Security Beginner 8 min read

How to Store Crypto Safely: Where Your Keys Actually Live

The single rule of crypto custody is "not your keys, not your coins". Whoever controls the private keys controls the funds. This guide explains the three places your crypto can live - exchange, hot wallet, hardware wallet - which attacks each one survives, and why a 60 USD device defeats every attack except a wrench.

Where your keys live
Exchange
Binance, Coinbase
Hot wallet
Metamask, Trust
Cold wallet
Ledger, Trezor
Who controls keys
You (online)
Risk level
Medium
Your $10,000 here
3 of 5 attacks survive
Vulnerable to phishing and malware. Convenient for daily use.
Attack survival
Exchange hack
FTX, Mt. Gox style
Vulnerable
Phishing
Fake site or email
Risky
Malware on device
Keylogger, clipboard hijack
Drained
Lost device or seed
Phone broken, seed gone
Recovery needed
$5 wrench attack
Physical coercion
Always vulnerable

Three places your crypto can live

Every coin you own sits in one of three places. Exchange means a company holds the keys for you. Hot wallet means you hold the keys on a device connected to the internet. Hardware wallet (cold) means you hold the keys on an offline device. Going from left to right you trade convenience for security. The slider above shows what each step actually buys you.

Exchange
Who controls keys
The exchange. You have an IOU.
Best for
Active trading. Funds you actually move every week.
Main risk
Exchange hack, bankruptcy, frozen account. FTX, Mt. Gox.
Hot wallet
Who controls keys
You. Keys live on your device, online.
Best for
Daily use. DeFi, NFTs, small balances under 1,000 USD.
Main risk
Phishing, malware, signing a malicious transaction.
Cold wallet
Who controls keys
You. Keys never leave the offline device.
Best for
Long-term holding. Anything over 500 USD value.
Main risk
Lost device with no seed backup. Physical coercion.

Not your keys, not your coins

Crypto ownership is defined by one number: the private key. Whoever knows the private key can move the funds. There is no customer support, no chargeback, no court order that can recover coins moved by someone with the key. This is the entire point of crypto and the entire reason storage matters.

When you "buy crypto on an exchange" the exchange takes your money and credits a number on your account page. The actual coins sit in the exchange's wallet, controlled by the exchange's keys. You hold an IOU. As long as the exchange is solvent and lets you withdraw, the IOU is good. When the exchange is hacked (Mt. Gox, 2014: 850,000 BTC gone), goes bankrupt (FTX, 2022: 8 billion USD missing), or freezes withdrawals, the IOU is worth zero.

Moving coins to a wallet you control means you receive the actual private key and become responsible for it. You gain real ownership and you gain real responsibility. The next sections cover what that responsibility looks like in practice.

Exchange storage: convenience over ownership

Keeping crypto on an exchange is the default for most beginners. The platform is familiar, withdrawal limits are low, and you can trade instantly. For amounts you actively trade this is fine. The convention used by experienced traders is: the exchange is a workspace, not a vault. Whatever you are not actively moving belongs somewhere else.

The risk profile is specific. You are protected against malware on your laptop (the keys are not on your machine), but exposed to everything that can go wrong with the exchange itself: hack, insolvency, regulator freeze, internal fraud, sanctions list. History shows the second category fires often enough to take seriously.

Practical rule: exchanges with strong reserves and multi-year track records (Binance, Coinbase, Kraken, Bybit, OKX) are reasonable for trading capital. Smaller or newer exchanges concentrate risk and should hold only what you would lose without flinching. Compare the major futures exchanges in our crypto exchange comparison.

Hot wallets: your keys, online

A hot wallet is a piece of software that stores your private keys on your phone or computer. Metamask is the dominant choice for Ethereum and EVM chains. Trust Wallet covers most chains in a mobile app. Phantom is the standard for Solana. All three are non-custodial: you hold the keys, they only handle the interface.

A hot wallet upgrades you from "trust the exchange" to "trust your own device". That is a genuine improvement against exchange-level risks but creates a new exposure: anything that can read your device can read your keys. Malware, browser-extension scams, fake support chats, signing a malicious transaction by mistake. The wallet itself does not betray you. The environment around it does.

Use a hot wallet for amounts where the convenience of one-click transactions matters more than the risk of losing them. A common rule: under 1,000 USD value, hot wallet is fine. Above that, the math tips toward hardware. And keep one rule absolute: never paste your seed phrase into anything, ever.

Hardware wallets: your keys, offline

A hardware wallet is a small physical device that holds your private keys in a chip that never connects to the internet. To send a transaction you plug the device in, the laptop sends the transaction details, the device signs them on its own chip, and only the signature comes back. The keys themselves never touch the laptop.

This is the structural defense. Even if your laptop is fully compromised by malware, the attacker cannot extract keys from a sealed offline chip. Every transaction must be physically confirmed by pressing a button on the device, with the destination address shown on the device's own screen. Phishing sites and malicious smart contracts both lose this fight: the device shows what is actually being signed, not what the website claims.

