Casa Blog - Bitcoin Security Made Easy

A wallet does not hold bitcoin or ether. The coins sit on a public ledger, and the wallet holds the private keys that produce the signatures authorizing them to move, along with the derivation path that turns those keys into your addresses. Every question about wallet security resolves into three smaller ones. Where were the keys generated, where do they live now, and who can sign with them.

Hot and cold describe whether the keys have ever touched an internet-connected device, while custodial and non-custodial describe who is able to produce a valid signature. The second one matters more, because it decides whether the storage question belongs to you at all.

The strongest arrangement available to an individual is a non-custodial cold wallet. Past the point where the balance would be painful to replace, splitting signing authority across several keys removes the last single point of failure. Casa's sizing rule is the fastest way to figure out what setup works best to secure your digital assets and as a general rule, we recommend that you secure your bitcoin as if it's worth 10x what it is today.

What makes a wallet hot or cold?

Temperature describes exposure, and it belongs to the key rather than to the app you are looking at. A hot wallet keeps private keys on a device that connects to the internet, so any code reaching that device can reach the keys. Cold storage keeps them on hardware that has never been online.

The distinction between hot and cold wallets is made throughout the lifetime of a seed starting from where it was generated. A seed phrase generated on an offline device and later typed into a phone becomes a hot key at that moment and stays one, no matter where the original device sits afterward. Plenty of wallets described as cold become hot wallets this way.

Cold keys still need an online counterpart to be useful. A watch-only wallet holds the extended public keys, derives your addresses, tracks the balance, and assembles unsigned transactions, all without the ability to spend anything. For bitcoin, that handoff usually travels as a partially signed bitcoin transaction, the PSBT format standardized in BIP 174. An unsigned transaction goes into the signing device over USB, a microSD card, or a sequence of QR codes. The device shows the amount and destination on its own screen, signs inside its secure element once you confirm, and sends back a signature while the key itself never leaves. Air-gapped describes the strictest version of that arrangement, where the device refuses a data cable outright and moves everything by card or camera.

How bitcoin transactions work: Addresses, UTXOs, and more
A lot happens when you send and receive bitcoin. Get to know the basics of peer-to-peer transactions.

Custodial and non-custodial wallets

A custodial wallet is an account at a company that holds the keys. Exchanges and brokerages work this way. You log in, press send, and the custodian signs on your behalf.

Three risks come attached, and you can control none of them.

  1. A breach at the company exposes assets you never controlled.
  2. Freezes, restrictions, and outages on their end stop your transaction regardless of what you intended.
  3. The company's solvency becomes part of your risk, because an account balance is a claim against a business rather than a key.

Custodians run hot and cold wallets of their own, and those practices matter a great deal to their own books. From the customer's side the operative fact sits one level up, since the signature is produced by someone else's infrastructure under someone else's policy.

In a non-custodial wallet, you hold the keys. No company can sign without you, and no company can stop you. These wallets come hot or cold, in software or on dedicated hardware, and self-custodial means the same thing.

Casa vaults are non-custodial. You hold the majority of keys on every vault, your own keys move your bitcoin without us, and you can recover independently at any time.

How Casa’s Sovereign Recovery works
Here we explain Sovereign Recovery and the information you need to access bitcoin held with Casa multisig, without ever touching Casa software.

Software wallets

A software wallet stores keys on a general-purpose device, a laptop, a phone, or a browser extension. Setup gathers entropy, converts it into a BIP 39 seed phrase, and derives every key and address from that starting point.

Convenience is the appeal, and the cost is that the wallet inherits the security of the machine underneath it. Infostealer malware sweeps disks and browser profiles for wallet files and unlocked sessions. A clipboard hijacker never needs the key at all, because swapping the address you pasted is enough to redirect the payment to someone else. Worse still, a browser extension you already trust can turn hostile in an automatic update. None of this requires breaking the cryptography, since reading a key off a compromised machine costs an attacker far less.

