Trading News Global

Markets, explained without the hype. Independent coverage of crypto, currencies and global markets.

Crypto

How to Store Crypto Safely: Hot Wallets, Cold Wallets and Seed Phrases

Custody is the one crypto decision with no undo button. Here is how each storage method actually fails, how to choose between them, and how to build a recovery plan that survives you.

Trading News Global Editorial TeamUpdated 6 min read
How to Store Crypto Safely: Hot Wallets, Cold Wallets and Seed Phrases

Every other decision in crypto is reversible. A bad trade can be closed. A poor entry can be averaged. Custody is different: there is no support line, no fraud department, no chargeback and no reset link. If keys are lost or stolen, the funds are gone.

This is the part of crypto with the highest ratio of consequence to attention.

What a wallet actually is

A wallet does not hold coins. Assets exist on the blockchain; the wallet holds the private key that authorises moving them.

That key is derived from a seed phrase — typically 12 or 24 words. From those words, every key and address in the wallet can be regenerated on any compatible device, anywhere.

Two consequences follow, and both are absolute:

  • Anyone with the seed phrase controls the funds. They do not need your device, your password or your presence.
  • Nobody without it can recover the funds. Not the wallet maker, not a developer, not you.

The categories

Hot wallets

Software on an internet-connected device: a phone app, a browser extension, a desktop program.

Good for: small amounts, frequent transactions, interacting with applications. Fails through: malware on the device, phishing sites that harvest the seed phrase, malicious transaction approvals, and compromised app updates.

Cold wallets

Keys generated and held on a device with no internet connection — almost always a hardware wallet.

Good for: anything you intend to hold rather than spend. Fails through: physical loss combined with a lost backup, counterfeit devices, tampered supply chain, and users being socially engineered into entering the seed phrase somewhere.

The essential property: the private key never leaves the device. You connect it, the computer sends an unsigned transaction, the device signs it internally and returns the signature. Malware on the computer never sees the key.

Exchange custody

You do not hold keys. The exchange does, and you hold a claim against it.

Good for: active trading balances and fiat conversion. Fails through: exchange insolvency, hacking, withdrawal freezes, regulatory seizure, and account takeover through SIM swap or credential theft.

This is not theoretical. Multiple large exchanges have failed with customer assets, and customers have frequently discovered that they ranked as unsecured creditors rather than as owners of segregated property.

Choosing by amount

A practical rule that most experienced holders converge on:

HoldingSensible arrangement
Trading floatExchange, with strong authentication
Small, actively usedHot wallet on a dedicated device
Meaningful long-termHardware wallet, seed backed up offline
Life-changingHardware wallet, multiple backups in separate locations, or multisig

The threshold that matters is emotional, not numerical: the amount whose loss would genuinely hurt. Above that, take custody seriously.

The seed phrase rules

These are the rules that determine outcomes, and they are short.

Never digitise it. No photograph, no cloud note, no password manager, no email draft, no text file, no screenshot. A camera roll that syncs to the cloud has destroyed a lot of wealth.

Write it on something durable. Paper burns and dissolves. For meaningful sums, stamped metal plates are inexpensive relative to what they protect.

Store copies in separate places. One backup is a single point of failure against fire and flood. Two in different buildings is meaningfully safer. Consider who else could access each location.

Never type it anywhere except into your hardware wallet during recovery. Every site or app asking you to enter a seed phrase to validate, sync, migrate, claim, or unlock is a theft. There are no exceptions to this, and it is the mechanism behind most seed phrase losses.

Consider a passphrase. Hardware wallets support an additional word of your choosing, creating an entirely separate wallet. It protects against someone finding the written seed. It also means forgetting it loses everything, so it must itself be backed up.

The attacks that actually work

The realistic threat is rarely cryptographic. It is social.

