How to Store Cryptocurrency: Wallets, Seed Phrases and Common Mistakes
How a cold wallet differs from a hot one, why an exchange account is not storage, how to write down a seed phrase properly and what Russia's digital depository changes. A practical guide with a checklist.

In brief: cryptocurrency is not stored "in a wallet" but on the blockchain; the wallet stores the private key, which is your access to the asset. Hence the main rule: keep the sums you do not need every day in a cold (offline) wallet, working funds in a hot wallet, and leave on an exchange only what you are trading right now. The only backup of your access is the seed phrase of 12 or 24 words, and it should never exist in digital form.
How it actually works
The coins are not sitting in the app. The blockchain records only addresses and balances; the wallet is a program or device that stores the private key and uses it to sign transactions. Lose the key and you lose the right to dispose of the asset, and neither the developer, nor an exchange, nor a court can restore it. This is the source of the key distinction:
- custodial wallet: the keys are held by a service (an exchange, exchanger or broker), and you are working with an entry in its database. Upside: access can be restored with a password and ID documents. Downside: platform risk, meaning hacks, bankruptcy or an account freeze;
- non-custodial wallet: the keys are yours alone. Upside: no one can freeze your funds. Downside: all the responsibility is on you, and there is no insurance.
Wallet types compared
| Type | Where the key is | Who it suits | Weak point |
|---|---|---|---|
| Exchange account | With the exchange | Active trading, short time frames | Exchange hack, account freeze, withdrawal restrictions |
| Mobile/desktop (hot) | On the device, online | Daily operations, small sums | Malware, phishing, phone theft |
| Browser extension | In the browser | Working with DeFi and NFTs | Malicious transaction signatures, fake extensions |
| Hardware (cold) | In the device's secure chip | Long-term storage | Physical loss, counterfeit device, tampering when bought second-hand |
| Paper/metal backup | On a physical medium | Backup copy | Fire, water, wear, theft, loss |
| Multisig | Several keys, N of M required | Large sums, family or joint ownership | Complexity of setup and recovery |
The basic hygiene standard looks like this: a hot wallet for current spending, a cold wallet for savings. A sensible proportion for a beginner is not to keep more in a hot wallet than you can afford to lose.
The seed phrase: what it is and how to store it
The seed phrase (also called a mnemonic phrase or recovery phrase) is a sequence of 12 or 24 English words from which all of the wallet's private keys are deterministically derived. Anyone who knows it can restore access to the assets on any other device and in any compatible app. That is exactly why it is equivalent to the money itself.
Rules that must not be broken:
- Never photograph the phrase and never type it on a keyboard outside the recovery procedure. A screenshot ends up in the cloud, a note in sync, a photo in the gallery, and malware pulls them out of there.
- Write it on paper or, better, on a metal plate, which will survive fire and flooding.
- Keep at least two copies in different physical locations: for example, a safe at home and a bank safe deposit box.
- Never dictate it to anyone or enter it on websites. Legitimate support never asks for a seed phrase; that is a sign of fraud in 100% of cases.
- Test the backup before depositing a large sum: restore the wallet from the phrase on another device and make sure the addresses match.
A passphrase is an additional word on top of the seed phrase. It creates a "hidden" wallet: even someone who finds your slip of paper with 24 words will see only a decoy balance. But losing the passphrase is irreversible.
What is new in 2026
Russia's digital depository: a new form of custody
Federal Law No. 282-FZ of 4 August 2026 introduced the institution of the digital depository: in the Russian legal framework, only a digital depository may open digital accounts and keep records of digital currencies. The Bank of Russia (the central bank) requires capital of RUB 50 million to RUB 250 million and membership in a self-regulatory organization; VTB, Sber, T-Bank, Alfa-Bank and Moscow Exchange have announced plans to operate in this capacity.
For the owner, this is essentially a custodial model with two restrictions worth knowing about in advance:
- withdrawing digital currency from a Russian depository to your own external wallet, whether hardware or non-custodial, is not allowed under the design of the law; withdrawals are provided for only to addresses of foreign platforms administered by corporate custodians;
- from 1 September 2027, a 48-hour cooling-off period is introduced for a number of transactions by resident individuals: in particular, transfers from a Russian digital depository of more than RUB 100,000 to an external address or more than RUB 300,000 to a third party. During those 48 hours the client can cancel the transaction.
More on how this changes buying in How to buy cryptocurrency legally in Russia.
Requirements for wallet developers in the EU
Since 11 September 2026, updated Cyber Resilience Act rules have been in force: EU-registered makers of hardware and software crypto wallets are required to report a discovered vulnerability within 24 hours and publish a full statement after 72 hours. For the user this is a practical signal: firmware and app updates now arrive faster, and they should not be ignored.
