First published 6 March 2019; rewritten August 2026. The old page was Bitcoin-only and a bit vault-shaped. The idea is broader: keep the keys that can spend off the daily-driver computer.
Hot versus cold
Hot means the keys live on a machine that also browses the web. Convenient, and in the blast radius of malware. Cold means signing happens on a device or paper that is not that machine. A hardware wallet is the usual middle path: keys stay in the device, the laptop proposes a transaction, you confirm on a small screen.
Paper is not magic
Writing words on paper is cold in the network sense and fragile in the house-fire sense. Steel plates exist because paper fails in boring ways. Anyone who can see the paper can spend. A photo of the paper is hot storage with extra steps.
What cold storage does not do
It does not protect you from sending to the wrong address. It does not protect a phrase you already typed into a fake site. It does not make a token “safer” because the logo is a vault. It also does not help if you never test a restore.
If the amount would change your year, read the hardware-wallet review and the safety checklist. Information only — not a recommendation to self-custody more than you can practise.






