This page is for someone who has bought (or is about to buy) crypto and wants to understand where it should live. It's the conceptual foundation for moving coins to a hardware wallet and protecting your recovery phrase.
The two keys, in plain English
Every wallet is built around a pair of cryptographic keys. Think of them like a lock and a key:
- The public key / address. This is like an account number — something you share so people can send you coins. It's fine to publish. You can have many; each points to the same underlying control.
- The private key. This is the secret that actually authorizes spending. Whoever holds the private key controls the coins. There is no "forgot password" and no company that can reset it, because there is no central party holding it for you in self-custody. If you lose it, the coins are unrecoverable. If someone else gets it, the coins are gone.
In practice you rarely handle the raw private key. Most wallets represent it as a recovery phrase — a list of 12 or 24 words that can regenerate the key. The recovery phrase is just a human-friendly form of the private key, which is exactly why protecting it is the single most important skill in self-custody. We cover that in depth in protecting your recovery phrase.
Custodial vs self-custody: the real decision
| Custodial (e.g., an exchange) | Self-custody (e.g., a hardware wallet) | |
|---|---|---|
| Who holds the keys | The company | You |
| Ease of use | High — a password and a login, like a bank app | Lower — you manage keys and backups yourself |
| If you forget your password | The company can reset it | Only your recovery phrase can restore access |
| If the company fails or is hacked | Your access depends on the company and applicable law | Not affected — the keys are yours, off their servers |
| If you lose your backup | Not your problem (the company has the keys) | The coins are unrecoverable |
| If you're scammed into sharing your secret | Limited to that account | Everything in that wallet is exposed |
| Best for | Trading, and amounts you're actively using | Amounts you intend to hold long-term |
The honest summary: custodial is easier, self-custody is more secure for holding. Neither is wrong. The mistake is using the wrong one for the job — parking a long-term holding on an exchange you don't control, or expecting a self-custody wallet to behave like a bank when you've lost your backup.
The common wallet types
- Exchange / custodial wallets. What you get when you buy on a platform. Convenient, and the right place for coins you're actively trading. The coins are held by the platform.
- Software (hot) wallets. Apps or browser extensions on your phone or computer. You control the keys, but the device is connected to the internet, so it's exposed to malware and phishing. Fine for smaller, actively-used amounts.
- Hardware (cold) wallets. A physical device that stores the private key offline and signs transactions on its own screen. The key never leaves the device in usable form. This is the standard for amounts you intend to hold. See our hardware-wallet shortlist.
- Paper / metal backups. Not wallets, but backups of the recovery phrase. These are your insurance against the device being lost or destroyed — and they must be kept offline and safe. See recovery-phrase protection.
The risks, honestly stated
A practical default for a beginner: keep what you're actively trading on a reputable exchange, and move what you intend to hold long-term to a hardware wallet once the amount is worth protecting. You don't need to self-custody a $20 experiment — but you should plan for it before the amount grows.
Frequently asked questions
Where are my coins actually "stored"?
On the blockchain, as public entries. What a wallet stores is the key (or recovery phrase) that lets you spend them. So "where are my coins" has two answers: the ledger says where they're recorded, and your key says whether you can move them. Lose the key and the coins still exist on the ledger — but not under your control.
Is a hardware wallet required?
No. It's a risk/reasonableness call. For small, actively-used amounts, a reputable exchange or software wallet is fine. For anything you intend to hold for years, a hardware wallet is the standard protection, because it keeps the key offline. The threshold is personal: buy one when the amount you're holding is worth the small cost and effort of protecting.
Can I use more than one wallet?
Yes, and many people do — for example, a software wallet for day-to-day and a hardware wallet for the long-term hold. Each wallet (or each address within one) can be independent. Just make sure you understand which keys control which coins, and back up each one.
What if I buy a wallet from a third party?
Buy new devices from the manufacturer's official store, not resellers. A used or pre-"activated" device could have its key already known to someone else, which defeats the entire purpose. This is a common and costly mistake — see scam awareness.
Where to go next
The natural next steps: choosing a hardware wallet, moving your coins to one, and the two safety pages that protect everything else — protecting your recovery phrase and avoiding scams.