[{"data":1,"prerenderedAt":41},["ShallowReactive",2],{"blog-content-en-keep-your-keys-using-a-hot-wallet":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9,"howToSteps":22},"keep-your-keys-using-a-hot-wallet","How to Keep Control of Your Crypto Keys While Using a Hot Wallet","A hot wallet can still be self-custody — if you keep the keys. Here's how key ownership actually works online, and the habits and hardware that keep it that way.","How to keep control of your crypto keys while using a hot wallet: self-custody vs custodial, seed-phrase hygiene, hardware factors and dual custody, explained step by step.","\u003Cp>To keep control of your crypto keys while using a hot wallet, do three things: \u003Cstrong>choose a non-custodial hot wallet\u003C\u002Fstrong> (one where you, not a company, hold the private keys), \u003Cstrong>protect the recovery method\u003C\u002Fstrong> (usually a seed phrase stored offline), and \u003Cstrong>add a hardware factor\u003C\u002Fstrong> so nobody can move funds with your password alone. A hot wallet is simply a wallet connected to the internet — that says nothing about who owns the keys. The trap is assuming \"online wallet\" means \"someone else holds your keys.\" It only does if the wallet is custodial.\u003C\u002Fp>\u003Cp>Custody is the whole question. An exchange app is technically a hot wallet, but you do \u003Cem>not\u003C\u002Fem> hold its keys — the exchange does. A \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-non-custodial-wallet\">non-custodial wallet\u003C\u002Fa> like the \u003Ca href=\"\u002Fhot-wallet\">WATS Hot Wallet\u003C\u002Fa>, MetaMask, Phantom, or Trust Wallet gives the keys to you. Below we explain exactly what \"keeping your keys\" means, how custodial and non-custodial hot wallets differ, the six steps to stay in control, and the hardware factors — including newer models like MPC and dual custody — that keep your keys yours even when you're transacting online every day.\u003C\u002Fp>\u003Ch2>What \"keeping your keys\" actually means\u003C\u002Fh2>\u003Cp>In crypto, whoever controls the private key controls the funds. \"Not your keys, not your coins\" is not a slogan — it is a literal description of how blockchains work. The key is what signs transactions; the address on-chain is derived from it. If someone else can produce a valid signature for your address, they can spend your assets, full stop.\u003C\u002Fp>\u003Cp>A \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-seed-phrase\">seed phrase\u003C\u002Fa> (usually 12 or 24 words) is a human-readable backup of the master key. From those words, your wallet can regenerate every private key and address it manages. That is why the seed phrase is the crown jewel: anyone with it has your wallet, and losing it with no backup means the funds are gone forever with no support line to call.\u003C\u002Fp>\u003Cp>\"Keeping your keys\" therefore means one of two things. In the classic model, \u003Cstrong>you and only you hold the seed phrase\u003C\u002Fstrong>, and no third party can sign on your behalf. In newer models, the raw single seed is replaced by something split or shared — MPC key shares, or dual custody — so that no single party (including a custodian) can move funds alone. Both count as keeping control. What does \u003Cem>not\u003C\u002Fem> count is handing your assets to a company that holds the keys for you and lets you log in with a password. That is custody, and it is a fundamentally different trust model.\u003C\u002Fp>\u003Ch2>Custodial vs non-custodial hot wallet\u003C\u002Fh2>\u003Cp>A \u003Cstrong>hot wallet\u003C\u002Fstrong> is any wallet whose keys live on an internet-connected device — a browser extension, a phone app, or a web wallet. Speed and convenience are the point: you can connect to a dApp, swap, or send in seconds. The trade-off, versus \u003Ca href=\"\u002Fblog\u002Fhot-wallet-vs-cold-wallet\">cold storage\u003C\u002Fa>, is a larger attack surface, because the signing key touches an online environment.