A wallet is a key manager
Cryptocurrency remains recorded on a network ledger. Wallet software helps generate and protect keys, derive addresses, display balances, build transactions, and create digital signatures. Whoever controls the relevant private keys can usually control the associated assets.
A wallet balance is an interpretation of network data. Deleting a wallet app does not erase the assets, but losing every usable key and backup can make them permanently inaccessible.
Hot, cold, software, and hardware wallets
| Type | Typical use | Main exposure |
|---|---|---|
| Mobile or desktop wallet | Frequent transactions and applications | Malware, device compromise, fake updates |
| Browser wallet | Web applications and token interactions | Phishing, malicious approvals, risky extensions |
| Hardware wallet | Keeping signing keys isolated | Bad backups, supply-chain tampering, blind signing |
| Paper or metal backup | Offline recovery material | Theft, fire, water, poor storage, unauthorized copies |
| Multisignature setup | Shared control or reduced single-key risk | Complex recovery, coordination, configuration errors |
Custodial versus self-custody
With custodial storage, an exchange or service controls the keys and grants access through an account. This shifts some key-management work to the provider but introduces account, operational, solvency, legal, and withdrawal risk.
With self-custody, you control the keys directly. That removes some provider dependency but makes you responsible for backups, device security, transaction verification, inheritance planning, and recovery tests.
Both approaches can fail in different ways. Choose only after understanding who can authorize transfers and how access is recovered.
Recovery phrases and backups
A recovery phrase can recreate a set of wallet keys. Anyone who obtains it may be able to recreate the wallet and transfer assets without the original device or password. Treat it as high-value access material.
- Generate it only in the intended wallet setup flow on a trusted device.
- Record it accurately and keep it offline.
- Do not photograph it, email it, upload it, or save it in ordinary cloud notes.
- Protect backups from theft, observation, fire, water, and accidental disposal.
- Do not invent a complex scheme you cannot reliably reverse years later.
- Test recovery procedures with a low-value setup before relying on them.
Common wallet threats
A fake site, message, app, or support agent requests credentials, a signature, or a recovery phrase.
Malware or a deceptive interface replaces the intended destination with an attacker’s address.
A token permission or smart-contract signature grants broader access than the user expects.
An attacker takes over a phone number and uses SMS recovery to access an exchange account.
A person or platform promises returns, builds trust, then blocks withdrawals or demands more payments.
Do not share it, enter it into a website, or disclose it in response to an unsolicited message. Possession can equal control.
Transaction safety checklist
- Confirm the asset and correct network before copying an address.
- Verify the destination through a second trusted channel when possible.
- Compare the first and last characters on the signing device itself.
- Read the amount, fee, network, and contract request before signing.
- Send a small test transaction before a high-value transfer.
- Wait for the test to settle and confirm the recipient can access it.
- Review token approvals and revoke permissions you no longer need.
- Keep account and transaction records appropriate for local tax rules.
If something goes wrong
Stop interacting with the suspicious site or person. Preserve transaction identifiers, addresses, messages, and screenshots. Move remaining assets only from a known-safe device and wallet when doing so will not expose additional keys. Contact the relevant service through a verified channel and report scams to the appropriate public agency in your location.
Blockchain transactions are often irreversible, and “recovery services” can themselves be scams. Be skeptical of anyone requesting an upfront payment or access credentials to recover funds.
