What Is a Crypto Wallet? Keys, Seed Phrases, Custody, and Signing
Research Desk · Sources cited in guide
Short answer: A crypto wallet does not hold coins. Coins and tokens live on the blockchain as ledger entries. A wallet holds the private keys that prove control of an address and uses them to sign transactions. Whoever holds the keys controls the funds at that address, and there is no central operator who can reverse a signed transaction or reset a lost key. A recovery phrase (a seed phrase) is a human-readable backup of the master secret from which a modern wallet derives all of its keys and addresses, so the phrase is the whole wallet in 12 to 24 words.
A wallet is a key manager, not a container
The name misleads. A physical wallet holds cash; remove the cash and the wallet is empty. A crypto wallet works differently. Your balance is a set of entries on a public ledger, recorded against addresses. The wallet stores the cryptographic secrets that let you move those entries, displays the balance the chain reports for your addresses, and builds and signs transactions. Ethereum's wallet documentation puts it plainly: wallets give you control over your account, wallet providers do not have custody of your funds, and you can swap wallet providers at any time because the account lives on the chain, not inside the app. If the app disappeared tomorrow, the same recovery phrase in different software would rebuild the same addresses and the same access. What you own, in operational terms, is a secret. Everything else is an interface.
This is why the same person can check a balance in three apps at once. Each app reads the same public ledger. Only the device holding the private keys can authorize a spend. Watching an address is free and public; spending from it requires the key.
For the ledger side of this picture, see how a blockchain works. For the networks whose addresses wallets manage, see layer 1 vs layer 2 and the markets page.
The key pair: one secret, one shareable half
Every account starts with a key pair: a private key and a public key, mathematically linked so that one can prove knowledge of the other without revealing it.
The private key is a secret number. It signs transactions and messages. A valid signature tells every node on the network: the holder of this address authorized this exact action. There is no separate password check and no fraud department. The signature is the authorization.
The public key is derived from the private key and can be shared. Network addresses are derived from the public key. You hand out an address the way you hand out an email address: anyone can send to it, and only the key holder can spend from it.
Three consequences follow, and they explain most wallet losses people describe as hacks.
First, knowledge is control. Anyone who learns a private key or the recovery phrase behind it can spend the funds, from anywhere, and the network will treat that spend as fully valid, because it is.
Second, addresses are public by design. Balances and transaction history at an address are visible to anyone. Pseudonymous is not private.
Third, transactions cannot be reversed by the network. Once a signed transaction is accepted and confirmed, the ledger keeps it. A mistaken or tricked signature is a valid signature with results the signer did not want. Prevention is the only remedy the protocol offers.
The recovery phrase: how 12 to 24 words rebuild a wallet
Typing raw keys is error-prone, so modern wallets generate one master secret and show it as a recovery phrase. The governing standard is BIP39, titled "Mnemonic code for generating deterministic keys," deployed in 2013 and used across Bitcoin and Ethereum wallet software.
The mechanics, from the specification:
| Initial entropy (bits) | Checksum (bits) | Phrase length (words) | Common use |
|---|---|---|---|
| 128 | 4 | 12 | The default in most software wallets |
| 160 | 5 | 15 | Less common |
| 192 | 6 | 18 | Some hardware wallets |
| 224 | 7 | 21 | Rare |
| 256 | 8 | 24 | The default in many hardware wallets |
Because the phrase deterministically regenerates every derived address, one written backup covers all accounts the wallet creates later, including change addresses you never saw. Bitcoin.org makes the same point from the backup side: most modern wallets are deterministic, so a single backup of the recovery phrase restores all past and future addresses. It also warns that older backups can miss keys a nondeterministic wallet created later, which is why the backup standard to check is the phrase, not a file.
The optional passphrase changes the wallet
BIP39 allows an extra user passphrase on top of the phrase. The passphrase is mixed into the seed derivation, so the same 12 or 24 words plus a different passphrase produce a completely different wallet. Every passphrase yields a valid wallet; only the right one shows the funds you expect. This is a real feature with a hard edge: if you use a passphrase and forget it, the phrase alone will open an empty or different wallet and the original is unreachable. Treat the passphrase as a second secret that deserves the same written backup discipline, stored separately from the phrase itself.