Data leaks at financial services
On 12 September 2026, on-chain investigator ZachXBT reported a possible leak of Revolut customer data: according to him, the company handed data to outsiders after mistaking a forged government agency request for a genuine one. The exposed information included names, contact details, copies of documents, verification selfies, bank details and transaction history, including bitcoin transfers. The takeaway: even flawless wallet hygiene does not protect you from the link between your identity and your address leaking from the service where you completed verification.
How cryptocurrency gets stolen: four scenarios
- Phishing and drainer scripts. A fake site asks you to sign a transaction, the signature grants an unlimited allowance on your tokens, and the wallet is emptied in a single operation. Defense: sign only what you understand, revoke permissions regularly, and keep a separate wallet with a small balance for DeFi.
- Malware and clipboard hijacking. A trojan replaces the copied recipient address with its own. Defense: check the first and last 4-6 characters of the address on the hardware device's screen, not in the app.
- Social engineering. "Exchange support" in a messenger, a fake dispute over a P2P trade. Defense: the single-channel rule, meaning verify any contact through the official app, not via a link you were sent.
- Physical and everyday risks. A lost phone, a fire, the owner's death. Defense: a recovery and inheritance plan thought through in advance.
Inheritance: why this is not a technical detail
Cryptocurrency is property, it forms part of the estate, and no personal income tax (NDFL) is charged on an inheritance. But a notary will not hand the heirs a private key: without the seed phrase, the asset disappears along with its owner. Working approaches include multisig with a key held by a trusted person, splitting the phrase among custodians using Shamir's scheme, and instructions in a sealed envelope held by a notary. The legal side is covered in Cryptocurrency tax for individuals.
Checklist: 10 points before your first large transfer
- Decide what sum counts as "long-term" and set up a separate cold wallet for it.
- Buy a hardware wallet only from the manufacturer or an official dealer, never second-hand.
- Check the integrity of the packaging and generate the seed phrase yourself on the device.
- Record the phrase on metal, make a second copy, and store them in different places.
- Test recovery from the phrase before depositing a large sum.
- Enable a PIN and two-factor authentication on linked services, via an authenticator app rather than SMS.
- Send a test transaction for the minimum amount.
- Set up a separate "spending" hot wallet for DeFi and small operations.
- Update the wallet's firmware and app regularly.
- Write down an access plan for your family, in a way that does not create a vulnerability while you are alive.
FAQ
Can I keep cryptocurrency on an exchange? Technically yes; legally it is not your custody but a claim against the platform. For active trading it is acceptable, for savings it is not. The community's formula "not your keys, not your coins" did not appear out of nowhere: stories of halted withdrawals and platform bankruptcies repeat regularly.
What should I do if I lose my hardware wallet? Nothing to worry about if you have the seed phrase: restore the wallet on a new device. If you suspect the phrase has been compromised, move the funds immediately to a new wallet with a new phrase.
How many wallets do I need? At least two: a cold one for savings and a hot one for operations. For active DeFi use, people add a third, a "sandbox" with a small balance.
What is multisig and does a beginner need it? A scheme in which a transfer requires N signatures out of M keys, for example 2 of 3. It reduces the risk of a single point of failure but complicates recovery. It is overkill for a beginner, but justified for significant sums or joint ownership.
Will storage in a Russian digital depository be safer? It is a different set of risks: the risk of losing the key and of fraud goes down, but you become dependent on an intermediary and face withdrawal restrictions, including the inability to send the asset to your own external wallet and the cooling-off period from 1 September 2027.
Do I have to pay tax on transfers between my own wallets? No, no taxable income arises. But keep the transfer history: you will need it to prove that it was not a sale.
Sources
- ForkLog, 14 September 2026. "The EU now requires crypto wallet vulnerabilities to be reported within 24 hours" — https://forklog.com/news/v-es-obyazali-soobshhat-ob-uyazvimostyah-kriptokoshelkov-v-techenie-sutok
- ForkLog, 12 September 2026. "ZachXBT reports a possible leak of Revolut customer data" — https://forklog.com/zachxbt-soobshhil-o-vozmozhnoj-utechke-dannyh-klientov-revolut
- GARANT.RU, 18 August 2026. "Cryptocurrency: new rules for investors and business from 1 September 2026" — https://www.garant.ru/article/2204420/
- Finuslugi. "Cold and hot wallets: how to protect cryptocurrency if you lose your smartphone in 2026" — https://finuslugi.ru/navigator/investirovat/stat_kholodnye_goryachie_koshelki_bezopasnost