\u003C\u002Fp>\u003Cp>The critical distinction is \u003Cem>custody\u003C\u002Fem>, and it cuts across the hot-wallet category:\u003C\u002Fp>\u003Ctable>\u003Cthead>\u003Ctr>\u003Cth>&nbsp;\u003C\u002Fth>\u003Cth>Custodial hot wallet\u003C\u002Fth>\u003Cth>Non-custodial hot wallet\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd>Who holds the keys\u003C\u002Ftd>\u003Ctd>The company \u002F exchange\u003C\u002Ftd>\u003Ctd>You (or your key + a co-signer)\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Recovery method\u003C\u002Ftd>\u003Ctd>Password reset, support ticket, KYC\u003C\u002Ftd>\u003Ctd>Seed phrase, key shares, or hardware factor\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Can you be frozen or blocked\u003C\u002Ftd>\u003Ctd>Yes — the custodian controls access\u003C\u002Ftd>\u003Ctd>No — signing is in your hands\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Who to blame if hacked\u003C\u002Ftd>\u003Ctd>The custodian's security\u003C\u002Ftd>\u003Ctd>Your device and habits\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Examples\u003C\u002Ftd>\u003Ctd>Exchange app \u002F web login\u003C\u002Ftd>\u003Ctd>WATS, MetaMask, Phantom, Trust Wallet\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>An exchange app is the clearest example of a \u003Cstrong>custodial hot wallet\u003C\u002Fstrong>. It is connected to the internet and lets you send crypto, so it behaves like a wallet — but the exchange holds the keys, can freeze the account, and can be compelled to. You trust the institution. That is a valid choice for some people, but it is \u003Cem>not\u003C\u002Fem> keeping your keys.\u003C\u002Fp>\u003Cp>A \u003Cstrong>non-custodial hot wallet\u003C\u002Fstrong> puts the keys on your device. MetaMask is the reference example on EVM chains and dApp signing; Phantom leads on Solana and now spans major EVM chains; Trust Wallet is broad and mobile-first; Rabby adds pre-transaction risk checks. The \u003Ca href=\"\u002Fhot-wallet\">WATS Hot Wallet\u003C\u002Fa> is a browser-based web wallet that swaps and bridges across EVM, Solana and TON, and charges every action — swap, transfer, staking — in a single fee token, \u003Ca href=\"\u002Fats-fee\">ATS\u003C\u002Fa>, instead of juggling each chain's native gas. In all of these, you control signing. Nobody can freeze you, and nobody can recover your funds for you either. That symmetry — full control, full responsibility — is the deal you accept to keep your keys.\u003C\u002Fp>\u003Ch3>A precise word on MPC — and where WATS stands\u003C\u002Fh3>\u003Cp>MPC keeps you in control \u003Cem>without\u003C\u002Fem> handing you a single raw seed to guard alone, and it's worth being exact about how it works — and about how WATS differs — so you don't mistake one model for the other.\u003C\u002Fp>\u003Cp>\u003Cstrong>MPC (multi-party computation)\u003C\u002Fstrong> splits the key into shares held in different places, so a full private key never exists in one spot. Zengo is a well-known keyless\u002FMPC mobile wallet: there is no seed phrase to steal, and signing requires cooperation between shares. You keep control because no single share is enough to move funds.\u003C\u002Fp>\u003Cp>The \u003Cstrong>WATS Hot Wallet is fully non-custodial\u003C\u002Fstrong>: you hold your own private keys and your own seed phrase, and \u003Cem>WATS never holds a key\u003C\u002Fem>. It is classic single-key self-custody — WATS cannot sweep your wallet, freeze it, or recover it for you, because it has nothing to sign with. The hardware security WATS offers sits alongside the keys, not inside them: the WATS NFC Metal Card is a tap-to-authenticate factor that pairs with a single device in the mobile app and stores no private keys, so you add a physical-presence check without ever splitting control of your seed. You carry the full responsibility of a single seed — and, in exchange, nobody else can ever sign on your behalf.\u003C\u002Fp>\u003Ch2>The steps to keep your keys\u003C\u002Fh2>\u003Cp>Here is the practical checklist. Follow it in order the first time you set up a non-custodial hot wallet, and revisit steps 5 and 6 as your holdings grow.\u003C\u002Fp>\u003Ch3>1) Pick a non-custodial hot wallet\u003C\u002Fh3>\u003Cp>Confirm the wallet is non-custodial before you fund it. The tell: during setup it shows \u003Cem>you\u003C\u002Fem> a seed phrase (or sets up MPC key shares \u002F a co-signing model), rather than asking you to create an account with just an email and password. If recovery is \"reset your password,\" it is custodial. Match the wallet to your chains and habits — MetaMask or Rabby for heavy EVM dApp use, Phantom for Solana, or the \u003Ca href=\"\u002Fhot-wallet\">WATS Hot Wallet\u003C\u002Fa> if you want EVM, Solana and TON in one place with single-token fees.\u003C\u002Fp>\u003Ch3>2) Record and store the seed phrase offline\u003C\u002Fh3>\u003Cp>When the wallet reveals your \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-seed-phrase\">seed phrase\u003C\u002Fa>, write it on paper or stamp it into metal. Never photograph it, never paste it into notes, cloud storage, email or a password manager, and never type it into any website. Store the backup somewhere private and, ideally, keep a second copy in a separate location so one fire or theft can't erase it. (If you chose an MPC wallet with no seed, follow that app's specific backup flow instead.)