Skip to content
Banking on Bitcoin

Security

Bitcoin Cold Storage Explained: How to Keep Coins Offline

Cold storage keeps your bitcoin keys on a device that never goes online. See how it works, the main options, what it protects against and a setup routine.

By · Published

Illustration of a large glowing orange bitcoin coin on a dark background

Key takeaways

  • Cold storage means your private keys are generated and kept on a device that is not connected to the internet, so remote attackers cannot reach them.
  • You can still spend from it. A connected device prepares the payment, the offline device signs it, and the signed result is broadcast.
  • A hardware wallet is the usual option. An offline computer or a multisig setup adds protection for those willing to learn more.
  • The device is the storage and the seed phrase is the backup. They need separate care and separate places.
  • Cold storage guards against hacking and exchange failure. It does not guard against loss, fire, scams or user error, so test recovery before trusting it with real money.

What is bitcoin cold storage?

Bitcoin cold storage is a way of holding bitcoin in which the private keys are created and kept on a device that never touches the internet. “Cold” refers to where the keys live, not to any brand or product. The opposite is a hot wallet, whose keys sit on a phone or computer that is online.

Your coins are entries on a public ledger, and a key is what authorizes moving them. Anyone who gets the key can spend the coins, and a confirmed transaction generally cannot be reversed. Bitcoin Wallets Explained covers the full range of wallet types.

A hot wallet is like the cash in your pocket: handy, and exposed to pickpockets. Cold storage is the safe at home, where you keep what you would not want to lose and visit only when you need to.

How does cold storage work?

Cold storage works by keeping signing separate from the internet: the private key never leaves the offline device, which signs transactions internally and hands back only the result. In practice, spending looks like this.

  1. A connected device, such as a phone or computer, holds only public information. It can see your balance and build an unsigned payment, but it cannot spend anything.
  2. The unsigned payment travels to the offline device. Depending on the setup, it moves by cable, QR code or memory card.
  3. You check the amount and destination on the offline device’s own screen and approve.
  4. The offline device returns a signed transaction. It contains the proof that you authorized the payment and none of the secrets.
  5. The connected device broadcasts the signed transaction to the network.

Think of signing a check at a desk with no phone line, then handing it to someone who mails it. If malware on the connected device alters the payment details, the offline device’s screen is where you catch it.

What are the main ways to do cold storage?

The main options are a hardware wallet, an air-gapped computer and multisig, and they differ in effort and in how much protection they add. Which fits depends on how much you hold and how comfortable you are with technical steps.

OptionHow it worksTrade-offs
Hardware walletA small dedicated device holds the keys and signs internallyThe most common choice. Buy from the maker, check the screen, protect the backup
Air-gapped computerA computer or phone kept permanently offline runs wallet software and signsMore technical. One careless connection undoes the setup
MultisigSeveral keys, often on separate devices and in separate places, must approve a paymentRemoves the single point of failure, adds backups and complexity

Some hardware wallets connect to a computer by cable or Bluetooth to pass transactions along, and the keys still never leave the device. Others are fully air-gapped and use QR codes or a memory card. Both count as cold.

Paper wallets, where keys are printed on paper, are an older method that is easy to get wrong, and most people now use paper only for the backup phrase. Bitcoin Multisig Explained covers how multisig works and who it suits.

Is a backup the same as cold storage?

No. The device is the storage, and the seed phrase is the backup, and keeping the two apart in your head prevents the most common mistakes.

The recovery phrase is a list of 12 or 24 words that can rebuild every key in the wallet on a compatible device. If the device is lost, broken or stolen, the phrase is how you get back in. It is also a complete copy of your money, because anyone who has it can take the coins without the device. What Is a Seed Phrase? explains how it works. A few rules follow.

  • Write it by hand and keep it offline, on paper or stamped into metal, which stands up better to fire and water.
  • Never keep a digital copy. A photo, an email or a cloud note defeats the point of cold storage.
  • Keep it apart from the device. If a thief finds both together, the device gives no protection.
  • Consider a second copy elsewhere, which protects against a single fire or flood.

What does cold storage protect against, and what does it not?

