Crypto Basics
Cold Wallet vs Hot Wallet: A Criteria Comparison
A hot wallet keeps keys on an internet-connected device. A cold wallet generates and stores keys offline. It signs inside the device. The trade is exposure against convenience, in the sources' own framing. This page compares the two on criteria. It picks no winner and names no products.
What this page compares
Two custody models, on the criteria the sources themselves use. A hot wallet stores keys on an internet-connected device. A mobile app, a browser extension, a desktop program.
A cold wallet generates and stores keys offline. They are never exposed to the internet.
The device signs inside itself [1].
This page picks nothing. Every table row is a sourced claim, attributed and dated. The reader maps their own situation onto it. That is deliberate. Wallet security is a threat-model question, and threat models differ.
One definition sits underneath both models. A wallet stores keys and signs with them. The funds sit on the blockchain, not in the wallet [1]. Hot and cold describe key storage, never coin storage.
The custody spectrum underneath
Both models sit on one side of a deeper line, the custody line. A hot wallet and a cold wallet are both self-custody. The holder controls the keys, or the seed phrase behind them. No one else can sign [1]. Every maker states the trade the same way. Lose the key material and its backup, and there is no reset and no recovery [1].
The other side of the line is exchange custody. A third party holds the keys. The customer holds an account claim instead. bitcoin.org’s characterization is quoted, not adopted. When a third party controls your keys, you rely entirely on their security and honesty [2]. The same source adds that exchanges and online wallets can be hacked, fail, or freeze access.
This page’s comparison lives on the self-custody side of that line. Custody versus self-custody is a prior decision. This paragraph is its only appearance here.
The comparison table
The table above states each side’s sourced wording per criterion. Three rows deserve prose.
On online compromise, the cold side’s advantage is structural. Cold keys are generated and stored offline and never touch the internet. A compromised computer does not expose them [1]. The hot side’s key sits where malware lives.
On physical threat, neither side wins, and the table says so honestly. Press reporting from 17 August 2026 documented shipping breaches that exposed hardware-wallet buyers’ home addresses [6]. The same reporting cites researcher counts of dozens of physical attacks on holders in 2025, up 75 percent year over year, with thefts upwards of 40 million dollars [6]. The figures are press-attributed context, dated and labeled. Cold custody changes the attack. It does not remove attackers.
On convenience, the honest framing comes from the Glacier Protocol itself. Accessing highly secure bitcoins is cumbersome and introduces security risk through human error, so it is best done infrequently [4]. That is a cost of cold custody, stated by an authority on cold custody.
Amount tiering, in the sources’ voice
bitcoin.org’s shared framing, quoted not adopted. Keep only small amounts for everyday use on connected devices, and the remaining part of your funds in a safer environment [2]. Trezor’s own hot-and-cold pages mirror the same shape [1]. This site reports the tiering as the sources’ shared observation. It does not turn their tiering into advice.
Where multisig fits
Multisignature wallets require m-of-n keys to spend, commonly two of three or three of five. The Glacier Protocol documents keys stored in different locations. One discovered key does not unlock the funds [4]. The documented trade-off runs both ways. Higher thresholds protect against key compromise. They also raise the odds of losing access [5]. Multisig is a tool for specific threat models. It is not a step up from every singlesig setup.
How this page was checked
Three tiers of sources, kept distinct. Maker docs carry the device rows, Trezor, BitBox, and Ledger, read 11 September 2026. The BitBox backup guide, updated 27 July 2026, carries the cost and phishing rows [3]. Practitioner material carries the protocol rows: bitcoin.org’s guide, the bitcoin.it wiki, Glacier, and Unchained. One press piece carries the 2026 shipping-breach context, dated and attributed. It is context, never a practice row [6].
What is absent is as deliberate as what is present. No review sites, roundups, or price comparisons were used. None of them carry dated claims a reader can re-check. The wipe counters stayed per maker. Three wrong PINs at one, sixteen at another. Generalizing them would invent a rule nobody published.
