Guide — 8 steps, one afternoon

Cold storage, done properly

Cold storage is not a product you buy, it is a discipline you adopt. This is the whole process, in order, with the specific places New Zealanders get stuck — and the one step nearly everyone skips.

  • 8 steps From decision to funded cold wallet
  • Step 6 The test restore almost everyone skips
  • 2 copies Minimum recovery phrase backups
  • 2 places Never store device and phrase together

What "cold" actually means

The word gets used loosely enough to be almost meaningless in marketing copy, so let us pin it down. A wallet is cold when the private key that authorises spending has never been present, in readable form, on a device connected to the internet — and cannot be extracted onto one. That is the entire definition. Everything else is implementation detail.

This has a consequence people find counterintuitive: a hardware wallet plugged into a laptop is still cold storage, because what crosses the cable is a signature, not a key. Conversely, a "cold wallet" app that generates a seed on your phone and asks you to keep it offline is not cold at all — the key was born on a networked device and any code with sufficient access could have read it at that moment.

The reason this matters practically is that cold storage buys you protection against one very specific and very common class of attack: remote compromise. Malware, infostealers, malicious browser extensions, drained clipboard, a compromised npm package in some tool you installed. All of those need the key to be reachable. Cold storage makes it unreachable. It does nothing whatsoever about someone with physical access, someone who tricks you into typing your phrase, or your own forgetfulness — and those are the failure modes we will spend most of this guide on, because they are the ones that actually get people.

Split your holdings before you buy anything

The single most useful thing you can do before spending a dollar on hardware is decide, honestly, how you use your crypto. Not how you intend to use it. How you actually do.

If you buy and hold and check the price occasionally, everything goes cold and you are done. If you swap tokens, sign into applications, or move funds most weeks, you need two tiers: a working balance in a good non-custodial phone or desktop wallet, and a savings balance on a device. The critical rule is that these never mix. The working wallet is not a staging area for the cold wallet and the cold wallet is not somewhere you dip into on a Tuesday.

We labour this point because the most common way cold storage fails is not technical. Someone sets up a device, finds that plugging it in and confirming on a tiny screen is annoying, and starts leaving "just a bit" in a hot wallet for convenience. Six months later "just a bit" is most of the portfolio, sitting in the exact place they bought the device to avoid. Design the setup around the friction you will actually tolerate, and read how many wallets you actually need before you commit to a structure.

A structure that survives contact with reality

One hardware wallet holding the savings tier, backed up twice in two locations. One phone wallet holding no more than you would be annoyed — not ruined — to lose. Nothing left on an exchange beyond the hours it takes to settle a trade and withdraw. That is the whole architecture, and it is enough for the overwhelming majority of New Zealand holders.

The setup

Eight steps, in this order

The order matters more than it looks. Every step exists because skipping it is how somebody lost money.

  1. Decide what belongs in cold storage and what does not

    Split your holdings into a savings tier you will not touch for months and a working tier you actually transact with. Only the savings tier goes cold. Mixing the two is what makes people give up on cold storage.

  2. Buy the signing device from a verifiable source

    Manufacturer direct or an authorised reseller only. Inspect the packaging on arrival and reject anything that arrives with a pre-written recovery phrase.

  3. Initialise the device offline and let it generate the seed

    The device creates the private key inside its own secure chip. You never type a seed in and you never let a computer generate one for you.

  4. Write the recovery phrase by hand, twice

    Once on the card supplied in the box, once on a second medium. Never photograph it, never type it into anything, never store it in a cloud service or password manager.

  5. Add a passphrase only if you understand the consequence

    A BIP39 passphrase creates a separate hidden wallet from the same seed. It defeats anyone who finds your written words — and it destroys your funds permanently if you forget it, because there is no record of it anywhere.

  6. Wipe the device and restore from your written backup

    This is the step almost everyone skips and the reason most cold storage failures happen. Do it before a single dollar goes in.

  7. Fund with a small test amount, confirm, then move the rest

    Send a token amount first. Confirm it appears at the address you expected. Only then move the balance that matters.

  8. Separate the device from the backup, geographically

    Different rooms is the minimum. Different buildings is the goal. A single fire, flood or burglary should not be able to take both.

Bitcoin token photographed on a dark surface, representing long-term cold storage savings
Cold storage is a savings instrument, not a payment method. Design it for the balance you intend not to touch.

