Back to Learn
2026-10-0615 min readWallets and Security

What Is a Crypto Wallet? Keys, Seed Phrases, Custody, and Signing

C
CryptosEyes Research

Research Desk · Sources cited in guide

Short answer: A crypto wallet does not hold coins. Coins and tokens live on the blockchain as ledger entries. A wallet holds the private keys that prove control of an address and uses them to sign transactions. Whoever holds the keys controls the funds at that address, and there is no central operator who can reverse a signed transaction or reset a lost key. A recovery phrase (a seed phrase) is a human-readable backup of the master secret from which a modern wallet derives all of its keys and addresses, so the phrase is the whole wallet in 12 to 24 words.

A wallet is a key manager, not a container

The name misleads. A physical wallet holds cash; remove the cash and the wallet is empty. A crypto wallet works differently. Your balance is a set of entries on a public ledger, recorded against addresses. The wallet stores the cryptographic secrets that let you move those entries, displays the balance the chain reports for your addresses, and builds and signs transactions. Ethereum's wallet documentation puts it plainly: wallets give you control over your account, wallet providers do not have custody of your funds, and you can swap wallet providers at any time because the account lives on the chain, not inside the app. If the app disappeared tomorrow, the same recovery phrase in different software would rebuild the same addresses and the same access. What you own, in operational terms, is a secret. Everything else is an interface.

This is why the same person can check a balance in three apps at once. Each app reads the same public ledger. Only the device holding the private keys can authorize a spend. Watching an address is free and public; spending from it requires the key.

For the ledger side of this picture, see how a blockchain works. For the networks whose addresses wallets manage, see layer 1 vs layer 2 and the markets page.

The key pair: one secret, one shareable half

Every account starts with a key pair: a private key and a public key, mathematically linked so that one can prove knowledge of the other without revealing it.

The private key is a secret number. It signs transactions and messages. A valid signature tells every node on the network: the holder of this address authorized this exact action. There is no separate password check and no fraud department. The signature is the authorization.

The public key is derived from the private key and can be shared. Network addresses are derived from the public key. You hand out an address the way you hand out an email address: anyone can send to it, and only the key holder can spend from it.

Three consequences follow, and they explain most wallet losses people describe as hacks.

First, knowledge is control. Anyone who learns a private key or the recovery phrase behind it can spend the funds, from anywhere, and the network will treat that spend as fully valid, because it is.

Second, addresses are public by design. Balances and transaction history at an address are visible to anyone. Pseudonymous is not private.

Third, transactions cannot be reversed by the network. Once a signed transaction is accepted and confirmed, the ledger keeps it. A mistaken or tricked signature is a valid signature with results the signer did not want. Prevention is the only remedy the protocol offers.

The recovery phrase: how 12 to 24 words rebuild a wallet

Typing raw keys is error-prone, so modern wallets generate one master secret and show it as a recovery phrase. The governing standard is BIP39, titled "Mnemonic code for generating deterministic keys," deployed in 2013 and used across Bitcoin and Ethereum wallet software.

The mechanics, from the specification:

1.The wallet generates random entropy of 128 to 256 bits. More entropy means a longer phrase.
2.A short checksum is taken from the SHA-256 hash of that entropy and appended to it. The checksum lets software catch most transcription mistakes when you re-enter the words.
3.The combined bits are split into groups of 11 bits. Each group is a number from 0 to 2047 that selects one word from a fixed 2048-word list. The first four letters of each word are enough to identify it uniquely, which is why hardware devices let you enter a phrase by its first letters.
4.To turn the phrase into keys, the software runs PBKDF2 with 2048 iterations of HMAC-SHA512 over the phrase, producing a 512-bit seed. That seed feeds deterministic derivation (BIP32 and its follow-ups), generating a tree of key pairs and addresses from the single backup.
Initial entropy (bits)Checksum (bits)Phrase length (words)Common use
128412The default in most software wallets
160515Less common
192618Some hardware wallets
224721Rare
256824The default in many hardware wallets

Because the phrase deterministically regenerates every derived address, one written backup covers all accounts the wallet creates later, including change addresses you never saw. Bitcoin.org makes the same point from the backup side: most modern wallets are deterministic, so a single backup of the recovery phrase restores all past and future addresses. It also warns that older backups can miss keys a nondeterministic wallet created later, which is why the backup standard to check is the phrase, not a file.

The optional passphrase changes the wallet

BIP39 allows an extra user passphrase on top of the phrase. The passphrase is mixed into the seed derivation, so the same 12 or 24 words plus a different passphrase produce a completely different wallet. Every passphrase yields a valid wallet; only the right one shows the funds you expect. This is a real feature with a hard edge: if you use a passphrase and forget it, the phrase alone will open an empty or different wallet and the original is unreachable. Treat the passphrase as a second secret that deserves the same written backup discipline, stored separately from the phrase itself.

