Cold, hot and burner wallets — how to split your crypto across three tiers, and what belongs in each
Most people run their whole on-chain life from one address: they buy there, farm there, claim airdrops there, and connect it to sites they had never heard of an hour earlier. The question is not whether you will eventually sign something you shouldn't — it is that when you do, the loss has no ceiling. Tiering puts a ceiling on it. You spread funds across a cold, a hot and a burner address according to how often the money moves and how much strangeness that address is allowed to touch, so one bad click can only empty one tier. This is not a wallet review. It covers what goes where, how to actually run a burner, and the five problems that only show up after you split.
⚠ Educational content only — not financial / investment / legal / security advice. On-chain transactions are irreversible, and a single bad signature can empty an entire address. Full disclosure → disclaimer.
You already have a wallet and your seed phrase is backed up, so none of that gets repeated here — if you need the groundwork first, start with self-custody wallet basics. This piece answers one narrower question: the coins are already in your own hands, so how should they be arranged across addresses?
Everything in one address is the most expensive default in crypto
Say the risk plainly first: while every coin you own sits in one address, the worst case of any single bad signature is your entire portfolio. It does not matter how expensive your wallet was or how long your password is. You clicked confirm yourself, and the chain does not accept "I didn't mean to" as an argument.
And this kind of mistake picks its moment. It happens at 1 a.m. when a mint is about to close, when a friend forwards a claim link that expires in an hour, when a domain you have used fifty times is spelled with one letter swapped. The judgement you bring to those thirty seconds is not the judgement you bring to a quiet afternoon reading documentation. Learning the phishing patterns is still worth it — they are catalogued in our wallet phishing defense guide — but staking your entire net worth on "I will spot it every single time" is a bet that you never have one bad night for the rest of your life.
Tiering assumes the opposite. It takes for granted that you will click the wrong thing eventually, and decides in advance how much that click is allowed to cost. I run three tiers myself, and the biggest change was not a feeling of being safer. It was that a suspicious link stopped making my pulse jump. The address my browser is connected to right now can be written off without it changing anything.
The three tiers are defined by what each is allowed to do, not by how safe it is
Plenty of people read cold and hot as "the secure wallet" and "the insecure wallet," and that reading makes them sort their funds wrong. The dividing line is which operations each tier is permitted to perform. A plain software wallet that you have decided will only ever receive and never connect to a site is functionally cold. A hardware device you plug in every evening to approve contracts you found on Twitter is functionally hot, whatever the box says.
| Tier | What lives here | Typical form | Allowed to do | Never does |
|---|---|---|---|---|
| Cold | Long-term holdings you have no plan to move soon | A hardware wallet, or a dedicated device with no extensions and no dApp connections | Receive; occasionally send a deliberate transfer down to the hot tier | Connect to any site, sign any approval, open any link someone sent you |
| Hot | The money you are actually using this month, capped at an amount you could lose in one go | A mobile wallet or a browser-extension wallet | Swaps, bridges, approvals for protocols you have used for a long time, everyday sending and receiving | Hold the portion whose loss would make you rethink your finances |
| Burner | Only the amount this one interaction needs, plus a little gas | A separate app or a separate browser profile, on its own seed phrase | Connect to a site you are seeing for the first time, mint, claim, poke at an unfamiliar interface | Hold anything overnight; keep being used after you signed something you did not understand |
The cold tier's keyword is stillness. The address itself can be public and receive funds all day; it is the key side that should stay away from anything networked. A hardware wallet is the mainstream way to do that. No brand or model is recommended here, but one rule is not negotiable: buy only from the manufacturer's own site or an officially authorized seller, and never use a device somebody handed you with the seed phrase already written down.
The hot tier's keyword is affordable. It is going to connect to applications and sign approvals — that is its job — so rather than trying to make it safe, control the number instead. The ceiling on your hot balance is simply the amount you could lose to one misread signature without it changing your week. This is the tier that does your on-chain swaps and your cross-chain transfers, both of which involve handing contracts permissions, which is exactly why the balance stays small.
The burner's keyword is disposable. It goes and touches contracts you do not trust yet, on your behalf. It is supposed to get contaminated. That only works if there is nothing valuable inside it.