Step six is not optional

Wiping the device and restoring it from your handwritten phrase, before you fund it, is the only way to know your backup works. Handwriting is ambiguous. Word order gets transposed. People write down the wrong list. Find out while the balance is zero.

Backing up the recovery phrase

Your recovery phrase — twelve or twenty-four words, generated by the device — is the actual asset. The hardware is replaceable and disposable. The words are not. Whoever holds them holds the funds, and nobody, including the manufacturer, can recover them if they are lost.

Every wallet ships with a card to write them on, and for a modest balance in a dry, low-risk home, that card in a sensible hiding place is a defensible backup. For larger amounts, paper's weaknesses become relevant: it burns, it dissolves, ink fades, and a curious flatmate can read it in three seconds. The upgrade is a steel backup plate — stamped or punched metal that survives fire and water. The Bitcoin Shop in Tauranga stocks these locally alongside its hardware, which saves the import wait.

Two copies, in two locations, is the standard we would hold ourselves to. One at home, one somewhere else — a family member's house, a workplace safe, a private vault. The reason for two is simple: a single copy means a single fire, flood or burglary ends your access. The reason for two locations is that a single copy in two places in the same house is not two locations.

The full treatment, including the split-backup schemes and why we are cautious about them, is in the seed phrase backup guide.

Passphrases: the double-edged upgrade

Most hardware wallets support an optional passphrase — sometimes marketed as a "hidden wallet" or "25th word". It is genuinely powerful and genuinely dangerous, and it is worth understanding exactly what it does before you enable it.

The passphrase is combined with your recovery phrase to derive a completely different set of keys. The same twenty-four words with no passphrase open one wallet; with the passphrase "kereru" they open a different wallet; with "Kereru" they open a third. None of these wallets knows about the others, and crucially, the passphrase is not stored anywhere — not on the device, not in the seed, nowhere.

The benefit: someone who finds your written words gets an empty or decoy wallet. This is real protection against a burglary, a nosy relative, or the specific scenario where a device manufacturer's customer list leaks and somebody decides to visit. The cost: forget the passphrase and the funds are gone permanently, with no recovery path of any kind. There is no support line for this.

Our view is that a passphrase makes sense above roughly NZ$20,000, and only if you treat the passphrase itself as a second backup problem to be solved rather than something you will obviously remember. People are extremely confident about remembering strings they will not type for three years, and they are wrong at a rate that should worry you. If you use one, write it down too — separately from the seed words, in a different place, so that finding one does not give you both.

Tax note: moving to cold storage is not a disposal

Transferring cryptoassets between wallets you control is not a taxable event. Inland Revenue treats cryptoassets as property, and tax arises on income — typically a sale, swap, or receipt of rewards — not on relocating your own holdings. You still need records: keep the date, the amounts, the addresses and the network fee, because the fee may be relevant to a later calculation and because you will eventually need to prove that a transfer was internal rather than a sale. See our IRD and CARF guide, and the official position at ird.govt.nz/cryptoassets. General information, not tax advice.

Offsite storage options in New Zealand

"Put the second copy somewhere else" is easy advice to give and slightly awkward to follow in New Zealand, because the obvious answer has quietly disappeared. Over the past decade most of the major banks exited the safe deposit box business. ANZ, BNZ and the old National Bank handed their box operations to New Zealand Vault. Westpac still offers boxes — around NZ$200 including GST for a standard size and NZ$600 for a large one at the time of our last check — but the branch network for them is thin.

The remaining routes are private vaults and improvisation. New Zealand Vault has been operating since 1931 with facilities in Auckland and Wellington; Imperial Vaults and Commonwealth Vault operate in Auckland; Vault NZ offers boxes in Dunedin. Annual fees and restricted access hours apply, and for a seed phrase backup — a piece of steel you hope never to retrieve — restricted access is not much of a downside.

The improvised options are perfectly reasonable for most people: a locked fireproof document safe at a parent's or sibling's house, a workplace safe if you have that kind of workplace, or a bank box in a different city if you happen to have access to one. What matters is that it is a different building, that you can get to it within a day if you need to, and that the person whose house it is does not know what the sealed envelope contains. Our city pages list the specific facilities that exist in each main centre, along with the regional risks — Christchurch's seismic history, Rotorua's geothermal humidity and its effect on metal, Hawke's Bay flood zones.

