How much should I keep in a hot wallet versus cold storage?
Confirmed Published 4 min read
Short answer
No public authority sets an amount or ratio for hot versus cold storage as of October 1, 2026. FINRA describes hot wallets as convenient but exposed to hackers, and cold wallets as better for long-term storage. Cold storage still fails if the holder approves a wrong transfer, is coerced, or loses the backup.
The full answer
What regulators mean by hot and cold storage
FINRA, the US broker-dealer regulator, defines hot wallets as wallets connected to the web through software on a phone or computer. Cold wallets, in its definition, are paper or hardware devices that generally aren’t connected to the internet [1]. FINRA’s investor guide says hot wallets are convenient, because access is usually through an ordinary password. It also says that “like any service connected to the internet,” hot wallets “are vulnerable to hackers and malicious code” [1].
Cold wallets “tend to be better for long-term storage and more difficult for malicious actors to hack,” the same guide says, because they are disconnected from the internet [1]. FINRA adds a warning about that offline side. Hardware wallets “can break down, suffer functionality defects or get lost or stolen,” and they “aren’t totally immune from sophisticated hacking techniques.” Funds behind a paper wallet can be destroyed or lost [1]. The page on the difference between hot, cold and paper wallets covers each type in more detail.
Whether any authority sets an amount for each
The guidance below describes what each kind of storage is for. None of it gives a figure or a ratio. XRPL.org, the XRP Ledger’s documentation, describes keeping an account’s master key “enabled but offline.” That way no one can reach it over the internet, and the owner can still find it in an emergency [2]. In a public service announcement on September 3, 2024, the FBI said not to store seed phrases, private keys or wallet logins on internet-connected devices [3].
Canada has a split rule for platforms. On September 8, 2025, the Ontario Securities Commission’s investor site said a registered trading platform may not hold all its clients’ crypto in its own hot or cold wallets. It must use a third-party custodian holding at least 80% of client crypto [4]. That rule applies to the platform, not to a person holding their own XRP.
What cold storage does not protect against
Offline storage protects the key. The ledger then acts on whatever that key signs. XRPL.org says digital signatures are the only way to authorize XRP Ledger transactions, and no administrator can undo one after it has applied [2]. The FBI’s crypto crime page says transactions “are irrevocable” [5].
FBI Denver warned on April 26, 2024, about address poisoning. The FBI said in April 2024 that criminals send tokens from addresses that closely resemble one the victim has corresponded with before, so the first and last few characters might be identical to a familiar address, and it advised checking the entire address before sending [6]. Malicious signing requests and wallet drainers exploit the same point: the holder approves something they did not intend.
A device is also only as isolated as its recovery phrase. D’CENT, a wallet maker, says in its app FAQ that if a hardware wallet’s phrase was ever entered into an app or other software wallet, “the two wallets share the same private keys and the hardware wallet should not be treated as isolated” [7].
The backup is the third weak point. The US National Institute of Standards and Technology wrote in February 2021 that anyone who finds the seed words can restore the tokens. It added that “both paper and digital backups of the seed phrases can be lost, stolen, or destroyed” [8]. XRPL.org says no one can restore access to an XRP Ledger account if something goes wrong [9].
How coercion risk bears on what is kept within reach
Ledger’s CEO wrote on December 21, 2020, after a customer data leak. He advised against keeping the recovery sheet in a safe at home and called a bank vault much more secure, saying “not having immediate access to your backup increases your resilience to physical threats” [11]. TRM Labs wrote on May 23, 2025, that multi-signature wallets make it “much harder for coercion alone to succeed.” It also advised holders to avoid publicly linking their identity to their wallet addresses [12]. The page on physical attacks on crypto holders covers the cases.
Moving XRP between hot and cold
Every move between a hot wallet and a cold one is a transaction that cannot be reversed [2][5]. The full-address check FBI Denver describes applies to each of them [6]. The steps are set out in moving XRP from an exchange to your own wallet without losing it.
Splitting the cold portion
Splitting helps only when the parts don’t share a phrase, as D’CENT’s FAQ shows [7]. Trezor, a hardware wallet maker, documents a split backup. In a two-of-three scheme one lost share leaves the wallet recoverable, while losing enough shares to fall below the threshold makes it unrecoverable [13]. NIST says multi-signature wallets can restore access after keys are lost, as long as enough keys remain to meet the requirement [8]. The trade-offs are covered in spreading XRP across several exchanges and wallets.
