Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › Cold vs warm wallets

Cold wallet vs warm wallet

By Yair Revach · Co-founder, Chain Pursuit · 8 min · Last updated 1 October 2026

A cold wallet keeps your private keys on a device that never connects to the internet. A warm wallet keeps them on a device that does. The real difference is not which is safer in the abstract. It is that cold storage removes an entire category of remote attack while leaving every attack that works by persuading you untouched, which is why most people who hold a meaningful amount end up running both.

The short answer

Use both. A warm wallet for the amount you can afford to lose in a bad week, and a cold wallet for the rest.

That arrangement costs a few minutes to set up and removes most of the worst outcomes. Everything below explains why, and what each one is doing for you.

What the terms mean

Cold wallet. A dedicated device that stores your private keys and signs transactions without those keys ever leaving it. Ledger, Trezor, Coldcard, Keystone and BitBox are common examples. Sometimes called a hardware wallet.

Warm wallet. Software on an internet-connected device: a browser extension, a mobile app, a desktop application. MetaMask, Rabby, Phantom, Trust Wallet. Often called a hot wallet; the terms are used interchangeably.

Neither holds your coins. Both hold a key. The assets exist on the blockchain, and the key is what authorises moving them. That is why losing a device is survivable and losing a recovery phrase is not.

The comparison that matters

Cold walletWarm wallet
Keys exposed to malwareNoYes, if the device is compromised
Keys exposed by a bad websiteNoPossible
Protects against approving a malicious transactionOnly partlyNo
Protects an exposed recovery phraseNoNo
Speed of useSlow, deliberateImmediate
CostDevice purchaseFree
Practical for daily usePoorGood
Risk if you lose the deviceLow, restore from phraseLow, restore from phrase
Physical theft or coercionVulnerableVulnerable

Read the third and fourth rows together, because they are where the common assumption breaks.

What cold storage does not protect you from

Buying the device is not the end of the job, and treating it that way is how people with hardware wallets still lose money.

It does not stop you approving a malicious transaction. If you sign something harmful, the device signs it faithfully. It shows you a destination on a screen your computer does not control, which is valuable, but it cannot tell you whether the transaction is a good idea.

The clearest demonstration is Bybit in February 2025. The exchange lost more than $1.4 billion from a multisig cold wallet, with several authorised people reviewing the transfer before approving it. Analysis by NCC Group found attackers had compromised the interface those signers used. The cryptography held; the humans could not see what they were signing. Our guide to verifying what you sign covers what that means for an individual.

It does not protect a recovery phrase you have exposed. If the phrase is known to someone else, the device is irrelevant. They recreate the wallet anywhere.

It does not protect against a tampered device. A wallet supplied with a phrase already written down is compromised before you fund it. Our guide to hardware wallet scams covers this and the related fakes.

It does not help under coercion. Physical control of you plus the device defeats any technical measure.

What warm wallets are good at

The comparison usually runs one way, so it is worth stating the other side.

A warm wallet is free, instant, and usable. For anything you interact with regularly, a cold wallet introduces enough friction that people work around it, and the workarounds are worse than the original risk.

A warm wallet is also disposable. A drained wallet holding $200 is an annoyance. That is the whole argument for separation: it converts a catastrophe into an inconvenience.

And modern warm wallets do real work. Transaction simulation, drainer warnings and approval management are built into Rabby and available as layers elsewhere. Those catch a meaningful share of attacks that a hardware wallet would sign without comment.

How to split holdings

There is no correct percentage. The useful question is different.

Ask what you would need to replace. The amount whose loss would change your life belongs in cold storage. The amount whose loss would irritate you can sit in a warm wallet.

A workable arrangement for most people:

If you hold enough that the loss would be serious, consider a third layer: a cold wallet that has never signed anything at all, holding the largest portion, separate from the cold wallet you use occasionally.

When cold storage is not worth it

Being honest about this matters, because the advice is usually given as though it were universal.

Small holdings. If you hold a few hundred dollars of crypto, a hardware wallet costs a meaningful fraction of it and adds a new failure mode: a recovery phrase you now have to keep safe for years.

Frequent, small transactions. If you transact daily, cold storage will be worked around.

No secure way to store a backup. A cold wallet moves the risk from your computer to your recovery phrase. If you have no way to store that phrase safely, you may have made things worse rather than better. Our seed phrase guide covers doing it properly.

An exchange is not a wallet, and it is a different trade entirely: you hold no keys, the platform does, and your protection is its solvency and security rather than your own. That is a real option with real trade-offs, and it is not what this comparison is about.

Red flags either way

Checklist

What this guide cannot do

Both arrangements reduce risk in different ways, and neither eliminates it. A hardware wallet is not a guarantee, a warm wallet is not automatically unsafe, and the largest theft on record happened to an organisation using cold storage with multiple reviewers.

This is general information, not legal or financial advice.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Sources

NCC Group, Bybit Hack: In-Depth Technical Analysis, March 2025. https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/

Loss figures for the Bybit incident vary between $1.4 billion and $1.5 billion across sources; we use "more than $1.4 billion" following NCC Group.

Frequently asked questions

Is a cold wallet always safer than a warm wallet?

Against remote key theft, yes, decisively. Against approving a malicious transaction, barely. Against an exposed recovery phrase, not at all. The categories it does not cover are where most individual losses happen.

How much should I keep in a hot wallet?

What you would use in the next month or two, and no more than you could absorb losing. The purpose of the split is to convert a catastrophic loss into an irritating one.

Do I need a hardware wallet if I only hold a small amount?

Probably not. The device costs a meaningful fraction of a small holding and adds a recovery phrase you must keep safe for years. Below a few thousand dollars, a well-run warm wallet with separated holdings is a reasonable position.

Can I use a hardware wallet with MetaMask?

Yes, most browser wallets pair with hardware devices so signing happens on the device. That is a genuine improvement, because the destination appears on a screen your computer does not control. It still cannot tell you whether a transaction is safe.

What happens if my hardware wallet breaks or I lose it?

Your funds are on the blockchain, not on the device. Buy a replacement and restore from your recovery phrase. This is exactly why the phrase matters more than the hardware.

Is keeping crypto on an exchange the same as a warm wallet?

No. On an exchange you hold no keys at all; the platform does. Your protection is its security and solvency rather than your own. That can be a reasonable choice, and it is a different trade-off from either wallet type.

Should I use more than one cold wallet?

If you hold enough that a single failure would be serious, splitting across two is reasonable: one that has never signed anything for the bulk, one used occasionally. For most people it adds complexity without much benefit.

Does a passphrase make a cold wallet meaningfully safer?

Against someone finding your written backup, yes, meaningfully. It also means forgetting it loses those funds permanently, with no recovery path. Use one only with a dependable way to remember and back it up separately.

Already lost something?

Eleven questions showing which documentation and reporting routes are available in your case.

Check my case

Keep reading