Skip to content
Independent crypto magazine Updated Publish with us
MustangCoinCrypto explained, without the hype

Explainers for people who hold keys, pay fees and read the fine print.

Security

Cold Storage Explained

Hardware wallets keep private keys offline and confirm transactions on the device, but the backup and recovery process that matters, not just the device.

Published Reading time 4 minDesk MustangCoin editorial

Magdeburg Stahlkammer
Photo: Rudolf Hatzold / Wikimedia Commons, Public domain
Contents 4 sections
  1. What the device actually protects
  2. Recovery phrases and passphrases
  3. Multiple signers for more protection
  4. How backups fail

Cold storage is considered the safest way to hold crypto because it means the private key never touches an internet-connected device.

They do this by using the hardware wallet's screen to walk you through confirming the details of the transaction - the recipient address and the amount - and requiring your approval of those details on that screen. It's that in-device screen that makes the difference, because it is a line of defense that even malware cannot beat. Without this screen, malware could change the transaction details on the computer screen as part of an attack. So the big claim is true as far as it goes: your private key is kept offline.

If the backup isn't secure, or the recovery process breaks down, then any security benefit from keeping the key offline is wasted.

What the device actually protects

So what does a hardware wallet actually guard against? It stops your key from ever touching a computer where it might be at risk, and forces the important transaction sign-off onto that device. Those are real benefits, but not the full story.

A hardware wallet doesn't automatically recover from a dropped device or a lost key. It doesn't stop a lightning strike from blowing up the tablet next to you. It doesn't eliminate the problems of a shared household, or mixing business with pleasure in the wallet you share with your partner.

A hardware wallet physically locks the private key - that is, it hides the key from malicious software by showing a human the control at the right moment. This is useful in fakes and scams, because anyone looking at the right moment can choose to click pad or key.

Recovery phrases and passphrases

The key to recovering from a lost or damaged hardware wallet is the recovery phrase - or seed phrase - that is created when you set up the wallet. Each device generates a seed phrase "on-device" - never on the computer, never shared with a server, and only displayed on the hardware wallet itself.

The importance of that recovered seed can't be overstated - it allows you to restore your private key to a new hardware wallet, without needing to find the original device. But with that power comes the responsibility of keeping the seed phrase secure.

The recommended approach is to write down the seed phrase in a secure, offline location that is separate from the device itself.

If you take a photo of the seed phrase, put it in a cloud note, or type it into a website, it is no longer cold, like your private key is cold. Any of those is an online copy, open to the same scanning and access problems as any other unsecured data.

One particularly tricky aspect of seed phrases are optional passphrases that are not stored on the device or in the seed, but can create a separate derived wallet. This passphrase is known as the 25th word. If you forget a passphrase, you can't recover the associated wallets, which is one of the drawbacks.

Multiple signers for more protection

The problem with a hardware wallet is that it's a single point of compromise - if you lose the device, have it stolen, or lose the seed phrase, the funds are at risk.

Multisignature makes this better by requiring more than one key to authorize spending. A common example, a 2-of-3 multisignature setup, means that you put separate keys in separate locations, such as home, a safety-deposit box, and a friend's house, and it takes 2 of the 3 to authorize a transaction.

This means you could lose one key and still be in business. It slows down transactions by requiring that two people step up to authorize them - which is a disadvantage. And it isn't a complete solution, because all the multisignature keys need to be kept secure through the same backup and recovery process.

How backups fail

The key problem is that a hardware wallet doesn't eliminate headline risks like a lightning strike or a sharehouse fire. Without proper paperwork, arrangements or backups, loss, theft or a bad recovery setup can still hit the wallet.

Second-hand devices in particular are a standing risk, because users who fail to go through the full hardware wallet setup, issuing a new seed, can end up holding a wallet that is vulnerable to anyone who has access to the previous owner's seed.

Older hardware-wallet owners have the chilling experience of telling security experts that the best thing to do with a second-hand wallet is to throw it in the trash. This is why manufacturers urge users to take control - and choose "restore" as the default. If they find a seedphrase already preloaded, they should refuse to buy the device and walk away.

There are a few more important safety tips that apply to homes, safes, and computers for key holders - don't keep wallets unprotected, don't share them with strangers. And write down notes, reminders and passwords, in case the secret sharer forgets something. But make sure they're in the same secure storage.

The hardware wallet hype tells you that it's the physical device - the safe, offline thing you touch - that holds your money. It's the device per se that's safe. A hardware wallet carries the seed - and displays it on your screen. A seed is the same: you are responsible for writing it down, storing it, sending it, keeping it in trust.

Ultimately, cold storage is not about the device, but the arrangement of recovery - if the backup gets lost, compromised, or hidden behind an unrecoverable passphrase, then cold storage fails.