The case against moving most holdings into cold storage
The strongest objection is lockout. The US Federal Trade Commission says that if a holder loses the password to a digital wallet, no one is likely to be able to step in and recover the funds [14]. A Rotfleisch & Samulovitch article published on Mondaq on June 15, 2026, said that beneficiaries may be unable to recover crypto if keys and recovery phrases are lost or unavailable at death. It added that multi-signature wallets can complicate estate administration when succession steps are not documented [15]. The ways holders lose XRP without anyone hacking them are set out on a separate page.
What we know
- FINRA’s investor guide on crypto storage (undated) defines hot wallets as wallets connected to the web through software on a phone or computer, and cold wallets as paper or hardware that generally is not connected to the internet.
- The same FINRA guide says hot wallets are vulnerable to hackers and malicious code, that cold wallets tend to be better for long-term storage, and that hardware wallets can break, be lost or stolen, and are not totally immune from sophisticated hacking.
- XRPL.org’s cryptographic keys page (checked September 2026) describes keeping the master key enabled but offline so it is out of reach of the internet yet usable in an emergency, and says no administrator can reverse a transaction once it has applied.
- The FBI said on September 3, 2024, not to store seed phrases, private keys or wallet logins on internet-connected devices.
- The Ontario Securities Commission’s investor site said on September 8, 2025, that a registered Canadian trading platform may not hold all client crypto in its own hot or cold wallets and must keep at least 80% with a third-party custodian.
- FBI Denver warned on April 26, 2024, that address-poisoning attackers use lookalike addresses whose first and last characters match a familiar one, and advised checking the entire address.
- NIST wrote in February 2021 that paper and digital backups of seed phrases can be lost, stolen or destroyed.
- Chainalysis reported on August 6, 2026, that 46 violent crypto-related incidents had been documented worldwide through late June 2026, against 40 at the same point in 2025, with $58 million in known stolen value in 2025.
What we reason Analysis
- FINRA’s guide presents hot storage as convenient but exposed and cold storage as better for long-term holding, so the amount kept hot comes down to how much a holder needs to spend or move soon against how much they are willing to leave exposed. Neither FINRA nor XRPL.org turns that trade into a number.
- Cold storage protects the key, not the decision. XRPL.org says signatures are the only way to authorize a transaction and that applied transactions cannot be reversed, and FBI Denver documents lookalike-address attacks, so a hardware wallet can correctly sign a payment to the wrong address.
- Ledger’s December 2020 advice to keep the backup out of immediate reach, read alongside Chainalysis’s August 2026 finding that most violent attacks are premeditated, suggests that keeping the bulk of holdings slow to reach limits what a coercer can take at once. The cost is slower access for the owner.
- The FTC, NIST and the June 2026 Mondaq estate article all describe permanent loss when a password, phrase or key is lost. Each layer that keeps an attacker out can also keep the owner or heirs out.
What's still open
- As of October 1, 2026, no regulator, consumer-protection body or XRPL.org page publishes a recommended amount or percentage for individuals to keep in hot versus cold storage.
- As of October 1, 2026, no public dataset compares how often XRP holders lose funds from hot wallets against cold wallets.
In plain English
Some XRP can be kept in a wallet connected to the internet, which is handy but easier to attack. The rest can be kept offline, which is harder to hack but still needs a safe backup. No regulator says how much should go in each. Offline storage does not stop someone sending to the wrong address, being forced to hand over funds, or losing the backup and being locked out.
Key terms
Sources
- Cryptocurrency storage — FINRA, undated Primary
- Cryptographic Keys — XRPL.org, undated Primary
- Public service announcement on North Korean social engineering targeting the crypto industry — FBI Internet Crime Complaint Center, September 3, 2024 Primary
- Understanding crypto asset trading platforms — Ontario Securities Commission (GetSmarterAboutMoney.ca), September 8, 2025 Primary
- Cryptocurrency — FBI Internet Crime Complaint Center, undated Primary
- FBI warns of cryptocurrency token impersonation scam — FBI Denver, April 26, 2024 Primary
- FAQ: DCENT App — D'CENT, September 16, 2026 Company-reported
- NISTIR 8301: Blockchain Networks: Token Design and Management Overview — National Institute of Standards and Technology, 2021-02 Primary
- Disable Master Key Pair — XRPL.org, undated Primary
- Violent crypto wrench attacks in 2026 — Chainalysis, August 6, 2026 Company-reported
- Message by Ledger's CEO: update on the July data breach — Ledger, December 21, 2020 Company-reported
- The rise of wrench attacks and crypto-related violent crime — TRM Labs, May 23, 2025 Company-reported
- What is Shamir backup? — Trezor, undated Company-reported
- What to know about cryptocurrency and scams — US Federal Trade Commission, undated Primary
- Crypto estate planning in Canada: CRA tax treatment on death, wills and inheritance — Mondaq (Rotfleisch & Samulovitch), June 15, 2026 Secondary
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
