Home › Knowledge Hub › Cold vs warm wallets
Cold wallet vs warm wallet
A cold wallet keeps your private keys on a device that never connects to the internet. A warm wallet keeps them on a device that does. The real difference is not which is safer in the abstract. It is that cold storage removes an entire category of remote attack while leaving every attack that works by persuading you untouched, which is why most people who hold a meaningful amount end up running both.
The short answer
Use both. A warm wallet for the amount you can afford to lose in a bad week, and a cold wallet for the rest.
That arrangement costs a few minutes to set up and removes most of the worst outcomes. Everything below explains why, and what each one is doing for you.
What the terms mean
Cold wallet. A dedicated device that stores your private keys and signs transactions without those keys ever leaving it. Ledger, Trezor, Coldcard, Keystone and BitBox are common examples. Sometimes called a hardware wallet.
Warm wallet. Software on an internet-connected device: a browser extension, a mobile app, a desktop application. MetaMask, Rabby, Phantom, Trust Wallet. Often called a hot wallet; the terms are used interchangeably.
Neither holds your coins. Both hold a key. The assets exist on the blockchain, and the key is what authorises moving them. That is why losing a device is survivable and losing a recovery phrase is not.
The comparison that matters
| Cold wallet | Warm wallet | |
|---|---|---|
| Keys exposed to malware | No | Yes, if the device is compromised |
| Keys exposed by a bad website | No | Possible |
| Protects against approving a malicious transaction | Only partly | No |
| Protects an exposed recovery phrase | No | No |
| Speed of use | Slow, deliberate | Immediate |
| Cost | Device purchase | Free |
| Practical for daily use | Poor | Good |
| Risk if you lose the device | Low, restore from phrase | Low, restore from phrase |
| Physical theft or coercion | Vulnerable | Vulnerable |
Read the third and fourth rows together, because they are where the common assumption breaks.
What cold storage does not protect you from
Buying the device is not the end of the job, and treating it that way is how people with hardware wallets still lose money.
It does not stop you approving a malicious transaction. If you sign something harmful, the device signs it faithfully. It shows you a destination on a screen your computer does not control, which is valuable, but it cannot tell you whether the transaction is a good idea.
The clearest demonstration is Bybit in February 2025. The exchange lost more than $1.4 billion from a multisig cold wallet, with several authorised people reviewing the transfer before approving it. Analysis by NCC Group found attackers had compromised the interface those signers used. The cryptography held; the humans could not see what they were signing. Our guide to verifying what you sign covers what that means for an individual.
It does not protect a recovery phrase you have exposed. If the phrase is known to someone else, the device is irrelevant. They recreate the wallet anywhere.
It does not protect against a tampered device. A wallet supplied with a phrase already written down is compromised before you fund it. Our guide to hardware wallet scams covers this and the related fakes.
It does not help under coercion. Physical control of you plus the device defeats any technical measure.
What warm wallets are good at
The comparison usually runs one way, so it is worth stating the other side.
A warm wallet is free, instant, and usable. For anything you interact with regularly, a cold wallet introduces enough friction that people work around it, and the workarounds are worse than the original risk.
A warm wallet is also disposable. A drained wallet holding $200 is an annoyance. That is the whole argument for separation: it converts a catastrophe into an inconvenience.
And modern warm wallets do real work. Transaction simulation, drainer warnings and approval management are built into Rabby and available as layers elsewhere. Those catch a meaningful share of attacks that a hardware wallet would sign without comment.
How to split holdings
There is no correct percentage. The useful question is different.
Ask what you would need to replace. The amount whose loss would change your life belongs in cold storage. The amount whose loss would irritate you can sit in a warm wallet.
A workable arrangement for most people:
- Warm wallet: what you plan to use in the next month or two. It connects to applications, claims things, tries things.
- Cold wallet: everything else. It connects to nothing it has not connected to before, ideally nothing at all.
- Move from cold to warm when you need funds, not the reverse. The friction is the feature.