Software wallets earn a place at the front of the stack for the same reason a physical wallet does. Keep what you expect to spend there, and keep the rest somewhere software cannot reach.

Why phishing reaches software wallets first

Verizon examined more than 22,000 confirmed breaches for its 2026 Data Breach Investigations Report and found phishing behind 16% of them, with the human element involved in 62%. The mechanics travel well from corporate email to wallet software, because both rely on the same moment of trust.

Search ads now carry a large share of that traffic. Security Alliance researchers blocked 356 malicious ads in the second half of March 2026, cloning the front ends of Uniswap, Morpho and PancakeSwap and taking more than $1.2 million in eighteen days. Cloaking scripts served a harmless page to anyone who looked like a researcher, so the listing stayed clean right up until it reached a real visitor.

Once a visitor lands, the ask arrives in one of three shapes. The crudest sites request the seed phrase outright, framed as validation, a migration, or an urgent security check. Others present a transaction that sends funds directly. The most effective version is the third, a signature request dressed up as a login or a connection step.

The extra signature risk on Ethereum

On Ethereum, a signature can grant a smart contract permission to move your tokens later. Token approvals exist so that exchanges, bridges, and lending contracts can function at all, and permit-style signatures let that grant happen off-chain, with no gas spent and no transaction in your history to notice. A drainer collects the signature, waits, and moves the balance on its own schedule. Reviewing outstanding approvals and revoking the ones you no longer need closes that window, and it is worth doing on a schedule rather than after something goes wrong.

Four threats account for most of the bitcoin taken from individuals year after year.

  1. A social engineering attack
  2. A phished device
  3. A physical attack
  4. A lost seed phrase.

A software wallet running on an internet-connected machine leaves you exposed to all four.

A Social Engineering Story
Analysis of a call from a social engineer posing as Google support.

Hardware wallets

A hardware wallet is a dedicated signing device. It generates keys from entropy produced on the device itself and stores them in dedicated hardware, usually a secure element built to resist physical extraction. Every transaction appears on its own screen and waits for a physical confirmation before it is signed. Connecting one to a computer does not surrender the key, because the signature is computed on the device and only the signature comes back out.

The screen of a hardware wallet is one of the most valuable components. A compromised computer can display one address while sending to another, so verifying the receiving address and the destination on the device's own display is what turns isolation into protection. Skip that step and the device degrades into an expensive USB stick.

Two habits protect the device before it ever holds value. Buy direct from the manufacturer rather than a marketplace reseller, and initialize it yourself so the seed phrase is generated in front of you. A device that arrives with the words already filled in has been compromised, without exception.

That design raises the cost of an attack enough that most attackers look elsewhere, toward exchanges, software wallets, and the people holding the devices. For anyone moving past an exchange balance, a hardware wallet is the right first purchase, and the differences between models matter less than getting one in hand.

How a bitcoin hardware wallet works
Hardware wallets let you secure your bitcoin away from hackers. Learn the basics of how they operate.

Where a single hardware wallet runs out

Cold storage relocates risk from the internet to the physical world, where the failure modes are easier to picture and no less real. A device can be lost in a move, destroyed in a fire, retired by its manufacturer, or bricked by a firmware update. Worse, a single disclosed flaw can undermine every key that model ever generated. Coldcard owners met that scenario in July 2026, when a firmware bug in seed generation surfaced and attackers drained 1,366 BTC from the affected wallets across 30 and 31 July.

The seed phrase carries the same authority as the device. Anyone who reads it can rebuild your keys without touching your hardware, which makes the phrase the thing most worth planning around. Someone impersonating hardware wallet support demonstrated the point on 10 January 2026. The attacker never went near the device, asked for the recovery phrase, received it, and moved 1,459 BTC along with roughly 2.05 million LTC, worth about $282 million that day. One device plus one phrase leaves a single conversation standing between an attacker and the entire balance, which is the argument for asking whether one hardware wallet is enough.

