A crypto wallet is software or hardware that holds the private keys controlling your cryptocurrency and lets you send and receive it. At no point do the coins leave the blockchain. What the wallet holds is the ability to move them. Scam Sniffer recorded $83.85 million stolen through wallet phishing in 2025, almost all of it from keys or signatures being handed over rather than wallet software failing.
What a crypto wallet actually holds
Keys, not coins. That is the one sentence most beginners need to hear before anything else about wallets makes sense, and it explains nearly every confusing thing that follows.
Every cryptocurrency balance lives on its blockchain, recorded against an address. What a wallet stores is the private key that authorizes spending from that address, and the tools to sign transactions with it.
Several things beginners find confusing follow from that distinction. In two wallet apps, the same funds can appear if both hold the same key. Deleting a wallet app does not delete your coins. And losing the key means losing access permanently, even though the coins are still visible on the blockchain to everyone.
The two axes: custodial or not, hot or cold
Custodial vs non-custodial. Who holds the key. On an exchange, the platform does. In a self-custody wallet, you do.
Hot vs cold. Whether the key touches the internet. A hot wallet runs on a connected device. A cold wallet keeps the key offline.
On both axes every wallet type sits somewhere, and the trade-offs that define it, what it protects against and what it leaves exposed, follow directly from where it lands on each.
The main types of crypto wallet
| Type | Key holder | Online | Best for | Main risk |
|---|---|---|---|---|
| Exchange account | The platform | Yes | Trading, beginners | Platform failure |
| Mobile or browser wallet | You | Yes | Everyday use, DeFi | Malware, phishing |
| Hardware wallet | You | No | Long-term holdings | Losing the device and backup |
| Paper wallet | You | No | Rarely used now | Physical damage, awkward to spend |
| Multisig | Several parties | Varies | Shared funds, institutions | Coordination |
How self-custody wallets work
Almost all modern wallets generate a seed phrase, 12 or 24 words from a standardized list of 2,048, defined by a specification called BIP-39.
From those words the wallet derives every private key and address it will ever use. One phrase backs up an unlimited number of accounts across multiple blockchains. Write it down, store it offline, and the wallet can be restored on any compatible device. Lose it without another copy, and the funds are unrecoverable.
Whoever has the words has the funds. No password stands in front of them. That is why no legitimate service ever asks for a seed phrase, and why any request for one is theft.
Custodial wallets: what you gain and give up
Even when someone else holds the key, an exchange account is still a wallet.
What you gain: account recovery through support, no seed phrase to protect, and, on a regulated platform, segregated client funds under a supervisor's oversight.
What you give up: unconditional control. Your access depends on the platform's solvency and conduct. In November 2022, FTX collapsed having commingled customer funds with company money, and customers who had done nothing wrong lost access to their assets.
What separates that outcome from a recoverable one is the platform's regulatory status. With segregated funds and a supervisor, a licensed exchange is a different counterparty from an offshore one with neither.
How wallets get drained
In almost every case, the wallet software worked fine. The user got tricked.
- Seed phrase phishing. A fake site or support impersonator asks for the words.
- Malicious signatures. A transaction that looks like a login or a claim actually grants a contract permission to spend your tokens. Permit-based attacks accounted for 38% of losses among incidents over $1 million in 2025.
- Address poisoning. A look-alike address seeded into your transaction history, copied by mistake. One victim lost $50 million this way in December 2025.
- Malware. Clipboard hijackers swap addresses as you paste them.
- Physical letters. In early 2026, scammers mailed official-looking letters impersonating hardware wallet manufacturers, with QR codes leading to fake setup pages.
How to protect your wallet
- Never type a seed phrase into any website. Ever.
- Store the phrase offline, on paper or metal, in more than one location.
- Read what a transaction does before signing it, especially anything requesting approval.
- Send a small test transaction before any large one.
- Revoke old token approvals periodically.
- Buy hardware wallets from the manufacturer directly, never second-hand.
- Treat any unexpected token, message, or letter as suspicious.
Security you can verify on mb.io
With self-custody, the entire burden falls on your key management. Regulated custody moves it to an audited institution, which is a different trade rather than a strictly better one.
mb.io is a regulated crypto spot exchange backed by MultiBank Group, a financial institution founded in 2005 that serves more than 2 million clients across 100+ countries.
- Institutional-grade MPC custody powered by Fireblocks, with segregated client funds
- 10/10 security score from Hacken, an independent blockchain security auditor
- Regulated by VARA in the UAE and AUSTRAC in Australia
- Withdrawal controls that let you verify a destination before funds move
- Buy, sell, and swap in three steps, from sign-up to purchase
- 24/7 multilingual client support
Open your account and start trading on mb.io.
Frequently asked questions
Does a wallet hold my coins?
No. Coins live on the blockchain. A wallet holds the private keys that authorize moving them, which is why the same funds can appear in two apps holding the same key and why losing the key means losing access.
What is the safest type of crypto wallet?
For long-term holdings, a hardware wallet with the seed phrase stored offline. For trading, a regulated exchange with segregated client funds. Each is safest for a different purpose and neither removes all risk.
What is a seed phrase?
12 or 24 words that back up an entire wallet. Every key and address is derived from them, so anyone holding the words controls the funds. No legitimate service ever asks for it.
What happens if I lose my crypto wallet?
If you have the seed phrase, restore the wallet on any compatible device. If you have lost both the device and the phrase, the funds are permanently unrecoverable.
Is an exchange account a wallet?
Yes, a custodial one. The exchange holds the keys, and you hold an account. You trade recoverability for dependence on the platform's solvency, which is why regulatory status matters.
How do crypto wallets get hacked?
Almost always through the user rather than the software: phishing for seed phrases, malicious signatures that grant spending permission, address poisoning, and malware. Scam Sniffer recorded $83.85 million in phishing losses in 2025.
Can I have more than one crypto wallet?
Yes, and many people do: an exchange account for trading, a mobile wallet for everyday use, and a hardware wallet for long-term holdings. Splitting funds limits what any single failure can cost.
What is a multisig wallet?
One requiring signatures from several keys before a transaction executes, such as two of three. It protects against a single compromised key and is common for shared or institutional funds.

