Hot wallet vs cold wallet: online keys for convenience vs offline keys for security. A side-by-side comparison, example split and safety tips.

Hot wallet vs cold wallet is the difference between keeping a crypto wallet's private keys on an internet-connected device (hot) and keeping them on a device that stays offline (cold). Hot wallets are faster and easier for daily use; cold wallets are much harder to hack remotely. Most experienced users hold both.
A hot wallet is any wallet whose keys live on a device that is online: a browser extension, a mobile wallet app or a desktop app. Exchange accounts are also "hot" in the sense that the exchange keeps operational funds in online wallets, though there the keys belong to the exchange.
A cold wallet keeps the keys on hardware that never exposes them to the internet. The most common form is a hardware wallet, a small device that signs transactions internally and only sends out the signature. Air-gapped devices and, historically, paper wallets are also forms of cold storage.
Both can be non-custodial: hot vs cold is about where the keys are stored, not who owns them.
| Hot wallet | Cold wallet | |
|---|---|---|
| Key location | Online phone, browser or computer | Offline hardware device |
| Main threat | Malware, phishing, malicious approvals | Physical loss, supply-chain tampering, lost backup |
| Speed | Instant, good for DeFi and frequent trades | Slower; device must be connected and confirmed |
| Cost | Usually free | Usually a one-off hardware purchase |
| Best for | Spending money and active positions | Long-term holdings |
Hypothetical: say you hold 20,000 USD of crypto and use DeFi a few times a week. A common split is a 90/10 rule:
Now say you approve a malicious contract on a fake airdrop site. A drainer can take everything the hot wallet holds or has approved, up to 2,000 USD. The 18,000 USD in cold storage is untouched, because the attacker would also need you to physically confirm a transaction on the hardware device. The split does not prevent the mistake; it caps the damage.
Hot wallets are where most everyday attacks land, usually through phishing and malicious signatures rather than broken cryptography. Our guide to wallet drainers and approval phishing shows how these attacks work.
A cold wallet is safer but not foolproof:
For funds controlled by a team or treasury, a multisig wallet combining several cold keys removes the single point of failure.
A cold wallet is safer against remote attacks because its keys never touch an online device. It is still vulnerable to physical loss, a poorly stored seed phrase, or approving a malicious transaction.
A hot wallet is a wallet whose private keys are stored on an internet-connected device, such as a phone app or browser extension. It is convenient for frequent transactions but more exposed to malware and phishing.
Yes. Most hardware wallets connect to a wallet app that can interact with DeFi protocols; each transaction is confirmed on the device. It is slower than a hot wallet, so many users keep only active positions in a hot wallet.
JewelSwap Crypto Glossary · educational, not financial advice. Updated 2 October 2026. Browse the full glossary.