The single rule of crypto custody is "not your keys, not your coins". Whoever controls the private keys controls the funds. This guide explains the three places your crypto can live - exchange, hot wallet, hardware wallet - which attacks each one survives, and why a 60 USD device defeats every attack except a wrench.
Every coin you own sits in one of three places. Exchange means a company holds the keys for you. Hot wallet means you hold the keys on a device connected to the internet. Hardware wallet (cold) means you hold the keys on an offline device. Going from left to right you trade convenience for security. The slider above shows what each step actually buys you.
Crypto ownership is defined by one number: the private key. Whoever knows the private key can move the funds. There is no customer support, no chargeback, no court order that can recover coins moved by someone with the key. This is the entire point of crypto and the entire reason storage matters.
When you "buy crypto on an exchange" the exchange takes your money and credits a number on your account page. The actual coins sit in the exchange's wallet, controlled by the exchange's keys. You hold an IOU. As long as the exchange is solvent and lets you withdraw, the IOU is good. When the exchange is hacked (Mt. Gox, 2014: 850,000 BTC gone), goes bankrupt (FTX, 2022: 8 billion USD missing), or freezes withdrawals, the IOU is worth zero.
Moving coins to a wallet you control means you receive the actual private key and become responsible for it. You gain real ownership and you gain real responsibility. The next sections cover what that responsibility looks like in practice.
Keeping crypto on an exchange is the default for most beginners. The platform is familiar, withdrawal limits are low, and you can trade instantly. For amounts you actively trade this is fine. The convention used by experienced traders is: the exchange is a workspace, not a vault. Whatever you are not actively moving belongs somewhere else.
The risk profile is specific. You are protected against malware on your laptop (the keys are not on your machine), but exposed to everything that can go wrong with the exchange itself: hack, insolvency, regulator freeze, internal fraud, sanctions list. History shows the second category fires often enough to take seriously.
Practical rule: exchanges with strong reserves and multi-year track records (Binance, Coinbase, Kraken, Bybit, OKX) are reasonable for trading capital. Smaller or newer exchanges concentrate risk and should hold only what you would lose without flinching. Compare the major futures exchanges in our crypto exchange comparison.
A hot wallet is a piece of software that stores your private keys on your phone or computer. Metamask is the dominant choice for Ethereum and EVM chains. Trust Wallet covers most chains in a mobile app. Phantom is the standard for Solana. All three are non-custodial: you hold the keys, they only handle the interface.
A hot wallet upgrades you from "trust the exchange" to "trust your own device". That is a genuine improvement against exchange-level risks but creates a new exposure: anything that can read your device can read your keys. Malware, browser-extension scams, fake support chats, signing a malicious transaction by mistake. The wallet itself does not betray you. The environment around it does.
Use a hot wallet for amounts where the convenience of one-click transactions matters more than the risk of losing them. A common rule: under 1,000 USD value, hot wallet is fine. Above that, the math tips toward hardware. And keep one rule absolute: never paste your seed phrase into anything, ever.
A hardware wallet is a small physical device that holds your private keys in a chip that never connects to the internet. To send a transaction you plug the device in, the laptop sends the transaction details, the device signs them on its own chip, and only the signature comes back. The keys themselves never touch the laptop.
This is the structural defense. Even if your laptop is fully compromised by malware, the attacker cannot extract keys from a sealed offline chip. Every transaction must be physically confirmed by pressing a button on the device, with the destination address shown on the device's own screen. Phishing sites and malicious smart contracts both lose this fight: the device shows what is actually being signed, not what the website claims.
Two brands cover 95% of the market. Ledger (France) is the larger of the two, with the Nano S Plus around 80 USD and Nano X around 150 USD. Trezor (Czech Republic) is fully open source, with the Model One around 60 USD and Safe 3 around 80 USD. Either is dramatically better than no hardware wallet. The price of the device pays for itself the first time it stops a phishing transaction.
The standard hardware wallet for over 6 million crypto holders. Supports BTC, ETH, Solana, and 5,500+ other assets. Order from the official site to avoid tampered devices from third-party sellers.
Order from Ledger →First-time setup takes about 30 minutes. Do it once, do it carefully, never touch the seed phrase again unless you are recovering.
The seed phrase is everything. Whoever has the 24 words controls the funds. These seven rules are non-negotiable.
The same four patterns drain accounts every week. Each one is preventable in 60 seconds.
Everything above is a breakdown of how crypto storage works and which threats each storage type defends against. It is not a recommendation to buy specific products or to hold any amount of cryptocurrency.