Cold storage protects against remote attacks and leaves most human and physical risks untouched. Knowing where the line falls helps you decide what else you need.

What it helps protect against:

  • Malware on your everyday computer or phone stealing keys.
  • Remote hacking of an online wallet or account.
  • An exchange failing, freezing withdrawals or being breached, because the keys are yours and not held in a company’s account.

What it does not protect against:

  • Losing every copy of the seed phrase, or forgetting a passphrase. What Happens to Lost Bitcoin? shows how permanent that is.
  • Fire, flood or theft of the backup.
  • Scams that trick you into typing your phrase somewhere, such as fake support, cloned apps and tampered devices. Is Bitcoin Safe? lists the red flags.
  • Mistakes such as sending to the wrong address. What Is a Bitcoin Address? explains how to check one.
  • Dying without a plan that lets your heirs find the coins.

Cold storage swaps one group of risks for another, which is the trade at the core of The Power of Self-Custody.

How do you set up cold storage step by step?

A careful setup takes an afternoon and finishes with a recovery test, not with the first deposit. Follow the steps in order and do not skip the small test amounts.

  1. Decide whether it fits. For a small amount you are still learning with, an exchange account with strong security may be enough for now. Cold storage suits an amount that would hurt to lose.
  2. Get the device from the maker. Buy directly from the manufacturer, because tampered devices sold through resellers are a known scam. Never use a device that arrives with recovery words already written for you.
  3. Set it up in private. Let the device generate a new seed phrase, write the words by hand and in order, and set a PIN. Add a passphrase only if you understand it and can store it separately.
  4. Store the backup apart from the device, after checking that every word is written correctly.
  5. Send a small test amount. Receive a small payment to an address shown on the device’s screen, confirm the first and last characters match, and wait for it to arrive.
  6. Test recovery. Wipe the device or use a second compatible one, restore from your written phrase alone, and confirm the same balance appears. Then send a small amount out to prove you can spend.
  7. Move the rest. Transfer the larger amount, ideally in more than one step. How to Buy and Secure Bitcoin covers the exchange side.
  8. Write down where everything is. Record your devices and where each backup is kept, but not the secrets themselves.

How do you maintain cold storage and plan for inheritance?

Cold storage needs a little upkeep and a plan for the day you are not around. Check once in a while that your backup is still readable and where you expect it. Install device updates only from the maker’s own website, reached by typing the address yourself. Devices can fail or go out of production, which is why a standard recovery phrase matters: it lets you restore the wallet on other compatible software.

Inheritance is the part people skip, because your family cannot ask a bank to release coins that no bank holds. Make sure a trusted person knows the bitcoin exists and where the instructions are, without leaving the phrase in plain view. An attorney familiar with digital assets can help, since estate rules vary by state.

Bitcoin’s price can fall sharply, and nothing in cold storage is insured. This article is educational, so for a large holding consider speaking with a qualified financial professional. If you are new here, the Start Here path covers the fundamentals first.

Where to go next

Frequently asked questions

What is bitcoin cold storage?

Cold storage means the private keys that control your bitcoin are generated and kept on a device that never connects to the internet. Because the keys stay offline, a remote attacker has no direct way to reach them. Transactions are signed on the offline device and then broadcast by a connected one.

Is a hardware wallet cold storage?

Generally yes. A hardware wallet keeps private keys inside the device and signs transactions internally, so the keys never reach your computer or phone. Some devices connect by cable or Bluetooth to pass transactions along, while others stay fully air-gapped and exchange data through QR codes or a memory card.

Can cold storage be hacked?

Remote hacking of keys that never go online is much harder, but cold storage is not risk-free. Tampered devices, fake apps, impersonation scams, a stolen backup or a simple mistake can all cost you coins. It removes some risks and leaves others.

What happens if my hardware wallet breaks?

If you still have the seed phrase, you can restore the wallet on a replacement device or another compatible wallet and see the same bitcoin. If both the device and every copy of the phrase are gone, the coins cannot be recovered by anyone.

How do I send bitcoin from cold storage?

A connected device builds an unsigned transaction, the offline device signs it after you check the details on its own screen, and the signed transaction goes back to the connected device to be broadcast. The private keys never leave the offline device.

Related articles