Custodial vs self-custody: who holds the keys

When you leave assets on an exchange, the exchange holds the keys and operates an internal ledger of who is owed what. You hold an account claim, protected by a password and whatever recovery process the company runs. Bitcoin.org's security guidance is direct about the trade: when a third party controls your keys, you rely entirely on their security, and exchanges and online wallets have been hacked, failed, or frozen access in the past. A custodial account is convenient and recoverable, and it is also a counterparty exposure. If the custodian stops honoring withdrawals, the chain does not know your name.

In self-custody, you or your device holds the keys. No company can freeze the address, and no company can restore it either. Forgotten credentials for Bitcoin have, in Bitcoin.org's words, very limited recovery options compared with a bank: if the password and backups are gone, the funds stay at the address permanently, visible to all and spendable by none.

Neither model is the correct one in the abstract. The real question is which failure you are better equipped to prevent: a company failing or being breached, or you losing a piece of paper. The custody decision table below makes the trade explicit.

QuestionCustodial (exchange holds keys)Self-custody (you hold keys)
Who can move the funds?The company, under your account instructionsAnyone with the key or phrase; in practice, you
If credentials are lostPassword reset and identity checks are possibleNo reset. The phrase backup is the only recovery path
If the operator fails or is hackedYour claim is exposed to their balance sheet and securityYour funds are unaffected by any company's failure
If your device is lostLog in from another deviceRestore from the written phrase on a new device
If your backup is stolenAccount security depends on passwords and two-factor settingsThe thief can take everything; see the loss table below
Best suited toSmall, active balances and simple accessStored value you are prepared to back up carefully

A common split follows Bitcoin.org's everyday-cash analogy: keep only small amounts on a computer or phone for everyday use, the way you would not carry a large sum in a pocket wallet, and keep the rest in a safer environment.

Hot, cold, and hardware wallets

A hot wallet keeps keys on an internet-connected device: a phone app, a browser extension, a desktop program. It is the most convenient way to sign and the most exposed, because the device that holds the secret also runs email, browsers, and everything else that can be attacked.

A cold wallet keeps keys on a device or medium that is not connected to the network. Bitcoin.org describes the offline approach as the highest level of security for savings, including offline transaction signing: an online computer builds an unsigned transaction, an offline machine signs it, and the online machine broadcasts the result. The network-facing computer never holds a key, so a compromise there cannot forge a signature.

A hardware wallet is the packaged form of cold storage: a small device built from the ground up to be a wallet and nothing else. Keys are generated and stored on the device and signatures are produced inside it, so the private key is never typed into or stored on the general-purpose computer. Bitcoin.org calls hardware wallets the best balance between very high security and ease of use, and notes that a backup lets you recover funds if the device itself is lost. The device reduces one class of risk (malware reading keys off your computer) and concentrates another (the physical backup of the phrase becomes the master copy of your money).

Whichever form you use, the software version matters. Bitcoin.org's guidance to keep wallet software up to date applies across chains: updates carry stability and security fixes, and the same applies to the operating system underneath.

Multisig: splitting control across keys

A multisignature setup requires approvals from several independent keys before funds can move. Bitcoin includes this feature natively: a transaction can be set to require, for example, 3 of 5 designated signers. Bitcoin.org describes organizations giving members treasury access where a withdrawal needs three of five signatures, and individuals using multisig so that stealing one device or one location is not enough to steal the funds.

Multisig trades simplicity for resilience. It tolerates the loss or compromise of individual keys up to the threshold, which makes it the standard pattern for shared treasuries and larger holdings. It also raises the backup burden: every signer key needs its own backup, and losing more keys than the threshold allows locks the funds as surely as losing a single key would. On smart-contract networks, the same idea is usually implemented as a contract account that checks several owner signatures before executing, rather than as a native address feature.

Signing is the moment of risk

Most wallet losses do not start with someone guessing a key. They start with a signature the owner was talked into making. A signature authorizes exactly what the software asks the key to approve: a transfer, or on smart-contract chains, an approval that lets a contract move a token on your behalf. Approvals can be broad, they persist until revoked, and they are granted to contract addresses that most people cannot read.

The working habits that follow from how signing works:

Read the device screen, not just the computer screen. Where a hardware device shows the destination and amount, that display is generated from the transaction the device is about to sign. If the two disagree, stop.
Treat every signature request as a spend. A message that asks you to sign to prove ownership, claim an allocation, or verify a wallet is still a signature from your key. If you cannot tell what it authorizes, do not sign it.
Keep approvals narrow and temporary. Prefer limited amounts over unlimited approvals where the app offers the choice, and revoke approvals you no longer use. An old unlimited approval is a standing instruction your key already signed.
Separate the money. A hot wallet that interacts with new contracts should hold only what that activity needs. The address that signs experiments should not be the address that stores savings. Address separation costs nothing and contains the damage any single bad signature can do.

This is educational material on how wallets work, not financial advice, and it is not a recommendation to buy, hold, or move any asset.

Backup and loss scenarios

Backups fail in predictable ways. Bitcoin.org's guidance covers the main ones: back up the entire wallet secret rather than individual visible keys, encrypt any backup that touches a network because online backups are highly vulnerable to theft, use more than one secure location because a single point of failure is bad security, and remember that a forgotten password with no recovery path means permanently lost funds. It also raises the inheritance case: if nobody knows where your wallet and passwords are when you are gone, there is no way for your family to recover the funds.

