
What happens if I lose my seed phrase?
If you lose the seed phrase for a non-custodial wallet and have no other backup, the funds are almost always unrecoverable. No company can reset it, because no company holds it. That is why the standard advice is to write the words on paper, store copies offline in separate places, and never share them with anyone.
Sources, and what is behind them
- Ethereum wallets: what they are and how they work, Ethereum FoundationDocumentation
- How Bitcoin works, Bitcoin.orgDocumentation
- What To Know About Cryptocurrency and Scams, U.S. Federal Trade CommissionDocumentation
- Lost Bitcoin: 3.7 million Bitcoin are probably gone forever, Decrypt (January 3, 2021)Press report