How much goes where: skip the percentages, use the sleep test
You will see ratios quoted everywhere — 90/10 cold to hot, or some 80/15/5 split across three tiers. I would not sort money that way, because the same percentage means completely different things at different portfolio sizes. Five per cent of a two-thousand-dollar stack barely covers gas for one mint. Five per cent of a two-hundred-thousand-dollar stack is an absurd amount to leave in an address that talks to strangers.
Ask three questions of each pile of money instead, and put it wherever the answer lands:
- If this went to zero tomorrow, would my life change? If yes — cold tier. Pull that out first, then talk about the rest.
- Will I genuinely touch this in the next week or two? If yes — hot tier. If no, get it out of the hot tier even if the amount is small, because anything sitting there is paying the daily exposure whether you use it or not.
- Am I about to point this at a contract I do not trust yet? If yes — move only the amount this interaction needs into the burner, and not a cent more.
I am not going to give you a dollar figure, because the right one depends on your income and on whether a loss would reach your rent. There is a crude test that works better than any ratio: say a number out loud, then finish the sentence — "and it is gone tomorrow." If nothing moves in your chest, that number is a reasonable ceiling for your hot tier. If you immediately start working out how you would earn it back, that money belongs in cold storage.
One tier gets forgotten in these discussions: an exchange account can legitimately hold part of the money you are not moving. Not your keys, not your coins is a useful maxim, not a religion, and the honest version of it is that custody risk and self-custody risk are different risks rather than one being universally smaller. What it does mean is that when you do withdraw, withdrawing in batches by destination tier is much less painful than untangling it later; network selection and the small-test-first routine are covered in withdrawing from an exchange to your own wallet.
Running a burner properly: create, use, retire
The burner is the easiest tier to describe and the easiest one to get wrong. Its whole life is three steps.
Create. Install an app you do not use day to day, or open a separate browser profile, and generate a brand-new seed phrase — the next section explains why brand-new is not optional. Give it a name you can recognise in a fraction of a second. Do not let it sit in the account switcher looking like a slightly different version of your main account, because signing from the wrong account is a real and frequent accident, not a theoretical one.
Use. Fund it immediately before you connect to the unfamiliar site, never in advance. Send the amount this interaction needs plus enough native token for a few transactions, get what you came for, and sweep the remainder back out. The balance should ebb and flow like a tide rather than quietly accumulate. And if the site asks for an approval you cannot read, the situation is actually easy: there is almost nothing in there, so write the address off and walk away.
Retire. You cannot delete an address from a blockchain, so retiring one is purely a decision you make and keep: nothing of value ever goes to this address again. Before you call it done, confirm on a block explorer that the balance really is zero — native token and tokens are listed separately, and the reading method is in how to read a transaction on a block explorer. Then write the address into a retired list, so that six months from now you do not paste it into a withdrawal form out of muscle memory.
Four ways people misuse a burner:
- Overfunding it. The classic is topping it up far beyond what a mint needs, in case the price goes up or gas spikes. The burner's entire protective value comes from the balance being small; overfund it and you have simply created a second hot wallet with worse hygiene.
- Signing a standing approval and then carrying on with it. Once it has granted an allowance you did not fully read, it should be retired. Continuing to send funds there re-arms that approval every time. If you insist on keeping the address in service, clear the allowances first — the procedure is in the token approval and revoke guide.
- Farming everything from one burner. After a year of claims and interactions, that address is a high-value target with a long, public history — but it is still named burner in your wallet and still being treated as scratch paper. Rotate to a new one on a schedule.
- Keeping its seed phrase in a notes app. The reasoning is that it is a throwaway account, which is true right up until the evening you send it an amount that is not throwaway. Every seed phrase you generate gets backed up the same way, no exceptions.
One honest trade-off, and it is the real cost of this whole approach: a lot of airdrops are allocated on an address's interaction history. Interact through a burner and the eligibility lands on the burner, not on you. There is no clever way around it. Either you accept that some allocations will be missed, or you let your main address carry the risk of unfamiliar contracts. I take the first option, but I am not going to pretend it is free.
