Crypto wallets and private keys, explained
A crypto wallet stores your keys, not your coins. Whoever holds the private key controls the crypto. According to the SEC and NIST, a lost private key cannot be replaced, so the assets are lost for good. If a platform holds your keys, its hacks or failure become your risk.
What does a crypto wallet actually hold?
The name is misleading. Your coins are not stored inside a wallet app the way cash sits in a leather wallet. Ownership is recorded on a blockchain. What a wallet holds, in NIST’s words, are “private keys, public keys, and associated addresses” — and it may also show you a total of your holdings.
- Private key: a secret number that lets you authorise moving the crypto linked to it. Treat it like the only key to a safe that has no locksmith.
- Public key and address: derived from the private key; you can share an address so people can send you crypto.
What happens if you lose your private key?
You lose the crypto. NIST explains that it is “computationally infeasible to regenerate the same private key”, so the assets tied to it are gone. The SEC puts it plainly: a private key cannot be changed or replaced, and if you lose it, you permanently lose access. EU supervisors describe the loss as “permanent and irreversible”.
There is no “forgot password” button and no customer service that can reset it. This is the single biggest difference between crypto and a bank account.
What is a seed phrase?
The SEC describes a seed phrase (sometimes called a recovery phrase) as a random sequence of words that can restore a wallet if the wallet or key is lost. Because it can recreate your keys, anyone who sees your seed phrase can take your crypto.
- Never type it into a website, a chat or an email.
- Never share it with “support staff” — the SEC’s guidance is never to share private keys or seed phrases with anyone.
- Store it offline, somewhere it cannot be lost, damaged or photographed.
What is the difference between self-custody and platform custody?
The SEC defines custody as “how and where you store and access your crypto assets”. There are two broad options:
| Self-custody | Third-party (platform) custody | |
|---|---|---|
| Who holds the keys | You alone | The platform |
| Main risk | You lose the key or seed phrase, or your device is stolen, damaged or hacked | The platform is hacked, shuts down or goes bankrupt and you lose access |
| Other risks the SEC names | Mistakes are permanent | Your assets may be lent out as collateral (rehypothecation) or pooled with other customers’ assets (commingling) |
The SEC has also warned that people who deposit crypto with a platform “might cease to have legal ownership” of it if the platform fails. Neither option is risk-free; they move the risk to different places.
Hot wallet or cold wallet — which is safer?
The SEC draws the distinction this way:
- Hot wallets are connected to the internet — convenient for frequent use, but exposed to cyber threats.
- Cold wallets are offline devices — harder to hack remotely, but they can be physically lost or damaged.
NIST notes that many users keep their keys on special secure hardware. Whatever you use, the seed phrase backup is what protects you if the device fails.
How do scammers try to steal wallet keys?
Because a key gives total control and transfers generally cannot be undone, criminals go after the key rather than the blockchain. Typical approaches include fake “wallet support” agents asking for your seed phrase, phishing sites that copy real wallet apps, and messages pressing you to “verify” or “sync” your wallet. The SEC’s tips: watch for phishing, keep your holdings private, use strong passwords and multi-factor authentication, and never share keys or seed phrases. See our full list of crypto scam red flags.
A beginner’s wallet safety checklist
- Decide who will hold the keys — you or a platform — and understand the risk you are taking on.
- If you self-custody, write the seed phrase down offline and keep it somewhere safe and private.
- If you use a platform, research it first and check whether it is authorised in your country (see Safety).
- Turn on multi-factor authentication everywhere.
- Test with a small amount before moving anything larger — mistakes cannot be reversed.
- Only put in money you could afford to lose entirely. UK regulators say you should be prepared to lose all of it.
Frequently asked questions
Are my coins inside my wallet app?
No. The coins are recorded on the blockchain. The wallet holds the keys that let you move them.
Can a wallet provider reset my private key?
No. The SEC says a private key cannot be changed or replaced once created. Only your seed phrase backup can restore access.
Is crypto on an exchange legally mine?
Not necessarily. The SEC has warned that customers who deposit assets with a crypto platform might cease to be the legal owners if the platform fails.
Is a cold wallet completely safe?
No. It is offline, which reduces hacking risk, but the SEC notes it can be lost or damaged. You still need a secure backup of the seed phrase.
Sources
- SEC Office of Investor Education and Assistance, 12 Dec 2025 — Crypto Asset Custody Basics for Retail Investors – Investor Bulletin — investor.gov (accessed 2026-10-02)
- NIST (Yaga, Mell, Roby, Scarfone), Oct 2018 — NISTIR 8202 Blockchain Technology Overview — nvlpubs.nist.gov (accessed 2026-10-02)
- SEC / Investor.gov, 23 Mar 2023 — Exercise Caution with Crypto Asset Securities: Investor Alert — investor.gov (accessed 2026-10-02)
- EBA/ESMA/EIOPA, 2025 — Joint ESAs Warning on crypto-assets — eiopa.europa.eu (accessed 2026-10-02)
- FCA, last updated 29 Jan 2026 — Crypto: The basics — fca.org.uk (accessed 2026-10-02)