Hot Wallets
Learn hot wallets: how it works, practical trade-offs, security risks and operational considerations for crypto users.
Reading progress — saved on this device
A hot wallet is a wallet whose signing environment is connected to an internet-enabled device or is readily available for online transaction signing. Hot wallets prioritise accessibility and transaction speed, which makes them useful for active use but increases exposure to online threats.
Last reviewed: 20 August 2026
Quick navigation
Visual mapCore conceptCompareWorked exampleRiskMistakesCheckpointFAQSummaryVisual map
The diagram shows the simplified control flow. The critical question is always: who can authorise a valid transaction?
Core concept
1. What “hot” means
Hot describes the wallet’s exposure to an online environment, not whether it is custodial or self-custodial. A mobile self-custody wallet is hot, and an exchange-controlled hot wallet is custodial.
2. Convenience vs attack surface
Because signing is available on a connected device, hot wallets can interact quickly with exchanges, dApps and payment flows. The same connectivity broadens the attack surface.
3. Typical implementations
Browser extensions, mobile wallets, desktop wallets and some server-based institutional systems can all be hot-wallet environments.
4. Exposure management
Many users separate a smaller transactional balance from larger long-term holdings. The hot wallet becomes an operating wallet rather than the only storage location.
5. Security controls
Device encryption, OS updates, phishing resistance, transaction simulation, address verification and limited approvals can reduce but not eliminate risk.
Key trade-offs
| Dimension | What it means | Why it matters |
|---|---|---|
| Availability | Keys or signing capability are readily accessible online | Fast, convenient transactions |
| Threat surface | Internet-connected device or service | Higher exposure to malware, phishing and browser compromise |
| Best fit | Frequent transactions and dApp interaction | Useful where operational speed matters |
| Balance discipline | Often used with smaller operational balances | Limits impact if the wallet is compromised |
| Custody | Can be custodial or self-custodial | “Hot” and “custodial” describe different dimensions |
Worked example
A trader keeps a modest amount of USDC and ETH in a mobile self-custody wallet to interact with a DEX. The phone is internet-connected, so the wallet is hot. The trader keeps larger long-term holdings elsewhere and periodically replenishes the operating wallet. This does not eliminate risk, but it limits the amount exposed to the device and dApp environment.
Main risks
- Malware can target browser extensions, clipboard data, session tokens or transaction prompts.
- Phishing sites can imitate legitimate wallet interfaces or dApps.
- Compromised devices may expose keys or alter transaction details before signing.
- Unlimited token approvals can leave assets exposed after the original transaction.
- Convenience can encourage users to keep more value online than their threat model justifies.
Wallet risk is layered. A user can choose a technically strong wallet design and still lose assets through social engineering, malicious approvals, weak backups or sending funds over the wrong network.
Common misunderstandings
- A hot wallet is not necessarily a custodial wallet.
- A wallet can be password-protected and still be vulnerable if the device is compromised.
- Disconnecting a wallet from a website does not automatically revoke existing token approvals.
- Closing a browser does not make a browser wallet a cold wallet.
Checkpoint
Before moving meaningful value into any wallet, you should be able to answer:
- How much value is appropriate for an always-online signing environment?
- Is the device dedicated or shared with general browsing and email?
- Are recovery materials stored offline?
- Do I regularly review token approvals and connected applications?
- Can I distinguish a legitimate signing request from a malicious one?
FAQ
Is a mobile wallet a hot wallet?
Usually yes if it can sign transactions on an internet-connected phone.
Can a hot wallet be safe?
It can be secured well, but it inherently has greater online exposure than a signing setup kept offline.
Is MetaMask a hot wallet?
A browser-extension wallet is generally considered a hot wallet because its signing environment operates on an internet-connected computer.
Should all crypto be kept in a hot wallet?
That is a risk-management decision. Many users separate operational funds from longer-term holdings to limit exposure.
Summary
Hot wallets optimise accessibility and transaction speed by keeping signing capability close to an online environment. Their main trade-off is a larger digital attack surface, so balance limits and strong device and approval hygiene are important.
Want this in a personalised order?
Take the crypto assessment and get a custom path of 10 modules matched to what you already know. Free, no card required.
Build my path →