WATS Wallet logoWATS Wallet
Guide8 min read

How to Keep Control of Your Crypto Keys While Using a Hot Wallet

A hot wallet can still be self-custody — if you keep the keys. Here's how key ownership actually works online, and the habits and hardware that keep it that way.

To keep control of your crypto keys while using a hot wallet, do three things: choose a non-custodial hot wallet (one where you, not a company, hold the private keys), protect the recovery method (usually a seed phrase stored offline), and add a hardware factor so nobody can move funds with your password alone. A hot wallet is simply a wallet connected to the internet — that says nothing about who owns the keys. The trap is assuming "online wallet" means "someone else holds your keys." It only does if the wallet is custodial.

Custody is the whole question. An exchange app is technically a hot wallet, but you do not hold its keys — the exchange does. A non-custodial wallet like the WATS Hot Wallet, MetaMask, Phantom, or Trust Wallet gives the keys to you. Below we explain exactly what "keeping your keys" means, how custodial and non-custodial hot wallets differ, the six steps to stay in control, and the hardware factors — including newer models like MPC and dual custody — that keep your keys yours even when you're transacting online every day.

What "keeping your keys" actually means

In crypto, whoever controls the private key controls the funds. "Not your keys, not your coins" is not a slogan — it is a literal description of how blockchains work. The key is what signs transactions; the address on-chain is derived from it. If someone else can produce a valid signature for your address, they can spend your assets, full stop.

A seed phrase (usually 12 or 24 words) is a human-readable backup of the master key. From those words, your wallet can regenerate every private key and address it manages. That is why the seed phrase is the crown jewel: anyone with it has your wallet, and losing it with no backup means the funds are gone forever with no support line to call.

"Keeping your keys" therefore means one of two things. In the classic model, you and only you hold the seed phrase, and no third party can sign on your behalf. In newer models, the raw single seed is replaced by something split or shared — MPC key shares, or dual custody — so that no single party (including a custodian) can move funds alone. Both count as keeping control. What does not count is handing your assets to a company that holds the keys for you and lets you log in with a password. That is custody, and it is a fundamentally different trust model.

Custodial vs non-custodial hot wallet

A hot wallet is any wallet whose keys live on an internet-connected device — a browser extension, a phone app, or a web wallet. Speed and convenience are the point: you can connect to a dApp, swap, or send in seconds. The trade-off, versus cold storage, is a larger attack surface, because the signing key touches an online environment.

The critical distinction is custody, and it cuts across the hot-wallet category:

 Custodial hot walletNon-custodial hot wallet
Who holds the keysThe company / exchangeYou (or your key + a co-signer)
Recovery methodPassword reset, support ticket, KYCSeed phrase, key shares, or hardware factor
Can you be frozen or blockedYes — the custodian controls accessNo — signing is in your hands
Who to blame if hackedThe custodian's securityYour device and habits
ExamplesExchange app / web loginWATS, MetaMask, Phantom, Trust Wallet

An exchange app is the clearest example of a custodial hot wallet. It is connected to the internet and lets you send crypto, so it behaves like a wallet — but the exchange holds the keys, can freeze the account, and can be compelled to. You trust the institution. That is a valid choice for some people, but it is not keeping your keys.

A non-custodial hot wallet puts the keys on your device. MetaMask is the reference example on EVM chains and dApp signing; Phantom leads on Solana and now spans major EVM chains; Trust Wallet is broad and mobile-first; Rabby adds pre-transaction risk checks. The WATS Hot Wallet is a browser-based web wallet that swaps and bridges across EVM, Solana and TON, and charges every action — swap, transfer, staking — in a single fee token, ATS, instead of juggling each chain's native gas. In all of these, you control signing. Nobody can freeze you, and nobody can recover your funds for you either. That symmetry — full control, full responsibility — is the deal you accept to keep your keys.

A precise word on MPC — and where WATS stands

MPC keeps you in control without handing you a single raw seed to guard alone, and it's worth being exact about how it works — and about how WATS differs — so you don't mistake one model for the other.

MPC (multi-party computation) splits the key into shares held in different places, so a full private key never exists in one spot. Zengo is a well-known keyless/MPC mobile wallet: there is no seed phrase to steal, and signing requires cooperation between shares. You keep control because no single share is enough to move funds.

The WATS Hot Wallet is fully non-custodial: you hold your own private keys and your own seed phrase, and WATS never holds a key. It is classic single-key self-custody — WATS cannot sweep your wallet, freeze it, or recover it for you, because it has nothing to sign with. The hardware security WATS offers sits alongside the keys, not inside them: the WATS NFC Metal Card is a tap-to-authenticate factor that pairs with a single device in the mobile app and stores no private keys, so you add a physical-presence check without ever splitting control of your seed. You carry the full responsibility of a single seed — and, in exchange, nobody else can ever sign on your behalf.

The steps to keep your keys

Here is the practical checklist. Follow it in order the first time you set up a non-custodial hot wallet, and revisit steps 5 and 6 as your holdings grow.

1) Pick a non-custodial hot wallet

Confirm the wallet is non-custodial before you fund it. The tell: during setup it shows you a seed phrase (or sets up MPC key shares / a co-signing model), rather than asking you to create an account with just an email and password. If recovery is "reset your password," it is custodial. Match the wallet to your chains and habits — MetaMask or Rabby for heavy EVM dApp use, Phantom for Solana, or the WATS Hot Wallet if you want EVM, Solana and TON in one place with single-token fees.

