What is a Cold Wallet? (Crypto for Beginners Ep.1)
Share
This is part of the Crypto for Beginners series. Ep.1.
I'm going to go through what a crypto cold wallet is in plain terms. What it holds, how it protects you, what the backup does, and what it does not protect you from.
Where is your crypto, actually?
Start with a comparison most people already understand: a debit card. Your money is not inside the card. The card is just the thing that lets you access money held somewhere else.
Crypto works similarly, and I like to picture it like iCloud. When you upload photos to iCloud, those photos sit in a digital place you can access from anywhere as long as you have your password. The photos are not physical, they are just digital. But when you log in, you can move them around.
A blockchain network works the same way. Take the Bitcoin blockchain as an example. Think of it as a cloud. Every Bitcoin that has ever existed lives inside that network and never leaves it. When you send someone Bitcoin, the Bitcoin does not travel anywhere. Ownership just changes inside the network.
What a hardware wallet actually holds
When people say they are storing Bitcoin on a hardware wallet, what is really happening is that the Bitcoin is still inside the Bitcoin network. The device just holds the password that lets you access and move the Bitcoin within that network.
That password is called a private key. It is a very long secret number. Whoever holds the private key can move the crypto that belongs to it.
When you set up a hardware wallet, you also get your own Bitcoin wallet address. That address is a string of numbers and letters. It is the place you send Bitcoin to after you have bought some on Coinbase, Binance, or wherever. Once the Bitcoin lands at that address, only the person with the private key can move it.
Private keys are stored on the hardware wallet device offline. That is why people call them cold wallets.
Why you cannot reset access
Here is the big difference between iCloud and a blockchain network. If you forget your iCloud password, you can reset it or contact Apple. Someone has your back.
With crypto, that is not possible. Only you are responsible for keeping your private keys safe. There is no company behind Bitcoin you can call. This makes the backup step critical.
Seed phrase vs seedless backup
The first time you set up a hardware wallet, it creates your private key inside the device, offline. During that setup you are shown the backup to that private key. Write it down and keep it safe. It is usually the only time you will be shown it.
If you later lose access to your device, the backup gets you back in.
Seed phrase backup is the traditional method. You are shown 12 or 24 words during setup. Write them down on paper, keep them somewhere safe, and never photograph them or type them anywhere. If you lose your device, buy any new one that supports seed phrases, type in the words, and you are back in. Most wallets use this method.
Seedless backup is a newer method. Instead of words, the private key is stored encrypted inside physical cards. You get multiple copies of the same card, store them in different locations, and any one of them gets you back in. All copies are also protected by a PIN. Tangem is the most well-known wallet that uses this method.
Both are solid backup options. Neither is strictly better. It depends on which approach suits how you manage your stuff.
How a transaction gets approved
Most hardware wallet brands have their own app or program. Ledger has the Ledger app, Trezor has Trezor Suite, Tangem has the Tangem app. These are the interfaces where you handle your crypto. They can show your balance and let you set up transactions.
But the app does not hold your private key. The physical device does. So when you try to send crypto, the app cannot do it alone. A message appears on your physical device where you have to approve the transaction in person. Either press a button or scan the card against your phone, depending on which wallet you have.
That physical approval step is what stops most remote hacks. A hacker who has access to your computer or phone still cannot move your crypto without physically having your device. That is the core difference between a cold wallet and a hot wallet like MetaMask.
Cold wallet vs hot wallet
A hot wallet is a wallet that lives on your phone or computer and stays connected to the internet. MetaMask, Trust Wallet, and exchange accounts are all hot wallets. Convenient, but if your phone or computer gets compromised, your crypto can be taken remotely.
A cold wallet keeps the private key offline on a separate physical device. You approve transactions in person. In exchange you get protection that requires someone to physically have your device in order to move your funds.
Most people who hold more than a small amount of crypto end up getting a hardware wallet because of this difference.
What a cold wallet does not protect you from
Scammers constantly create fake websites, fake apps, and fake emails. All of them want your seed phrase words. If you give them away, they can take everything in seconds.
Never share your seed phrase with anyone. No legitimate company will ever ask for it.
A cold wallet also does not protect you if you:
- Send crypto to the wrong address
- Use the wrong blockchain network when sending
- Click a scam link and then physically approve the transaction on your device yourself
The device protects against remote hacks. It does not protect against mistakes you make yourself.
Next steps
The next video in this series covers how to actually send crypto: exchange to exchange, exchange to cold wallet, cold wallet to exchange, and cold wallet to hot wallet. It also covers network selection, which trips up most beginners.
How to Send Crypto in 4 Ways → Ep.2
If you already feel ready to pick a wallet, the quiz takes about a minute and gives you a personal recommendation based on what matters to you.
Find your wallet with the quiz • Full comparison table (22 wallets)