Cold wallet
A cold wallet keeps keys on something that is never connected to the internet. Transactions are signed inside the device, so malware on the computer has no path to the key.
How it works
The computer assembles a transaction and hands it to the device. The device shows the amount and address on its own screen, you confirm with a button, and only a signature comes back out. The key physically never leaves the device.
Which is what the device's own screen is for: an infected computer can swap the recipient address in the interface but not on the device's display. That display is where the address must be checked.
Cold storage is not only a hardware wallet. A key written on paper and never typed into a computer is cold as well, just awkward to use and risky at the moment of entry.
When it is worth it
- An amount you would mind losingA simple rule: if losing the money would change your life, it does not belong in a phone wallet.
- Long-term holdingAssets you will not touch for months lose nothing from taking an extra minute to reach.
- Dealing with unfamiliar sitesMain holdings cold, a separate hot wallet for connections: a mistake then costs only what was in the hot one.
What it does not protect against
- Losing the seed phraseThe device is not the backup. If it breaks or is lost you restore from the phrase, and without the phrase there is nothing to restore from.
- Signing without lookingThe device protects the key, not you from your own consent. Approve a malicious permission and you hand over the tokens willingly.
- Buying usedA device that arrives with a seed phrase already in the box is a trap. The phrase is generated by the owner at first setup, by nobody else.