Dossiers
Dossier: storing crypto with hardware and software wallets
Anyone who buys crypto eventually has to decide where those coins live: on a trading platform, in an app on a phone, or on a device that never shares its keys with the internet. This dossier compares the options: the types of wallet that exist, how hardware wallets such as Ledger, Trezor, NGRAVE, BitBox and Coldcard differ, what software wallets are genuinely good at, and how to pick a setup that matches the amount you hold.
Timeline
- Trezor launches the first commercial hardware wallet.
- Ledger introduces the Nano line with a secure element chip.
- Air-gapped wallets such as NGRAVE and Coldcard gain ground: signing without cable or bluetooth.
- FTX collapse: millions of users move funds from exchanges to self-custody wallets.
- Passkeys, multisig and smart accounts make recovery without a single seed practical.
What a wallet actually stores
A wallet does not store coins. The coins live on the blockchain; the wallet stores the private key that signs transactions. Whoever holds the key can move the balance, regardless of the brand or app involved. That is why every piece of security advice ultimately concerns key management rather than the coins themselves.
Almost every modern wallet derives those keys from a single recovery phrase of twelve or twenty-four words. That phrase is not a password you can reset; it is the root of every address you own. Lose both the phrase and the device and the balance is gone for good. Let someone copy the phrase and they have full access without ever touching your device.
The distinction that matters is therefore not hardware versus software, but where the key is generated, where it is stored, and which device uses it at the moment you sign.
- Custodial: a platform holds the keys and you hold a claim on that company
- Software wallet: keys stored encrypted on your phone or computer
- Hardware wallet: keys never leave a separate, offline device
- Multisig: several keys in different places must sign together
Hardware wallets: how the well-known brands differ
A hardware wallet is a small device that generates and keeps the private key internally. Your computer or phone sends a draft transaction to the device, you verify the amount and address on the device's own screen and confirm with a button. The signed transaction goes back out; the key stays in. Even on a compromised computer an attacker cannot force a valid transaction without your physical approval.
Ledger, with its Nano and Stax lines, is the best-known brand and supports a very wide range of networks through its own app. Its firmware is partly closed, and the device uses a secure element chip that resists physical extraction. Trezor takes the opposite approach with fully open source firmware that independent researchers can audit, and recent models add a secure element as well.
NGRAVE positions itself as fully air-gapped: no USB data connection, no wifi and no bluetooth, communicating only through QR codes, with the initial key partly derived from sensor data and your own finger movements. Coldcard targets experienced bitcoin users with SD-card transfer, a duress PIN and extensive multisig support. BitBox02 and Keystone sit in between, emphasising simplicity and large-screen QR signing respectively.
Always buy a hardware wallet directly from the manufacturer or an official reseller. Marketplace devices can arrive preloaded with an attacker's seed; any wallet that ships with a ready-made recovery phrase on paper is unsafe by definition.
- Ledger: broad network support, secure element, partly closed firmware
- Trezor: open source and auditable, strong desktop software
- NGRAVE: air-gapped over QR, no wireless radios, focus on key generation
- Coldcard: bitcoin specialist, SD card, advanced multisig and duress options
- BitBox02 and Keystone: simple operation or large-screen QR signing
Software wallets: convenient, with a different risk profile
Software wallets such as MetaMask, Rabby, Phantom, Trust Wallet, BlueWallet, Sparrow and Exodus keep keys encrypted on your phone or computer. They are free, instantly usable and indispensable for anyone interacting daily with applications on Ethereum, Solana or layer 2 networks. The trade-off is that the key sits on an internet-connected device where you also read email and install software.
That makes a software wallet excellent as a wallet for everyday amounts and unsuitable as a vault for your entire holdings. A common split is a small amount in a hot wallet for transactions and the bulk behind a hardware wallet that you only touch when you genuinely move funds.
The best of both worlds is a software wallet as the interface and a hardware wallet as the signer. MetaMask, Rabby, Sparrow and Phantom can all drive a Ledger, Trezor or Keystone: you keep the familiar app, but every signature is physically confirmed on the device.
- Hot wallet: small amount, daily use, fast access to applications
- Hardware wallet: main holdings, few transactions, physical confirmation
- Software as interface plus hardware as signer combines convenience and protection
- Check what each signature approves, not only the amount
Choosing a setup that fits the amount
The right setup follows from two questions: how much do you hold, and how bad would it be if something went wrong. For a few hundred euros a well-configured software wallet with screen lock and a carefully stored recovery phrase is defensible. From a few thousand euros upwards, the cost of a hardware wallet is trivial against the risk.
If the amount would change your life, consider multisig: two or three keys in different locations, of which for example two are required to sign. A single stolen or burnt key then no longer means loss. It demands more discipline and a rehearsed recovery procedure, but it removes the single point of failure.
Think about what happens if you are no longer around. Record where keys and backups are kept and how a relative can reach them, without combining that information in one place. A test recovery on an empty device, once a year, is the only way to know your emergency plan actually works.
Frequently asked questions
Do I need a hardware wallet if I hold very little crypto?
For small amounts a well-secured software wallet is usually sufficient. Once the holding outweighs the price of a device, roughly from a few thousand euros, a hardware wallet is the logical step.
What happens to my crypto if the manufacturer disappears?
Nothing. Your recovery phrase follows open standards and can be restored in almost any other wallet, so you do not depend on Ledger, Trezor or NGRAVE continuing to exist.
Can I use the same recovery phrase on two devices?
Yes, and it is a common way to keep a spare device ready. Bear in mind that every extra device is another place where someone could gain physical access.
Is crypto on an exchange the same as crypto in a wallet?
No. On a platform you hold a claim on that company and the company holds the keys. In your own wallet you hold the keys yourself, with all the freedom and responsibility that entails.