Two brands cover 95% of the market. Ledger (France) is the larger of the two, with the Nano S Plus around 80 USD and Nano X around 150 USD. Trezor (Czech Republic) is fully open source, with the Model One around 60 USD and Safe 3 around 80 USD. Either is dramatically better than no hardware wallet. The price of the device pays for itself the first time it stops a phishing transaction.

Recommended
Get a Ledger Nano S Plus

The standard hardware wallet for over 6 million crypto holders. Supports BTC, ETH, Solana, and 5,500+ other assets. Order from the official site to avoid tampered devices from third-party sellers.

Order from Ledger →

Setting up cold storage in 6 steps

First-time setup takes about 30 minutes. Do it once, do it carefully, never touch the seed phrase again unless you are recovering.

01
Order from the official source
Buy directly from ledger.com or trezor.io. Never from Amazon, eBay, or third-party sellers. Tampered devices have stolen significant amounts of crypto.
02
Verify the box on arrival
Check that the seal is intact and the device is sealed in factory plastic. If the device prompts you with a pre-filled seed phrase, return it immediately. A genuine device generates a fresh seed in front of you on first boot.
03
Generate the seed phrase on the device
Set a PIN code (4 to 8 digits). The device displays a 24-word seed phrase one word at a time. Write each word on the supplied paper card. Verify by re-entering the words on the device when prompted.
04
Make two physical copies of the seed
Copy the 24 words onto a second paper or, better, a metal backup plate (steel survives fire and flood). Store the two copies in two different physical locations, both private.
05
Install Ledger Live or Trezor Suite
Download from the official site only. The desktop app is the safest interface. Add accounts for the chains you use. The wallet addresses appear in the app and on the device screen - they should match.
06
Send a test amount first
From the exchange, withdraw a small amount (10 to 50 USD) to your hardware wallet address. Confirm it arrives. Then send the rest. Always test with small first on a new address.

Seven seed phrase rules

The seed phrase is everything. Whoever has the 24 words controls the funds. These seven rules are non-negotiable.

01
Never type it anywhere digital
Not in a browser. Not in an email. Not in a notes app. Not in a password manager. Not in a screenshot. The seed only ever exists on physical paper or metal.
02
No support agent will ever ask
Not Ledger support, not Trezor, not Metamask, not any exchange. Anyone asking for your seed phrase is a scammer, no exceptions. Ledger has never had reason to ask, and never will.
03
Two physical copies, two locations
One copy at home, one with a trusted family member or in a safe-deposit box. House fire, flood, theft - any single event must not destroy both copies.
04
Use metal for serious holdings
Stainless steel plates with stamped letters survive fires that destroy paper. Brands: Cryptosteel, Billfodl, Trezor Keep. Around 50 to 100 USD per plate. Worth it above 5,000 USD value.
05
Never split it across services
Do not store half on Google Drive and half on iCloud. Do not split words across apps. Splits get reassembled in compromise. The seed is one secret. Treat it as one secret.
06
Test the recovery once
Before transferring large amounts, factory-reset the device and restore from your seed. If recovery works, the seed is correct. If not, you find out before it matters.
07
Plan for the worst case
Tell one trusted person where the seed is, sealed, with instructions. If you die or lose memory, the funds are not recoverable without that information. This is the most overlooked rule.

Four mistakes that lose coins

The same four patterns drain accounts every week. Each one is preventable in 60 seconds.

01
Photographing the seed phrase
"I will just take a picture for backup." The photo lands in iCloud or Google Photos, both syncing to multiple devices. One compromised account exposes the seed and drains every wallet it controls.
Never photograph the seed. Paper or metal only.
02
Buying a used hardware wallet
A "great deal" on eBay or marketplace. The seller pre-loaded the seed and waits for you to deposit. As soon as funds arrive, they are swept. Used hardware wallets are a known scam vector.
Order new directly from the manufacturer site only.
03
Approving "permission" transactions blind
Connecting a wallet to a DeFi site and clicking through approval dialogs without reading. A malicious contract can request unlimited approval to spend your tokens. One signature drains the wallet weeks later.
Read every approval. Use revoke.cash to clear old permissions.
04
Telling people you hold crypto
Posting holdings on social media, bragging in person, telling colleagues. The wrench attack section of the slider is a real category. People have been kidnapped for known crypto holdings. Privacy is part of security.
Never disclose holdings publicly. No exceptions for "small amounts".

This is not financial advice

Everything above is a breakdown of how crypto storage works and which threats each storage type defends against. It is not a recommendation to buy specific products or to hold any amount of cryptocurrency.

DYOR · Do Your Own Research
Self-custody puts full responsibility on you. Lost seed = lost funds, with no recovery. Practice with small amounts before moving real holdings. Test the recovery procedure before you need it.
A hardware wallet does not protect against a forgotten or destroyed seed phrase.
Affiliate links above support this site at no cost to you.
Brand mentions are informational and do not imply endorsement.
Tax treatment of crypto holdings varies by jurisdiction. Consult a local accountant.
Stuck on a term? Every crypto term explained simply in our glossary. Open the glossary