Three accounts from one seed phrase are not three tiers
The extra accounts you get by clicking "add account" inside one wallet app are not isolated from each other. Multi-account support in mainstream wallets derives every one of those addresses from the single seed phrase you wrote down. BIP-32 defines how one seed produces an entire tree of keys; BIP-44 adds the account level on top of it so that funds from different accounts are not mixed together. That phrase — not mixed together — is bookkeeping separation, not cryptographic isolation. There is still exactly one seed, and whoever gets it gets the whole tree at once.
Which turns into one concrete requirement: the cold tier must run on its own independent seed phrase, not on an account created inside your main wallet. This is the single point in this article I will not soften. Get it wrong and every tier you built collapses simultaneously on the day that phrase leaks, while you spend the whole time believing you had separated things.
The hot tier and the burner leave you some room. The strictest arrangement is three tiers on three independent seed phrases. A more manageable one is a seed for hot, a seed for burners, and a seed for cold. What is never acceptable is a burner and the cold tier sharing a seed. This is also the reason phishing pages are so single-mindedly obsessed with getting you to type a seed phrase into a recovery form: a stolen private key costs you one address, and a stolen seed phrase costs you the entire set in one move.
Five things that get harder after you split
Tiering introduces its own set of problems. Every one of these appears only after you have separated your funds, which is why nobody warns you about them beforehand.
Problem 1: a brand-new address has no native token, so the tokens you sent are stuck
This is the wall people hit on day one. You send USDT to a fresh address, the balance shows up, and it will not move. Every on-chain operation costs a fee, and that fee has to be paid in the chain's native token — ETH on Ethereum, and its equivalent elsewhere. A new address has zero of it, so your tokens are visible and immovable at the same time. The fix is trivial once you know it: send a little native token first, then send the tokens. If the wallet interface is confusing you, look the address up on a block explorer instead, where the native balance and the token balances are listed in separate places.
Problem 2: one backup becomes three
This is the honest cost of tiering. You used to protect one piece of paper; now there are three, and you also have to remember which one belongs to which tier. Copying a word wrong, storing one in the wrong place, or hiding one so well that you cannot find it again produces exactly the same result as being robbed. What works: three separate physical locations, each sheet labelled with its tier, and no sheet containing any hint about where the other two are. Also, every new seed phrase gets a recovery rehearsal before it holds anything — uninstall the wallet, reinstall it, import from the phrase, confirm the same address comes back. Fund it only after that.
Problem 3: moving funds between tiers links them on-chain
Every transfer you make is public. Cold to hot, hot to burner — anyone with a block explorer can see those edges. Tiering separates financial risk, not identity. If somebody already knows one of your addresses, whether because you posted it or because they once sent you funds, walking the transaction graph to your other two tiers usually takes no skill at all. Accepting this is more useful than fighting it: the goal here is capping a loss, not anonymity, and anonymity is a much harder discipline with a completely different rulebook.
Problem 4: the cold tier gets so cold you cannot use it
Cold storage rarely fails by being insufficiently secure. It fails by becoming unusable: the device is stored somewhere far away, it has not been powered on in a year, its firmware stopped updating two versions ago, and you have never once rehearsed sending funds out of it. Then the day comes when you actually need it, and you discover the battery has swollen or the app demands an update before it will sign anything. Treat the cold tier as equipment that needs servicing: power it on periodically, confirm it boots and can still sign, and walk a small transfer from cold down to hot from start to finish at least once. Do not let the first real attempt happen on the day you are in a hurry.
Problem 5: you split the funds but kept the same signing habits
The last one is psychological. Some people get noticeably more careless after tiering — it is only the hot wallet, so who cares what I sign. But the hot wallet usually holds several weeks of working capital. Tiering changes the maximum size of a loss; it does not change the standard you hold yourself to. Signatures you cannot read still get refused, gas-free signature requests still get a second look, and allowances still get cleared out on a schedule.
A five-step tiering checklist
Set aside half an hour and do it in one sitting:
- [ ] List every holding you currently have and ask of each one: if this went to zero tomorrow, would my life change? Everything that gets a yes goes cold
- [ ] Put the cold tier on an independent seed phrase, not an account created inside your main wallet, and rehearse recovery on it before funding it
- [ ] Set a ceiling for the hot tier using one standard: I could lose all of this to one misread signature and still be fine. Move the excess to cold
- [ ] Create a burner: separate app or separate browser profile, its own seed phrase, an unmistakable name, emptied after every use
- [ ] Fund every new address with a little native token before sending any tokens, then verify the balance on a block explorer
One-line rule: sort funds by what you could stand to lose, sort operations by what you are willing to connect to, and keep the cold tier on its own seed.
