Encyclopedia Bitcoin basics · Entry 381
Bitcoin wallets explained: hot, cold, hardware, custodial, and what they actually store
In this article
At a glance
Key facts
| Fact | Detail | Source |
|---|---|---|
| What a wallet stores | Keys and information for recognizing and spending outputs; a watch-only wallet need not hold private keys | [1] |
| Hot wallet | Keys kept on an internet-connected device; convenient but exposed | [1] |
| Cold wallet | Signing keys are kept offline; recovery, physical protection and transaction review still matter | [1][3] |
| Hardware wallet | A device dedicated to running a signing-only wallet | [1][3] |
| Custodial wallet | A third party holds the keys; you rely on its security and honesty | [3] |
| Modern backup | A BIP39 mnemonic plus any passphrase regenerates a seed; recovery also needs compatible derivation and script information | [4][5] |
| Wallet backup | Wallet backups preserve the keys or derivation information and metadata needed by that wallet; a seed is not a universal substitute | [1] |
Separate the wallet, its keys and its displayed balance
A wallet manages information used to find and spend outputs. Its displayed balance is a calculation over the outputs it recognizes and the conditions it can satisfy. The bitcoin is not a file physically stored inside the application.
A watch-only wallet can display the same receipts as a signing wallet without possessing the private keys. A custodial account adds a different layer: the service keeps the on-chain keys and maintains a customer balance in its own records. Check which kind of authority the interface actually gives you.
Hot means online, cold means offline
A hot wallet keeps the private keys on a device that is connected to the internet: a phone app, a desktop program, a browser extension. The developer guide calls the typical version a full-service wallet, because it does everything, from generating keys to broadcasting transactions. That convenience has a price. The guide’s stated disadvantage is that the keys sit on an internet-connected device, where malware or a stolen login can reach them.
A cold wallet keeps the keys on something that never touches the network. The bitcoin.org guidance is blunt: “An offline wallet, also known as cold storage, provides the highest level of security for savings.” In the developer guide’s terms this is a signing-only wallet paired with a networked one. The online half builds an unsigned transaction and watches the ledger; the offline half checks the transaction and signs it; the signed result is carried back across the gap, on a USB stick or by scanning a code, and broadcast.
Hot and cold are not different kinds of key. The same secret number works either way. The difference is how exposed it is while it sits there, and how much friction stands between you and spending. Bitcoin.org frames it like cash: “If you wouldn’t keep a thousand dollars in your pocket, you might want to have the same consideration for your Bitcoin wallet.”
A hardware wallet is a signing machine with no other job
A hardware wallet is a small device, often the size of a USB stick, whose only purpose is to hold keys and sign transactions. The developer guide defines them as “devices dedicated to running a signing-only wallet.” Plugged into a laptop or phone, the device receives an unsigned transaction, shows you the amount and destination on its own screen, signs it inside the device, and passes the signature back. In the intended design, ordinary signing does not export the private key; device compromise and recovery-seed handling remain separate risks.
Bitcoin.org rates this as “the best balance between very high security and ease of use,” because the device is “designed from the root to be a wallet and nothing else,” with no software to install that could carry a virus. The developer guide makes a similar point in plainer terms: it is more secure than a full-service wallet, “with much less hassle than offline wallets.” The costs are that you have to buy one and carry it.
A hardware wallet is not a backup. Devices are lost, broken and superseded. What survives them is the recovery phrase the device shows you when it is first set up, which, with any passphrase and required derivation or script information, can recover the keys derived from that seed on a compatible replacement. Treat the device as the lock and the phrase as the master key.
Custodial means someone else holds your keys
Most people’s first bitcoin sits in an account at an exchange. That is a custodial wallet: you have a username and a password, and the company has the keys. Your balance is a number in their database, a promise that they will hand over coins when you ask. The bitcoin.org security guidance says what that means: “When a third party controls your keys, you rely entirely on their security and honesty.” It adds that “history has shown that exchanges and online wallets can be hacked, fail, or freeze access to funds.”
The site’s history dossiers show what that looks like when it goes wrong. The collapse of Mt. Gox, once the largest exchange, documents how a withdrawal freeze became a bankruptcy and a creditor process that lasted far longer than the exchange itself. The history of Bitcoin exchanges traces the pattern through Bitfinex and Quadriga, each failing in a different way, and explains why an exchange balance is a claim on a company rather than a coin on the chain.
