A wallet does not store coins, since they are recorded on the blockchain. It stores the keys that give you the right to move them. So the security question comes down to one thing: does the key touch the internet.
Cold
The key never leaves the device. A transfer is signed inside it, and only the finished signature comes out. Malware on your computer cannot reach the key, but losing the device together with the written down seed phrase means losing the funds for good.
Hot
The key sits on your phone or in your browser. That is fast and convenient for everyday amounts, but any program that gains access to the device gains access to the funds.
How people usually split them
Savings in cold storage, working amounts in a hot wallet. Much the same way nobody carries all their cash around.
The seed phrase matters more than the device
When you set it up, the wallet shows you twelve or twenty four words. That is the access to your funds: the device can be lost and everything restored from the phrase, but lose the phrase along with the device and nothing can be restored.
Write the phrase on paper and keep it apart from the device. A screenshot in your phone gallery or a note in the cloud turns a cold wallet into a hot one, stripping it of its only purpose.
A wallet on an exchange is a third case
It is not your wallet at all: the platform controls the keys and shows you an entry in its database. That is fine for trading, but not for storage.
Hence the rule repeated after every exchange collapse: keep on the platform exactly as much as you intend to exchange in the near future.
Read more: Hardware wallet or phone: where to keep your savings