Types of Crypto Wallet, Compared
Custodial, hot, cold, hardware, multisig. What each protects against, what it does not, and how to pick one for the amount you actually hold.
The one distinction that matters
Every wallet classification reduces to one question: who controls the private keys? Everything else is detail.
| Type | Who holds keys | Best for |
|---|---|---|
| Custodial (exchange) | The platform | Active trading, small balances |
| Hot wallet (mobile/browser) | You, on an internet-connected device | Everyday amounts, DeFi use |
| Hardware wallet | You, on an offline device | Long-term holdings of real value |
| Paper / metal backup | You, entirely offline | Deep cold storage |
| Multisig | Split across several keys | Shared control, large holdings |
Custodial wallets
Holding crypto on an exchange is convenient: trading is instant, recovery is possible if you lose your password, and you do not have to think about key management.
The cost is that your claim is against the platform rather than on-chain. Exchange failures have wiped out user balances repeatedly, and a platform can also freeze an account for reasons unrelated to you. For funds you are actively trading this is a reasonable trade; for savings it is a different proposition.
Hot wallets
Software wallets on a phone or browser hold keys on a device that connects to the internet. You have real control, and you carry real exposure: malware, malicious browser extensions and phishing sites all target them.
They are the right tool for amounts you are prepared to lose and for interacting with applications. They are not where a long-term position belongs.
Hardware wallets
A hardware wallet stores keys on a dedicated device and signs transactions internally, so the key never touches your computer even while you use it. A compromised computer can show you a wrong address, but it cannot extract the key.
This is why verifying the destination address on the device screen matters β the device's display is the part malware cannot forge. Reviews of specific models are in the hardware wallet section.
Multisig
A multisig wallet requires several keys to authorise a transaction β two of three, three of five, and so on. No single compromised key loses the funds, and no single lost key locks them.
It is the strongest common arrangement and the most operationally demanding. It suits shared treasuries and large individual holdings where the setup cost is justified.
A practical allocation
- Trading balance β on the exchange, sized to what you are actively trading.
- Spending balance β hot wallet, an amount you would be annoyed but not damaged to lose.
- Core holdings β hardware wallet, with a verified seed backup.
- Long-term or large β hardware with passphrase, or multisig.
The common failure is not choosing the wrong wallet type. It is leaving everything on an exchange by default because moving it was never urgent β until it was.
What each type actually protects against
Choosing a wallet is easier when framed as a threat question rather than a feature comparison. Different wallets defend against different attacks, and none defends against all of them.
| Threat | Custodial | Hot wallet | Hardware | Multisig |
|---|---|---|---|---|
| Platform insolvency | No | Yes | Yes | Yes |
| Malware on your computer | Yes | No | Yes | Yes |
| Phishing a signature out of you | Partly | No | Partly | Partly |
| Losing one key or device | Yes | No | No | Yes |
| Physical theft or coercion | Yes | No | No | Partly |
Note that a hardware wallet only "partly" protects against phishing. It stops a key being extracted, but if you are tricked into approving a malicious transaction, the device signs exactly what you told it to. The device protects the key, not your judgement.
Token approvals: the risk that outlives the transaction
When you use a decentralised application, you typically grant it permission to move a token on your behalf. Many applications request unlimited approval by default, and that permission persists after you finish.
If the contract is later compromised, that standing approval can be used to drain the token from your wallet β long after you last used the application. Reviewing and revoking unused approvals periodically is one of the higher-value security habits, and one almost nobody does.
Practical advice on backups
- Back up the recovery phrase before funding the wallet, not after.
- Test the backup by restoring it on a second device while the wallet is still empty.
- Keep the backup physically separate from the device itself.
- Record which derivation path and wallet software you used, which matters when restoring years later.
The last point is quietly important: restoring an old backup into different software can produce an apparently empty wallet purely because of a different derivation path, and the resulting panic has caused people to conclude, wrongly, that their funds were stolen.
Further reading
- More crypto guides and explainers
- Crypto glossary β terms explained
- Crypto tax in India
- Best crypto exchanges in India
Educational content only, not financial advice. Crypto assets are volatile and you can lose money. Do your own research and consider your circumstances before investing.
Enjoyed this article? Put it into practice.
SmartViewAI gives you live portfolio analytics, AI-graded signals, and a built-in academy. All in one place.