TL;DR

  • Three jobs: it keeps keys, signs transactions, and reads the chain. The coins stay on the blockchain; the wallet is how you exercise the right to move them.
  • The word covers both an account at a company that holds keys for you, and software or hardware that gives the keys to you. Establishing which you have is an early security question, because risk, responsibility and recovery all differ between the two.
  • Whether the keys touch an internet-connected device. Hot wallets (apps, extensions) keep keys where using them is instant and attacking them is remote-capable; cold wallets (hardware, offline storage) keep keys where signing requires the device, at the price of convenience. Each product can be placed somewhere on this line.
  • For self-custody: recovery material that must exist and survive (a seed phrase and any passphrase, or the recovery factors of an MPC or smart-account design), a phrase that is typed only into a restore you started, and the habits the security guides teach. The commitments begin at the setup screen, which is why this guide comes before the buying guide.
In one block

A crypto wallet is a key-management tool that generates addresses for receiving crypto, signs transactions to send it, and shows balances by reading the blockchain. The assets stay on the chain; the wallet holds the keys, or in some designs key shares, that authorise moving them. The word also covers custodial accounts, where a company holds the keys on the customer's behalf.

If the wallet holds no coins, what does it actually do?

Quick answer

Three jobs: it keeps keys, signs transactions, and reads the chain. The coins stay on the blockchain; the wallet is how you exercise the right to move them.

The keeping is the heart. When a wallet is created, it generates a private key (in hierarchical deterministic designs, a whole family of keys derived from one master secret) and from each key a public address that others can pay. The private key is the authority: whoever knows it can sign transfers from its address, from any device, anywhere, for as long as the key exists. The guide to how a blockchain works explains the ledger those transfers live on; the point here is the division of labour: assets on the chain, authority in the key, interface in the wallet.

The signing is the action. Sending crypto means composing an instruction (this amount, to that address) and signing it with the private key; the network verifies the signature against the address and executes. The wallet's job is to do this correctly and to show you clearly what you are signing, the property the guide to blind signing examines at length.

The reading is the display. Balances in a wallet app are the chain's records, fetched and presented; the wallet holds no funds to display, only the addresses whose entries it looks up. This is why a wallet correctly restored on a new phone shows the same funds once it has synced: the funds were on the chain all along, and the restore regenerated the keys that control them.

What regenerates the keys depends on the design

What restores control differs by design. In a seed-phrase wallet the recovery material regenerates every key, so whoever holds it effectively holds the wallet; in MPC and smart-account designs recovery can combine several factors, and no single item need be equivalent to the wallet.

Seed-phrase wallets typically follow two Bitcoin standards, which many wallets for other chains also implement. BIP-39 starts from random entropy and encodes it as a list of words, the seed phrase (the standard calls it a mnemonic); the words, together with an optional passphrase, are then stretched into a 512-bit seed (BIP-39, bitcoin/bips). BIP-32 derives a tree of keys from that seed, with each key sitting at a numbered position called a derivation path (BIP-32, bitcoin/bips). Because the passphrase is an input to the seed, the same words with a different passphrase, or with none, produce a different, valid wallet, which may or may not hold funds; the funds sit in the wallet derived with the passphrase that was actually set (BIP-39, bitcoin/bips). Two consequences follow. Restoring a BIP-39 wallet needs the words, the passphrase if one was set, and a wallet that looks along the same derivation paths; a restore that lacks any of these can show an empty balance while the funds sit untouched on the chain. And these standards describe BIP-39 wallets only; a wallet that does not use them recovers differently.

In an MPC wallet (multi-party computation), the full private key is typically never held in one place. Where the design uses distributed key generation, the parties or devices create their key shares jointly, so a complete key need never exist, and a threshold of them cooperates to produce a signature without reconstructing the key on any one machine (NIST, Threshold Cryptography project). That is a different operation from taking an existing secret and dividing it, which is what Shamir-style backup schemes do to a seed. There is often no seed phrase to write down; recovery depends on the provider's specific design, such as re-issuing a share from an encrypted backup or a recovery file. The arrangement removes one specific single point of failure, a single written secret that hands over the whole key to whoever finds it, and adds dependencies of its own: the provider's availability, its recovery process, the correctness of its implementation, and the coordination the parties need in order to sign. What a lost phone costs, and whether the provider can act without you, are questions to put to that specific design. The guide to threshold cryptography and MPC explains the mechanics.

In a smart-account wallet (on Ethereum and similar chains; some designs build on the ERC-4337 standard and others use different mechanisms), the account is a contract whose rules can be programmed: several signing keys, a spending limit, or recovery through trusted contacts who can together authorise a key change (ethereum.org, account abstraction roadmap). Recovery there is a rule in the contract, and it brings its own questions: whether the contract code is correct, and whether the recovery contacts stay reachable and trustworthy.

It follows that in each of these designs the device is replaceable and whatever the design uses for recovery is what must survive, so a useful early question about any wallet is which kind of recovery material it uses. The guide to what a seed phrase is covers the BIP-39 case in depth, and the comparison of hardware, software and MPC key storage covers the others.

