Hot Wallet vs. Multisig: How to Store Crypto Reserves Safely

iEXExchanger
Hot Wallet vs. Multisig: How to Store Crypto Reserves Safely

An exchanger's real risk isn't just a hacked hot wallet — it's a single lost key to cold storage. Here's how a three-tier scheme with multisig protects against both, without slowing down daily payouts.

A multisig wallet isn't a paranoid extra for the security team — it's the difference between losing a signer's laptop and losing the whole reserve in one bad night. Any working exchanger sits on tens or hundreds of thousands of dollars in crypto at any given moment, and the real question was never whether someone will eventually go after the hot wallet. It's how much you lose when they do, and whether the reserve has a backup plan.

Three kinds of wallets — and why an exchanger has to care

A hot wallet is online and pays out instantly. A cold wallet sits offline, out of reach of a remote hack. Multisig isn't really a separate "place" — it's a rule: a transfer only goes through when several keys sign it together, not one employee with one password.

For a casual crypto holder, that's a matter of taste. For an exchanger, it's how the till is built. Picture a currency exchange booth: some cash sits in the drawer for walk-in customers, the bulk sits in a safe nobody can open alone. Crypto infrastructure runs on the same logic — the safe is just called multisig.

Hot wallets: the workhorse that never stops being a target

Without a hot wallet, an exchanger can't settle in real time — a customer expects seconds, not hours waiting on an offline confirmation. But the same connectivity that gives you speed makes the wallet a target: a phished employee, a compromised laptop, a software bug, and the funds move in a single transaction.

A rule of thumb many operators use: keep roughly one or two days of turnover in the hot wallet, no more than you could shrug off in a worst case. Anything above that threshold belongs in cold storage, moved on a fixed schedule — not once a quarter, whenever someone remembers.

Cold storage and multisig: a reserve nobody can steal alone

A cold wallet removes the remote-hack risk, but it creates a different one: if the one person who knows the seed phrase gets sick, quits, or loses the laptop holding the key, the reserve can end up just as frozen as it is protected. Multisig is built to solve exactly that.

The standard setup is "2-of-3" or "3-of-5": keys live with different people or in different physical locations, and signing a transaction requires reaching quorum. Losing one key isn't a disaster — the scheme keeps working. And stealing the funds alone isn't possible either, even if one keyholder is compromised.

  • Keys are physically spread out — not in one office, not in one cloud account
  • No single employee holds enough keys to reach quorum alone
  • The signing threshold (M-of-N) is documented in writing and isn't changed on the fly

Building a tiered storage scheme

A working model usually has three tiers, not two. The first is the hot wallet for live settlements. The second is a "warm" buffer with tighter access, where the day's surplus lands at close of business. The third is the cold multisig reserve, touched rarely and by a fixed procedure.

The detail teams often miss: moving funds between tiers should run on a schedule, not on whoever's in charge that day feeling like it. An exchanger that sweeps surplus into cold storage every evening off a checklist loses a bit of convenience but gains predictability — and predictability is exactly what keeps you from panicking mid-incident.

Common mistakes when switching to multisig

The word "multisig" by itself doesn't protect you from sloppy process. The most common mistake: the same person ends up holding two of three keys "for convenience," and a 2-of-3 scheme quietly becomes a single-owner wallet.

  • All keys stored in one office or on one device
  • The recovery procedure has never actually been tested
  • No written protocol for a lost key or a departing employee
  • Storage thresholds haven't been revisited as turnover grew

Each of these looks minor on its own. Together, they turn multisig into security theater — reassuring on a diagram, useless in an actual incident.

Conclusion

There's no universal split between hot, warm and cold — it depends on your turnover, your headcount, and how much risk your business can stomach. But the underlying principle — separation and distributed key control — holds up almost everywhere, and it's worth the setup cost. You can launch an exchanger with a built-in wallet of your own, no middleman fee, and storage control from day one on iEXWallet.

Questions and answers

Frequently asked questions about this article

How is a multisig wallet different from a regular cold wallet?

A cold wallet just stores a key offline, and whoever holds that key controls the funds. Multisig requires several keys to sign together (say, 2-of-3), so losing or compromising a single key doesn't let anyone move funds alone.

How much crypto should an exchanger keep in a hot wallet?

There's no fixed rule, but a common benchmark is roughly one or two days of turnover. Anything beyond that should move to cold storage on a schedule, not sit online "just in case."

What happens if one multisig key gets lost?

In a properly set up scheme, like 2-of-3, losing one key doesn't lock you out — the remaining keys are enough to sign a transaction. That's exactly why the signing quorum needs to be lower than the total number of keys, not equal to it.

Can an exchanger skip multisig and just use a single cold wallet?

Technically yes, but then the person holding the seed phrase becomes a single point of failure. Their illness, resignation or a simple mistake turns cold storage into the same kind of risk as a hot wallet — it just happens less often.

How often should a reserve's storage scheme be reviewed?

The real trigger is growth — turnover or headcount with key access — not a fixed calendar. A scheme built for a small operation often stops making sense once the business scales several times over.