Skip to content
MyCryptoStart

Wallets & security

What Is a Cold Wallet?

Short answer

A cold wallet is any wallet whose private keys have never touched the internet. The keys live on an offline device — typically a hardware wallet — and transactions are signed offline before being broadcast by a connected device. Because there's no online key to steal, malware and phishing can't reach your funds. Cold storage is the standard for meaningful long-term holdings.

Key takeaways

  • Cold = keys generated and stored offline; signing happens on the offline device.
  • Immune to remote attack: no malware, phishing site, or breach can touch an offline key.
  • In practice, 'cold wallet' usually means a hardware wallet (Ledger, Trezor) — though a paper wallet is also cold.
  • Less convenient: every spend requires plugging in the device and approving on it.
  • The trade shifts from hackers to you: the seed phrase backup becomes the thing to protect.

What makes a wallet “cold”?

One test: has the private key ever existed on a networked device? Generate the keys on a dedicated offline device, and they can’t be exfiltrated remotely — there’s nothing to connect to. Transactions still happen normally: your computer builds an unsigned transaction, hands it to the offline device, the device signs internally, and the signed transaction goes back online for broadcast. The private key never crosses that gap. This is why hardware wallets have buttons and screens — physical confirmation is the boundary.

Cold storage vs exchange custody

Cold storage (your keys)Exchange custody (their keys)
Who can spendWhoever holds the device + phraseThe exchange, on your instruction
Remote hacking riskNone on the keyAccount phishing, SIM swaps, breaches
Third-party riskNoneSolvency, freeze, mismanagement
Recovery pathYour seed phrase — or nothingPassword reset, support tickets
Best forLong-term savingsActive trading, small balances

Exchange custody outsources the cold storage problem — good exchanges keep the bulk of customer funds in institutional cold storage — but keeps you dependent on the company’s security, solvency, and honesty. Exchange history includes spectacular failures where customers learned that “not your keys, not your coins” the expensive way. Self-custody inverts it: nobody can lose your money for you, and nobody can steal it remotely either.

A common beginner path: start in exchange custody for its simplicity, then move long-term holdings to cold storage once the amount would genuinely hurt to lose. The two coexist fine — trading size on the exchange, savings size in the vault.

What are cold storage’s real weaknesses?

It removes remote attackers and adds physical-world ones. The seed phrase backup — paper or metal — is now the crown jewels: anyone who finds and reads it owns everything, which is why where and how you store it matters more than the hardware itself. Buy hardware wallets only from the manufacturer (tampered resale units are a real, documented scam), verify addresses on the device’s screen rather than your computer monitor, and rehearse recovery with a small amount before trusting the setup with serious money.

One more, rarely said out loud: cold storage shifts risk onto your future self. The phrase you can’t find in five years, the device you never tested, the inheritance nobody can access — these lose more crypto annually than hackers do. Cold means you are now the system of record, and systems of record need backups, documentation, and — for meaningful amounts — a plan for someone else.

The inheritance problem

Nobody likes planning for their own absence, but cold storage concentrates a risk that exchange accounts don’t have: if you die or are incapacitated, there is no password reset, no support ticket, no next of kin portal. The phrase is the only key, and an unshared secret dies with its keeper — estimates of crypto lost this way run to enormous sums, because early adopters rarely wrote wills for their wallets.

The practical middle ground, without handing anyone live access:

  • Document, don’t disclose. A sealed letter — where the phrase lives, what wallet it belongs to, what the assets are — stored with a lawyer, in a safe deposit box, or with a trusted person who holds it unopened.
  • Instruct, in writing. The person who eventually reads it needs the sequence: what a seed phrase is, that it must never be typed into a website, how to restore it into a wallet, and to move funds promptly once restored.
  • Rehearse the handover. The person who would act should know the plan exists and where to start — not the words themselves, just the map.

Cold storage makes you the system of record; inheritance planning is what makes the record survive you. For meaningful holdings, it belongs on the same checklist as the metal plate.

Frequently asked questions

Is a paper wallet still a good cold storage option?
It's cold, but it's a legacy method with real footguns: printing exposes the keys to compromised computers and printers, paper burns and fades, and spending from a paper wallet usually imports the private key into a hot device — breaking the cold chain at the worst moment. Hardware wallets do everything paper does without the fragile parts; paper survives today mainly as a last resort.
Can cold storage be hacked at all?
Not remotely — that's the design. Every documented 'cold wallet hack' was actually physical or human: tampered devices bought from resellers, fake setup apps, supply-chain interdictions, or the attacker simply finding the seed phrase backup. The offline key can't be reached; the physical world around it can, which is why [where you store the phrase](/glossary/seed-phrase/) and where you buy the device matter as much as the device itself.
How often should I check a cold wallet?
Rehearse recovery at setup with a small amount, then check whenever you deposit or withdraw — quarterly balance glances are plenty. What deserves a fixed schedule is the backup: once a year, confirm the seed phrase is legible and both copies are where you think they are. The wallet itself doesn't decay; paper and memory do.

Editor-in-Chief & Lead Researcher

Lucas Almeida

Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.

View author page →

Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.

Learn more about cold wallet

Our full guides that cover this term in depth.