Crypto Wallets and Custody: How Private Keys, Hot Wallets and Cold Storage Work
Learn what crypto wallets store, how private and public keys work, and how hot, cold, self- and third-party custody shift practical risks.

Photo by Hanna Pad on Pexels. View photo.
A crypto wallet does not hold digital coins in the way a physical wallet holds cash. The record of ownership resides on the blockchain, while the wallet provides the keys and tools needed to access, receive, manage or transfer the associated crypto assets.
That distinction matters because crypto custody is fundamentally about control of keys. The central questions are: Who controls the private key, where is it kept, and what could prevent it from being used when needed?
What a crypto wallet actually controls
A wallet generally stores or manages two related pieces of information: a public key and a private key.
The private key is a secret alphanumeric code used to authorize transactions. It functions like a password, but with an important difference: once created, it cannot be changed or replaced, so losing it may permanently eliminate access to the associated assets. Anyone who obtains it may also be able to exercise control over those assets. It should never be shared.
The public key serves a different purpose. It can be used to verify transactions and generate a receiving address, which allows crypto assets to be sent to the wallet. It does not reveal the private key or authorize transactions by itself.
A useful shorthand is:
- Public information helps assets reach the correct address.
- Private information enables control and transfers.
This resolves a common misunderstanding: the wallet is not the asset, and an app password is not necessarily the underlying private key. Some hot wallets let users sign in with a familiar password while the wallet or service handles the keys behind the scenes. The private-key mechanism still exists even when it is invisible to the user.
Hot and cold describe connectivity, not ownership
Hot and cold storage answer one question: Is the environment holding the private key connected to the internet? They do not, by themselves, identify whether the user or a company controls the key.
| Storage method | Typical form | Main practical benefit | Material exposure |
|---|---|---|---|
| Hot wallet | Desktop, mobile or web wallet | Convenient access for transactions | Internet-connected systems are exposed to hackers and malicious code |
| Cold wallet | Disconnected hardware, USB drive, hard drive or paper | Greater isolation from online threats | The device or record can be lost, stolen, damaged or destroyed |
A hot wallet keeps keys in an internet-connected environment. It is generally convenient for receiving, using and transferring crypto assets, but that connectivity creates exposure to cyberattacks. A mobile or desktop wallet that stores keys locally can also fail if the device is lost, destroyed or stolen. In some circumstances, losing a phone containing locally stored keys may mean permanently losing access to the assets.
A cold wallet keeps private keys in an environment that generally is not connected to the internet. This makes the keys harder for an online attacker to reach, but cold storage is not automatically safe. Physical media can disappear, break or fall into someone else’s hands. Hardware also costs money, unlike many hot-wallet services that are available without a storage charge.
Paper storage illustrates the trade-off. Writing or printing a private key removes the key from an online environment, but the paper remains vulnerable to accidental loss, destruction and theft. Saving a private key or seed phrase in an internet-connected file, such as cloud storage, undermines that isolation because hackers routinely search such systems for valuable credentials and keys.
Self-custody and third-party custody are a separate choice
The second custody question is who controls access to the private key.
With self-custody, the user has sole control of the keys and sole responsibility for securing them. This removes dependence on a custodian for key access, but it also leaves no provider responsible for recovering a lost key. A lost, damaged, stolen or hacked self-custody wallet can produce permanent loss of access.
With third-party custody, a service such as a crypto exchange or dedicated custody provider manages and controls the keys. The service may keep them in hot wallets, cold wallets or a combination of both. This arrangement can reduce the user’s direct key-management burden, but it introduces dependence on the provider. If the custodian is hacked, shuts down or enters bankruptcy, customers may lose access to their assets.
The two classifications therefore form separate axes:
- A wallet can be hot and self-custodied, such as software holding keys on the user’s connected device.
- It can be cold and self-custodied, such as a disconnected hardware wallet controlled by the user.
- A third-party custodian may use hot storage, cold storage or both.
“Cold” does not mean “self-custodied,” and “hot” does not necessarily mean “held by an exchange.” Confusing these terms can obscure the risk that actually matters.
Custodial services also should not be assumed to work like ordinary bank accounts. In describing custodial wallets, federal educational material warns that customer funds are not federally insured or segregated, may be mixed with other assets and may be exposed to a platform’s operational costs. The same material identifies custodians as attractive targets for hackers. Those warnings make the provider’s controls and financial condition part of the custody risk.
A practical way to evaluate the trade-offs
No custody method removes every failure point. A clearer evaluation starts by separating four questions:
- Who can authorize a transaction? Identify whether the user or a third party controls the private key.
- Is the key online? Internet connectivity improves convenience but increases exposure to online attacks.
- What is the recovery path? Consider what happens after a forgotten password, lost device, damaged hardware or unavailable provider. A private key itself cannot simply be replaced.
- Where is the concentrated failure risk? Self-custody concentrates responsibility with the user; third-party custody concentrates reliance on the provider and its systems.
Basic safeguards follow from those questions. Private keys and seed phrases should never be shared. Online crypto accounts should use strong passwords and multi-factor authentication, and users should remain alert to phishing attempts. Keeping holdings private can also reduce unnecessary exposure to people seeking access information. These steps address particular risks; they do not turn any wallet into a risk-free storage method.
Finally, secure custody is not the same as a sound investment. Custody determines how assets are accessed and who can authorize transactions. It does not evaluate the asset itself, prevent price losses or guarantee that access will always remain available. The practical goal is not to find a wallet with no risk, but to understand which risks shift to the user, the device, the internet connection or the custodian.
Sources
- Storing Crypto Assets | FINRA.org — finra.org
- Crypto Asset Custody Basics for Retail Investors – Investor Bulletin | Investor.gov — investor.gov
- Crypto Assets – Key Terms | FINRA.org — finra.org
- 10 Digital Asset Terms You Should Know — cftc.gov