If this happensWith a written phrase backupWithout one
Phone or computer is lost or brokenRestore the same addresses on a new deviceFunds are stranded at addresses nobody can sign for
Wallet app is deleted or the company closesImport the phrase into other wallet softwareSame stranding, unless the keys were exported elsewhere
Hardware device is lostRestore from the phrase onto a replacement deviceThe device was the only key copy; funds are unreachable
PIN or wallet password is forgottenThe password locks the app, not the keys; restore from the phraseIf there is also no phrase, no reset exists
Phrase is photographed or stored in cloud notesAnyone who reaches the photo or note controls the walletSame exposure; storage method is the vulnerability
Phrase is destroyed in a fire or floodOnly survives if a second copy exists in another locationTotal loss; the chain keeps the balance and no one can move it

A minimum backup checklist

1.Write the phrase by hand, in order, and check it against the device word by word before moving any funds you care about.
2.Store at least two copies in separate physical locations, so one fire or theft cannot take both.
3.Never type the phrase into a website, a form, a chat, or a support ticket. No legitimate service needs it; anyone asking for it is asking for the wallet itself.
4.Do not photograph the phrase or keep it in synced notes or email. A picture in a cloud library is an online backup with no encryption.
5.If you use a BIP39 passphrase, write it down separately from the phrase and record which wallet it belongs to. An unrecorded passphrase turns a good backup into an empty wallet.
6.Test recovery once, with the wallet empty or holding a trivial amount, by restoring into a second app or device. A backup you have never tested is a hope, not a backup.
7.Decide who should know where the backups are if something happens to you, and record that while keeping the phrase itself out of casual reach.

Frequently Asked Questions

Does a wallet store my coins?

No. Balances are entries on the blockchain, recorded at addresses. The wallet stores the private keys that control those addresses, shows you the balance the chain reports, and signs transactions. Delete the app and the funds stay exactly where they were; restore the phrase and the same access comes back.

What is the difference between a private key, a public key, and an address?

The private key is the secret that signs. The public key is derived from it and can be shared. The address is derived from the public key and is what you give out to receive funds. Sharing an address is safe; sharing a private key gives away control of everything at that address.

Why do wallets show 12 or 24 words instead of a key?

Because words are harder for people to copy wrong than a long string of numbers. Under BIP39, the wallet encodes 128 to 256 bits of randomness as 12 to 24 words from a fixed 2048-word list, with a built-in checksum that catches most copying errors. From those words the software derives the seed and then every key and address the wallet will use.

What happens if I forget my wallet password?

It depends on the wallet. A password usually locks the app or device, not the keys themselves, so restoring from the recovery phrase sets a new password and recovers access. If you have also lost the phrase, there is no reset process: the network has no record of who you are, only of which key signs.

What does the optional passphrase do?

It changes the wallet. BIP39 mixes the passphrase into the seed, so the same phrase with a different passphrase opens a different, valid wallet with different addresses. It can protect a phrase that is found, but a forgotten passphrase makes the intended wallet unreachable even with a perfect phrase backup.

Is a hardware wallet safe if I lose the device?

The funds are safe if your phrase backup is safe. The device is one copy of the keys; the phrase regenerates them on a replacement device. Anyone considering the device itself should still treat a found device as sensitive, and a slow PIN retry limit is a device feature to confirm in the maker's own documentation rather than an assumption.

Can I use the same recovery phrase in different wallet apps?

Usually yes. BIP39 phrases and the standard derivation methods are implemented across many wallets, which is the point of the standard. Compatibility is not guaranteed for every coin, account layout, or newer derivation path, so a small test restore is worth doing before you rely on a second app as your backup plan.

Why is multisig safer, and what does it cost?

A multisig address needs several independent keys to agree before funds move, so one stolen device or one phished signer cannot empty it. The cost is operational: more keys to back up, more signers to coordinate, and a hard lock if too many keys are lost. It fits shared or larger holdings better than everyday spending.

Sources

Bitcoin.org, Securing your wallet: custody trade-offs, backup rules, offline signing, and multisig. https://bitcoin.org/en/secure-your-wallet
BIP39, Mnemonic code for generating deterministic keys (bitcoin/bips): entropy sizes, checksum, the 2048-word list, and PBKDF2 seed derivation. https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki
Ethereum.org, Ethereum wallets: what a wallet is, accounts, keys and addresses, wallet types, and seed phrase safety. https://ethereum.org/en/wallets/

Background on this site: How a Blockchain Works explains the ledger these keys act on, and the Crypto Glossary defines the terms used here.

Continue the foundations

Terms used here are defined in the Crypto Glossary, and the networks covered are priced on Markets.

Important: Educational Purposes OnlyThe data, charts, treasury tracking metrics (including mNAV and SPS), and research provided on CryptosEyes.com are for informational and educational purposes only. They do not constitute certified financial, investment, or trading advice. Digital assets like Bitcoin and Ethereum are highly volatile. Always conduct your own research and consult with a registered financial advisor before making investment decisions.