Hardware vs software wallets
Every wallet is a way of using a private key. The real question is whether that key ever touches a device connected to the internet.

On this page
- What does a crypto wallet actually store?
- How do hardware, software and exchange wallets compare?
- How does a hardware wallet sign without exposing the key?
- When does a software wallet make sense?
- What can a hardware wallet not protect you from?
- What mistakes do beginners make when choosing a wallet?
- Questions readers ask
- Sources
- A wallet does not hold coins; it holds or uses the private keys that control them on the blockchain.
- A software wallet keeps keys on an internet-connected phone, computer or browser, which is convenient but exposed to malware and phishing.
- A hardware wallet keeps keys on a dedicated offline device that signs transactions without revealing the key.
- Neither type protects you if your seed phrase leaks or if you approve a malicious transaction yourself.
- Bitcoin.org suggests keeping only small amounts on everyday devices and using offline storage for savings.
A software wallet is an app that stores your private keys on an internet-connected phone, computer or browser. A hardware wallet is a dedicated device that keeps the keys offline and only sends out signed transactions. Software is more convenient; hardware cuts the key's exposure to online attacks.
What does a crypto wallet actually store?
Ethereum's official wallet page makes a point that clears up most confusion: a wallet is a tool that lets you interact with your account using your keys. Your coins and tokens are recorded on the blockchain itself. What the wallet guards is the private key, the secret that signs transactions, plus the seed phrase that can regenerate it.
So the difference between wallet types is not where your money is. It is where the signing key lives and how often it sits on a machine that is online. A key on a laptop that browses the web, opens email attachments and installs extensions faces far more threats than a key on a device that does nothing but sign.
Ethereum.org lists five broad kinds of wallet: physical hardware wallets, mobile apps, browser wallets, browser extensions and desktop apps. The last four are software wallets, often called hot wallets because the key lives on an internet-connected device.
How do hardware, software and exchange wallets compare?
Many people start with a third option: an account at a crypto exchange, where the company holds the keys for you. The table puts all three side by side.
| Software wallet (app or extension) | Hardware wallet | Exchange account (custodial) | |
|---|---|---|---|
| Who holds the key | You, on your phone, computer or browser | You, inside a dedicated device | The exchange |
| Key exposed to the internet? | Yes, whenever the device is online | No; ethereum.org says the key never touches the internet | Held on the company's systems |
| Main risks | Malware, malicious extensions, phishing, lost phone | Losing the device and the seed phrase, signing a bad transaction | Company failure, frozen withdrawals, account takeover |
| If you forget a password | Restore from your seed phrase | Restore from your seed phrase | Ordinary account recovery with the company |
| Everyday convenience | High | Lower: you need the device to sign | High |
Ethereum.org notes the trade-off with exchanges directly: you get a username and password you can recover in the usual way, but you are trusting the exchange with custody, and if it gets into financial trouble your funds are at risk. Before using one, check its licence with how to check if a platform is registered.

How does a hardware wallet sign without exposing the key?
The idea is older than hardware wallets themselves. Bitcoin.org describes offline signing with two computers: one that never goes online holds the keys and signs, while a second, online computer broadcasts the signed transaction. A hardware wallet packs the offline half into a small device built to do nothing else, which bitcoin.org calls the best balance between very high security and ease of use.
The signature proves you approved the transaction, but it does not contain the private key. So even if the computer that relays it is infected, the attacker gets a signed transaction for the exact amount and address you approved, not the key that would let them sign anything they like.
When does a software wallet make sense?
Software wallets are not a mistake. They are usually free, quick to set up and practical for small, frequent payments or for trying an app. The useful habit is to size what each wallet holds to the risk it faces. Bitcoin.org's guidance is to keep only small amounts on a computer or phone for everyday use and to keep savings offline.
Browser extensions deserve extra care. Ethereum.org warns that many extensions ask for permission to read and change site data, and that automatic updates can slip in malicious code. Install only from trusted sources and remove extensions you no longer use.
What can a hardware wallet not protect you from?
A hardware wallet guards the key. It cannot judge whether the transaction you approve is a good idea.
- A leaked seed phrase. The recovery words rebuild the key on any device. If someone has them, the hardware is irrelevant. See seed phrases explained.
- Approving a malicious contract. On Ethereum-style chains, an ERC-20 approval lets a contract withdraw your tokens later, up to the limit you set. If you sign one for a scam site, your device has done exactly what you asked. Our guide to token approvals and wallet drainers covers this.
- Sending to the wrong address. Blockchain transfers cannot be reversed. Ethereum.org's advice is to check that the destination matches the intended address exactly; address poisoning is built to defeat a quick glance.
What mistakes do beginners make when choosing a wallet?
- Treating the device as the backup. Devices get lost, broken or stolen. The seed phrase, written down and stored safely, is the backup.
- Using a device that someone else set up. Whoever saw the recovery words during setup can rebuild the wallet. Always generate a fresh phrase yourself.
- Typing the hardware wallet's seed phrase into a computer. Doing so copies the offline secret onto an online machine and undoes the point of the device.
- Keeping everything on an exchange by default. That can be a reasonable choice, but it is a different kind of risk, not no risk.
- Signing what you have not read. If the address or amount on screen is not what you expected, reject the request.
Questions readers ask
Is a hardware wallet the same as cold storage?
It is one form of it. Cold storage means keeping keys offline; a hardware wallet does that while still letting you sign transactions conveniently.
Do I still need a seed phrase with a hardware wallet?
Yes. The device protects the key while it works; the seed phrase is how you rebuild the wallet if the device is lost or fails.
Can a hardware wallet be hacked through my computer?
Malware on the computer cannot read a key that never leaves the device, but it can try to trick you into signing a bad transaction. Read what you approve.
Should I use more than one wallet?
Many people keep a small hot wallet for daily use and a separate offline wallet for savings, as bitcoin.org's guidance suggests. For larger amounts, multisig spreads control across several keys.
The choice is not hardware or software forever; it is how much to keep where. Online wallets suit small, frequent use; offline keys suit savings. Whichever you use, the seed phrase and your own signature remain the weak points, so protect the first and read before you give the second.
Sources
- ethereum.org, Ethereum wallets (2026)Primary source
- ethereum.org, Ethereum security and scam prevention (2026)Primary source
- bitcoin.org, Securing your walletPrimary source
- Bitcoin Improvement Proposals, BIP-39: Mnemonic code for generating deterministic keys (2013)Primary source
- Ethereum Improvement Proposals, ERC-20 Token Standard (EIP-20) (2015)Primary source
Educational content only — not financial, investment, legal or tax advice. Crypto-assets are high-risk and you could lose all the money you put in. Rules differ by country; check with your national regulator. See our risk disclosure and editorial policy.



