One night an exchanger loses access to its hot wallet — phishing, a compromised API key, doesn't matter which. There's only one question that matters: how much money was sitting in it? If the answer is “almost all our working capital,” the business is done. If it's “one day's limit,” it's a bad day, not a bankruptcy. The balance between a hot wallet and a cold wallet isn't a technical footnote — it's the main line of defense for any exchanger.
Why split your wallets at all
A hot wallet is connected to the internet and serves customers automatically — think of it as the cash register on the counter, where the clerk hands out change without walking to the safe. A cold wallet isn't connected to any network at all: the keys live on a device or inside a multisig setup where a signature has to be assembled by hand. That's the safe in the back room, the one you actually have to walk to.
Exchangers need both. Without a hot wallet, a payout that should take minutes stretches into hours, and requests pile up unprocessed. Without a cold wallet, the entire float sits somewhere that anyone who breaches the server perimeter can theoretically reach.
How much to keep in the hot wallet
There's no universal percentage, but there is a working rule of thumb: the hot balance should cover payouts for the peak 24-48 hours, not the whole month's turnover. An exchanger doing $50,000 a day with occasional spikes can typically keep $5,000-10,000 in the hot wallet — everything else stays cold.
Watch three numbers: the average payout size, the maximum number of requests in a peak hour, and how fast you can top up the hot wallet from cold storage if there's a rush. If refilling takes 15 minutes with an operator on standby, you can afford to keep less hot. If your signing ceremony eats half a day, you'll need a bigger hot buffer — and that's a risk you should accept consciously, not by default.
How cold storage actually works
In practice it's rarely a single safe — it's usually a multisig wallet that needs 2-of-3 or 3-of-5 signatures from separate keys held by different people. That way no single employee, even one with full server access, can move the reserve alone.
Hardware wallets add another layer: the private key never leaves the device, even if the computer it's plugged into is compromised. For an exchanger moving several hundred thousand dollars a month, multisig on hardware keys stops being a luxury and becomes basic hygiene.
When it's time to revisit the balance
- Turnover has doubled or tripled in a quarter, but hot wallet limits haven't moved;
- customers are starting to complain about payout delays during peak hours;
- you have no log of who moved funds between wallets, or when;
- the signing ceremony for the cold wallet is still done by one person instead of two or three;
- you haven't tested cold wallet recovery even once in the past year.
If two or more of these sound familiar, it's time to rebuild the storage scheme — not to wait for an incident to force your hand.
Common mistakes
The most common one is keeping “a bit extra” in the hot wallet just to avoid thinking about refills. A two-day buffer quietly turns into a two-week buffer, and nobody notices until it's too late.
The second is cold storage with a single key holder. Technically that's no longer a “cold wallet” — it's just a wallet that happens to be offline. If something happens to that person, or they go on vacation somewhere unreachable, access to the reserve disappears with them.
Bottom line
Splitting funds between hot and cold only works if the limits get revisited as turnover grows, instead of being set once and forgotten. Exchangers that want their own storage infrastructure without paying a middleman's fee should take a look at iEXWallet — a ready-made crypto wallet built for exchanger operators.



