What a wallet actually stores
A crypto wallet doesn't hold coins — coins only ever exist as entries on the blockchain. What a wallet holds is the private key that authorizes moving them. Whoever controls the key controls the coins; that's the entire ownership model, and everything about wallet security follows from it.
An exchange account works differently: the exchange's wallets hold the keys, and what you hold is a custodial claim on the exchange. That works fine day to day, and fails exactly when it matters: hacks, withdrawal freezes, insolvency. It's why long-term holdings tend to migrate to self-custody.
The wallet taxonomy
| Type | Traits | Examples |
|---|---|---|
| Hot wallet | Internet-connected; convenient, more exposed | MetaMask, mobile wallets, exchange accounts |
| Cold wallet | Keys kept offline; strongest protection against remote attack | Ledger, Trezor hardware devices |
| Custodial | A third party holds the keys for you | Exchange balances |
| Non-custodial | You hold the keys — and the responsibility | MetaMask, hardware wallets |
The standard arrangement is a split: a hot wallet (or exchange balance) for active funds, cold storage for the long-term stack. Convenience and security don't have to fight if each job gets the right tool.
The seed phrase is everything
Creating a wallet produces a 12- or 24-word seed phrase — the master backup from which every key in the wallet can be regenerated. Two blunt consequences: anyone who reads it owns your coins, and if you lose it (and the device), the coins are gone permanently. No support desk, no reset flow.
- Never digitize it. No photos, no cloud notes, no password managers, no email drafts. Every digital copy is an additional avenue for theft.
- Write it on paper (or stamped metal, for fire/water resistance) and store it where documents of real value live.
- Split the risk — two secure locations beat one.
- Only ever type it into the wallet's own official app or device. Any website or "support agent" asking for a seed phrase is a theft in progress — no exceptions exist to this rule.
Hot wallet hygiene
Browser wallets like MetaMask are the doorway to DeFi and the most-targeted software in crypto. The risks are manageable with habits:
- Install only from the official domain — search ads regularly place fake wallet sites above the real one.
- Be stingy with connections: every site your wallet connects to is added attack surface.
- Review and revoke token approvals periodically — an unlimited approval granted once to a compromised contract can drain you years later.
- Keep serious funds in a separate wallet that never touches unfamiliar contracts. (The threat landscape in DeFi specifically is covered in the DeFi guide.)
Hardware wallets
A hardware wallet keeps keys inside a dedicated device that never exposes them — transactions are signed on the device itself, so the key is designed to stay off your computer entirely (though a compromised computer can still present malicious transaction details, which is why verifying details on the device screen matters). For holdings above what you'd carry as cash, the device meaningfully reduces remote-theft risk. One mental model fix: the device is not the wallet — the seed is. A lost or broken device restores fully onto a new one from the seed phrase; a leaked seed empties the wallet while the device sits safely in its drawer.
The security checklist
- Unique passwords per venue; app-based 2FA (not SMS) everywhere it's offered.
- Verify both the start and end of any address you paste — clipboard-hijacking malware swaps addresses mid-copy.
- Send a small test amount before any large transfer.
- Treat unsolicited airdrops and "free token" messages as hostile; interacting with unknown token contracts is how many drains begin.
- Assume anyone DMing you help, support, or urgency is an attacker until proven otherwise.
Where wallets fit in a beginner's overall setup is covered in the beginner's guide — and if the vocabulary here is new, the glossary fills the gaps.