A non-custodial wallet is the opposite arrangement: the keys are on your device or your paper, and no company sits in between. Bitcoin.org’s wallet guide scores this under the heading “Control,” and its wording is precise: “Some wallets give you full control over your bitcoin. This means no third party can freeze or take away your funds.” The trade is that no third party can reset your password either. If the keys are lost, there is no help desk. Neither arrangement is free of risk; they put the risk in different places.
A deterministic backup has a defined recovery scope
Early wallets were a headache to back up because every new address meant a new random key, and a backup taken last month did not include it. BIP32, a proposal by Pieter Wuille dated 11 February 2012, fixed that with hierarchical deterministic wallets: every key is derived, in a fixed order, from a single master seed of between 128 and 512 bits of randomness (256 is advised). The seed backs up the keys derived from that seed, provided the wallet can reconstruct the relevant paths and scripts; imported keys and multisignature policies need separate consideration.
BIP-39, dated 10 September 2013, encodes entropy and a checksum as a mnemonic of 12 to 24 words. For example, 128 entropy bits produce 12 words and 256 produce 24. The checksum can detect some transcription errors; it does not make every mistaken phrase invalid. The mnemonic and optional passphrase are inputs to seed derivation, rather than the words being a direct encoding of that derived seed.
Keep recovery material in protected locations that avoid a single point of failure. A phrase can expose keys derived from it, but an additional passphrase or multisignature policy may also be required to spend. Preserve the complete recovery arrangement, not merely the most visible secret.
The labels matter less than six practical questions
Hot, cold, hardware and custodial describe where the keys live. Bitcoin.org’s wallet directory rates wallets on six things that matter day to day: control (who holds the keys), validation (whether the wallet checks transactions itself by running a full node or trusts someone else’s server), transparency (whether the code is open source and can be built reproducibly), environment (how well the device resists malware), privacy (whether it rotates addresses and can route through Tor), and fees (whether you can set what you pay the network).
One more feature cuts across all the categories. Bitcoin itself supports multi-signature, which bitcoin.org describes as allowing “a transaction to require multiple independent approvals to be spent.” A family, a company or a cautious individual can spread keys across several devices or people so that no single loss or theft is enough. It is the on-chain version of a safe that needs two keys turned at once.
A seed is only one part of a recovery plan
BIP-39 applies Unicode NFKD normalization to the mnemonic and optional passphrase before deriving the seed. A different normalized passphrase derives a different valid seed without a built-in indication of which wallet was intended.
Recovery also requires compatible derivation paths and script types. Imported keys, multisignature policies and cosigner information may need separate backups. The relevant wallet documentation determines the complete recovery procedure.
Direct answers
Questions people ask
Does a Bitcoin wallet actually contain bitcoin?
No. Outputs are recorded on the public ledger. A wallet manages the keys, scripts and transaction information needed to recognize or spend them. A watch-only wallet can display outputs without holding spending keys.
What is the difference between a hot wallet and a cold wallet?
A hot wallet keeps keys on a device connected to the internet, which is convenient and exposed. A cold wallet keeps them offline, which bitcoin.org calls “the highest level of security for savings.” The keys are the same kind of secret number; what differs is how reachable they are.
Is a hardware wallet the same as cold storage?
It is one way of doing it. The device keeps the keys off your computer and signs transactions internally, and bitcoin.org lists hardware wallets under offline wallets for savings, calling them the best balance of security and ease of use. You still need to back up the recovery phrase, because the device can be lost or broken.
What does custodial mean for a Bitcoin wallet?
A custodial wallet is one where a company holds the private keys and you hold a login. Your balance is a claim on the company. Bitcoin.org warns that you then “rely entirely on their security and honesty,” and that exchanges and online wallets have been hacked, failed, or frozen withdrawals. The Mt. Gox dossier on this site is the long version.
Do I need to back up my wallet every time I get a new address?
Not with a modern wallet. Under BIP32, every key is derived from one master seed, and BIP39 turns that seed into a phrase of 12 to 24 words. Bitcoin.org’s guidance is that “a single backup of the recovery phrase is sufficient.” Older loose-key wallets did need repeated backups, which is why they were phased out. Recovery still requires the correct optional passphrase, compatible derivation paths and script types; imported keys or multisignature policy data may require additional backups.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
A Bitcoin wallet manages the keys, scripts and transaction information used to receive and spend bitcoin. The spendable outputs are recorded on the blockchain. A signing wallet controls keys; a watch-only wallet can track outputs without spending them. Hot and cold describe whether signing keys are exposed to an online device. With a custodial service, the provider controls the on-chain keys and the customer relies on its account records.
Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.