If you hold enough that the loss would be serious, consider a third layer: a cold wallet that has never signed anything at all, holding the largest portion, separate from the cold wallet you use occasionally.
When cold storage is not worth it
Being honest about this matters, because the advice is usually given as though it were universal.
Small holdings. If you hold a few hundred dollars of crypto, a hardware wallet costs a meaningful fraction of it and adds a new failure mode: a recovery phrase you now have to keep safe for years.
Frequent, small transactions. If you transact daily, cold storage will be worked around.
No secure way to store a backup. A cold wallet moves the risk from your computer to your recovery phrase. If you have no way to store that phrase safely, you may have made things worse rather than better. Our seed phrase guide covers doing it properly.
An exchange is not a wallet, and it is a different trade entirely: you hold no keys, the platform does, and your protection is its solvency and security rather than your own. That is a real option with real trade-offs, and it is not what this comparison is about.
Red flags either way
- A hardware wallet arriving with a recovery phrase supplied
- Any process asking you to enter a recovery phrase into a computer
- A wallet app downloaded from a search advertisement
- An approval prompt for a site that has no need for one
- A device you did not order arriving in the post
- Advice that a hardware wallet makes you safe, full stop
Checklist
- [ ] Long-term holdings in a wallet that connects to nothing
- [ ] Day-to-day amount only in the wallet that connects to applications
- [ ] Recovery phrases for both stored offline, in separate places
- [ ] Destination addresses verified on the device screen before signing
- [ ] Hardware bought from the manufacturer or a listed reseller
- [ ] Approvals on the warm wallet reviewed periodically
What this guide cannot do
Both arrangements reduce risk in different ways, and neither eliminates it. A hardware wallet is not a guarantee, a warm wallet is not automatically unsafe, and the largest theft on record happened to an organisation using cold storage with multiple reviewers.
This is general information, not legal or financial advice.
Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.
Sources
NCC Group, Bybit Hack: In-Depth Technical Analysis, March 2025. https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/
Loss figures for the Bybit incident vary between $1.4 billion and $1.5 billion across sources; we use "more than $1.4 billion" following NCC Group.
Frequently asked questions
Is a cold wallet always safer than a warm wallet?
Against remote key theft, yes, decisively. Against approving a malicious transaction, barely. Against an exposed recovery phrase, not at all. The categories it does not cover are where most individual losses happen.
How much should I keep in a hot wallet?
What you would use in the next month or two, and no more than you could absorb losing. The purpose of the split is to convert a catastrophic loss into an irritating one.
Do I need a hardware wallet if I only hold a small amount?
Probably not. The device costs a meaningful fraction of a small holding and adds a recovery phrase you must keep safe for years. Below a few thousand dollars, a well-run warm wallet with separated holdings is a reasonable position.
Can I use a hardware wallet with MetaMask?
Yes, most browser wallets pair with hardware devices so signing happens on the device. That is a genuine improvement, because the destination appears on a screen your computer does not control. It still cannot tell you whether a transaction is safe.
What happens if my hardware wallet breaks or I lose it?
Your funds are on the blockchain, not on the device. Buy a replacement and restore from your recovery phrase. This is exactly why the phrase matters more than the hardware.
Is keeping crypto on an exchange the same as a warm wallet?
No. On an exchange you hold no keys at all; the platform does. Your protection is its security and solvency rather than your own. That can be a reasonable choice, and it is a different trade-off from either wallet type.
Should I use more than one cold wallet?
If you hold enough that a single failure would be serious, splitting across two is reasonable: one that has never signed anything for the bulk, one used occasionally. For most people it adds complexity without much benefit.
Does a passphrase make a cold wallet meaningfully safer?
Against someone finding your written backup, yes, meaningfully. It also means forgetting it loses those funds permanently, with no recovery path. Use one only with a dependable way to remember and back it up separately.
Already lost something?
Eleven questions showing which documentation and reporting routes are available in your case.
Check my case