\u003C\u002Fp>\u003Ch3>3) Verify you can recover\u003C\u002Fh3>\u003Cp>Before you move meaningful funds in, test recovery. Remove the wallet or use a spare device, then restore from your written seed and confirm the same address appears. This proves you copied the words correctly and understand the process, so you are not discovering a transcription error during an emergency.\u003C\u002Fp>\u003Ch3>4) Add a hardware or biometric factor\u003C\u002Fh3>\u003Cp>Add a second factor so a stolen password or an unlocked laptop isn't game over. Turn on biometric unlock (Face ID \u002F fingerprint) in a mobile wallet such as the \u003Ca href=\"\u002Fdownload\">WATS Mobile App\u003C\u002Fa>. Pair a hardware signer for high-value activity, or use a tap-to-sign companion like the \u003Ca href=\"\u002Fnfc-card\">WATS NFC Metal Card\u003C\u002Fa> — a physical card you tap to authenticate an action, which does not store your keys but does require your physical presence to approve it.\u003C\u002Fp>\u003Ch3>5) Keep large holdings in cold storage\u003C\u002Fh3>\u003Cp>A hot wallet is for spending money, not savings. Keep the bulk of your assets in \u003Ca href=\"\u002Fblog\u002Fhot-wallet-vs-cold-wallet\">cold storage\u003C\u002Fa> — a hardware wallet like Ledger, or a key-storing NFC cold card like Tangem — and leave only what you actively trade or spend in the hot wallet. If the hot device is ever compromised, your losses are capped at the hot balance.\u003C\u002Fp>\u003Ch3>6) Revoke approvals and dodge phishing\u003C\u002Fh3>\u003Cp>Most hot-wallet losses come from signing, not from cracked keys. Periodically review and revoke token approvals you no longer use, so a stale permission can't drain a token later. Bookmark real dApp URLs, ignore \"support\" DMs, and read every signature request — if a transaction looks like it grants sweeping access, reject it.\u003C\u002Fp>\u003Ch2>Hardware factors that reinforce a hot wallet\u003C\u002Fh2>\u003Cp>Hardware doesn't only mean going fully cold. Several devices strengthen a hot wallet without giving up its convenience, and they work in different ways — so it helps to know which does what.\u003C\u002Fp>\u003Cul>\u003Cli>\u003Cstrong>Hardware wallets (Ledger, and similar):\u003C\u002Fstrong> the private key lives on the device and never touches your online computer. You pair it with a hot wallet like MetaMask and physically confirm each transaction on the device. This is the strongest factor for large balances.\u003C\u002Fli>\u003Cli>\u003Cstrong>NFC cold cards (Tangem, Arculus):\u003C\u002Fstrong> these \u003Cem>store keys on the card\u003C\u002Fem> and sign offline — they are cold storage in card form, seedless in Tangem's case. Tap to sign; the key never leaves the card.\u003C\u002Fli>\u003Cli>\u003Cstrong>Tap-to-authenticate companions (WATS NFC Metal Card):\u003C\u002Fstrong> a different category. The \u003Ca href=\"\u002Fnfc-card\">WATS NFC Metal Card\u003C\u002Fa> does \u003Cem>not\u003C\u002Fem> store private keys and is not a cold wallet — it is a durable steel companion (IP68 waterproof, MIL-STD-810 rated, AES-128, NTAG 216) that you tap to authenticate an action, adding a physical-presence factor to your mobile wallet. It complements your key security; it doesn't replace your key storage.\u003C\u002Fli>\u003Cli>\u003Cstrong>Biometrics:\u003C\u002Fstrong> Face ID or a fingerprint on a mobile wallet gates access to the signing key on that device. It's not a substitute for a seed backup, but it stops casual access if your unlocked phone is grabbed.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The distinction matters because it's easy to over-trust a card. A key-storing cold card (Tangem) is genuinely holding your keys offline. A tap-to-authenticate companion (the WATS card) is a presence check layered on a hot wallet whose keys live elsewhere. Both are useful; they are not the same thing, and you shouldn't treat one as if it were the other.\u003C\u002Fp>\u003Ch2>Bottom line\u003C\u002Fh2>\u003Cp>You can absolutely keep your keys while using a hot wallet — the word \"hot\" describes connectivity, not custody. Choose a non-custodial wallet, back up the seed offline (and verify you can restore it), add a hardware or biometric factor, keep the bulk of your net worth in cold storage, and stay disciplined about approvals and phishing. If you'd rather not shoulder a single raw seed alone, an MPC wallet like Zengo splits the key into shares so there's no single seed to guard. The \u003Ca href=\"\u002Fhot-wallet\">WATS Hot Wallet\u003C\u002Fa> takes the classic route — it is fully non-custodial, so you hold your own keys and seed phrase and WATS never holds a key, and control never leaves your hands. Pick the model that matches how much responsibility you actually want to carry, and your hot wallet stays genuinely yours. For more on the underlying concepts, see \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-non-custodial-wallet\">what a non-custodial wallet is\u003C\u002Fa> and \u003Ca href=\"\u002Fblog\u002Fhot-wallet-vs-cold-wallet\">hot wallet vs cold wallet\u003C\u002Fa>.