What a cold wallet is, and whether you need one
A cold wallet keeps the private keys to your crypto offline, usually on a small dedicated device. Because the keys never touch an internet-connected computer, malware and compromised exchange accounts cannot reach them. Whether you need one depends less on how sophisticated you are and more on how much you hold: if losing it would genuinely hurt, a device is worth the cost. If you own a small amount, it very likely is not yet.
Below is what the device actually does, what it does not protect you from, and how to decide.
The thing that matters is keys, not coins
Your crypto does not sit inside a wallet the way cash sits in a physical one. The coins exist on a blockchain; what you hold is a private key that proves you can move them. Whoever has the key controls the funds. That is the entire security model.
So the real question is always: who holds your keys?
On an exchange, they do. You have an account and a balance, but the exchange holds the keys. That is convenient — password resets, support, no phrase to lose — and it means your funds depend on that company staying solvent, secure, and willing to let you withdraw.
In a self-custody wallet, you do. Nobody can freeze your funds and nobody can help you if you lose access. The trade-off is total: full control, full responsibility.
"Not your keys, not your coins" is a slogan, but the reasoning behind it is sound: several large exchanges have failed or frozen withdrawals, and customers with balances on them discovered their claim was on the company rather than on the coins.
Hot wallet vs cold wallet
Both can be self-custody. The difference is whether the keys ever touch an online device.
| Hot wallet | Cold wallet | |
|---|---|---|
| Where keys live | On a phone or computer, online | Offline, on a dedicated device |
| Main risk | Malware, phishing, compromised device | Losing the device and the recovery phrase |
| Convenience | High — spend or trade quickly | Lower — deliberate by design |
| Cost | Free | Typically $50–$200 for a device |
| Suits | Small amounts you use | Amounts you intend to hold |
A common setup is both: a small amount in a hot wallet for actual use, the rest in cold storage. That mirrors the separation principle from the budgeting lesson — money you might spend sits somewhere different from money you are keeping.
How a hardware wallet actually works
The device generates and stores your private keys internally. When you want to send crypto, the transaction is prepared on your computer or phone, sent to the device, signed inside the device, and returned signed. The keys themselves never leave.
This is why malware on your laptop cannot drain a hardware wallet: it can see the transaction, but it cannot sign one without physical confirmation on the device.
During setup the device shows you a recovery phrase — a sequence of words that can regenerate your keys. Write it down, on paper, offline. That phrase is your funds. Anyone who reads it can take everything, and nobody can restore it for you if you lose it. Never photograph it, never type it into a computer, never store it in a password manager or cloud note.
What a cold wallet does not protect you from
It is not a general-purpose safety device, and being clear about that matters more than the sales pitch.
- Approving a malicious transaction. If you are tricked into signing something, the device signs it. Confirming on the screen is your last line of defence — read what it says.
- Price falling. Obvious, but worth saying: custody is not an investment decision.
- Giving away your recovery phrase. The most common way people lose funds is telling someone the phrase, usually to a fake support account. No legitimate company will ever ask for it.
- Losing the phrase. Losing the device is fine — the phrase restores it. Losing both is permanent.
When a device is worth buying
Weigh the cost against what it protects. A $79 device guarding $200 of crypto is a poor trade; the same device guarding several thousand is cheap insurance.
Signals that it is time:
- Losing your holding would genuinely hurt rather than annoy you.
- You intend to hold for years rather than trade.
- You are uncomfortable with the amount sitting on an exchange.
If none of those are true yet, keeping a modest amount on a reputable exchange with two-factor authentication is a reasonable position, and we would rather say so than sell you a device you do not need.
Buying one safely
This part matters more than which brand you pick. A hardware wallet is only trustworthy if nobody has tampered with it before it reached you.
- Buy from the manufacturer directly, or an officially listed reseller. Never second-hand, never from a marketplace listing.
- Check the packaging for the manufacturer's tamper indicators.
- Generate your own recovery phrase during setup. If a device arrives with a phrase already written on a card, it is compromised — that is a known scam.
- Update the firmware through the official app before transferring anything.
The two established makers are Ledger and Trezor. We compare them in Ledger vs Trezor, including where each one is weaker.
If you have decided you want one, Ledger's official store is the safe place to buy theirs — going direct is the point, not a formality.
Common questions
What is a cold wallet?
Storage that keeps your private keys offline, usually on a dedicated device, so malware and account compromises cannot reach them.
Do I need a hardware wallet for a small amount of crypto?
Often not. The device can cost a meaningful share of a small holding. It becomes worthwhile once losing the amount would genuinely hurt.
What happens if I lose my hardware wallet?
The device is replaceable using your recovery phrase. Losing both the device and the phrase means the funds are gone permanently.
Is an exchange account a wallet?
Functionally it holds your balance, but the exchange holds the keys. You have a claim on the company rather than direct control of the coins.