Hardware wallet or phone: where to keep your savings

The question is not which is safer in general, but how much you hold and how often you touch it. A hardware wallet removes exactly one class of threats: access to your key from an infected computer or phone.

The key never leaves the chip, so a virus that sees your entire screen and every file still does not see the key itself. Three other ways to lose funds remain untouched by hardware: blind signing, a tampered device bought from the wrong place, and phishing dressed up as support. None of the three is cured by buying a more expensive model.

So the real choice is not between devices but between jobs: savings and spending money are kept apart.

What hardware actually gives you

A hardware wallet isolates the private key from the network. The words are generated inside the device, the key is derived there too, and it is never sent outside.

When you sign a transfer of cryptocurrency, the app on your computer builds the transaction, hands it to the device, and the signing happens inside the chip. The computer gets back a signed transaction, never the key.

That is what makes this kind of wallet cold. The practical difference shows up in a simple scenario: if your working laptop is infected, a hot wallet on it empties out the moment you unlock the app.

A hardware wallet does not empty out, because the key was never on the laptop. All an attacker can do is push a transaction at you to sign. And that is where the second half of this conversation starts.

What hardware does not give you

First and most important: blind signing. The device shows raw data instead of the meaning of the transaction, and a person confirms a transfer without seeing either the amount or the recipient address.

This is the main way people with hardware still lose funds, and manufacturers admit it openly: Ledger promotes clear signing precisely as an answer to this hole. Which means the readability of a transaction depends on the app, not on the device. We covered the limits of that protection separately: what a hardware wallet protects and what it does not.

Second: a tampered device at purchase. A genuine wallet never ships with a ready-made recovery phrase or a PIN already inside a sealed box. That is the manufacturer's own wording.

An unpleasant detail: the built-in chip authenticity check does not detect physical modifications to the hardware, and the manufacturer admits that too. So buying secondhand, from a classified ad or from a random marketplace seller is a separate risk that has nothing to do with the quality of the model.

Third: phishing dressed up as support. It feeds on leaked contact databases. In 2020 Ledger's marketing database was published: around 1.1 million email addresses and 272,000 records with names, phone numbers and home addresses. In January 2026 there was a breach at payment partner Global-e, with the number of affected customers undisclosed.

The consequence was predictable: in 2025 owners received paper letters on official letterhead with a QR code leading to a cloned site that asked them to enter their words. Neither Ledger nor Trezor ever asks for a recovery phrase.

The Ledger Recover episode of May 2023 belongs here too. The outrage was not about the cloud backup service itself but about what support conceded: it had always been technically possible to write firmware that extracts the key. The argument was never about a hack, it was about the trust model turning out to be different from what buyers assumed.

The phone: convenience and the cost of a mistake

An app holding a key on your phone is a hot wallet, whatever it calls itself. Being non-custodial has nothing to do with it: that only means the key is yours and not the company's.

If the key sits on a device that is online every day, installs updates, opens links and runs messengers, then the key is online. The words cold mode in an app's name do not change that.

The price of convenience is not the phone itself, it is the cost of a mistake. One bad tap on a fake app from an ad, one pasted-from-clipboard wallet address swapped out by malicious code, one backup of your notes to the cloud, and the money is not coming back.

With a thousand hryvnia that is an annoyance. With several years of savings it is a different kind of event.

A word on the built-in swap feature in apps like Exodus: the fee is baked into the rate rather than shown as a separate line. Officially from 0.5%, in practice noticeably higher depending on the pair and the amount.

That is not deception, but what you compare is the final amount you receive, not the advertised percentage. We are an exchange service, so we have our own interest here, and that is exactly why we keep it simple: count what actually arrived.

How to split by purpose

The same way nobody carries all their cash around. Your spending balance is what you use this month: payments, swaps, small transfers. You keep it where it is convenient, meaning on your phone, and you knowingly accept the risk within that amount.

Savings, the money that sits still, are kept separately, and the main property of that wallet is not speed but the fact that it is rarely touched.

Everyone draws the line for themselves, but the guide is simple: if losing the amount would change your plans for the year, it should not sit on the device you read email on. And the other way round, hauling out hardware for two hundred dollars of turnover means spending money and time defending against a threat that cannot afford you.

How to split the amounts in practice

Start with a monthly figure, not a percentage. Look at what you actually spent on swaps and transfers over the past two or three months, and take the largest of those months. That is your spending balance, and it lives on the phone.

Everything above that figure moves to a separate wallet. Not part of it, not half of it, but the whole remainder: the point of the split is that the everyday device holds nothing whose loss would change your year.

Top up the spending wallet from savings, not the other way round. One transfer a month towards the phone means one operation in which you touch the cold device. The reverse pattern, with money moving back and forth constantly, cancels the split out.

Before the first large transfer, send a test one for the minimum amount and wait for it to arrive. That checks the address, the network, and whether you can actually see the balance on the new wallet. Picking the wrong network on a test transfer costs a few dollars, on the real one it costs everything.

Test recovery right after setup. Reset the device to factory settings and restore the wallet from the words you wrote down, while there is still no meaningful amount on it. A phrase you have never used once is an assumption, not a backup.

A third wallet is rare but sometimes sensible: a separate address for receiving funds from other people, tied to neither the spending nor the savings side. It is useful for anyone who takes payments regularly and would rather not show a counterparty their whole turnover.

What matters more than the choice of device

The recovery phrase. The device is secondary: it can break, get soaked or get lost, and the wallet is restored on a new one from the same words.

Losing the phrase along with the device means losing the funds for good, because there is no participant in the system with the technical ability to return them.

Manufacturers agree on storage: offline only, no photos, never typed into a computer or phone, never kept in the cloud. The medium is paper or a steel backup, stored apart from the device itself.

Any request for your phrase, PIN or password, no matter who it comes from, is fraud by definition. We went through storage methods and their weak points in detail: how to store a recovery phrase.

The summary is short. Hardware closes one hole, and closes it well. The rest is closed by the habit of reading what you sign, buying the device from the manufacturer, never entering your words at a stranger's request, and keeping savings apart from everyday money.

Author: MW ExchangeUpdated
01

Read next