What is a crypto wallet?
7 min read · Updated Oct 6, 2026 · By Coinucation Editorial
- A wallet holds the private keys that control your coins; the coins themselves live on the blockchain.
- Custodial wallets trade control for convenience; self custody gives you full control and full responsibility.
- Hot wallets are online and convenient; cold and hardware wallets keep keys offline for better security.
- Your seed phrase can recreate your entire wallet, so it must never be shared or stored online.
The short answer
A crypto wallet is software or hardware that holds the private keys which let you control coins and tokens on a blockchain. The name is slightly misleading. Your coins are not inside the wallet the way cash is inside a leather one. They are recorded on the blockchain, and the wallet holds the secret that proves you are allowed to move them.
A wallet generates a pair of keys. The public key, or an address derived from it, is what you share so people can send you funds. The private key is what you use to sign transactions that spend those funds. Whoever holds the private key controls the coins, which is why protecting it is the entire job of a wallet.
Wallets come in many forms: mobile apps, browser extensions, desktop programs, small physical devices, and accounts at exchanges that manage keys on your behalf. Each offers a different balance of convenience, security, and control. Most people end up using more than one, matching the tool to the amount of money involved and how often they need to access it. The sections below walk through the main types.
Custodial versus self custody
The first distinction is who holds the keys. A custodial wallet, such as your account at an exchange, means the company holds the private keys and you hold a login. This is convenient, since you can reset a password and the company handles the technical details. But you are trusting that company not to fail, get hacked, or freeze your account.
A self custody wallet means you hold the keys yourself. Nobody can freeze your funds or stop a transaction, and no company failure can take your coins. In exchange, there is no password reset. If you lose your keys or recovery phrase, the funds are gone permanently, and if someone else obtains them, they can take everything.
The collapse of the exchange FTX in November 2022, which left customers unable to withdraw billions of dollars, is the most cited example of custodial risk. The phrase not your keys, not your coins captures the lesson. That said, self custody requires discipline, and for small amounts or active trading many people reasonably choose a reputable custodian.
Hot wallets and cold wallets
A hot wallet is connected to the internet. Mobile apps and browser extensions like MetaMask or Phantom are hot wallets. They are convenient for everyday use, interacting with applications, and small balances, but because the keys live on an internet connected device, they are exposed to malware, phishing, and remote attacks.
A cold wallet keeps keys offline. The most common form is a hardware wallet, a small device from makers such as Ledger or Trezor that stores keys in a secure chip and signs transactions internally. The private key never touches your computer or phone. To send funds, you confirm the transaction on the device itself, which protects you even if your computer is compromised.
A common setup is to use a hot wallet for small amounts and daily activity, and a hardware wallet for long term holdings. Some people also use multisig wallets, which require several keys to approve a transaction, so no single lost or stolen key can move the funds. Businesses and DAOs commonly use multisig for shared treasuries.
- Hot wallet: online, convenient, higher exposure to attack
- Cold wallet: offline keys, best for larger or long term holdings
- Hardware wallet: a physical device that signs transactions without exposing keys
- Multisig: multiple keys required, reducing single points of failure
The seed phrase
When you create a self custody wallet, it generates a recovery phrase, also called a seed phrase, usually 12 or 24 common English words. This phrase is a human readable form of the master secret from which all of your wallet's keys are derived. Anyone who has the phrase can recreate your wallet on any device and take the funds.
Write the phrase down on paper or stamp it into metal, and store it somewhere safe and private. Never type it into a website, never store it in a screenshot or cloud note, and never share it with anyone, including people claiming to be support staff. Legitimate wallet companies will never ask for it.
If your phone breaks or your hardware device is lost, you restore the wallet by entering the phrase into a new wallet. This is why the phrase, not the device, is what truly needs protecting. Test your backup by restoring it before you move significant funds in. Many wallets now prompt you to confirm the phrase during setup for this reason.
Common mistakes and threats
Phishing is the most common way people lose funds. Fake websites, fake support accounts, and fake wallet apps trick users into entering their seed phrase or signing a malicious transaction. Always download wallets from official sources, bookmark the sites you use, and treat unsolicited messages as hostile. No legitimate service will ever ask you to verify your wallet by entering its phrase.
Another frequent mistake is sending funds on the wrong network. Many tokens exist on several blockchains, and an address that works on one may not be recoverable on another. Double check the network and address before every transfer, and send a small test amount first when dealing with a new destination.
Approving unlimited token access to an application is a subtle risk. When you connect a wallet to a DeFi app, you may be asked to let its contract spend your tokens. If that contract is later exploited, those tokens can be taken. Review approvals periodically and revoke ones you no longer need.
How to get started
If you are new, begin with a well known self custody mobile or browser wallet and a small amount of funds you would not mind losing. Practice receiving, sending, and restoring from your seed phrase. Learn what a transaction confirmation looks like and how fees are shown. This builds habits that matter more than any product choice.
Once you hold an amount that would hurt to lose, buy a hardware wallet directly from the manufacturer, never second hand or from a marketplace. Set it up yourself, confirm the device generates the seed phrase rather than shipping with one, and store the phrase separately from the device. A device that arrives with a pre printed phrase is a scam.
Review your setup from time to time. Are your backups still readable? Does a trusted person know how to access your funds if something happens to you? Have you revoked old approvals? Security in crypto is an ongoing habit rather than a one time task. A short checklist reviewed once or twice a year is enough for most people.
What does a crypto wallet actually store?
Coinucation