A wallet manages access
Crypto is recorded on a blockchain. A wallet manages the keys and interactions used to control it. A receiving address can be shared to receive funds. A private key is secret authority to spend. A wallet password commonly protects an app or local installation; it is not necessarily the secret that restores your assets.
With self-custody, you control the signing keys and carry the responsibility for protecting and recovering them. With a custodial service, the provider controls the keys on your behalf. Your account balance is then also a claim on that provider, subject to its operations and terms.
Hot and cold are different trade-offs
Hot wallets are available on connected devices and convenient for frequent use. Cold storage keeps signing keys offline. A hardware wallet can protect the key from a compromised computer, but it cannot make a harmful transaction safe once you approve it.
There is no single setup that removes every risk. Consider access, recovery, device security and what happens if a provider stops withdrawals.
Backups and approvals
A recovery phrase can restore control in many wallets. Anyone who obtains it may be able to take the assets. Store backups securely and never give a phrase to someone claiming to be support. Wallet designs vary, so follow the recovery process for the wallet you actually use.
Before sending, check the full destination, token, network and amount through an independently verified source. A small test can reveal some errors, but does not prove every later payment is safe. Before signing, read what the request permits: connecting a wallet, approving token spending and sending assets are different actions.
Takeaway: know who holds the keys, how recovery works, and exactly what you are authorising.
Further reading
Provider documentation explains particular designs. It is not a product endorsement.
