Hot wallet vs cold wallet: which to use for each amount

By Vault Capital Team·Published on ·Updated on ·6 min read·Also available in Português

The hot wallet vs cold wallet question shows up right after the first purchase, when the balance sitting at the exchange starts to feel uncomfortable. The choice is not between right and wrong but between convenience and exposure. This guide explains what each one is, walks through three scenarios by amount and frequency of use, and shows how most people end up using both.

What a hot wallet is

A hot wallet is any wallet whose private key lives on a device connected to the internet: the exchange app, MetaMask in the browser, Phantom on the phone. Convenience is total. You sign a transaction in seconds, connect to DeFi applications and pay with a stablecoin without taking anything out of a drawer.

The price is the attack surface. Trezor's documentation sums it up in one line: because the key sits on a connected device, the wallet is more vulnerable to hacking, which is why it suits small amounts you need frequent access to. Malware on the computer, a fake browser extension, a phishing site and a link in a message are all routes that only exist because the key is online.

What a cold wallet is

A cold wallet is one where the private key never touches the internet. The most common form is the hardware wallet, such as Ledger and Trezor, which generates and stores the key inside a chip and only ever returns the signature of a transaction, never the key itself. An older variant is a computer that is never connected to anything.

According to Trezor's guide to hardware wallets, the key is generated and stored offline and is therefore never exposed, which makes the device suitable for larger amounts or for assets you plan to hold for a long time. In exchange, every operation needs the device in hand, the PIN and a few minutes. What holds all of it together is the backup of the words, explained in what is a seed phrase.

Scenario 1: everyday money

Picture someone who pays for services abroad in stablecoins, tries out applications and moves the equivalent of one or two months of salary. A hot wallet does the job. What changes is hygiene: a dedicated phone or browser, no unknown extensions, the app downloaded from the official site and the seed written on paper, never photographed. The practical rule is to keep in the hot wallet only what you could lose to a scam without changing your month.

Scenario 2: the medium-term reserve

Now think of someone who has accumulated the value of a car in bitcoin and ether, trades a few times a month and has no plan to sell within a year. Here the hot wallet starts to cost too much in risk. A hardware wallet bought directly from the manufacturer becomes the main storage, and the hot wallet keeps a small fraction for whatever needs speed. Transfers between the two happen in batches, with a small test transaction before each large one.

Scenario 3: long-term wealth

In the third scenario, crypto is a meaningful part of the person's net worth and the horizon is measured in years. Cold storage is mandatory, and the discussion moves to layers: a passphrase on the hardware wallet, a metal backup in two locations, a succession plan that tells heirs where each piece is and, for very large holdings, multi-signature setups. The hot wallet, if it exists at all, is almost symbolic. People at this stage usually need a professional review of the structure, and the custody model for each situation is compared in crypto custody: self-custody vs third-party custody.

The trade-off in real life: the Bybit case

Cold does not mean infallible. On February 21, 2025, the exchange Bybit lost more than 400,000 ETH, roughly US$ 1.5 billion, from a multi-signature cold wallet. According to Bybit's own statement, the attackers altered the signing interface during a routine transfer to the hot wallet, and the signers approved a transaction that was not the one shown on screen. Elliptic, Arkham and TRM Labs attributed the attack to North Korea's Lazarus Group.

The lesson applies to individuals. The key was offline, but the decision to sign was based on a compromised screen. Checking the destination address on the hardware wallet's own display, not on the computer, is the step that separates a cold wallet from a merely disconnected one.

The scale of the problem is in the data. Chainalysis recorded US$ 3.4 billion stolen in 2025, and personal wallet compromises accounted for 20% of that value, across about 158,000 incidents with at least 80,000 victims, according to its report of December 18, 2025. Most of those cases involve no broken cryptography, only exposed seeds, phishing and signatures approved without checking.

How people combine the two

In practice, almost nobody picks just one. The most common arrangement is a hot wallet holding a few weeks of spending and a cold wallet holding the rest, topped up in batches. The two use different seeds, stored in different places. The hot wallet never receives the cold wallet's seed, and the cold wallet is never connected to a website to "sync" or "validate" anything.

Two routines prevent most accidents. The first is the test transaction: before moving a large amount, send a minimal one and confirm it arrived. The second is a review every six months: check that the backup is still legible, the passphrase is still remembered and the succession plan is still current.

Crypto assets carry high risk, including significant volatility and the possibility of losing the invested capital. This article is educational and is not investment advice. Vault Capital is a securities advisory firm authorized by Brazil's CVM under Resolução CVM nº 19/2021, never takes custody of client assets, and its obligations are detailed on the compliance and regulation page.

Frequently asked questions

Is leaving crypto at an exchange a hot wallet?

It is worse than that: the key is not yours. At an exchange you hold a claim against the company, subject to freezes, insolvency or an attack like Bybit's in 2025. A hot wallet of your own at least leaves the key with you.

From what amount is a hardware wallet worth it?

When a total loss would change your year. Since the device costs a small fraction of most positions, the math usually works early. Setup and testing the backup matter more than the price.

Can a hardware wallet be hacked?

The device itself is rarely the target. Real cases involve a seed typed into a fake site, a device bought from a reseller with a pre-set seed, and transactions signed without checking the display, as happened at Bybit.

Can I use the same seed in both wallets?

No. If the cold wallet's seed is imported into an online app, it stops being cold. Use different seeds and treat each one with the care its balance deserves.

Let's talk

Setting up a hot plus cold structure takes an afternoon when someone shows the way and a month of doubt when nobody does. At Vault's Self-Custody Immersion the setup is done live, from the hardware wallet to the backup, and nobody ever needs to see your words.

Want to hold your crypto safely, on your own?

Vault's Self-Custody Immersion teaches wallets, seed backups and succession planning, hands on.

Learn about the Immersion