Cookies on BBB.org

We use cookies to give users the best content and online experience. By clicking “Accept All Cookies”, you agree to allow us to use all cookies. Visit our Privacy Policy to learn more.

Manage Cookies
Latest News

BBB Tip: How to store and secure cryptocurrencies

By Better Business Bureau. September 22, 2020.
hand holding phone

(Getty Images)

By BBB Institute and FINRA staff

Storing and transferring cryptocurrencies is very different from managing traditional cash or investments. Here are a few things to keep in mind regarding crypto storage and security.

Two Types of Keys

First, it is important to remember that public key and a private key represent your cryptocurrency. Think of a public key like an email address—this identifies the cryptocurrencies you receive, and you can use it to send or transfer cryptocurrencies to another individual. A private key is a secret key—an alphanumeric code—that represents your personal way, such as a password, to access your cryptocurrency. Managing your private key is an essential component of storing your cryptocurrencies.

New Security Challenges

To store and transfer cryptocurrency and its associated private keys, you can use a number of different methods, including mobile applications, third-party online services, and specialized hardware—even printing your keys (i.e., the alphanumeric code) on a piece of paper. However, because cryptocurrency is, in essence, a piece of computer code, it is vulnerable to hackers, destruction or accidental loss.

Keeping cryptocurrencies safe involves a different set of challenges than keeping cash assets, stocks or bonds secure. Crucially, because many cryptocurrencies are not recognized legally in the same way that cash assets are recognized by governments, the same safety nets, such as FDIC coverage for bank assets and legal remedies for damages and restitution, may not be available if your cryptocurrencies are stolen, lost or destroyed. Therefore, it is important to learn about the different ways to store cryptocurrencies.

Cold Storage Versus Hot Storage

There are two general methods for storing cryptocurrencies, often referred to as “cold” storage and “hot” storage.

Cold Storage refers to holding your private keys in an environment that is not connected to the Internet. Examples include storing keys on disconnected hard drives, printing or writing them on a piece of paper or storing them on USB drives. You can also use a “hardware wallet,” a type of device similar to a USB drive that lets you store your private keys.

While these storage methods tend to prevent your cryptocurrencies from being hacked by a malicious actor, they are vulnerable in other ways. Hardware, such as hard drives and USB devices, can break down, be lost or suffer functionality defects. Paper can be destroyed or burned, and hardware wallets are not immune from hacking. Finally, thieves can steal hardware, paper and other physical means of storage.


Hot storage
uses services connected to the Internet to store cryptocurrency keys. While there are a number of hot storage options available, most are described as cryptocurrency “wallets.” Cryptocurrency wallets (different from the hardware wallet discussed above) refer to types of software that can be installed on any Internet-connected device that stores your public and private crypto keys. Cryptocurrency wallets include:

  • Desktop wallets: Desktop wallets are software that can be downloaded to your PC or laptop and allow you to store your private keys on that computer.

  • Mobile app wallets: Mobile app wallets are apps that let you store your keys on your mobile device. Many mobile app wallets allow you to use your cryptocurrencies for small retail transactions with certain businesses.

  • Online wallets: Online wallets are software that lets you store and access your keys from any Internet-connected device. In this case, your private keys are stored remotely on third-party servers owned by the provider of the online wallet. You create a username and password just as you would for a traditional online bank account, and then you can easily use the software. Online wallets are commonly associated with cryptocurrency exchanges, which are entities that facilitate the trading of fiat currency for cryptocurrencies.


Cryptocurrency wallets are convenient because you don’t have to memorize your private key, write it down or store it elsewhere. However, a downside of wallets is that they, like any service connected to the Internet, are vulnerable to hackers and malicious code. Desktop and mobile app wallets that store keys locally on a device are susceptible to loss, destruction and theft. For example, if you lose your phone which has a mobile app wallet that stores your cryptocurrency keys, you may permanently lose your investment.

Online wallets that are associated with cryptocurrency exchanges are vulnerable to a number of different risks. They are common targets of cyberattacks. In addition, these exchanges do not work the same way as a registered securities exchange – meaning that your investment might be trading on an exchange that is not subject to regulatory oversight and could be more susceptible to fraud and theft. Moreover, there are many scammers and bad actors looking to lure unsuspecting investors into storing their public and private keys with fake exchanges. Many scammers also pose as fake tech support staff for legitimate cryptocurrency exchanges. Therefore, it is important to scrutinize an institution before using its online wallet service. 


Use Caution

Cryptocurrencies present a new set of challenges when it comes to keeping your assets safe and secure. Do your research into the type of technology, platform, or service you use to store your cryptocurrencies. Know the pluses and minuses of each storage option—and remember that if measures aren’t taken to properly secure and store your assets, you may lose some or all of your investment.

To receive the latest Investor Alerts and other important investor information, go to Finra.org/investors.