Nobody can count the coins that lost keys have taken out of circulation, because a ledger cannot distinguish a forgotten key from a patient owner. The provable floor still shows the shape of the problem. Coinbase director Conor Grogan counted 913,111 ETH stranded in broken contracts and burn addresses in July 2025, and that figure excludes every coin sitting behind a phrase somebody cannot find.

Bitcoin seed security analysis | Casa
An analysis of Bitcoin seed security.

Seed phrase storage depends on your setup

Generic seed phrase advice causes real losses, because the right answer changes with the number of keys you hold. It also settles a question people ask early, which is whether to memorize the phraseinstead of writing it down.

Singlesig. Store the phrase somewhere other than the device. One key means the phrase is your only redundancy, and separating the two forces an opportunistic thief to find both. Paper survives most things except water and fire, which is why stamped metal is the standard upgrade.

A 3-key vault. Keep each seed phrase with the key it belongs to. Redundancy already comes from keys held in different places, so splitting a phrase from its device adds another location to defend without adding a recovery path.

A multi-key setup carries one more thing worth writing down, which is the wallet configuration that records which public keys form the quorum. That configuration cannot spend on its own. It tells recovery software which addresses to look for, and rebuilding without it turns a routine restore into a research project.

Test your recovery by rebuilding the wallet

Confirming that your words are still legible proves nothing about recovery. Wipe the device and restore it from the seed phrase alone, or buy a second device of the same model and rebuild from the seed there, then confirm you can see and spend the funds. Anything short of a rebuild leaves you guessing about the one process you will need under pressure.

What are the levels of key security?

Casa treats key security as a spectrum, and each step buys something specific.

Singlesig. One device, one key, one seed phrase. This is where most self-custody begins and it handles ordinary balances well, with the understanding that the device and the phrase are the only two things standing between you and a loss.

Singlesig plus a passphrase. A BIP 39 passphrase is an extra secret only you know, a word or a phrase of your choosing, and it derives an entirely separate wallet from the same seed. An attacker holding both your device and your written phrase finds an empty or decoy wallet. The tradeoff is symmetrical, since a forgotten passphrase is as final as a lost seed, so it belongs in your backup plan from the first day.

A 3-key vault. Three keys, any two of which can sign. You hold two of them and Casa holds one, so your own keys move your bitcoin without us, and losing a single key costs you a replacement rather than the balance. For bitcoiners managing significant positions, this is what the next level looks like.

A 5-key vault. Five keys, any three of which can sign. You hold four and Casa holds one, so the vault survives the loss of two keys. Premium members run this alongside a 3-key vault rather than in place of one.

Adding keys buys tolerance for loss, which inverts the intuition people bring from physical locks. Every lock on a door is one more thing that can jam, while every key in a quorum is one more way to recover.

Distribution is what converts those keys into protection. Keys in separate locations mean no single fire, burglary, or flood reaches enough of them to matter. For any keyset holding more than one hardware key, Casa recommends spreading those keys across manufacturers so that no single device type accounts for a quorum. The Coldcard disclosure made the reasoning concrete, because a quorum built entirely from one manufacturer's devices inherits that manufacturer's next flaw in full.

Protect your stablecoins: Hold USDC and USDT with Casa
You can now hold two stablecoins within a Casa vault: Tether (USDT) and USD Coin (USDC). This makes Casa a comprehensive, self-custodial vault for bitcoin, ethereum, and dollar-pegged stablecoins.

Which wallet type is most secure?

Ranked by what they defend against, a custodial account comes last, because someone else produces the signature and their problems become yours. Non-custodial software returns control and leaves phishing wide open. Hardware closes most of that gap and leaves one object and one phrase to protect.

Past a certain amount, the question stops being which wallet and becomes how many keys stand between you and losing your coins. Casa vaults can hold bitcoin, ethereum, USDT and USDC across multiple keys in separate locations, with one key at Casa used for recovery and convenience.

Learn more about Casa memberships at https://casa.io/pricing.