FAQ · six questions people actually ask
What is the actual difference between a cold wallet and a hot wallet?
Two things: whether the private key is ever exposed to a networked environment, and what you allow that address to do. A hot wallet, meaning a mobile or browser-extension wallet, keeps its key on an internet-connected device so you can sign and connect to dApps whenever you like; the price is that a compromised device or one wrong signature exposes the funds directly. A cold wallet keeps the key offline, most commonly on a hardware wallet where signing happens inside the device. But the thing that really decides cold or hot is your usage discipline. A software wallet that only ever receives and never connects to a site is functionally cold, and a hardware device you use every night to approve unfamiliar contracts is not meaningfully cold at all.
I only have a few hundred dollars in crypto. Do I really need three wallets?
Not three, but at least two. At small balances, splitting into an everyday hot wallet plus a burner reserved for unfamiliar sites already blocks the most common category of loss, and it costs you nothing but a few minutes. The cold tier can wait until you hold something you have specifically decided not to touch for a while and would hate to lose; that is also the point at which buying a hardware wallet starts to make sense. Having a small balance is not a reason to skip this. Phishing kits scan addresses in bulk and do not check your net worth before targeting you.
Do I need to destroy a burner wallet after using it, and how?
An address cannot be deleted from a blockchain, so destroying one is really just a decision you commit to: empty it, and never send anything of value to it again. In practice that means sweeping the funds out, confirming on a block explorer that the balance is genuinely zero with the native token and the tokens checked separately, and then writing the address into a retired list so you do not accidentally reuse it as a receiving address months later. If you signed an approval on it that you could not read, retiring it is not optional. Spinning up a replacement burner costs essentially nothing.
Does creating extra accounts in the same wallet app count as splitting my funds?
Not in any security sense. Multi-account support in mainstream wallets derives every account from the same seed phrase: BIP-32 describes how one seed generates an entire tree of keys, and BIP-44 adds the account level on top of it. What that gives you is bookkeeping separation, so funds from different accounts do not get mixed together, and not cryptographic isolation. There is still only one seed, and if it leaks, every account under it falls at the same moment. That is why the cold tier has to run on its own independent seed phrase rather than on an account created inside your main wallet.
Do I have to buy a hardware wallet for the cold tier?
A hardware wallet is the least troublesome way to do it, but it is not the only option. A workable compromise is a spare phone kept as a near-cold device: factory reset it, install only the wallet app, add no extensions, connect it to no dApps, and keep it powered off or offline except when receiving or making a rare outbound transfer. Be clear with yourself that this is a compromise. The key still lives on a general-purpose operating system, which is not equivalent to a dedicated signing device. If the size of your long-term position has started to bother you at night, that is the signal to buy hardware, and when you do, buy only from the manufacturer or an officially authorized seller.
If I send funds from my burner back to my main wallet, does that link the two addresses?
Yes, and the link is permanently searchable. Every transfer is public, so once two addresses have sent value directly to each other, anyone with a block explorer can see that edge. Tiering isolates financial risk, not identity. If somebody already recognizes one of your addresses, following the transaction graph to the other one is usually trivial. The practical response is to accept it rather than fight it: avoid publishing your addresses, and do not mistake a tiered setup for an anonymity setup, which is a much harder problem with different tools.
Sources cited
- BIP-32, hierarchical deterministic wallets (one seed derives the whole key tree) · github.com/bitcoin/bips · bip-0032
- BIP-39, the mnemonic seed phrase standard · github.com/bitcoin/bips · bip-0039
- BIP-44, multi-account hierarchy (the account level and the original not-mixed-together wording) · github.com/bitcoin/bips · bip-0044
- ethereum.org · wallet types and hardware wallets · ethereum.org/en/wallets
- ethereum.org · gas and fees overview (fees are payable only in the native token) · ethereum.org/en/developers/docs/gas
- ethereum.org · security and scam-avoidance guidance · ethereum.org/en/security