Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › How to secure a cold wallet

How to secure a cold wallet

By Yair Revach · Co-founder, Chain Pursuit · 11 min · Last updated 1 October 2026

A cold wallet keeps your private keys off any internet-connected computer. That removes a whole category of theft, and it leaves several others untouched. The keys stay on the device. What still has to be right is how you set it up, how you back up the recovery phrase, and how carefully you check what you are approving when you sign. The largest crypto theft on record happened to an organisation using cold storage with multiple human reviewers, because the interface showing them the transaction had been tampered with.

Who this is for

You have bought a hardware wallet, or you are about to, and you hold enough that losing it would be serious. You do not need to be technical. Where a term appears for the first time, it is explained.

If you think funds have already gone, this is the wrong page. Start with what to do in the first 48 hours.

1. What cold storage does and does not protect against

If you are still deciding between approaches, our cold and warm wallet comparison sets out the trade-offs side by side.

A cold wallet, sometimes called a hardware wallet, is a small device that stores your private keys and signs transactions without those keys leaving it. Ledger, Trezor, Coldcard, Keystone and BitBox are common examples.

The important distinction is that a hardware wallet is a signing device, not a vault. Your coins are not inside it. They exist on the blockchain, and the device holds the key that authorises moving them. If the device is lost, the coins are still there and your recovery phrase gets you back to them. If someone obtains your recovery phrase, the device becomes irrelevant.

Cold storage reducesCold storage does little about
Remote extraction of keys by malwareApproving a transaction you did not understand
Keys exposed by a compromised exchangeYour recovery phrase being seen, photographed or stored badly
Browser-based phishing that captures keysA tampered or counterfeit device
Keylogging your wallet passwordFake wallet software and fake update prompts
Your computer being compromised while idleSomeone forcing you to unlock it

Every row on the right involves a person being persuaded or coerced. That is where most of the remaining risk lives, and it is why the rest of this guide spends more time on verification than on storage.

There is one category that neither column covers, and it is worth stating plainly because it undercuts the usual pitch.

When the device itself is the problem

Beginning 30 July 2026, attackers drained Coldcard hardware wallets made by Coinkite. A firmware defect introduced in March 2021 weakened the randomness used to generate seed phrases, cutting key strength from 128 bits to as little as 40. That made the resulting private keys brute-forceable on ordinary hardware, without any access to the device.

TRM Labs traced roughly 1,816 BTC taken from more than 5,200 addresses across four waves, worth around $116 million. Other estimates run higher; TechCrunch and several analytics firms put the total above $130 million across at least 7,300 wallets, and TRM identified at least 15 distinct threat actors, some likely opportunistic.

One victim who lost $1.6 million wrote that he had never shared his seed phrase with anybody and that his devices had never touched the internet. Both statements were true. Neither helped.

The detail that matters most for anyone affected: updating the firmware fixes future wallet creation and does nothing for a seed already generated under the vulnerable version. If you created a wallet on a Coldcard between March 2021 and the patch, the seed should be treated as compromised, and funds moved to a wallet generated on a device you trust.

This does not mean hardware wallets are a bad idea. It means the guarantee is narrower than it is usually sold as. A hardware wallet removes an entire category of remote attack against your computer. It does not remove the possibility that the device generated a weak key years before anyone noticed.

What cold storage does and does not cover
COLD STORAGE REDUCESIT DOES LITTLE ABOUTRemote extraction of keys by malwareKeys exposed by a compromised exchangeBrowser phishing that captures keysKeylogging your wallet passwordYour computer compromised while idleApproving something you did not understandYour recovery phrase being seen or stored badlyA tampered or counterfeit deviceFake wallet software and update promptsSomeone forcing you to unlock itEverything on the right involves a person being persuaded or coerced.
Every item on the right involves a person being persuaded or coerced, which is why the rest of this guide spends more time on verification than on storage.

2. Before you buy

Buy from the manufacturer directly, or from a reseller the manufacturer lists on its own site. Not a marketplace, not an auction listing, not a discounted third-party seller. A device that passed through unknown hands is a device you cannot reason about.

A new device must generate its own recovery phrase, in front of you, during setup. If a device arrives with a phrase already written on a card, a scratch panel, or a slip of paper inside the box, it is compromised. Someone else has that phrase and is waiting for you to fund the wallet. This has been a recurring scam for years, and it works because the packaging looks convincing.

Tamper-evident seals are weak evidence. They can be reproduced, and counterfeit and tampered devices are a documented problem. Treat an intact seal as mildly reassuring and a broken one as disqualifying, rather than the reverse.

Never accept a hardware wallet as a gift or prize from someone you do not know. Unsolicited devices arriving in the post have been used to distribute tampered hardware.

3. Setting it up

Do this when you have an hour and are not rushed. Most mistakes at this stage come from hurrying.

Generate the recovery phrase on the device. The device will show you a sequence of words, usually 12 or 24. Write them on paper as they appear. Do not type them into anything. Do not photograph them. Do not read them aloud near a voice assistant.

Verify the phrase when the device asks. It will request several words back. This step exists because a transcription error discovered now is an inconvenience, and the same error discovered after a device failure is a permanent loss.

