Crypto Wallets: Custody, Types and Security

A crypto wallet does not hold coins. The coins exist only as entries on a blockchain; the wallet holds the private keys that allow those entries to be moved. Whoever controls the keys controls the assets. This page explains the types of wallet, how their security works and which mistakes cost money most often. It does not recommend specific products.

Custodial or self-custody

The choice is a trade between two risks: trusting a company, or trusting one’s own care.

Hot and cold wallets

A hot wallet is software on a phone, computer or in a browser that is connected to the internet. It is convenient for frequent transactions and exposed to malware and phishing. A cold wallet keeps the keys offline, usually on a hardware device that signs transactions internally, so the key never touches an internet-connected computer. Paper backups of the keys also count as cold storage. Many owners split holdings: a small amount in a hot wallet for daily use, the rest offline.

The seed phrase

Most wallets derive all keys from a recovery phrase of 12 or 24 words, based on a common standard (BIP-39). Anyone who knows these words can rebuild the wallet on any device and move the coins. Some rules follow from that:

For larger amounts, multi-signature setups require several keys to approve a transaction, so a single lost or stolen key is not fatal.

Common scams

Checking the first and last characters of an address before sending, and testing with a small amount, prevents many of these losses.

Rules for transfers in the EU

Since 30 December 2024, the EU Transfer of Funds Regulation also covers crypto-assets. Regulated providers must send and receive information about the sender and recipient with every transfer. When coins move between an exchange and a self-custody wallet and the amount exceeds 1,000 euros, the provider has to verify that the wallet belongs to its customer, for example through a signed message or a small test transfer.