What Is a Cold Wallet?
Private key stored offline. Never connected to internet during normal operation.
Remote attack needs internet access to the device. No internet access, no remote attack. That's the whole security model in one sentence.
Hardware wallet is the practical version most people use. Physical device. Plugs into computer only when signing transactions. Private key generated on the device, stays on the device, never leaves.
What Actually Happens When You Use One
Computer sends transaction details to the device. Amount, destination, what's being moved.
Signing happens internally. Private key performs the cryptographic signature on the device itself. Signed transaction returns to the computer. Key never transmitted. Never exposed to anything internet-connected.
Device screen shows exactly what's being signed. Physical button press required to confirm. Malware sitting on the computer watching everything can't do anything about it. Can't click a physical button. Can't modify what the device's own screen displays.
That button is genuinely the security. Simple. Works.
The Devices Worth Knowing
Ledger. Most popular by a distance. Nano X, Nano S Plus. Widest token support. French company. Two incidents worth knowing about: 2020 data breach exposed customer shipping information, funds unaffected. 2023 supply chain attack through a compromised front-end library hit DeFi users who signed malicious transactions. Neither was a direct device compromise but the 2023 incident shook confidence. Closed source secure element is a genuine criticism from security researchers.
Trezor. Open source firmware. Fully auditable. Czech company. Trezor Model T, Safe 3. Physical extraction attack possible with specialized equipment but requires having the device in hand and real technical capability. Remote attack still impossible. Open source argument actually meaningful if that matters to you.
Coldcard. Bitcoin only. Most paranoid option available in a good way. Air-gapped signing. Never needs USB connection ever. Popular with people who've thought deeply about their threat model and only hold Bitcoin.
Keystone. Air-gapped. QR code signing. No USB required. Reduces the attack surface of the connection itself. Less mainstream but genuinely well thought out security model.
Passphrase
Optional feature. Underused.
Additional word or phrase added on top of the seed phrase. Creates an entirely separate wallet. Standard seed alone shows one wallet. Seed plus passphrase shows a completely different one.
Someone finds seed phrase backup. Enters it. Sees a wallet with small amount. Real holdings sitting in passphrase-protected wallet. Untouched.
Serious downside: passphrase must be remembered or backed up separately. Forgotten passphrase means that wallet is gone. No recovery. Unlike seed phrase which can be written and stored, passphrase lives in memory or requires its own secure backup. Adds security and adds a new way to lose access.
How Most People Actually Use This
Not cold wallet OR hot wallet. Both. Different purposes.
Hardware wallet: significant holdings, stuff not needed for months/years. Sitting offline in a secure location. Rarely connected.
Hot wallet: regular DeFi, active trading, daily amounts. MetaMask or Phantom. Convenient. Accept the risk for the working balance.
Hot wallet gets drained through a bad approval or a moment of not paying attention. Painful. Main holdings on hardware wallet, untouched.
Whole net worth in MetaMask is a bet that nothing goes wrong. Might be fine for years. Eventually tends not to be.
