In this guide
- A crypto wallet manages access to funds
- Custodial and self-custody wallets divide responsibility differently
- Hot wallets and hardware wallets describe another difference
- A seed phrase is a recovery secret, not a login password
- Set up recovery before making a meaningful deposit
- Check the asset, network and recipient before sending
- Recognize scams before the signing screen
- If something goes wrong, identify the kind of failure
A crypto wallet manages access to funds
A crypto wallet lets you receive assets, check balances and authorize transactions. The cryptocurrency itself is recorded on its blockchain. What the wallet manages is access: the keys or other signing arrangements that let someone move those assets.
A receiving address can be shared with someone who needs to pay you. A private key must remain secret because it can authorize spending. Confusing these two pieces of information can turn a routine payment into a loss.
For a beginner, the first decision is who controls that authority. The second is how to recover access if a phone disappears or a device breaks. Only then does it make sense to compare the convenience of individual apps.
Custodial and self-custody wallets divide responsibility differently
With a custodial service, such as a centralized exchange account, the provider manages the private keys. You sign in and ask the service to send or withdraw funds. Account recovery may be available if you forget your password, subject to the provider's identity and security checks.
That convenience creates dependency. Withdrawals depend on the provider's systems and policies. A security incident, financial failure or restriction can affect access. Strong account security helps protect your login, but it does not remove the risk of the business holding your assets.
In a conventional self-custody wallet, you control the private keys and authorize transactions yourself. The wallet company supplies the interface; it does not ordinarily have the ability to reset your keys. Losing your device need not mean losing funds if you have a working recovery method. Losing every usable recovery method can be permanent.
Ask a direct question before funding either arrangement: if I lose access today, who can restore it, and what exactly will they need? Read the product's recovery documentation rather than assuming every product described as a wallet works identically.
Hot wallets and hardware wallets describe another difference
Custody describes who has control. Hot and cold storage describe how signing secrets are protected. A self-custody mobile app can be a hot wallet, while a custodian can keep some of its own keys offline.
A hot wallet operates on an internet-connected device. This makes frequent payments convenient, but the device and its software become part of the security boundary. Keep software updated and protect access to the phone or computer.
A hardware wallet is a dedicated signing device designed to keep private keys away from the connected computer. An app prepares a transaction, the device signs it after approval, and connected software broadcasts it. The hardware does not store coins inside a physical box.
Hardware changes the attack surface, not the consequences of an authorized mistake. If you approve a malicious transaction or disclose the recovery backup, the device cannot make that action safe. Separating routine activity from less frequently accessed funds can also reduce exposure. The Bitcoin profile explains the network behind a common use of this setup.
A seed phrase is a recovery secret, not a login password
Many wallets generate a recovery phrase, often called a seed phrase. Common formats use 12 or 24 words, but those are not universal lengths. Trezor's documentation, for example, also describes 20-word backups and arrangements requiring multiple backup shares.
The correct backup can restore the keys after a device is lost, damaged or reset. Compatibility matters: confirm that a replacement wallet supports the original backup format and the assets you use. Follow the wallet's own instructions for creating and checking the backup.
Write the words in their correct order and protect the record from theft, damage and accidental disposal. Do not photograph a phrase or put it into an ordinary cloud note. A copied recovery secret may let someone access the same accounts without your original device.
A device PIN or app password is a different layer. Changing it does not change the underlying recovery phrase. Some wallets also support an optional passphrase that creates a separate wallet when combined with the backup. Trezor warns that the exact passphrase is needed to reopen that wallet; a typo can reveal an empty, different wallet. Treat this as an advanced recovery responsibility, not a compulsory setup step.
Set up recovery before making a meaningful deposit
Obtain wallet software through the project's verified distribution channel. For hardware, use the manufacturer's setup instructions and generate your own new wallet. A device accompanied by an already completed recovery card is a reason to stop, not a shortcut.
Use the official backup-checking procedure, if available, before depending on the wallet. Do not erase your only working device simply to experiment with restoration. Know where the backup is, whether it remains readable and how you would obtain a compatible replacement.
Think about physical failure as well as hacking. A backup kept beside a device can be lost in the same incident. An inheritance plan also needs a way for an authorized person to find the necessary instructions without exposing the secrets during ordinary use.
Check the asset, network and recipient before sending
A token's name alone is not enough to identify a safe transfer route. Receiving platforms support particular assets on particular networks. The same ticker can appear on several chains, and a valid-looking address does not establish that the recipient supports your chosen route.
This distinction matters with assets such as Tether USDT. Check the receiving service's current deposit instructions instead of selecting a network solely because its withdrawal fee is lower.
- Open the recipient's receive or deposit screen. Select the intended asset and the exact supported network.
- Obtain the address from that screen. Include any required memo or destination tag, which may identify an individual customer behind a shared address.
- Match the sending network to the receiving network. Stop if either side does not offer the same route.
- Check the entire address against the trusted destination after pasting it. With hardware, verify the address and transaction details on the device's own display.
- Review the amount, transaction fee and any receiving minimum. Where practical, send a small test that meets the receiving requirements.
- Confirm that the recipient actually received and can access the test before sending the remainder. Recheck the details for the next transaction.
Keep the transaction identifier so you can inspect its status on the correct network's block explorer. A transfer broadcast to a blockchain and a deposit credited by an exchange are separate stages. An unsupported-network error may be unrecoverable; never assume support can undo it.
Recognize scams before the signing screen
A fake support agent may claim your wallet needs synchronization or validation, then ask for the recovery phrase. Do not disclose it. Legitimate support does not need your signing secrets to explain a problem. Only enter recovery information through a verified recovery process you deliberately initiated.
Phishing pages and advertisements can resemble familiar services. Reach important tools through independently verified addresses or bookmarks. Do not treat a convincing logo or a reassuring message as authentication.
Check what a wallet prompt actually authorizes. On networks with token approvals, a signature or transaction can grant an application permission to spend tokens. An unlimited allowance can expose more than the small amount you intended to use.
MetaMask distinguishes disconnecting an application from revoking its token allowance. Disconnecting alone does not cancel an existing spending approval. Review permissions and revoke unwanted allowances through a verified tool; on-chain revocations generally require a network fee.
If something goes wrong, identify the kind of failure
A lost device, a missing deposit and an exposed seed phrase require different responses. With a lost device, recovery depends on your backup. For a missing deposit, check the asset, network, transaction status and any required memo before contacting the receiving service.
If a recovery phrase has been disclosed, changing an app password is insufficient. Treat the signing authority as compromised and use official security guidance to move remaining assets to a newly secured wallet where possible. Revoking one token allowance does not repair a stolen private key.
Keep private information out of public support requests. Someone offering to recover funds after receiving an advance payment or your seed phrase may be continuing the original scam. Good wallet practice begins with understanding which information is public, which information authorizes spending and which recovery process you can actually carry out.