  • Fake support. Someone contacts you after you post about a problem, offering help, then requests your seed for verification.
  • Approval drain. You connect to a site and sign a transaction granting unlimited spending permission on a token. The site later empties the balance. Review what you are approving, and revoke old approvals periodically.
  • Address poisoning. An attacker sends a dust transaction from an address resembling one you use, hoping you copy it from your history later. Always verify the full address, not the first and last four characters.
  • SIM swap. Your phone number is transferred to an attacker, who then resets accounts secured by SMS. Use an authenticator app or hardware key, never SMS, for exchange accounts.
  • Counterfeit hardware. Buy only from the manufacturer directly. A pre-configured device with a seed phrase already supplied in the box is a theft device.
  • Clipboard malware. Software that swaps a copied address for the attacker's. Verify the destination on the hardware wallet screen, which malware cannot alter.

The inheritance problem

A great deal of crypto has been permanently lost because the only person who could access it died without leaving a usable path.

This requires planning that most people never do:

  • Ensure someone trusted knows that the assets exist and roughly where the recovery material is.
  • Leave clear instructions, separate from the seed itself, that explain the process to someone non-technical.
  • Consider splitting a seed across trusted parties, or using multisig, so no single person can act alone but a defined group can.
  • Review the arrangement periodically. Locations change; relationships change.

A password manager entry with sealed instructions, or a solicitor holding a sealed envelope, are both workable. Doing nothing is not.

A workable setup

  1. Buy a hardware wallet directly from the manufacturer.
  2. Initialise it yourself and generate a fresh seed on the device.
  3. Write the seed on metal. Verify it by performing a test recovery.
  4. Store two copies in separate secure locations.
  5. Move long-term holdings off exchanges to the hardware wallet.
  6. Keep a small hot wallet for day-to-day use, funded only with what you can afford to lose.
  7. Enable authenticator-app or hardware-key authentication on every exchange account.
  8. Test recovery once a year, and write down the inheritance instructions.

The bottom line

Self-custody trades one risk for another. On an exchange you depend on an institution remaining solvent and honest. In self-custody you depend on your own process being sound for as long as you hold.

Neither is free of risk. The difference is that the risk in self-custody is one you can actually control — and the effort required is a few hours once, against the possibility of a total, irreversible loss.

This article is educational and is not financial advice. Cryptocurrency transactions are irreversible.

Frequently asked questions

What is a seed phrase and why does it matter so much?+

A sequence of 12 or 24 words that mathematically generates every private key in your wallet. Anyone holding it controls the funds completely, from anywhere, without needing your device. Losing it means losing access permanently. It is not a password that can be reset; it is the asset itself in written form.

Is a hardware wallet worth it?+

For any amount you would be seriously unhappy to lose, yes. The keys are generated and stored on a dedicated device and never touch your internet-connected computer, so malware on that computer cannot extract them. Transactions must be physically confirmed on the device, which also blocks a large class of remote attacks.

Should I leave crypto on an exchange?+

Small working balances you actively trade, arguably. Long-term holdings, no. Exchange failures, freezes and hacks have caused very large permanent losses, and in insolvency customers have often ranked as unsecured creditors rather than owners of segregated assets. The industry maxim about not owning your keys exists because of a long documented history.

Where should I store the seed phrase?+

Offline, on durable material, in at least two geographically separated locations you control. Never as a photograph, a cloud note, a password manager entry, an email to yourself, or anything typed on an internet-connected device. Fire and flood destroy paper, so metal backup plates are a reasonable investment for meaningful sums.

Sources and further reading

Risk warning

Trading cryptocurrencies, forex and leveraged derivatives involves substantial risk of loss and is not suitable for every investor. Our content is journalism and education — never personalised financial advice. Full disclaimer.

Topicscustodywalletssecurityseed phrasecrypto basics

Published by

Trading News Global

Trading News Global is an independent publication. Our articles are researched, written and edited in-house against the standards set out in our editorial policy, and published under the newsroom byline rather than individual names. Responsibility for everything on this site sits with the publication, and every article carries a route to correct it.

Share this article

Share

Related reading