2) Record and store the seed phrase offline

When the wallet reveals your seed phrase, write it on paper or stamp it into metal. Never photograph it, never paste it into notes, cloud storage, email or a password manager, and never type it into any website. Store the backup somewhere private and, ideally, keep a second copy in a separate location so one fire or theft can't erase it. (If you chose an MPC wallet with no seed, follow that app's specific backup flow instead.)

3) Verify you can recover

Before you move meaningful funds in, test recovery. Remove the wallet or use a spare device, then restore from your written seed and confirm the same address appears. This proves you copied the words correctly and understand the process, so you are not discovering a transcription error during an emergency.

4) Add a hardware or biometric factor

Add a second factor so a stolen password or an unlocked laptop isn't game over. Turn on biometric unlock (Face ID / fingerprint) in a mobile wallet such as the WATS Mobile App. Pair a hardware signer for high-value activity, or use a tap-to-sign companion like the WATS NFC Metal Card — a physical card you tap to authenticate an action, which does not store your keys but does require your physical presence to approve it.

5) Keep large holdings in cold storage

A hot wallet is for spending money, not savings. Keep the bulk of your assets in cold storage — a hardware wallet like Ledger, or a key-storing NFC cold card like Tangem — and leave only what you actively trade or spend in the hot wallet. If the hot device is ever compromised, your losses are capped at the hot balance.

6) Revoke approvals and dodge phishing

Most hot-wallet losses come from signing, not from cracked keys. Periodically review and revoke token approvals you no longer use, so a stale permission can't drain a token later. Bookmark real dApp URLs, ignore "support" DMs, and read every signature request — if a transaction looks like it grants sweeping access, reject it.

Hardware factors that reinforce a hot wallet

Hardware doesn't only mean going fully cold. Several devices strengthen a hot wallet without giving up its convenience, and they work in different ways — so it helps to know which does what.

  • Hardware wallets (Ledger, and similar): the private key lives on the device and never touches your online computer. You pair it with a hot wallet like MetaMask and physically confirm each transaction on the device. This is the strongest factor for large balances.
  • NFC cold cards (Tangem, Arculus): these store keys on the card and sign offline — they are cold storage in card form, seedless in Tangem's case. Tap to sign; the key never leaves the card.
  • Tap-to-authenticate companions (WATS NFC Metal Card): a different category. The WATS NFC Metal Card does not store private keys and is not a cold wallet — it is a durable steel companion (IP68 waterproof, MIL-STD-810 rated, AES-128, NTAG 216) that you tap to authenticate an action, adding a physical-presence factor to your mobile wallet. It complements your key security; it doesn't replace your key storage.
  • Biometrics: Face ID or a fingerprint on a mobile wallet gates access to the signing key on that device. It's not a substitute for a seed backup, but it stops casual access if your unlocked phone is grabbed.

The distinction matters because it's easy to over-trust a card. A key-storing cold card (Tangem) is genuinely holding your keys offline. A tap-to-authenticate companion (the WATS card) is a presence check layered on a hot wallet whose keys live elsewhere. Both are useful; they are not the same thing, and you shouldn't treat one as if it were the other.

Bottom line

You can absolutely keep your keys while using a hot wallet — the word "hot" describes connectivity, not custody. Choose a non-custodial wallet, back up the seed offline (and verify you can restore it), add a hardware or biometric factor, keep the bulk of your net worth in cold storage, and stay disciplined about approvals and phishing. If you'd rather not shoulder a single raw seed alone, an MPC wallet like Zengo splits the key into shares so there's no single seed to guard. The WATS Hot Wallet takes the classic route — it is fully non-custodial, so you hold your own keys and seed phrase and WATS never holds a key, and control never leaves your hands. Pick the model that matches how much responsibility you actually want to carry, and your hot wallet stays genuinely yours. For more on the underlying concepts, see what a non-custodial wallet is and hot wallet vs cold wallet.

Frequently asked questions

Is a hot wallet the same as a custodial wallet?

No. "Hot" only means the wallet is connected to the internet; it says nothing about who holds the keys. A hot wallet can be non-custodial (you hold the keys, like MetaMask, Phantom or the WATS Hot Wallet) or custodial (a company holds them, like most exchange apps). The custody model, not the connectivity, decides whether you're actually keeping your keys.

Can I keep control of my keys without memorizing or storing a seed phrase?

Yes — MPC wallets such as Zengo split the key into shares, so there is no single seed to store and no single share can move funds alone. Don't lump every wallet into that model, though: the WATS Hot Wallet is fully non-custodial single-key self-custody — you hold your own keys and seed phrase, and WATS never holds a key — so with WATS you do keep and back up a seed. MPC is the route to take if you specifically want to avoid guarding one raw seed yourself.

Does the WATS NFC Metal Card store my private keys?

No. The WATS NFC Metal Card is a tap-to-authenticate companion, not a cold wallet — it does not store private keys. You tap it to add a physical-presence factor when approving an action in your mobile wallet. If you want a card that actually stores keys and signs offline, that's a cold NFC card like Tangem, which is a different category of device.

How much crypto should I keep in a hot wallet?

Only what you actively spend, trade, or need for dApps and gas — treat it like the cash in your pocket rather than your savings account. Keep the bulk of your holdings in cold storage such as a hardware wallet (Ledger) or a key-storing NFC cold card (Tangem). That way, if the hot device is ever compromised, your losses are capped at the small balance you keep online.