Set a PIN you have not used elsewhere. The PIN protects the physical device. It is not what protects your funds; the recovery phrase is.

Consider a passphrase, carefully. Many devices support an optional extra word, sometimes called a 25th word or a hidden wallet. It creates a separate wallet that cannot be reached with the recovery phrase alone. It improves resistance to someone finding your written backup. It also means that forgetting the passphrase loses those funds permanently, with no recovery path. Use one if you have a reliable way to remember and back it up separately. Skip it if you are unsure.

Send a small test amount first. Move a trivial sum in, then out again, before transferring anything significant. This confirms the whole chain works before it matters.

4. Backing up the recovery phrase

This is where most permanent losses originate, and the failure is usually a backup that was either too fragile or too exposed.

Where a phrase should never go: a photograph, a cloud drive, an email to yourself, a notes app, a password manager, a text message, a spreadsheet, or any website. Each of these has produced documented losses. The recovery phrase is the wallet; anywhere it exists, the wallet exists.

Paper works until it does not. Water, fire and ordinary fading are the common failure modes. Steel backup plates cost less than most people's holdings and survive conditions paper does not.

Make at least two backups, stored in different places. A single backup means one flood or one fire loses everything. Two backups in the same drawer is one backup.

Think about who else can reach it. A safe at home protects against a burglar and not against a household member. A bank deposit box protects against both and adds a third party to the arrangement. Neither is wrong; the point is to decide deliberately rather than by default.

Plan for your own absence. If something happens to you, the funds are unreachable unless someone can find and use the backup. Solutions range from a sealed letter with a solicitor to formal inheritance arrangements. Whatever you choose, it should not require writing the phrase anywhere new.

5. Signing: the part that matters most

Here is the section most guides skip, and the reason this article exists.

What Bybit demonstrated

On 21 February 2025, the cryptocurrency exchange Bybit detected unauthorised activity during a routine transfer from an Ethereum multisig cold wallet to a warm wallet. More than $1.4 billion in assets, including 401,347 ETH, were taken. It remains the largest cryptocurrency theft on record.

The attackers did not break the cryptography and did not steal the keys. Bybit's arrangement required multiple authorised people to approve a transaction. Analysis by NCC Group found that the attackers instead targeted the web interface used to manage the multisig, altering what the signers saw when approving the transfer. Forensic work reported by Sygnia found malicious JavaScript had been introduced into the Safe{Wallet} interface used in that workflow. Safe{Wallet} stated its smart contracts were unaffected.

The signers reviewed the transaction, saw what appeared to be a legitimate internal transfer to a known address, and approved it. The underlying transaction logic and destination were different.

Reporting has attributed the attack to North Korean state-linked actors. That attribution comes from investigators rather than a court, and is worth treating as a strong claim rather than a settled fact.

The lesson is not that cold storage failed. It is that reviewing a transaction on a screen is not the same as verifying it, because the screen can be wrong. Three sets of trained eyes reviewed that transfer.

What this means for you

Verify the destination address on the hardware device's own display. The device screen is driven by the device, not by your computer. If the address shown there differs from the one on your monitor, stop. This single habit is the reason hardware wallets have a screen at all.

Check the whole address, not the ends. Address poisoning attacks work by seeding your transaction history with look-alike addresses that match the first and last few characters. In December 2025 and January 2026, Scam Sniffer reported individuals losing approximately $50 million and $12.25 million respectively after copying the wrong address from their own history.

Do not copy addresses from your transaction history. Use a saved contact in your wallet software, or paste from the source and verify on the device.

Understand blind signing, and refuse it where you can. Some transactions, particularly complex smart contract interactions, cannot be fully decoded by the device, so it shows you a hash rather than readable details. Approving that is blind signing. It is sometimes unavoidable, and it is always a decision. If your device cannot tell you what a transaction does and you cannot independently establish it, declining costs you nothing.

Prefer devices and apps that support clear signing, where transaction details are rendered in readable form rather than as raw data.

Use a separate wallet for experimentation. Keep long-term holdings in a wallet that never connects to an unfamiliar site. Our guide to wallet drainers and token approvals explains how a single approval can authorise later transfers you never see coming.

6. Firmware, apps and fake updates

Update firmware through the manufacturer's official application, reached by typing the address yourself. Never through a link in an email, a message, a search advertisement, or a pop-up.

Fake update prompts are a standing lure. A message saying your device needs an urgent security update, followed by a page asking for your recovery phrase to "restore" the wallet, is a complete attack in two steps.

No firmware update, no support process, no migration, and no verification tool ever requires your recovery phrase. There is no exception. Any request for it, from anyone, in any context, is theft in progress.

Download companion software from the official domain, typed rather than clicked. Malicious wallet applications appear regularly in app stores and search results, sometimes purchased as advertisements above the genuine result.

7. Physical risks

Travel. Consider whether the device needs to travel at all. Crossing borders with it may invite questions in some jurisdictions. A wallet you can reconstruct from a backup at your destination may be simpler than one you carry.

