News recently emerged that virtual assets associated with Upbit had been affected by a security breach. Hopefully, the situation will be resolved without customers suffering significant losses.
According to Upbit's announcement, some assets held in a hot wallet were affected, while most customer assets remained secure in cold storage. But what exactly are hot wallets and cold wallets?
At first, these terms may sound like complicated cybersecurity jargon. Once you understand how they work, however, the distinction is relatively straightforward. This guide explains what hot and cold wallets are, why cryptocurrency exchanges use both, and why the difference matters whenever a security incident occurs.
What Is a Hot Wallet?
A hot wallet is a cryptocurrency wallet that is connected to the internet or to an online system.
Cryptocurrency exchanges need to let customers deposit and withdraw assets at almost any time. To make that possible, exchanges keep a certain amount of cryptocurrency in online wallets connected to automated transaction systems.
When you request a withdrawal and the transaction is processed almost immediately, the assets will often be sent from one of the exchange's hot wallets.
For individual users, common examples of hot wallets include:
- Mobile cryptocurrency wallet apps
- Desktop software wallets connected to the internet
- Browser-extension wallets such as MetaMask
- Wallets built into cryptocurrency exchanges
- Web-based wallets and decentralized application wallets
The defining characteristic is not the type of device being used. What matters is whether the wallet's signing environment or private keys are exposed to an internet-connected system.
Why Do Exchanges Use Hot Wallets?
The main advantages of a hot wallet are speed and convenience.
An exchange may need to process thousands of deposits and withdrawals every day. It would be impractical for an employee to manually approve and sign every transaction.
Hot wallets allow software to create, sign, and broadcast transactions automatically. This gives customers fast access to their assets and allows the exchange to operate around the clock.
However, the same connectivity that makes a hot wallet convenient also creates additional security risks.
If an attacker compromises a server, signing system, administrator account, API, or another connected service, they may be able to access private keys or obtain permission to authorize transactions. Once a malicious transaction has been signed and transmitted to the blockchain, the assets can be moved to an external address very quickly.
For this reason, well-designed exchanges generally try to keep only the liquidity required for normal withdrawals in hot wallets. The majority of customer assets are usually stored in more isolated systems.
What Is a Cold Wallet?
A cold wallet is a cryptocurrency wallet whose private keys are stored offline or kept isolated from internet-connected systems.
The purpose of cold storage is to prevent attackers on the internet from directly reaching the keys required to move the assets.
Examples of cold-storage methods include:
- Hardware wallets
- Dedicated offline computers
- Air-gapped signing devices
- Specialized institutional custody systems
- Multisignature or multiparty authorization systems with offline components
- Paper wallets, although these are now generally considered difficult to use safely
For an exchange, cold storage usually means keeping most customer assets in a highly restricted environment and transferring only the amount needed for routine operations into a hot wallet.
A cold wallet is therefore designed primarily for secure storage rather than frequent transactions.
Why Are Cold Wallets Considered Safer?
The main security advantage of a cold wallet is its separation from online systems.
Even if an exchange's website or operational servers are compromised, an attacker should not automatically gain access to private keys stored in a properly isolated cold-storage environment.
To move assets from cold storage, authorized personnel may need to follow several additional steps. These could include using a dedicated signing device, obtaining approval from multiple employees, verifying destination addresses, and physically accessing a secure location.
This makes unauthorized transfers significantly more difficult.
Cold storage is not completely immune to risk. A hardware device can be lost or stolen, recovery phrases can be exposed, employees can make mistakes, and internal access controls can fail. Supply-chain attacks and physical security breaches are also possible.
The key difference is that cold storage greatly reduces exposure to remote online attacks.
The Main Disadvantage of Cold Storage
Cold wallets are less convenient than hot wallets.
Assets stored in a cold environment cannot always be moved instantly. A transfer may require manual verification, multiple approvals, offline signing, and additional security checks.
This makes cold wallets unsuitable for processing every routine customer withdrawal in real time.
Exchanges therefore need to maintain a balance:
- Hot wallets provide the liquidity needed for fast deposits and withdrawals.
- Cold wallets protect assets that do not need to move frequently.
Security depends not only on using cold storage, but also on carefully controlling how assets are transferred between the two environments.