Custodial vs self-custody: who holds the keys
When you leave assets on an exchange, the exchange holds the keys and operates an internal ledger of who is owed what. You hold an account claim, protected by a password and whatever recovery process the company runs. Bitcoin.org's security guidance is direct about the trade: when a third party controls your keys, you rely entirely on their security, and exchanges and online wallets have been hacked, failed, or frozen access in the past. A custodial account is convenient and recoverable, and it is also a counterparty exposure. If the custodian stops honoring withdrawals, the chain does not know your name.
In self-custody, you or your device holds the keys. No company can freeze the address, and no company can restore it either. Forgotten credentials for Bitcoin have, in Bitcoin.org's words, very limited recovery options compared with a bank: if the password and backups are gone, the funds stay at the address permanently, visible to all and spendable by none.
Neither model is the correct one in the abstract. The real question is which failure you are better equipped to prevent: a company failing or being breached, or you losing a piece of paper. The custody decision table below makes the trade explicit.
| Question | Custodial (exchange holds keys) | Self-custody (you hold keys) |
|---|---|---|
| Who can move the funds? | The company, under your account instructions | Anyone with the key or phrase; in practice, you |
| If credentials are lost | Password reset and identity checks are possible | No reset. The phrase backup is the only recovery path |
| If the operator fails or is hacked | Your claim is exposed to their balance sheet and security | Your funds are unaffected by any company's failure |
| If your device is lost | Log in from another device | Restore from the written phrase on a new device |
| If your backup is stolen | Account security depends on passwords and two-factor settings | The thief can take everything; see the loss table below |
| Best suited to | Small, active balances and simple access | Stored value you are prepared to back up carefully |
A common split follows Bitcoin.org's everyday-cash analogy: keep only small amounts on a computer or phone for everyday use, the way you would not carry a large sum in a pocket wallet, and keep the rest in a safer environment.
Hot, cold, and hardware wallets
A hot wallet keeps keys on an internet-connected device: a phone app, a browser extension, a desktop program. It is the most convenient way to sign and the most exposed, because the device that holds the secret also runs email, browsers, and everything else that can be attacked.
A cold wallet keeps keys on a device or medium that is not connected to the network. Bitcoin.org describes the offline approach as the highest level of security for savings, including offline transaction signing: an online computer builds an unsigned transaction, an offline machine signs it, and the online machine broadcasts the result. The network-facing computer never holds a key, so a compromise there cannot forge a signature.
A hardware wallet is the packaged form of cold storage: a small device built from the ground up to be a wallet and nothing else. Keys are generated and stored on the device and signatures are produced inside it, so the private key is never typed into or stored on the general-purpose computer. Bitcoin.org calls hardware wallets the best balance between very high security and ease of use, and notes that a backup lets you recover funds if the device itself is lost. The device reduces one class of risk (malware reading keys off your computer) and concentrates another (the physical backup of the phrase becomes the master copy of your money).
Whichever form you use, the software version matters. Bitcoin.org's guidance to keep wallet software up to date applies across chains: updates carry stability and security fixes, and the same applies to the operating system underneath.
Multisig: splitting control across keys
A multisignature setup requires approvals from several independent keys before funds can move. Bitcoin includes this feature natively: a transaction can be set to require, for example, 3 of 5 designated signers. Bitcoin.org describes organizations giving members treasury access where a withdrawal needs three of five signatures, and individuals using multisig so that stealing one device or one location is not enough to steal the funds.
Multisig trades simplicity for resilience. It tolerates the loss or compromise of individual keys up to the threshold, which makes it the standard pattern for shared treasuries and larger holdings. It also raises the backup burden: every signer key needs its own backup, and losing more keys than the threshold allows locks the funds as surely as losing a single key would. On smart-contract networks, the same idea is usually implemented as a contract account that checks several owner signatures before executing, rather than as a native address feature.
Signing is the moment of risk
Most wallet losses do not start with someone guessing a key. They start with a signature the owner was talked into making. A signature authorizes exactly what the software asks the key to approve: a transfer, or on smart-contract chains, an approval that lets a contract move a token on your behalf. Approvals can be broad, they persist until revoked, and they are granted to contract addresses that most people cannot read.
The working habits that follow from how signing works:
This is educational material on how wallets work, not financial advice, and it is not a recommendation to buy, hold, or move any asset.
