A crypto wallet doesn’t actually store coins — it stores the private key that proves ownership of coins recorded on a blockchain. That distinction sounds academic right up until it explains everything about wallet security: lose the key, lose the coins, no customer service line to call. Understanding what a wallet really is makes every decision after this — hardware or software, custodial or self-custody, which app to trust — much easier to reason through.
Custodial vs. self-custody: who actually holds the keys
An exchange account, like a Coinbase or Kraken balance, is a custodial wallet: the exchange holds the private keys on the buyer’s behalf, the same way a bank holds cash on a depositor’s behalf. It’s convenient and requires no technical setup, but it means access to the coins depends on that company staying solvent and functioning — a risk that’s played out expensively for customers of exchanges that later collapsed.
A self-custody wallet flips that: the person holding the seed phrase controls the keys directly, with no company standing between them and their coins. That independence is the entire point of self-custody, and it comes with a trade-off — there’s no support line to call and no password reset if the seed phrase is lost. Self-custody trades convenience for control, and it’s worth it for anything meant to be held longer than a few weeks.
Hot wallets vs. cold wallets
A hot wallet is connected to the internet — a phone app, a browser extension, desktop software. It’s built for speed: sending, receiving, and swapping coins happen in seconds, which makes it the right tool for spending money and everyday transactions. That same internet connection is also its weak point, since malware, phishing, and compromised devices all target software that’s always online.
A cold wallet, almost always a small hardware device, keeps the private key offline at all times, only connecting briefly to sign a transaction. It’s slower and less convenient by design — that inconvenience is a feature, not a bug, because it removes the always-on internet exposure that makes hot wallets a target. Cold storage is the standard recommendation for anything meant to sit untouched for months or years.
Most people who hold crypto for more than a passing interest end up running both: a hardware wallet for the bulk of their holdings, treated like a vault, and a hot wallet loaded with a small spending balance for day-to-day use. Splitting balances this way limits what’s actually exposed if a phone gets compromised or a hot wallet app has a bad day.
What a hardware wallet actually costs
Hardware wallets are a one-time purchase, not a subscription, and prices have stayed fairly stable. The Ledger Nano X sits around $99 and supports well over 10,000 coins and tokens through its companion app, connecting over USB-C or Bluetooth. The Trezor Safe 5 runs about $129 and leans on fully open-source firmware that anyone can audit, connecting over USB-C only — Trezor treats Bluetooth as an unnecessary attack surface and leaves it out deliberately.
Neither is objectively “better” across the board. The Nano X’s broader coin support and Bluetooth convenience suit someone managing a varied portfolio from a phone; the Safe 5’s open-source firmware and wired-only connection suit someone who weighs auditability and a smaller attack surface above convenience. Either is a reasonable first hardware wallet, and either beats leaving a meaningful balance on an exchange indefinitely. For a smaller starting budget, the Trezor Safe 3 covered in this site’s small-balance wallet roundup gets into cold storage for roughly half the price.
The seed phrase is the whole wallet
Every wallet, hardware or software, generates a seed phrase — usually 12 or 24 words — when it’s first set up. That phrase can regenerate every private key the wallet controls. Anyone who has it can move the funds, and if it’s lost with no backup, the funds are gone permanently. There’s no password reset, no support ticket, no override.
The practical rules that follow from that are strict for a reason:
- Never type it into a website, app, or email — no legitimate wallet provider or exchange will ever ask for a seed phrase. Any prompt asking for one is a phishing attempt, full stop.
- Never store it as a photo or in cloud storage. A screenshot that’s been backed up to a photo library or cloud account has likely already left the device it was taken on, and deleting the image afterward doesn’t undo that. If a seed phrase has ever touched a cloud-synced app, the safer move is generating a brand-new wallet and moving funds over, not trusting the old one going forward.
- Write it down physically — pen and paper works, and steel backup plates rated for fire and water damage are a worthwhile upgrade for anything holding meaningful value.
- Keep backups in more than one physical location. A single paper copy in a drawer is one house fire away from being the only backup that mattered.
Setting up a wallet the right way
Buy hardware direct, never secondhand
A hardware wallet should come straight from the manufacturer or an authorized retailer, never a marketplace listing or a “discounted” reseller. Devices tampered with before sale, including pre-loaded seed phrases designed to look freshly generated, are a documented scam pattern — and there’s no way to visually verify a device hasn’t been altered.
Generate the seed phrase on the device itself
The device should generate its own seed phrase during first setup, displayed only on its own screen. If any app, website, or piece of paper in the box already has a seed phrase written on it before setup even starts, that’s a strong sign the device is compromised. Treat it as unsafe and don’t fund it.
Verify the receiving address on the device screen
Malware on a computer can, in rare but real cases, swap a copied wallet address for an attacker’s address without any visible change on screen. A hardware wallet’s own display, separate from the computer, is what confirms the address actually matches what the device is signing — always check it there before confirming a transaction of any size.
Software wallets worth knowing
Not every hot wallet is created equal. A browser extension wallet like MetaMask is built around Ethereum and its many compatible networks and is the default for interacting with decentralized apps. A multi-chain app wallet like Exodus, covered in more depth in this site’s wallet app review, trades some of that DeFi-native flexibility for a friendlier interface and built-in swapping across a wide range of chains. Neither is inherently unsafe — the risk with software wallets comes from the device they run on, not usually from the wallet code itself.
A simple way to decide what goes where
| Situation | Recommended setup |
|---|---|
| Learning the basics, small first purchase | Exchange custody or a free hot wallet is fine short-term |
| Everyday spending, small recurring balance | Hot wallet on phone or browser |
| Long-term holding, meaningful balance | Hardware wallet, seed phrase backed up offline |
| Interacting with DeFi apps regularly | Browser extension wallet, ideally paired with hardware signing |
None of this needs to be perfect on day one. What it needs is a starting point that matches how much is actually at stake: small and casual can stay in a hot wallet, anything meant to last should move to hardware, and the seed phrase — wherever it ends up — should never touch a camera roll, a cloud backup, or a website asking for it.
Leave a Reply