Diagram of wallet anatomy showing the blockchain holding the actual asset entries, the wallet holding private keys that authorise transfers and deriving public addresses for receiving, signing as the action that moves entries, the balance display as a read of the chain rather than contents, and the recovery material (seed phrase with optional passphrase, MPC recovery factors, or smart-account recovery rules) as what restores control of the keys, with the note that the recovery material outranks any device
Figure 1. What a wallet actually is: keys, signatures and a view of the chain. The coins stay on the ledger; the keys are the authority, and the recovery material (a BIP-39 seed phrase plus any passphrase, an MPC design's recovery factors, or a smart account's recovery rules) is what restores control of them.

Is your "wallet" actually a wallet? Custodial and self-custodial

Quick answer

The word covers both an account at a company that holds keys for you, and software or hardware that gives the keys to you. Establishing which you have is an early security question, because risk, responsibility and recovery all differ between the two.

The custodial version is what many beginners meet first: an exchange account with a wallet icon. Its keys sit with the platform; your access is a login; what you hold is an entitlement against the company whose exact nature depends on the account terms, the entity you contracted with and the law of its jurisdiction. The Exchange Failure Index examines how those entitlements fared in past exchange failures. The experience is familiar, password resets exist, and the trust is concentrated: the platform's solvency, honesty and security are the product.

The self-custodial version is the subject of most of this guide. In its simplest form, a single-key or seed-phrase wallet, the keys are generated on your device, known to no company and exercised by you alone. The trade arrives at setup, because full control and full responsibility come together: no provider can reset the access you lose, and no provider can move the funds without your keys. The custody guides, starting with Who Holds Your Crypto?, weigh the arrangements in depth, including multisig and threshold designs, which spread signing across several keys or parties and bring their own coordination and recovery questions.

Two limits on "no one else can touch it"

Self-custody controls the key, and control of the key is not the same as control of every asset behind it. Some tokens carry issuer controls that operate at the token contract regardless of who holds the key. Circle's USDC terms reserve the right to block the transfer of USDC to and from an address on chain, and state that Circle may be required to freeze USDC under a legal order from a valid government authority (Circle, USDC Terms, section 13, last updated 12 December 2025); Tether's terms of service likewise provide for freezing Tether tokens and blacklisting addresses that hold them (Tether, Terms of Service, sections 2 and 8, last updated 26 February 2026). A self-custodied balance of such a token can therefore be immobilised by the issuer even though the private key never left your device. Native coins such as bitcoin or ether have no such issuer. The guide to what a stablecoin is explains why these controls exist.

The second limit is the provider role in the newer designs. A wallet can be self-custodial in the sense that no company can spend from it, while a provider still holds one MPC share or is named as a recovery contact in a smart account. Such a provider is not meant to be able to move funds alone. Its co-operation, or its continued existence, may be needed for recovery or for signing at all. How such arrangements compare is a question the custody guides take up; here the point is that "self-custody" is a family of designs, and the right questions expose the differences.

The three questions that replace the old test

Beginners are often given a shortcut: if an email can reset your access, the company has the keys; if you wrote down a phrase and no reset exists, you have them. The shortcut fails in both directions. An MPC or smart-account wallet may offer email-linked recovery of one factor while no company can spend from the account, and a seed-phrase wallet is not the only form of self-custody. The questions that actually settle it are:

1. Who can authorise a transfer? A company alone, you alone, or some combination of devices, parties or contacts that must agree? 2. What combination of factors recovers access if a device is lost? A phrase and passphrase, a share plus a backup file, a set of trusted contacts, or an account login and identity check? 3. Can any provider act on the funds, or block their use, without you? Through account control, through a held key share, or through issuer controls on the tokens themselves?

Answer those three for any product and you know which of this academy's security programmes applies to you: account security for custodial holdings, key security for your own, and a mixture where a provider holds a share or a recovery role.

What do hot and cold actually mean?

Quick answer

Whether the keys touch an internet-connected device. Hot wallets (apps, extensions) keep keys where using them is instant and attacking them is remote-capable; cold wallets (hardware, offline storage) keep keys where signing requires the device, at the price of convenience. Each product can be placed somewhere on this line.

The distinction is about exposure rather than quality. A hot wallet's keys live on a phone or computer: malware, phishing and the attack classes catalogued in the guide to crypto scams and threats can reach toward them over the network, and the same connection is what makes possible the daily use described in the guide to dApps. A hardware wallet moves the keys into a dedicated device that signs internally; the computer receives signatures and, by design, not the keys, and the device's own display makes it possible to check what is being signed even on a compromised computer. The Wallet Vulnerability Ledger adds the caveat: hardware is code in a case, vendors have shipped flaws, and isolation limits what can reach the keys without removing risk.

The wallet security pillar describes a tiered arrangement that uses both temperatures, previewed here at definitional level: a hot wallet for amounts whose loss with a phone would be tolerable, a cold arrangement for the rest, and deliberate transfers between them, with the extra devices, backups and transfer steps that tiering brings. At the definitional level, the point is to know a wallet's temperature and what its exposure means for what it holds.