Hot Wallet vs. Cold Wallet at a Glance
| Category | Hot Wallet | Cold Wallet |
|---|---|---|
| Connectivity | Connected to an online system | Private keys remain offline or isolated |
| Main purpose | Frequent transactions and withdrawals | Secure long-term storage |
| Speed | Fast and convenient | Slower and more procedural |
| Automation | Commonly automated | Usually requires additional approval |
| Online attack exposure | Relatively higher | Significantly lower |
| Typical examples | Exchange wallets, mobile apps, browser wallets | Hardware wallets, air-gapped devices, institutional cold storage |
| Best suited for | Small amounts used regularly | Larger amounts held for longer periods |
Understanding Security Announcements After an Exchange Incident
Following a cryptocurrency exchange incident, reports often include a statement such as:
Some assets were transferred from a hot wallet, while most customer assets remained secure in cold storage.
This usually means that the affected area was part of the exchange's internet-connected operational environment. The offline or isolated storage used for longer-term custody was reportedly not affected.
However, that statement alone does not reveal the full seriousness of the incident.
Several additional questions need to be answered:
- Which wallets and cryptocurrencies were affected?
- How much was transferred?
- How did the attacker gain access?
- Were private keys exposed, or was a transaction system compromised?
- Were deposits and withdrawals suspended?
- Did the exchange move remaining assets to new wallets?
- Will the exchange reimburse affected customers?
- Has an independent security investigation confirmed the exchange's explanation?
The distinction between hot and cold storage is important, but it should be considered alongside the amount lost, the exchange's financial position, and the results of the investigation.
A Simple Bank Analogy
A useful way to understand the difference is to compare a cryptocurrency exchange with a bank.
A hot wallet is similar to the cash kept at bank counters or inside ATMs. Customers need access to that money, so a limited amount must remain readily available.
A cold wallet is more like a secure vault deep inside the bank. Accessing it takes more time and requires additional procedures, but it is much harder for an outside attacker to reach.
When an exchange says that only a hot wallet was affected, it is essentially saying that the incident reached part of its operational funds but did not reach the main reserve stored in the vault.
This does not make a hot-wallet breach unimportant. It simply helps explain which part of the custody system was affected.
What Does This Mean for Individual Investors?
The same distinction can help individuals decide how to store their cryptocurrency.
A small amount used for regular trading, payments, or decentralized applications may be kept in an exchange account or a convenient hot wallet. Assets intended for long-term storage are often better protected in a carefully managed hardware wallet or another cold-storage setup.
A basic approach might be:
- Keep only frequently used funds in a hot wallet.
- Move long-term holdings to a separate wallet.
- Protect recovery phrases offline.
- Never share private keys or recovery phrases.
- Verify wallet addresses before approving transactions.
- Use strong, unique passwords and multifactor authentication.
- Be cautious of phishing sites, fake wallet apps, and malicious browser extensions.
- Test with a small transaction before transferring a large amount.
Self-custody also comes with significant responsibility. If a recovery phrase is lost, damaged, or exposed, there may be no company capable of restoring the assets. Cold storage can reduce online risk, but only when it is set up and managed correctly.
Cold Storage Does Not Mean Zero Risk
It is tempting to think of cold wallets as completely safe, but no storage method eliminates every risk.
Cold-storage failures can result from:
- Lost recovery phrases
- Incorrect backups
- Physical theft
- Fire or water damage
- Insider threats
- Poor multisignature procedures
- Address-substitution attacks
- Compromised hardware or software
- Mistakes made during offline signing
Good cryptocurrency security therefore relies on multiple layers of protection. These include technical controls, physical security, access management, transaction monitoring, backup procedures, and clear incident-response plans.
For exchanges, one of the most important principles is limiting the amount stored in hot wallets. Even if an operational wallet is compromised, the potential loss should remain contained.
Final Thoughts
A hot wallet is an internet-connected wallet designed for convenience and frequent transactions. A cold wallet keeps private keys offline or isolated, making it more suitable for protecting assets that do not need to move regularly.
Hot wallets provide speed but have greater exposure to online attacks. Cold wallets reduce that exposure but require more time and effort when assets need to be transferred.
Whenever these terms appear in news about an exchange security incident, consider where the affected assets were stored, how much was exposed, and whether the exchange's main reserves remained protected.
Understanding the difference between hot and cold wallets makes it much easier to evaluate cryptocurrency security announcements and make more informed decisions about storing your own assets.
Thank you for reading, and stay safe!
This article is also available in Korean: Read the Korean version