What would change the answer
The comparison shifts with documented events, not opinions. If hot-wallet operating systems hardened against malware, the online-compromise row would narrow. If hardware-wallet shipping leaked again at scale, the physical row would widen against cold custody. A person’s own situation moves the weights on every row. Transaction frequency, amounts held, physical security. The page re-reviews on vendor doc changes. The dates on every row are the contract.
Where this page sits
The seed phrase safety page covers the backup both models depend on. The cryptocurrency introduction defines the assets being secured. The stablecoins hub covers the tokens most often held this way. The cryptocurrency hub frames the cluster. Every claim above carries its source and date.
| Criterion | Cold or hardware side | Hot or software side |
|---|---|---|
| Online compromise | Keys generated and stored offline, never exposed to the internet; a compromised computer does not expose them | Key stored on a connected device, more vulnerable to hacking |
| Phishing and social engineering | Signing happens on-device, with address and amount verified there, reducing seed-exposure paths | Every input surface is an attack surface; the offline rule for recovery words names the hot-side danger |
| Physical and supply-chain threat | Not solved by cold custody. 2026 reporting documented shipping breaches exposing buyers' addresses | The same physical risks apply to any identified holder, with remote-theft paths on top |
| Cost | One-time device purchase plus optional backup medium; steel costs more and needs careful setup | Software is free to acquire; costs are operational and loss-bearing |
| Convenience | Signing requires the device and PIN; best done infrequently, per the Glacier Protocol's own caution | Convenience and quick access, suited to amounts needing frequent use |
| Recovery | Seed-based. Funds recover on a replacement device from the backup, with the backup's own hygiene governing outcomes | Also seed-based, with the risk that the same connected device is both wallet and most-attacked environment |
In favor
- Cold custody keeps keys off the internet for their whole life, which removes whole classes of remote attack, per the maker docs.
- Cold custody suits larger amounts and long holds, in the sources' own tiering language.
- Hot custody gives convenience and quick access, which frequent transacting needs.
Trade-offs
- Cold custody adds a device dependency, and access turns cumbersome. Glacier itself warns that infrequent access adds human-error risk.
- Cold custody does not answer physical threats. 2026 reporting shows buyers' addresses leaking through shipping partners.
- Hot custody places keys on the most-attacked device a person owns, with malware drainage documented since the early era.
Frequently asked questions
What is a crypto wallet?
A tool that holds private keys and signs with them. The funds sit on the blockchain, not in the wallet, per the maker docs this site cites. Hot and cold describe the keys, never the coins.
Cold wallet vs hot wallet: which?
This site does not pick. The comparison runs on sourced criteria. Cold custody keeps keys offline, cutting online exposure and costing convenience. Hot custody keeps keys on a connected device, trading exposure for access. The sources share one framing, in their own voice. Keep small amounts on connected devices for everyday use. Keep the rest somewhere safer.
Can an old phone be used as a long-term cold wallet?
No consensus supports it. The docs this site researched endorse purpose-built offline key storage. None of them endorse old phones as cold storage. The absence is the finding. This site reports it rather than inventing a verdict.
Is a multi-signature wallet safe?
Multisig spreads control across m-of-n keys in different locations, per the protocols this site cites. One compromised key is not enough to spend. The trade-off runs the other way too. Higher sign thresholds make loss of access easier. That is a risk, not a safety feature.
How are wallets actually secure?
By keeping keys away from whoever should not have them. A hardware wallet signs inside the device, with keys that never reach the internet. A software wallet guards keys on a connected device that malware can reach. Both depend on the backup phrase staying offline and intact. That discipline has its own page on this site.
How do I protect stablecoins long-term without a hardware wallet?
The same hygiene applies wherever keys live. Generate the phrase on the device. Keep every copy offline and physical. Store copies apart from the device. Test recovery before funding. Custodial accounts are the other documented path, with the third-party risk stated on this page.
Last verified