Crypto Wallets Explained: Private Keys, Seed Phrases and Custody
The decisive question in choosing a wallet is not the brand; it is who can sign and who can recover access after an incident. Self-custody puts loss prevention and signing security on the user. Third-party custody adds dependence on the provider’s controls, withdrawal process and insolvency terms. This guide separates private keys, public keys, addresses and seed phrases, compares hot/cold and self/third-party custody as two axes, and builds a backup, inheritance and recovery drill.
Who this guide is for: People creating a first wallet, moving beyond exchange custody or reviewing an existing recovery process
Key points to understand first
- A wallet handles keys and addresses that control ledger entries; it does not literally contain the asset.
- Giving another person a private key or complete seed phrase generally gives away transfer authority.
- Hot versus cold describes connectivity; self versus third-party custody describes who controls keys.
- A backup is not complete until recovery has been verified in an isolated environment.
Check signing, recovery and dependencies—not just the balance
- 01Key controller
Who can sign alone or jointly?
Terms, device configuration, signing screen - 02Authentic source
Was the official domain and publisher verified?
Official site, signature, app publisher - 03Backup
Is the seed or key stored offline and separately?
Inventory, seal and location check - 04Recovery drill
Did a clean device derive the same address?
Test date, device and matching address - 05Transfer controls
Are test sends, allowlists or delays available?
Settings and test transaction hash - 06Succession plan
Can an authorized person discover the process?
Instruction, contact and review date
A wallet is fundamentally a signing authority, not a balance display
A crypto wallet manages private keys used to sign transactions and public keys or addresses used to identify accounts or destinations. Assets remain recorded on the network ledger rather than being physically placed inside an app or device. Deleting an app does not destroy the asset if a correct key or seed can restore access. Conversely, a visible balance cannot be moved if the required signing material is lost.
In self-custody, the user directly controls keys. In third-party custody, an exchange or custodian controls keys while the user requests withdrawals under a contract. A slogan cannot decide which is safer for a particular person. Self-custody reduces provider dependence but concentrates loss, succession and operating risk on the user. Third-party custody can provide account recovery but adds withdrawal, breach, insolvency and terms risk.
| Method | Key control | Potential benefit | Main failure paths |
|---|---|---|---|
| Self-custody hot wallet | User; online device | Convenient for regular use | Malware, phishing, device compromise |
| Self-custody cold wallet | User; isolated device or process | Reduces online attack surface | Loss, counterfeit device, failed backup |
| Third-party custody | Provider | Account recovery and integrated trading | Withdrawal freeze, insolvency, insider abuse |
| Shared control | Multiple keys or parties | Can reduce single-point failure | Coordination failure, bad setup, lost signers |
Cold storage and self-custody are not synonyms; a third-party custodian can also use cold storage.
Separate private keys, public keys, addresses and seeds
A private key is a secret value used to make a signature. A public key is used to verify that signature, and an address is usually a destination representation derived from a public key or script. Systems are designed so that deriving a public key from a private key is practical while reversing the process is not. Anyone who obtains the signing key may be able to move the asset. A support representative, accountant or executor does not need the live secret merely to inspect records.
A seed phrase or mnemonic is commonly an entry point that deterministically recreates many keys. The same seed can show unexpected addresses when the derivation path, optional passphrase, network or wallet implementation differs. An extra passphrase can increase separation but makes recovery impossible if forgotten. Record the recovery standard and configuration—not just the statement that a seed exists.
Private key → creates a transaction signaturePublic key/address → verifies authority or identifies a destinationSeed phrase + derivation settings (+ passphrase) → regenerates multiple private keysDerivation and address formats vary across implementations and networks.Plan for disclosure, destruction and undiscoverability at the same time
Hiding a key is not enough. Storage must address confidentiality, integrity and availability: unauthorized people cannot read it, substitutions can be detected, and an authorized person can retrieve it when needed. One paper copy in one building creates a single point of failure for fire, flood, theft and accidental disposal. Photos, cloud notes and email drafts are easy to duplicate but expand the online attack surface. A split backup requires a clear understanding of how many pieces are needed and what each piece reveals.
Phishing manufactures urgency: “enter your seed,” “synchronize your wallet,” or “claim this airdrop.” Common routes include lookalike domains, search ads, counterfeit apps, tampered hardware and remote-access requests. Open known services from saved official links, read what is being signed, confirm the destination on an independent device display, and remove unnecessary token allowances. A message signature can also authorize harmful actions even when no obvious transfer screen appears.
Separate medium, location and discovery instructions
A backup inventory can record creation date, supported network, address prefix and suffix, backup method, coded location, whether a passphrase exists, last recovery test and retirement date. Keep the secret separate from the inventory that explains where it is. A metal backup can improve resistance to fire and water without preventing theft or photography. An encrypted drive adds dependence on a password and compatible decryption software. List at least two failure modes for each medium.
