GLOSSARY · SECURITY

Hot Wallet

A hot wallet is any cryptocurrency wallet that is connected to the internet: browser extensions (MetaMask, Phantom), mobile apps (Trust Wallet, Coinbase Wallet), and exchange accounts. Hot wallets are convenient for frequent transactions but expose private keys to phishing, malware, drainer attacks, and exchange hacks. They should hold only funds you need for active use.

What Is a Hot Wallet?

The term "hot" simply means internet-connected. Any wallet where your private keys or seed phrase are stored on a device that connects to the internet is a hot wallet. This includes browser extension wallets like MetaMask, mobile apps like Trust Wallet, and custodial wallets on exchanges like Binance or Bybit where the exchange holds your keys on your behalf.

Hot wallets are the entry point for most crypto users. They are required for DeFi interaction — you cannot connect a cold wallet directly to Uniswap or Aave without bridging through a hot wallet interface. The internet connection that makes hot wallets useful is also what makes them vulnerable.

Examples of Hot Wallets

  • Browser extension wallets: MetaMask, Rabby, Phantom (Solana), Keplr (Cosmos)
  • Mobile wallets: Trust Wallet, Coinbase Wallet, Rainbow, Exodus
  • Exchange (custodial) wallets: Binance, Bybit, OKX, Kraken, Coinbase — here the exchange holds the private keys, not you
  • Web wallets: Any wallet accessible through a website without a local app

Exchange accounts are a special category: they are custodial hot wallets. You do not hold the private keys — the exchange does. This introduces a different risk profile than self-custodial hot wallets like MetaMask.

Risks Specific to Hot Wallets

Hot wallets face several attack vectors that cold wallets are immune to:

  • Phishing: Fake websites or browser extensions that capture your seed phrase or private key the moment you enter them.
  • Malware and infostealers: Programs like RedLine Stealer scan your file system and browser data for wallet files, seed phrases, and private keys. MetaMask stores an encrypted vault in your browser profile — infostealers can extract it.
  • Drainer contracts: Malicious smart contracts that empty your tokens via a phishing-induced approval signature. Hot wallets are the primary target because they are always connected.
  • Session hijacking: An attacker who gains access to your browser session or device can interact with your wallet without knowing your seed phrase.
  • Exchange hacks and freezes: With custodial exchange wallets, you are exposed to the exchange's own security failures, insolvency, or regulatory account freezes.

Hot Wallets vs. Cold Wallets

The core distinction is where the private key lives. In a hot wallet, the key is held in software on an internet-connected device — accessible to any attacker who can reach that device. In a cold wallet (hardware wallet like Ledger or Trezor), the key is generated and stored on a device that never connects to the internet and never transmits the key, only signed transactions.

Cold wallets are immune to remote attacks. Hot wallets are not. This does not make hot wallets useless — they are necessary for DeFi activity and small daily transactions — but it makes them unsuitable for storing significant holdings long-term.

Best Practices for Hot Wallet Users

If you use a hot wallet, reduce your risk with these measures:

  • Use a dedicated wallet for DeFi interactions, funded only with what you need for that session. Keep your main holdings in a separate address or cold wallet.
  • Install Rabby Wallet instead of MetaMask — Rabby shows a human-readable breakdown of what each transaction actually does before you sign.
  • Never enter your seed phrase on any website. No legitimate service ever asks for it.
  • Audit your token approvals monthly using revoke.cash and revoke any you no longer need.
  • For exchange accounts: enable 2FA with an authenticator app (not SMS), use a withdrawal whitelist, and keep only active trading funds on exchange.
  • Move any amount above your "risk tolerance" threshold to a hardware wallet.

Frequently Asked Questions

What are examples of hot wallets?

MetaMask, Trust Wallet, Coinbase Wallet, Phantom (Solana), and any exchange-linked wallet (Binance, Bybit, OKX). All are internet-connected and thus 'hot'. Exchange accounts are technically custodial hot wallets — you don't hold the private keys.

Is a hot wallet safe?

Safe for small amounts used frequently. Not recommended for long-term storage of significant holdings. The convenience-security trade-off: hot wallets are instantly accessible, but any malware, phishing site, or drainer can steal funds without you noticing until it's done.

What is the main difference between a hot wallet and a cold wallet?

A cold wallet stores private keys on a device never connected to the internet (Ledger, Trezor). A hot wallet's keys are in software on an internet-connected device. Cold wallets are immune to remote attacks; hot wallets are not.

Should I keep crypto on an exchange (hot wallet)?

Only what you actively trade. Exchange accounts are custodial hot wallets — you don't hold your keys. Exchange hacks, account freezes, and insolvencies are real risks. The industry phrase is 'not your keys, not your coins.'

How much crypto is safe to keep in a hot wallet?

There is no universal rule, but a common guideline is to keep in hot wallets only what you plan to spend or trade within the next 30 days. Everything else belongs in a cold wallet or hardware wallet.

Related Terms

Useful Resources