Cold wallet

A cold wallet keeps your private keys away from the internet, so malware on your everyday computer cannot reach them.

Branch covered in spiky frost crystals

Photo: “Ice, frost and snow II” by tillwe, CC BY-SA 2.0, via Flickr (edited: cropped and resized).

Quick answer

A cold wallet is a wallet whose private keys are stored on a device that is not connected to any network — a dedicated hardware wallet or an offline computer [1]. Transactions are prepared online but signed offline, so a hacked computer cannot spend your coins [2].

Key points

  • 1Also called cold storage or an offline wallet; the opposite is a wallet on an internet-connected phone or computer.
  • 2Keys stay offline; only unsigned and signed transactions cross between the two devices.
  • 3It protects against hacking, not against a leaked recovery phrase or a scam you approve yourself.

How does a cold wallet work?#

Bitcoin.org describes an offline wallet, also known as cold storage, as storing a wallet in a secured place that is not connected to the network; done properly, it gives very good protection against computer vulnerabilities [1]. The keys live on the offline side. A separate online “watching” wallet can see your balance and build transactions, but it cannot sign them [2]. A hardware wallet is one form: a device built only to hold keys and sign [2]. NIST notes that private keys matter so much that many users store them on special secure hardware [3].

StepValue
1. Online computerCreate the unsigned transaction; save it to a USB stick
2. Offline computerCheck amount and address, then sign
3. Online computerBroadcast the signed transaction
Private keys sent onlineNone

Because the connected computer cannot sign, it cannot be used to withdraw funds even if it is compromised [1].

What is the difference between a cold wallet and a hot wallet?#

A wallet app on an internet-connected phone or computer — often called a hot wallet — is convenient, but its keys sit on a device that can be compromised, and an internet connection makes it easy to send stolen keys to an attacker [2]. Bitcoin.org suggests keeping only small amounts on such devices for everyday use and the rest somewhere safer [1]. The trade-off for cold storage is hassle: you need the offline device every time you spend [2].

What can a cold wallet not protect?#

  • A recovery phrase someone else has seen: whoever has it can access every account [4].
  • An approval or transaction you confirm on a scam site: the device signs what you approve.
  • A payment to the wrong address: it cannot be reversed [4].
  • Coins left on an exchange: those keys belong to the company, not your cold wallet. See custodial vs self-custody.

Frequently asked questions#

Is a hardware wallet a cold wallet?

Yes. Ethereum.org describes hardware wallets as devices that let you keep your crypto offline [5], and the developer guide calls them dedicated signing devices [2]. That makes them one kind of cold wallet.

Can a cold wallet be hacked?

Keeping keys offline removes the most common attack — malware stealing keys from a connected device. The protection assumes the signing device itself is not compromised or flawed, and that you check every transaction before signing [2].

Do I need a cold wallet for small amounts?

Not necessarily. Bitcoin.org compares a phone wallet to cash in your pocket: fine for small everyday amounts, while larger savings belong in a safer environment [1].

Sources#

Grade A = primary source (regulator, protocol specification, client code, original author). Grade B = expert secondary source used for explanation only.

  1. ABitcoin.org. Securing your wallet, 2026.
  2. Abitcoin.org developer documentation. Wallets (Developer Guide), 2026.
  3. AU.S. National Institute of Standards and Technology. NISTIR 8202: Blockchain Technology Overview, 2018. Section 3.4.1, Private Key Storage
  4. Aethereum.org. Ethereum security and scam prevention, 2026.
  5. Aethereum.org. Ethereum wallets, 2026.