Household. Most people's threat model is not a state actor. It is a visitor, a contractor, a flatmate, or a family dispute. Storage should account for that without becoming so elaborate that you lose access yourself.

Coercion. If someone can compel you to unlock the device, technical controls stop mattering. A passphrase-protected hidden wallet provides some options here, and discussing specifics publicly reduces their usefulness. The general principle: do not advertise your holdings, online or in person.

8. If something may already be wrong

Act on suspicion rather than waiting for certainty.

If the recovery phrase may have been seen, photographed, typed into anything, or stored somewhere it should not be: generate a new wallet on the device, move all funds to it, and treat the old phrase as burned. Do this now rather than later. Attackers frequently monitor a compromised address and sweep anything that arrives.

If you approved a transaction you do not understand: check what permissions the address now holds using a token approval checker such as Revoke.cash or the approval tool on Etherscan. Navigate there by typing the address; fake revocation sites exist and are themselves drainers. Revoking stops future transfers. It does not reverse what has already moved.

If the device behaved unexpectedly during setup, showed a phrase you did not generate, or arrived pre-configured: stop using it and contact the manufacturer through their official site.

Then preserve what you have. Our evidence checklist sets out what matters and why transaction identifiers decide whether a report can be acted on.

Red flags

What not to do

Cold wallet checklist

Buying

Setup

Backup

Ongoing

What this guide cannot do

Security controls reduce risk. They do not eliminate it. Following everything here does not guarantee that funds cannot be stolen, and no honest guide can promise otherwise. New attack methods appear, software has flaws, and people under pressure make decisions they would not otherwise make.

This is general information, not legal, tax or financial advice. Where jurisdiction matters, consult someone qualified where you live.

If you think you have been targeted

People who lose crypto are frequently approached afterwards by someone offering to recover it. They may present as investigators, lawyers, exchange staff, or government officials, and they may know details about your loss, which feels like proof and is not. Read how to spot a crypto recovery scam before replying to anyone.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Sources

TRM Labs, The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack, August 2026. https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack

TechCrunch, Hackers steal over $130M by exploiting bug in offline hardware wallets, 4 August 2026. https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/

The Hacker News, Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes, August 2026. https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html

NCC Group, Bybit Hack: In-Depth Technical Analysis, March 2025. https://www.nccgroup.com/research/in-depth-technical-analysis-of-the-bybit-hack/

Loss estimates for the Coldcard incident vary by source and by publication date, because researchers continued identifying affected addresses for days after disclosure. TRM Labs reported approximately $116 million across more than 5,200 addresses; TechCrunch and others reported above $130 million across at least 7,300. Attribution remains open, with TRM identifying multiple distinct actors rather than one group.

Frequently asked questions

I own a Coldcard. Is my wallet affected by the 2026 firmware flaw?

If you generated your seed on a Coldcard running firmware from March 2021 onward, before Coinkite's patch, treat it as compromised. Updating the firmware protects wallets created afterwards and does nothing for a seed already generated. Move funds to a wallet generated on a device you trust, using a new seed.

Does the Coldcard incident mean hardware wallets are not worth using?

No, and the claim it disproves is narrower than that. A hardware wallet still removes remote extraction of keys from a compromised computer, which is a large category. What it shows is that the device itself is part of your trust model, and a defect shipped years earlier can undo careful personal practice.

Is a hardware wallet safe on its own?

No. It reduces the risk of remote key theft, which is a large category. It does not protect against approving a malicious transaction, a recovery phrase being exposed, a tampered device, or physical coercion. The Bybit theft in February 2025 involved cold storage and multiple reviewers.

What happens if I lose the device?

Your funds are on the blockchain, not on the device. Buy a replacement and restore from your recovery phrase. This is exactly why the backup matters more than the hardware.

Can someone steal my crypto if they find the device but not the phrase?

The PIN protects against casual access, and devices wipe after repeated wrong attempts. A determined attacker with physical possession and specialist equipment is a harder problem. Treat physical loss as a reason to move funds to a new wallet.

Should I use a passphrase?

It meaningfully improves resistance to someone finding your written backup. It also means forgetting it loses those funds permanently, with no recovery path. Use one if you have a dependable way to remember and back it up separately.

Is it safe to buy a hardware wallet on a marketplace?

No. Buy from the manufacturer or a reseller listed on the manufacturer's own site. Tampered and counterfeit devices are a documented problem, and a device that has passed through unknown hands cannot be reasoned about.

What is blind signing and should I worry about it?

It means approving a transaction your device cannot fully decode, so it shows a hash rather than readable details. It is sometimes unavoidable and always a decision. Where you cannot establish what a transaction does, declining costs nothing.

My wallet software says I need to verify my recovery phrase. Is that normal?

The device asks you to confirm words during initial setup, on the device itself. Any request to enter the phrase into a computer, a website, an extension, or a chat is an attack, regardless of how official it appears.

Does a hardware wallet protect me from approving a scam transaction?

Only partly. It lets you verify the destination on a screen your computer does not control, which is significant. It cannot tell you whether the transaction is a good idea.

If you think something has already gone wrong

Ten questions showing which documentation and reporting steps are available in your case.

Recovery pathway assessment

Keep reading