For succession and emergencies, do not place the asset amount, seed and complete instructions in one document. An authorized person should be able to discover that something exists, whom to contact, what event activates the process and which separate materials must be combined. Wills, beneficiaries, tax and multisignature enforceability vary by jurisdiction. Technical ability to recover an asset is not automatically legal authority to transfer it.
- Medium: Test paper, metal and encrypted storage against fire, water, theft and decay.
- Location: Avoid one building or disaster zone and keep an access log.
- Discovery: Explain existence and process without exposing the secret.
- Change control: Retire old instructions after wallet, passphrase or signer changes.
Restore on a clean second environment before funding the wallet
A recovery drill does not require destroying a production wallet. Create a new empty test wallet, make its backup, restore it on another clean device or isolated environment, and confirm that the same receiving address is derived. Remove the temporary environment safely afterward and ensure that screen recordings, clipboard history or cloud synchronization did not retain the secret. With hardware wallets, use the vendor’s official process, authentic firmware and the device display for destination confirmation.
After restoration, complete a tiny receive-send cycle and reconcile the balance and history. Follow the address, confirmation and explorer workflow. A periodic check should cover media readability, signer contacts, device compatibility, firmware and the location of recovery instructions. Never use a website that asks you to type a seed merely to “check” it.
- Create an empty test wallet
Separate it from production assets and record the official source and device state.
- Make the backup
Avoid cameras, cloud sync, clipboard history and observers.
- Restore elsewhere
Confirm network, derived address and expected empty balance.
- Send a tiny amount
Record the receive, send, transaction hash and fee.
- Log the result
Record success or failure and the next review date—not the secret.
Allocate control by purpose instead of putting everything in one method
Regular spending, long-term holdings, DeFi interaction, business funds and shared custody require different balances of access and control. Putting everything in a frequently connected hot wallet concentrates the signing attack surface. Connecting a long-term wallet to unknown applications cancels much of the intended isolation. Separate wallets by purpose and consider transfer limits, allowlists, multiple signatures, delays and watch-only monitoring.
When using a third party, apply the exchange and custody due-diligence checklist to the legal entity, registration, client assets, key management, insurance scope, outsourcing, withdrawal terms and succession process. When moving to self-custody, do not transfer everything at once: run a small transaction on the correct network and verify it in both the explorer and recipient wallet.
The Financial Templates Hub can hold a wallet identifier, purpose, non-secret location code, recovery-test date, signers and next review date. Never enter a private key, seed phrase or sensitive personal data. The template records operations around the secret, not the secret itself.
Frequently asked questions
Are crypto assets stored inside a wallet?
Strictly speaking, the balance is recorded on a blockchain or similar ledger. The wallet manages the keys and addresses that authorize transfers of that balance.
Is a seed phrase the same as a private key?
No. A seed phrase commonly regenerates many private keys deterministically. An optional passphrase and derivation settings may also be required.
Is a hardware wallet completely safe?
No method is absolute. Authentic sourcing, destination checks, backups, firmware hygiene and phishing resistance remain necessary, and loss or malicious signing can still occur.
Should a seed phrase be stored in the cloud?
Online storage generally expands the attack surface. Build a threat model and consider offline storage distributed against both disaster and theft.
Primary sources and verification links
- Investor.gov | Crypto Asset Custody Basics for Retail InvestorsRetail guide to self-custody, third-party custody, hot/cold wallets and private keys
- ethereum.org | Ethereum accountsExternally owned accounts, contract accounts, keys and signing
- NISTIR 8202 | Blockchain Technology OverviewTechnical overview of distributed ledgers, hashes, consensus, keys and forks
- Japan FSA | List of Registered Crypto-asset Exchange Service ProvidersOfficial entry point for Japan’s list of registered crypto-asset exchange service providers
- Investor.gov | Crypto Asset Scam Warning SignsWarning signs involving social media, fake sites, added-fee demands and pump-and-dump schemes
Edited and published by: SG Group · Editorial approach: We prioritize primary materials from central banks, regulators and international institutions. Rules, product terms and release times can change, so verify current information at the linked source and with your provider before acting.
Important notice: This article is general education about crypto assets, blockchains, wallets and related services. It is not investment, legal or tax advice; a recommendation of any token, exchange, wallet or protocol; a trading signal; a price forecast; or a guarantee of profit or principal. Crypto assets can lose some or all value through volatility, lost keys, mistaken transfers, fraud, smart-contract failure, depegging, illiquidity, provider insolvency, or regulatory and tax changes. Figures are fictional learning examples unless expressly identified otherwise. Before use, verify the network, contract address, fees, registration or regulatory status, terms and tax treatment with primary sources and qualified professionals.

