Wallets & security
What Is a Cold Wallet?
Short answer
A cold wallet is any wallet whose private keys have never touched the internet. The keys live on an offline device — typically a hardware wallet — and transactions are signed offline before being broadcast by a connected device. Because there's no online key to steal, malware and phishing can't reach your funds. Cold storage is the standard for meaningful long-term holdings.
Key takeaways
- Cold = keys generated and stored offline; signing happens on the offline device.
- Immune to remote attack: no malware, phishing site, or breach can touch an offline key.
- In practice, 'cold wallet' usually means a hardware wallet (Ledger, Trezor) — though a paper wallet is also cold.
- Less convenient: every spend requires plugging in the device and approving on it.
- The trade shifts from hackers to you: the seed phrase backup becomes the thing to protect.
What makes a wallet “cold”?
One test: has the private key ever existed on a networked device? Generate the keys on a dedicated offline device, and they can’t be exfiltrated remotely — there’s nothing to connect to. Transactions still happen normally: your computer builds an unsigned transaction, hands it to the offline device, the device signs internally, and the signed transaction goes back online for broadcast. The private key never crosses that gap. This is why hardware wallets have buttons and screens — physical confirmation is the boundary.
Cold storage vs exchange custody
| Cold storage (your keys) | Exchange custody (their keys) | |
|---|---|---|
| Who can spend | Whoever holds the device + phrase | The exchange, on your instruction |
| Remote hacking risk | None on the key | Account phishing, SIM swaps, breaches |
| Third-party risk | None | Solvency, freeze, mismanagement |
| Recovery path | Your seed phrase — or nothing | Password reset, support tickets |
| Best for | Long-term savings | Active trading, small balances |
Exchange custody outsources the cold storage problem — good exchanges keep the bulk of customer funds in institutional cold storage — but keeps you dependent on the company’s security, solvency, and honesty. Exchange history includes spectacular failures where customers learned that “not your keys, not your coins” the expensive way. Self-custody inverts it: nobody can lose your money for you, and nobody can steal it remotely either.
A common beginner path: start in exchange custody for its simplicity, then move long-term holdings to cold storage once the amount would genuinely hurt to lose. The two coexist fine — trading size on the exchange, savings size in the vault.
What are cold storage’s real weaknesses?
It removes remote attackers and adds physical-world ones. The seed phrase backup — paper or metal — is now the crown jewels: anyone who finds and reads it owns everything, which is why where and how you store it matters more than the hardware itself. Buy hardware wallets only from the manufacturer (tampered resale units are a real, documented scam), verify addresses on the device’s screen rather than your computer monitor, and rehearse recovery with a small amount before trusting the setup with serious money.
One more, rarely said out loud: cold storage shifts risk onto your future self. The phrase you can’t find in five years, the device you never tested, the inheritance nobody can access — these lose more crypto annually than hackers do. Cold means you are now the system of record, and systems of record need backups, documentation, and — for meaningful amounts — a plan for someone else.
The inheritance problem
Nobody likes planning for their own absence, but cold storage concentrates a risk that exchange accounts don’t have: if you die or are incapacitated, there is no password reset, no support ticket, no next of kin portal. The phrase is the only key, and an unshared secret dies with its keeper — estimates of crypto lost this way run to enormous sums, because early adopters rarely wrote wills for their wallets.
The practical middle ground, without handing anyone live access:
- Document, don’t disclose. A sealed letter — where the phrase lives, what wallet it belongs to, what the assets are — stored with a lawyer, in a safe deposit box, or with a trusted person who holds it unopened.
- Instruct, in writing. The person who eventually reads it needs the sequence: what a seed phrase is, that it must never be typed into a website, how to restore it into a wallet, and to move funds promptly once restored.
- Rehearse the handover. The person who would act should know the plan exists and where to start — not the words themselves, just the map.
Cold storage makes you the system of record; inheritance planning is what makes the record survive you. For meaningful holdings, it belongs on the same checklist as the metal plate.
Frequently asked questions
Is a paper wallet still a good cold storage option?
Can cold storage be hacked at all?
How often should I check a cold wallet?
Related terms
Editor-in-Chief & Lead Researcher
Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.
View author page →Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.
Learn more about cold wallet
Our full guides that cover this term in depth.
What Is a Private Key? (And Why It's Secret)
A private key is the secret code that proves you own your crypto and lets you spend it. Learn how it works and how to keep it safe.
How to Withdraw from Binance (Crypto & Fiat)
How to withdraw from Binance — crypto to an external wallet or fiat to your bank — plus the fees, limits, and security settings that protect your funds.
What Is Cryptocurrency? A Beginner's Guide
Cryptocurrency is digital money secured by cryptography and recorded on a public ledger called a blockchain. Learn how it works and how to start safely.