Two-axis map of wallet types: the custody axis separating custodial accounts where the company holds keys and access is a login from self-custodial wallets where the holder controls keys or key shares after setup, and the temperature axis separating hot wallets whose keys live on connected devices for instant use from cold arrangements whose keys are kept offline, with the three custody questions and a note describing a tiered arrangement that uses both temperatures, with deliberate transfers between them and the extra devices, backups and steps that brings
Figure 2. Two questions that place a wallet on the map: who holds the keys, and do the keys touch the internet. Each product answers both, and the answers shape which risks apply.

What does creating a wallet commit you to?

Quick answer

For self-custody: recovery material that must exist and survive (a seed phrase and any passphrase, or the recovery factors of an MPC or smart-account design), a phrase that is typed only into a restore you started, and the habits the security guides teach. The commitments begin at the setup screen, which is why this guide comes before the buying guide.

The setup step deserves attention at the definitional stage because several costly mistakes begin there. Whatever the wallet shows or asks you to save at creation is recovery material, and in a seed-phrase wallet it amounts to the whole wallet: a seed phrase gets written physically and backed up following the design in the guide to backing up a crypto wallet, and is kept out of cloud photo libraries; an MPC or smart-account wallet's recovery factors get recorded and tested according to that provider's documented process. Requests for a seed phrase afterwards have one legitimate form, a restore you initiated on a device you control. Any other request, from support chats to verification pop-ups, follows the scam pattern described in the guide to common crypto scams. Where a phrase has already been disclosed, the guide to responding if your crypto is hacked or stolen sets out the steps and reporting routes; reporting does not guarantee recovery, and the FBI warns that firms offering to recover stolen crypto for an upfront fee commonly take the fee and either stop responding or ask for more, and that private recovery companies cannot issue seizure orders (FBI IC3 PSA, 11 August 2023). And the wallet's first real transfer can be the drill from the guide to sending and receiving crypto in miniature: a test amount, verified end to end, before anything that matters moves.

The next steps from here: the buying guide, for how purchases and transfers into a wallet work; the seed phrase guide for why a single phrase concentrates risk; the custody guides for arrangements beyond one phrase on one device; and the wallet security pillar for daily practice. This guide's job ends where those begin: the coins located on the chain, the authority located in the keys, and three questions (whose keys, what recovery, what temperature) ready to ask of any wallet.

Frequently asked questions

Can I use the same crypto wallet on two devices?

The same keys can live in two places, restored from the same recovery material, and both will control the same funds, which demonstrates the principle: funds follow keys rather than devices. Each copy is also a full set of the keys, so every device carrying them needs the same protection. MPC designs differ: a second device may hold a share rather than the whole key, and adding it follows the provider's process.

What happens to my crypto if I delete my wallet app?

Nothing, provided your recovery material exists: the funds sit on the chain, and a restore regenerates the keys. For a BIP-39 wallet that means the words, any passphrase, and a compatible wallet using the same derivation paths (BIP-39 and BIP-32, bitcoin/bips). Without a backup, deletion is loss, which is the entire argument of the backup guide compressed into one sentence.

Do I need a different wallet for every cryptocurrency?

Wallets differ in which chains they support: some follow one network, others several. Assets live on specific chains, as the guide to how blockchains differ explains, so the practical question is whether your wallet supports the chain your asset is actually on.

Are crypto wallets free, and how do wallet companies make money?

Many self-custodial apps are free to download, and their makers may earn through swap fees, service integrations or hardware sales; custodial platforms typically earn from trading fees, spreads and other services set out in their terms. A fee charged inside a wallet app, for a swap for example, is usually shown before signing, which is one more reason to read the signing screen. What a legitimate wallet needs from you is approval of signatures. It has no need for you to send your phrase anywhere, and anything asking for it has answered your due-diligence question for you.

Can my crypto be frozen in a self-custody wallet?

It depends on the asset and on the arrangement. Native coins such as bitcoin and ether have no issuer and no freeze function, while some tokens, including USDC and USDT, are issued under terms that allow the issuer to block addresses or freeze tokens (Circle, USDC Terms, section 13; Tether, Terms of Service, section 8). That control operates on the token contract: it does not give the issuer your private key, and it leaves the other assets at the same address untouched. A custodial account is a different case, because the platform itself can restrict withdrawals under its account terms. Whether a given token carries such a control is a fact to check in its issuer's documentation.

Which crypto wallet is best for beginners?

This academy recommends no product, and no single design suits every holder. The method it describes applies to any product: answer the three custody questions, establish the wallet's temperature, look at the vendor's public record of flaws and fixes (the Vulnerability Ledger shows why), and rehearse the recovery with a test before relying on it.

Sources and further reading

Primary and reference sources for this guide, checked on 23 and 24 September 2026.

Quick quiz: did it stick?

A few questions to check the fundamentals landed. Answers with explanations follow, and nobody is grading you except your future portfolio.

1/5 question
Where are your coins, actually?

Was this helpful?