Веерх ↑

Cold wallet

Learn what a cold wallet is, how it differs from a hot wallet, common cold-storage methods such as hardware and paper wallets

A cold wallet, also called cold storage, is a cryptocurrency wallet that keeps private keys completely offline, disconnected from the internet and from internet-connected devices.

Because the keys never reside on an online system during normal storage, cold wallets are designed to reduce exposure to remote hacking, malware, phishing, and other online attacks. They are commonly used for long-term or high-value holdings where security is prioritised over frequent access.

Core concept: offline key storage

Crypto assets are recorded on a blockchain. A wallet does not store coins or tokens directly; it manages the private keys that prove control over blockchain addresses.

A cold wallet’s defining property is that these private keys are generated, stored, and used to sign transactions in an offline environment. To move funds, a transaction is typically prepared on an online device but must be approved and cryptographically signed on the offline device or medium that holds the keys.

This “air gap” between the keys and the internet is the main security advantage of cold storage.

Cold wallet vs hot wallet

The difference between cold and hot wallets is primarily about connectivity.

Feature Cold wallet Hot wallet
Internet connection Keys are kept offline, not connected to the internet Keys are stored on internet-connected devices or services
Main benefit Lower exposure to online attacks and malware Higher convenience for frequent transactions
Typical use Long-term storage, larger holdings Daily spending, trading, DeFi, NFTs
Transaction flow Transaction prepared online, signed offline Transactions signed directly on the connected device

Many users combine both approaches: a hot wallet for regular activity and a cold wallet for longer-term storage.

Common types of cold wallets

Hardware wallets

A hardware wallet is a dedicated physical device designed to generate and store private keys in a secure, offline environment. Transactions are prepared on a computer or phone but are reviewed and signed on the device itself, often with a small screen and physical buttons.

Hardware wallets are the most common form of cold wallet for individual users. They offer a balance of strong offline security and practical usability.

Paper wallets

A paper wallet is a printed record of a private key or recovery phrase, sometimes along with a QR code representing the key or address. It is created offline and stored physically.

Paper wallets are simple but fragile. They can be damaged, lost, or degraded over time. Generating them securely requires care to avoid exposure to malware, insecure printers, or compromised systems.

Air-gapped computers or devices

An air-gapped device is a computer, phone, or other system that is kept permanently offline and has no active network connections. Wallet software can be installed on this device, and keys are generated and stored there.

Unlike fully air‑gapped systems, many hardware wallets can connect to a computer or phone via USB or Bluetooth, while the private keys remain isolated inside the device and are never exported.

Other offline storage methods

Some users use offline storage such as:

  • Metal plates or engraved backups for recovery phrases
  • Secure safes or vaults containing hardware wallets or paper records
  • Multi-signature setups where some keys are kept in cold storage

The common thread is that the key material remains offline during normal storage.

How a cold wallet works in practice

A typical cold-wallet workflow looks like this:

  1. Key generation offline
    The wallet generates private keys on an offline device or medium.
  2. Address derivation
    Public addresses are derived from the keys and can be shared to receive assets.
  3. Receiving funds
    Users share their public address to receive crypto. Receiving does not require the private key to go online.
  4. Preparing a transaction
    When the user wants to send funds, a transaction is prepared on an online device (for example, a computer or phone running a companion app).
  5. Signing offline
    The prepared transaction is transferred to the cold wallet (via USB, Bluetooth in some hardware wallets, QR code or another method), while the private key remains inside the device. The user reviews details on the device and approves the transaction. The private key signs the transaction inside the offline environment.
  6. Broadcasting
    The signed transaction is sent back to the online device, which broadcasts it to the blockchain network for confirmation.

In this flow, the private key remains isolated inside the cold wallet and is never exposed to the internet or to the online device in raw form.

Security benefits of cold wallets

Cold wallets are widely regarded as one of the most secure ways for individuals to store crypto assets over the long term.

Key benefits include:

  • Reduced exposure to online attacks
    Because keys are offline, remote attackers cannot directly access them through internet-based exploits.
  • Protection from malware on everyday devices
    Even if a user’s computer or phone is compromised, the private keys remain on the offline device or medium.
  • Strong fit for long-term storage
    Cold wallets are well suited for holdings that do not need to be moved frequently.
  • User control
    Most cold wallets are non-custodial, meaning the user controls the keys rather than a third party.

However, cold wallets do not eliminate all risks. Physical theft, loss, damage, poor backup practices, insecure key generation, and user error can still lead to loss of funds.

Limitations and risks

Cold wallets prioritise security but come with trade-offs.

Less convenient for frequent use

Because each transaction requires interaction with an offline device or medium, cold wallets are less convenient for frequent payments, trading, or DeFi activity. They are better suited for storage and occasional transfers.

Responsibility for backups

If a cold wallet is lost, damaged, or destroyed and the recovery phrase or private-key backup is missing or incorrect, the assets may be irrecoverable. Users must manage secure, redundant backups.

Physical security

Hardware wallets, paper records, and other offline media can be stolen, lost, or damaged by fire, water, or wear. Secure physical storage and careful handling are important.

Setup complexity

Generating keys securely, verifying device authenticity, updating firmware safely, and correctly backing up recovery information require attention and care. Mistakes during setup can undermine security.

False sense of security

Using a cold wallet does not make crypto “immune” to all threats. Users still need to:

  • Verify transaction details carefully
  • Protect recovery phrases
  • Avoid phishing sites and fake wallet software
  • Keep firmware and companion apps up to date from trusted sources

Cold wallets and card products

A crypto card product may interact with cold wallets indirectly. For example, a user might keep the majority of their crypto in cold storage and transfer only the amount needed for collateral or spending into a wallet or account connected to the card programme.

Cold wallets are generally not used for real-time card payments themselves. Card transactions require fast, automated access to funds and integration with payment infrastructure, which is more compatible with hot or operational wallets and custodial or programme-managed accounts.

In product documentation, it can be helpful to distinguish between:

  • Assets held in a user’s cold wallet (long-term storage, offline keys)
  • Assets in an operational or hot wallet used for day-to-day activity
  • Assets committed as collateral or held within the card programme’s operational environment

This helps users understand which funds are immediately available for spending or collateral, and which are intended for longer-term, offline storage.

Spend your
crypto.
Don’t sell it
Join the members who figured it out.

Cookies preferences

✕

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

Necessary

Necessary
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

Advertisement

Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.