Link to this claimWhat a wallet stores: Keys and information for recognizing and spending outputs; a watch-only wallet need not hold private keys
Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.
Link to this claimHot wallet: Keys kept on an internet-connected device; convenient but exposed
Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.
Link to this claimCold wallet: Signing keys are kept offline; recovery, physical protection and transaction review still matter
Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.
Link to this claimHardware wallet: A device dedicated to running a signing-only wallet
Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.
Link to this claimCustodial wallet: A third party holds the keys; you rely on its security and honesty
Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.
Link to this claimModern backup: A BIP39 mnemonic plus any passphrase regenerates a seed; recovery also needs compatible derivation and script information
Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.
Link to this claimWallet backup: Wallet backups preserve the keys or derivation information and metadata needed by that wallet; a seed is not a universal substitute
Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.
Link to this claimRevision history
- — Initial Bitcoin encyclopedia entry at this permanent URL.
- — Revised direct answer to preserve source scope and qualifications. Corrected key fact: What a wallet stores Corrected key fact: Cold wallet Corrected key fact: Modern backup Corrected key fact: Wallet backup Added missing passphrase, derivation and imported-key recovery qualifications. Corrected scope or wording: which regenerates every key on a replacement Corrected scope or wording: Back up the seed once and you have backed up every key the wallet will ever make. Corrected scope or wording: The private key never leaves.
- — Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.
- — Expanded explanation: Separate the wallet, its keys and its displayed balance. Worked examples are illustrative; source checks and independent verification are recorded separately.
On the Know who controls the funds path · Learn next: Private keys, public keys and seed phrases: what actually controls your bitcoin
Source register
Sources and references
Retrieval dates and locators are recorded individually.- WalletsBitcoin developer guide (developer.bitcoin.org)
Defines wallets as a collection of private keys, describes full-service, signing-only (offline and hardware) and distributing-only wallet roles, root seeds of 128, 256 or 512 bits, 12- and 24-word phrases, and the phasing out of loose-key wallets.
Locator: Defines wallets as a collection of private keys, describes full-service, signing-only (offline and hardware) and distributing-only wallet roles, root seeds of 128, 256 or 512 bits, 12- and 24-word phrases, and the phasing out of loose-key wallets. · Retrieved: 2026-10-02T14:48:38.019770+00:00Open source - Choose your walletbitcoin.org
Groups wallets into mobile, desktop and hardware and rates them on control, validation, transparency, environment, privacy and fees; states that full-control wallets mean no third party can freeze or take funds.
Locator: Groups wallets into mobile, desktop and hardware and rates them on control, validation, transparency, environment, privacy and fees; states that full-control wallets mean no third party can freeze or take funds. · Retrieved: 2026-10-02T14:48:38.199788+00:00Open source - Securing your walletbitcoin.org
Warns that a third party holding your keys means relying on its security and honesty, recommends small amounts online and cold storage for savings, describes hardware wallets, multiple backup locations, encrypted online backups and multi-signature.
Locator: Warns that a third party holding your keys means relying on its security and honesty, recommends small amounts online and cold storage for savings, describes hardware wallets, multiple backup locations, encrypted online backups and multi-signature. · Retrieved: 2026-10-02T14:48:38.097528+00:00Open source - BIP 32: Hierarchical Deterministic WalletsPieter Wuille · 2012-02-11Bitcoin Improvement Proposals (github.com/bitcoin/bips)
Specifies deriving every wallet key from one master seed of 128 to 512 bits, with 256 advised, and gives simpler backups as the motivation.
Locator: Specifies deriving every wallet key from one master seed of 128 to 512 bits, with 256 advised, and gives simpler backups as the motivation. · Version / scope: 927b6de9915c9262615a6399de51b200f81e5aa4 · Retrieved: 2026-10-02T15:04:11.762323+00:00Open source - BIP 39: Mnemonic code for generating deterministic keysMarek Palatinus, Pavol Rusnak, Aaron Voisine, Sean Bowe · 2013-09-10Bitcoin Improvement Proposals (github.com/bitcoin/bips)
Specifies the 12 to 24 word recovery phrase, its checksum and optional passphrase, and the conversion of the phrase into a seed for a BIP32 wallet.
Locator: Specifies the 12 to 24 word recovery phrase, its checksum and optional passphrase, and the conversion of the phrase into a seed for a BIP32 wallet. · Version / scope: 927b6de9915c9262615a6399de51b200f81e5aa4 · Retrieved: 2026-10-02T15:04:11.762465+00:00Open source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Bitcoin wallets explained: hot, cold, hardware, custodial, and what they actually store.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-wallets-explained/