\u003C\u002Fp>",[10,13,16,19],{"q":11,"a":12},"Is a hot wallet the same as a custodial wallet?","No. \"Hot\" only means the wallet is connected to the internet; it says nothing about who holds the keys. A hot wallet can be non-custodial (you hold the keys, like MetaMask, Phantom or the WATS Hot Wallet) or custodial (a company holds them, like most exchange apps). The custody model, not the connectivity, decides whether you're actually keeping your keys.",{"q":14,"a":15},"Can I keep control of my keys without memorizing or storing a seed phrase?","Yes — MPC wallets such as Zengo split the key into shares, so there is no single seed to store and no single share can move funds alone. Don't lump every wallet into that model, though: the WATS Hot Wallet is fully non-custodial single-key self-custody — you hold your own keys and seed phrase, and WATS never holds a key — so with WATS you do keep and back up a seed. MPC is the route to take if you specifically want to avoid guarding one raw seed yourself.",{"q":17,"a":18},"Does the WATS NFC Metal Card store my private keys?","No. The WATS NFC Metal Card is a tap-to-authenticate companion, not a cold wallet — it does not store private keys. You tap it to add a physical-presence factor when approving an action in your mobile wallet. If you want a card that actually stores keys and signs offline, that's a cold NFC card like Tangem, which is a different category of device.",{"q":20,"a":21},"How much crypto should I keep in a hot wallet?","Only what you actively spend, trade, or need for dApps and gas — treat it like the cash in your pocket rather than your savings account. Keep the bulk of your holdings in cold storage such as a hardware wallet (Ledger) or a key-storing NFC cold card (Tangem). That way, if the hot device is ever compromised, your losses are capped at the small balance you keep online.",[23,26,29,32,35,38],{"title":24,"body":25},"Pick a non-custodial hot wallet","Confirm the wallet is non-custodial before funding it: during setup it should reveal a seed phrase to you (or set up MPC key shares \u002F a co-signing model), not just ask for an email and password. Match it to your chains — MetaMask or Rabby for EVM, Phantom for Solana, or the WATS Hot Wallet for EVM, Solana and TON with single-token fees.",{"title":27,"body":28},"Record and store the seed phrase offline","Write the seed phrase on paper or stamp it into metal, and store it somewhere private. Never photograph it, paste it into notes, cloud, email or a password manager, or type it into any website. Ideally keep a second copy in a separate location so one fire or theft can't erase your backup.",{"title":30,"body":31},"Verify you can recover","Before moving meaningful funds in, test recovery on a spare device or after removing the wallet. Restore from your written seed and confirm the same address appears. This proves you copied the words correctly and won't discover a transcription error during an emergency.",{"title":33,"body":34},"Add a hardware or biometric factor","Add a second factor so a stolen password or unlocked device isn't game over. Turn on biometric unlock in a mobile wallet like the WATS Mobile App, pair a hardware signer for high-value activity, or use a tap-to-sign companion such as the WATS NFC Metal Card, which requires your physical presence to approve an action.",{"title":36,"body":37},"Keep large holdings in cold storage","Treat the hot wallet as spending money, not savings. Keep the bulk of your assets in cold storage — a hardware wallet like Ledger or a key-storing NFC cold card like Tangem — and leave only what you actively trade or spend online. That caps your losses at the hot balance if the device is ever compromised.",{"title":39,"body":40},"Revoke approvals and dodge phishing","Most hot-wallet losses come from signing, not cracked keys. Periodically review and revoke token approvals you no longer use so a stale permission can't drain a token later. Bookmark real dApp URLs, ignore \"support\" DMs, and read every signature request, rejecting anything that grants sweeping access.",1784634269513]