A cold wallet, or cold storage, is any method of holding cryptocurrency where the private keys never touch an internet-connected device. Hardware wallets are the most common form. Removing the attack surface that remote hackers and malware exploit is the purpose. During 2025, Chainalysis recorded $713 million in personal wallet compromises, and cold storage addresses the share of that theft that comes from a connected device being breached.
Cold wallets vs hot wallets
Whether the key is online is the distinction, and everything else about the two categories, their convenience, their cost, and the specific ways each one fails, follows from that single fact.
A hot wallet holds keys on a device that connects to the internet: a phone app, a browser extension, an exchange account. Convenient, and reachable by anything that reaches the device.
A cold wallet holds keys on something that does not connect: a hardware device, a paper printout, an air-gapped computer. Inconvenient by design, and unreachable remotely.
Neither is better. Not in the abstract. For money you use, hot wallets. For money you keep, cold wallets.
Types of cold storage
| Method | How it works | Trade-off |
|---|---|---|
| Hardware wallet | Dedicated device signs transactions internally | Costs money, easy to lose, needs a seed phrase backup |
| Paper wallet | Keys printed or written, never entered on a device | Fragile, awkward to spend from, largely superseded |
| Air-gapped computer | A machine that never connects, signs transactions transferred by QR or USB | Technical, overkill for most holders |
| Deep cold storage | Keys split and held in vaults across locations | Institutional. Slow to access by design |
| Metal seed backup | Seed phrase stamped on steel | Backup rather than wallet, survives fire and water |
For individuals, hardware wallets dominate because they combine offline key storage with practical signing. Common around 2013, paper wallets faded because spending from them safely is difficult.
How to use a cold wallet
Cold storage is not a vault you never open. Think of it as a signing device that stays offline.
- Build a transaction on a connected device.
- Move the unsigned transaction to the cold device, by cable, Bluetooth, or QR code.
- Verify and sign it on the cold device, which never sees the network.
- Move the signed transaction back and broadcast it.
The key never crosses the gap. Only the transaction and its signature do.
What cold storage protects against
- Malware on your computer or phone, since the key is not there.
- Remote hacks, for the same reason.
- Exchange failure, since you hold the keys yourself.
- Clipboard hijacking, provided you verify addresses on the device screen.
What a cold wallet does not protect against
Here is the section that matters most, because cold storage gets sold as comprehensive protection and it is not.
Seed phrase compromise. Every cold wallet has a seed phrase backup. Anyone holding it can restore the wallet online and drain it. The device being offline is irrelevant if the words are in someone else's hands. Scammers have mailed physical letters impersonating manufacturers specifically to harvest these phrases.
Malicious signatures. Sign a transaction granting a contract spending permission and the cold device signs it faithfully. It protects the key, not the decision.
Physical loss. Lose the device and the seed phrase and the funds are gone permanently.
Physical theft. Someone with the device and PIN, or with the seed phrase, has the funds.
Your own errors. Send to the wrong address or wrong network and cold storage does nothing.
Cold storage at exchanges
Regulated exchanges hold most client assets in cold storage too, with a difference in structure.
Typically, institutional cold storage uses multi-party computation, where signing capability is split into shares held separately, so no single complete key exists anywhere. Combined with segregated client funds and regulatory supervision, it provides offline protection without the individual bearing the seed phrase burden.
A different trade, in other words. Unconditional control goes, and recoverability and an accountable counterparty arrive.
How much crypto to keep cold
Descriptively, since it depends on your holdings and how you use them.
Commonly, people hold what they actively trade on an exchange and move what they intend to keep for a long time into cold storage. Because the friction is the point, funds you need to move quickly do not belong there.
Whatever the device costs, it should be less than what it protects. For small balances, the extra complexity may not be worth it.
Security you can verify on mb.io
With cold storage, the entire security burden falls on you. Regulated custody moves it to an audited institution using the same offline principles at scale.
mb.io is a regulated crypto spot exchange backed by MultiBank Group, a financial institution founded in 2005 that serves more than 2 million clients across 100+ countries.
- Institutional-grade MPC custody powered by Fireblocks, with segregated client funds
- 10/10 security score from Hacken, an independent blockchain security auditor
- Regulated by VARA in the UAE and AUSTRAC in Australia
- Withdrawal controls that let you verify a destination before funds move
- Buy, sell, and swap in three steps, from sign-up to purchase
- 24/7 multilingual client support
Open your account and start trading on mb.io.
Frequently asked questions
What is a cold wallet?
Any method of holding crypto where the private keys never touch an internet-connected device. Hardware wallets are the most common form. Removing the attack surface remote hackers exploit is the purpose.
What is the difference between a cold wallet and a hot wallet?
On a connected device, a hot wallet's keys are reachable by anything that reaches the device. Offline, a cold wallet's keys are not. For funds you use, hot. For funds you keep, cold.
Is a hardware wallet the same as a cold wallet?
A hardware wallet is one type of cold wallet. Paper wallets, air-gapped computers, and institutional vault storage are others. Hardware wallets dominate for individuals because they combine offline storage with practical signing.
Can a cold wallet be hacked?
Remotely, effectively no. The losses come from seed phrase phishing, malicious transaction approvals, physical theft, or tampered devices. The device protects the key, not the user's judgment.
What happens if I lose my cold wallet?
Restore from the seed phrase on a new device. Lose both the device and the phrase, and the funds are permanently unrecoverable.
Do exchanges use cold storage?
Regulated ones hold most client assets offline, typically using multi-party computation so that no single complete key exists. That provides offline protection with the institution rather than the individual carrying the seed phrase burden.
How much crypto should I keep in cold storage?
That depends on your holdings and use. The common approach is keeping actively traded funds on an exchange and moving long-term holdings cold. The device should cost less than what it protects.
Is a paper wallet safe?
Offline, yes, and awkward. Paper degrades, spending from one safely is difficult, and the method has largely been superseded by hardware wallets. Metal seed backups serve the durability purpose better.

