What does a crypto wallet actually hold?

Despite the name, a crypto wallet holds no coins. Your balances are entries on a blockchain, a public record that thousands of computers keep in sync. What the wallet stores is the secret that proves those entries are yours and lets you move them.

Ethereum's own documentation puts it this way: an account is a pair of keys, a public one that produces your address and a private one that signs transactions. The wallet is the tool that keeps the private key safe and uses it for you when you approve a payment.

What is the difference between an address and a private key?

They are a pair, but they are used in opposite ways:

  • Address: a long string such as 0x4f3a… that works like an account number. You can share it freely so people can send you tokens. Anyone can see its balance and history on a block explorer.
  • Private key: the secret that approves transfers out of that address. It must never be shared, typed into a website or photographed. Anyone who has it can empty the account, and a transfer cannot be reversed. (ethereum.org)
Diagram of two cards: the address, such as 0x4f3a…9b2c, is safe to share; the private key must be kept secret.
The address receives funds; the private key approves transfers out of it.Illustration: InfraIO Pay (concept: ethereum.org/wallets)

What is a seed phrase?

A seed phrase (also called a recovery phrase) is 12 or 24 ordinary words that encode your private key. It exists so you can restore the wallet on a new phone: type the words into a wallet app and the same address and funds reappear. (BIP-39)

That convenience is also the main risk. The words are the key, so anyone who sees them, in a photo, a cloud note or a fake website, controls the wallet. Ethereum's guidance is to write the phrase on paper, keep it offline and never share it with anyone, including anyone claiming to be support (ethereum.org). How a different design avoids this is covered in passkey wallets vs seed phrases.

What is the difference between a custodial wallet and self-custody?

The question is who holds the private keys.

In a custodial wallet, such as an account on a crypto exchange, the company holds the keys and you hold a claim on what it owes you. You sign in with a password and usually a code, and you can reset a forgotten password through support. The trade-off is trust: if the company is hacked, freezes your account or fails, your access depends on it. (ethereum.org)

In self-custody, you hold the keys. Nobody can freeze or move your funds, but nobody can recover them for you either. Lose the keys and the backup, and the funds are gone.

Compared onCustodial (exchange account)Self-custody wallet
Who holds the keysThe companyYou
Forgot your passwordReset through supportNo one can reset it; you rely on your backup
Can the provider freeze or move fundsYesNo
Main riskCompany failure or account takeoverLosing the keys or approving a scam yourself
Good forBuying, selling, getting startedHolding and using crypto on your own terms
Two panels. Custodial: you log in to a company that holds the keys. Self-custody: you hold the keys yourself.
The question that matters is who holds the keys.Illustration: InfraIO Pay (concept: ethereum.org/wallets)

What is the difference between a hot wallet and a hardware wallet?

A hot wallet is connected to the internet: a phone app, a browser extension or a desktop program. It is convenient for everyday use, but the device it runs on can be attacked.

A hardware wallet is a small dedicated device that keeps the private key inside it and signs transactions there, so the key never touches your computer. It is a strong choice for larger amounts you rarely move, at the cost of price and convenience. Buy one only from the maker, never from a reseller, and treat its recovery words with the same care. (ethereum.org)

A hardware wallet held in one hand, showing a transfer to confirm on its own screen with the words Hold to sign.
A hardware wallet asks you to confirm each transfer on its own screen; the private key stays inside the device.Photo: FlippyFlink, Wikimedia Commons, CC0

What is the difference between a regular wallet and a smart-account wallet?

A regular wallet (technically an externally owned account, or EOA) is one private key. Whatever that key signs is final, and losing it, or leaking its seed phrase, is the end of the story. MetaMask and most first-generation wallets work this way. (ethereum.org)

A smart-account wallet is a small program on the blockchain that holds your funds and decides who may approve a payment. Because it is a program, the rule can be more flexible than "one key": a passkey, a second device as a backup, or in some wallets several people who must agree. The common standard for this is ERC-4337, live on Ethereum since March 2023. (ethereum.org)

Where do passkey wallets fit in?

A passkey wallet is a smart-account wallet whose approving key is a passkey: the same technology many people already use to sign in without a password. The private part stays on your device or in your passkey manager, you unlock it with Face ID, a fingerprint or your device passcode, and no word list has to be written down to get started. (FIDO Alliance)

It is still self-custody: the funds are on the blockchain and the provider cannot move them. What changes is the day-to-day security and the way you recover. The full comparison is in passkey wallets vs seed phrases, and how the InfraIO Wallet works walks through one example end to end.

How do you choose a crypto wallet?

There is no single best wallet; there is the right one for what you are doing. A few questions settle most of it:

  • How much and how often? Small, frequent payments suit a phone wallet. A large amount you will not touch for years suits a hardware wallet.
  • Do you want to hold the keys? If not, an exchange account is simpler, but remember it is a promise from a company, not your own control.
  • How will you recover it? Know your answer before you add money: a written seed phrase, a second passkey, a hardware backup. If you cannot explain your recovery plan, do not fund the wallet yet.
  • Where does the app come from? Install wallets only from the official store listing or the maker's own site, and check the publisher. Fake wallet apps and extensions are a common way to lose funds.
  • Which networks and tokens do you need? Check that the wallet supports the network where your tokens live.

Where does InfraIO Wallet fit in?

InfraIO Wallet is one option in the passkey, smart-account category. It is non-custodial: your keys stay on your devices and InfraIO cannot move your funds. You approve with a passkey, can add backup passkeys, and a recovery phrase is optional. Apps for iOS and Android and a Chrome extension are coming soon; none is available to download yet. See the InfraIO Wallet page for what exists today.

Keep reading: What is a multisig wallet?, Why InfraIO Wallet, How to use InfraIO Wallet, InfraIO Wallet