Backup and loss scenarios
Backups fail in predictable ways. Bitcoin.org's guidance covers the main ones: back up the entire wallet secret rather than individual visible keys, encrypt any backup that touches a network because online backups are highly vulnerable to theft, use more than one secure location because a single point of failure is bad security, and remember that a forgotten password with no recovery path means permanently lost funds. It also raises the inheritance case: if nobody knows where your wallet and passwords are when you are gone, there is no way for your family to recover the funds.
| If this happens | With a written phrase backup | Without one |
|---|---|---|
| Phone or computer is lost or broken | Restore the same addresses on a new device | Funds are stranded at addresses nobody can sign for |
| Wallet app is deleted or the company closes | Import the phrase into other wallet software | Same stranding, unless the keys were exported elsewhere |
| Hardware device is lost | Restore from the phrase onto a replacement device | The device was the only key copy; funds are unreachable |
| PIN or wallet password is forgotten | The password locks the app, not the keys; restore from the phrase | If there is also no phrase, no reset exists |
| Phrase is photographed or stored in cloud notes | Anyone who reaches the photo or note controls the wallet | Same exposure; storage method is the vulnerability |
| Phrase is destroyed in a fire or flood | Only survives if a second copy exists in another location | Total loss; the chain keeps the balance and no one can move it |
A minimum backup checklist
Frequently Asked Questions
Does a wallet store my coins?
No. Balances are entries on the blockchain, recorded at addresses. The wallet stores the private keys that control those addresses, shows you the balance the chain reports, and signs transactions. Delete the app and the funds stay exactly where they were; restore the phrase and the same access comes back.
What is the difference between a private key, a public key, and an address?
The private key is the secret that signs. The public key is derived from it and can be shared. The address is derived from the public key and is what you give out to receive funds. Sharing an address is safe; sharing a private key gives away control of everything at that address.
Why do wallets show 12 or 24 words instead of a key?
Because words are harder for people to copy wrong than a long string of numbers. Under BIP39, the wallet encodes 128 to 256 bits of randomness as 12 to 24 words from a fixed 2048-word list, with a built-in checksum that catches most copying errors. From those words the software derives the seed and then every key and address the wallet will use.
What happens if I forget my wallet password?
It depends on the wallet. A password usually locks the app or device, not the keys themselves, so restoring from the recovery phrase sets a new password and recovers access. If you have also lost the phrase, there is no reset process: the network has no record of who you are, only of which key signs.
What does the optional passphrase do?
It changes the wallet. BIP39 mixes the passphrase into the seed, so the same phrase with a different passphrase opens a different, valid wallet with different addresses. It can protect a phrase that is found, but a forgotten passphrase makes the intended wallet unreachable even with a perfect phrase backup.
Is a hardware wallet safe if I lose the device?
The funds are safe if your phrase backup is safe. The device is one copy of the keys; the phrase regenerates them on a replacement device. Anyone considering the device itself should still treat a found device as sensitive, and a slow PIN retry limit is a device feature to confirm in the maker's own documentation rather than an assumption.
Can I use the same recovery phrase in different wallet apps?
Usually yes. BIP39 phrases and the standard derivation methods are implemented across many wallets, which is the point of the standard. Compatibility is not guaranteed for every coin, account layout, or newer derivation path, so a small test restore is worth doing before you rely on a second app as your backup plan.
Why is multisig safer, and what does it cost?
A multisig address needs several independent keys to agree before funds move, so one stolen device or one phished signer cannot empty it. The cost is operational: more keys to back up, more signers to coordinate, and a hard lock if too many keys are lost. It fits shared or larger holdings better than everyday spending.
Sources
Background on this site: How a Blockchain Works explains the ledger these keys act on, and the Crypto Glossary defines the terms used here.
Continue the foundations
How a Blockchain Works
How a blockchain works, mechanically: blocks and headers, SHA-256 hashing, Merkle trees, nodes, consensus, and finality, with an illustrative step-by-step block build.
Read guideLayer 1 vs Layer 2: How Blockchains Scale
Layer 1 vs Layer 2 explained plainly: what settles where, optimistic and zero-knowledge rollups, sidechains, sequencers, fees, and bridging risk, with named networks checked against official docs.
Read guideProof of Work vs Proof of Stake
Proof of work vs proof of stake: how each design stops Sybil attacks, pays for security, punishes cheating, uses energy, and reaches finality, with Bitcoin and Ethereum as the worked examples.
Read guideTerms used here are defined in the Crypto Glossary, and the networks covered are priced on Markets.