Hot wallet vs cold wallet: who can see
Published: September 29, 2026
Also available in:繁體中文
A hot wallet keeps the private keys on a device that goes online. A cold wallet keeps them where they never do. That single difference decides how hard your coins are to steal, and it decides nothing else. In particular it does not change what the chain records about you: the addresses, the amounts and the dates look identical either way, because the chain has no field for where you keep the key.
That second half is missing from almost every comparison of the two, and it is the half this page is about. We run notrace.exchange, a mixing service, so the last two sections say plainly where a service like ours fits and where it does not.
What the two words actually mean
The Bitcoin Wiki's definition is the one worth starting from, because it is narrow and it is precise: "Cold storage in the context of Bitcoin refers to storing Bitcoins offline and spending without the private keys controlling them ever being online."
Note what the definition is about. Not where the coins are — coins are not anywhere, they are entries in a public ledger. It is about where the key is, and specifically about whether the key ever touches a machine connected to the internet. The same page states what that buys you, in one sentence and without inflation: "This resists theft by hackers and malware, and is often a necessary security precaution especially dealing with large amounts of Bitcoin."
Theft by hackers and malware. That is the claim, and it is a real one.
A hot wallet is simply the other case: the wallet app on your phone, the desktop wallet, the browser extension. The key sits on a machine that goes online, which is what makes spending take four seconds instead of four minutes, and which is also the exposure.
Two things that get muddled into this pair:
- A hardware wallet is not a third category. It is one way of doing cold storage: the key is generated and kept inside the device, the signing happens inside the device, and what comes back out is a signed transaction. Plugging it into a laptop does not put the key online, because the key never leaves.
- An account at an exchange is neither. There is no key of yours involved at all. You have a balance in somebody else's database, and the wallet belongs to them. That is a different question from this one, with a different set of risks.
What the comparison is usually about
Ask the question and you will get the same answer everywhere: hot is convenient and exposed, cold is inconvenient and safe, keep spending money in one and savings in the other. It is reasonable advice. It is also the entire content of the discussion, and I checked rather than assuming.
On 29 September 2026 the phrase "hot wallet vs cold wallet" was searched about 800 times a month in the United States. It is not a passing question either — it has been asked steadily for five years, peaking around 1,200 a month in 2021 and drifting down to roughly 500 by this autumn. Google's first page for it holds Investopedia, Coinbase, Binance, Kaspersky, BitGo, two Reddit threads and a guide from a site with no authority at all.
Of those, three opened for me: Kaspersky, BitGo and WalletLab. They compare the two on connectivity, attack surface, speed of signing, convenience and which one suits long-term holdings. Between them, the word privacy does not appear once. That is not a complaint about their quality — the advice is sound — it is the gap this page exists to fill.
What neither of them changes
Here is the part the comparison leaves out. The Bitcoin Wiki's privacy page describes the ledger in nine words: "Bitcoins move between addresses; sender addresses are known, receiver addresses are known, and amounts are known."
Every one of those facts is recorded the same way whether your key is on a phone or on a steel plate in a safe. There is no flag on a transaction saying it was signed offline. A stranger holding one of your addresses gets the balance, the full history of what arrived, and the full history of what left — and the hardware you used is not among the things they can or cannot see, because it was never written down.
The strongest demonstration of this comes from the cold storage recipe itself. The standard setup has you keep a watch-only wallet on the online computer, and the wiki explains what it does: "The watch-only wallet on the online computer can provide bitcoin addresses used for receiving money, and can tell the user when transactions are received and how many confirmations they have."
That watch-only wallet works because your addresses are public and your incoming payments are public. It is not a special privilege of ownership. What it shows you is exactly what anybody else can pull up about those same addresses, using nothing but the address string. You are watching your cold wallet over the same public feed a stranger would use. If you want the longer version of what that feed gives away, what a wallet address is and who sees it goes through it.
Moving coins to cold storage is itself a transaction
This is where the upgrade can quietly make the other problem worse.
Setting up cold storage usually means sweeping what you already hold into it. Several old addresses, a few leftovers from different years, an amount from an account somewhere — all of it goes into the new wallet, often in one go, because doing it in one transaction costs less in fees than doing it in six.
That single convenient transaction is the most informative thing you can publish about yourself. The Bitcoin Wiki states the rule an analyst applies to it: "This is a heuristic or assumption which says that if a transaction has more than one input then all those inputs are owned by the same entity." Inputs from six addresses, spent together, are six addresses proven to belong to one person. Whatever was previously separate about them is separate no longer, and the proof is permanent.
The second effect is slower. A cold wallet used the way people actually use one — a savings address that receives for years — is address reuse by design, and the same page is blunt about the cost: "Addresses being used more than once is very damaging to privacy because that links together more blockchain transactions with proof that they were created by the same entity."
So the honest summary of a move to cold storage is two-sided. Theft risk goes down, genuinely and a lot. Linkability goes up, because of the consolidating transaction that created the wallet and the reuse that follows. Nobody selling hardware puts it that way, and it does not make the hardware a bad idea — it makes it an answer to one question and not to the other.
There is a small related trap worth knowing if you are holding coins for years: unexplained tiny amounts arriving at an address you own are sometimes a dusting attack, and the damage happens only when you spend the dust together with your own coins. In a long-term wallet that moment comes eventually. The defence is to leave it alone.
What actually changes what a stranger can follow
None of this is an argument against cold storage. It is an argument that the two questions have two different answers, and the second one needs its own habits.
The cheap habit is a fresh address for every payment, which most wallets already do by default. It stops the laziest kind of watching, and its limit is the heuristic above: coins received at two fresh addresses and later spent together are linked anyway.
Beyond that, the techniques involve other people, because a single wallet cannot break a link it created by itself. A CoinJoin builds one transaction with many participants and equal outputs, so that matching a particular input to a particular output stops being straightforward. A mixing service reaches something similar by a different route — and the two words used for such a service, tumbler and mixer, mean the same thing. For how the reading is done in the first place, and by whom, is Bitcoin traceable covers the methods and the cases where they were used in court.
Where we stand
notrace.exchange is a custodial service, and section 8 of the terms says it in those words: from the moment your deposit settles until the last transfer has left, the service is the custodian of those funds. That is the opposite of cold storage on the custody axis, and it is true for the length of one transfer rather than for years.
What the service does:
- the payout leaves as two transfers to two addresses you name, each with its own delay; on 29 September 2026 each delay could be set from zero to 6 hours, and a transfer leaves no earlier than the delay you chose;
- the payout can be in the same coin or in another one — taking it in another coin is what changes both the asset and the amount, because the same coin keeps both;
- each order comes with a letter signed with our PGP key, naming what you send, the least you will receive, both addresses and both delays;
- our fee on 29 September 2026 was 0.5% and it is the only thing added to the quote; the current figure is on the FAQ page.
The limit is worth stating as narrowly as the definition at the top of this page. What is already recorded stays recorded — we cannot remove or rewrite it, and neither can anyone else. What can change is whether the coins that leave a known address can be followed forward from it.
Where to start
If the question you came with was which wallet to use, the ordinary advice is right: keep what you spend in a hot wallet, keep what you are holding in a cold one, and treat the recovery phrase as the thing that actually matters.
If the answer left you wondering who is reading the other side of it, start with what a wallet address is and who sees it, then is Bitcoin traceable. And if the coins you are about to move are coming from an address that is already known, the bitcoin mixer page opens the form with its current minimum — the checks in how to choose a bitcoin mixer apply to us as much as to anyone else.