Monday, 28 September 2026  ·  Vol. 1  ·  No. 28Saved
The WatchPaper
Dispatches from the digital asset economy
Reported and on the record0 stories on file
Front page / Learn / Crypto Basics
Fundamentals

Hot wallet vs. cold wallet, in one line

One is connected to the internet and easy to spend from. The other isn't.

At a glance
  1. A hot wallet's key lives on an internet-connected device; a cold wallet's key never has.
  2. Hot is easier to spend from. Cold is harder to steal from remotely. That's the entire trade.
  3. Anything you'd call savings rather than spending money belongs in cold storage, not a hot wallet.

“Hot” and “cold” describe exactly one thing: whether the device holding your private key has ever touched the internet. A hot wallet's key lives on a phone, laptop, or exchange server that is online right now. A cold wallet's key lives on hardware, or paper, that has never connected to anything.

That single difference decides everything else. A hot wallet can sign and broadcast a transaction in seconds, which is why it's built into every exchange and every mobile app — convenience requires being reachable. It also means anyone who compromises that online device can, in principle, reach the key too.

A cold wallet can't be reached remotely at all, because it was never connected in the first place. Moving funds out of one means physically touching the device and deliberately signing the transaction offline before it's broadcast. That friction is the entire point.

The practical rule: keep in a hot wallet only what you'd be comfortable losing to a worst-case remote attack — spending money, not savings. Anything larger belongs in cold storage; the fuller version of this trade-off, including the middle ground of multisig, is covered elsewhere in this primer.

Key terms
Hot wallet
A wallet whose keys are held on an internet-connected device, for speed at the cost of exposure.
Cold wallet
Keys held on hardware or paper that has never connected to a network.
Attack surface
Everything an attacker could potentially reach to compromise a key — smaller for a device that has never been online.
Frequently asked
Is an exchange account a hot wallet?

Functionally yes — the exchange holds the key on servers connected to the internet, which is why exchange balances carry the same remote-theft exposure as any other hot wallet, plus the exchange's own security as an added variable.

Can a cold wallet ever be hacked?

Not remotely, which is the whole point — the realistic risks shift to physical theft of the device, losing it, or a flawed manufacturing process, not a stranger reaching it over a network.

Do I need a cold wallet if I only hold a small amount?

Only you can decide what counts as small enough to risk — the test is comfort with worst-case loss, not a specific dollar threshold.