"Cold" and "hot" get thrown around a lot in Bitcoin storage advice, usually without much explanation of what's actually different underneath. It's a simpler distinction than it sounds: does the device holding your private key ever touch the internet, or not.
A hot wallet is connected to the internet, a phone app, a desktop program, or an exchange account. That connectivity is exactly what makes it convenient: you can check a balance or send a payment in seconds, from anywhere. It's also what makes it the more exposed option. Malware, phishing, compromised apps, and (for exchange accounts) the exchange's own security all become part of your attack surface the moment the key touches an internet-connected device.
A cold wallet keeps the private key on a device that never connects to the internet, most commonly a dedicated hardware wallet, though a properly generated paper wallet counts too. Signing a transaction usually means the unsigned transaction gets passed to the offline device (by cable, QR code, or SD card), signed there, and passed back, without the key ever touching an online system at any point. It's slower and less convenient by design. That's the entire point.
| Hot wallet | Cold wallet | |
|---|---|---|
| Connectivity | Online | Offline |
| Convenience | High, instant access | Lower, extra steps to sign |
| Remote attack exposure | Real, ongoing | Effectively none |
| Best for | Small amounts, frequent spending | Savings, long-term holdings |
A common, pretty sensible pattern: keep a small amount in a hot wallet for everyday spending, the way you'd carry cash rather than your entire savings account, and keep the bulk of any real holdings in cold storage you rarely touch. That way a hot wallet compromise only ever costs you the small amount you deliberately kept exposed.
Cold storage removes remote attacks, not every risk. Physical theft of the device, a badly stored backup, or a compromised computer at the moment you generated the key in the first place (this is exactly why old-style paper wallet generators fell out of favor, since a compromised computer could produce a "random" key that wasn't random at all) can all still go wrong. Cold storage is a big step up, not a guarantee.
The private key for every Bitcoin wallet on Earth is on this website, even Satoshi's. But even if you try for a million years, you'll never find a funded one.
Try the key collider nowHot for spending money, cold for savings, and don't assume either one is bulletproof on its own. For the fuller list of what actually goes wrong in practice, see how to keep a private key safe.