The hard part

Inheritance and the bus problem

Ask anyone with a hardware wallet what happens to it if they die tomorrow. The honest answer, most of the time, is that the money is gone. This is the least discussed and most expensive failure in self-custody.

A

Sealed instructions with your will

A written explanation of what exists, where the backups are and how to use them, held by your solicitor with your will. Simple, cheap, and it works — provided the instruction is written for someone who does not know what a seed phrase is. Do not just leave twenty-four words; leave twenty-four words plus a page explaining what they open and what to do with them.

B

Multisig with a trusted third key

A two-of-three setup where you hold two keys and an executor or family member holds the third. No single person can spend, you can lose one key without consequence, and your estate has a workable path. This is the technically superior answer and the one we would choose above serious amounts. It is also more work — see multisig wallets explained.

C

What not to do

Do not put the recovery phrase in the will itself — wills can become public documents through the probate process. Do not rely on a "dead man's switch" service you have not tested. Do not assume a family member will work it out from your browser history. And do not split a phrase in half between two people without understanding that most naive splitting schemes weaken the phrase rather than protecting it.

Reality check

Nobody is coming to help

There is no regulator, insurer or dispute resolution scheme standing behind a lost seed phrase. The FMA does not supervise self-custody wallets. Your bank cannot reverse a blockchain transaction. Cold storage transfers the risk from a counterparty to you, and that is the deal — it is a good deal, but only if you take the operational side seriously.

How cold storage actually fails

We have read a lot of loss reports. The distribution is not what people expect — the exotic technical attacks barely register, and the boring operational failures dominate almost completely.

The backup was never tested. By far the most common. The device dies, gets lost, or gets reset, the owner reaches for their written phrase, and it does not work. A transposed word pair, an ambiguous letter, a phrase written from a different device. All discoverable in ten minutes at setup time, all fatal later.

The phrase was stored digitally. A photo in the camera roll that syncs to a cloud account, a note in a password manager, a draft email. When the cloud account is compromised — usually through a password reused from a breached site — the wallet follows within hours.

The owner typed the phrase into something. A convincing support page, a fake wallet update prompt, a "validate your wallet" form. Cold storage offers no protection here because the owner voluntarily handed over the master key. This is the mechanism behind a huge share of losses and it is covered in detail in the scam and drain guide.

The passphrase was forgotten. Enabled once, never used, gone three years later. Irreversible.

The device and backup were in the same place. A burglary or a house fire takes both. Trivially avoidable, regularly not avoided.

Notice that none of these are attacks on the cryptography or the secure element. The chip did its job in every case. The system around the chip is where the failures live, which is why we would rather you spent an extra thirty minutes on steps four through eight above than an extra NZ$200 on a device with a marginally better certification.

Step 6

Wipe and restore before funding. If we could enforce one instruction on this entire site, it would be this one.

Cold storage FAQ

Cold storage questions, answered

What is cold storage in crypto, exactly?

Cold storage means the private key that authorises spending has never existed on an internet-connected device and cannot be read by one. A hardware wallet is the practical implementation for most people: the key is generated inside a secure chip and only signatures — never the key — leave the device. The opposite is a hot wallet, where the key sits on a phone or computer that also browses the web. The distinction is not about brand or price, it is about whether the signing key and the internet have ever met.

How do I move crypto from an exchange to cold storage?

Set up the device first, get a receiving address from its companion app, and check the network matches — Bitcoin to a Bitcoin address, ETH on Ethereum mainnet to an Ethereum address. Send a small test amount, wait for confirmation, verify it appears in the wallet, then send the balance. Never paste an address you have not verified on the device's own screen, because clipboard-swapping malware is common and cheap. Our step-by-step transfer guide covers the whole flow with the specific traps.

Can I sell crypto directly from cold storage?

Not directly — cold storage does not include a market. To sell, you sign a transaction moving coins from your cold wallet to a deposit address at an exchange or broker, then sell there and withdraw NZD to your bank. That means your funds are briefly warm, so do it in one session rather than parking a balance on the platform for weeks. Some wallets offer in-app swaps that keep custody with you, but you are paying a spread for the convenience — see our fees guide.

What happens to my cold storage if I die?

Nothing good, unless you have planned it. A recovery phrase that only you know is a guaranteed permanent loss. The workable approaches are: a sealed written instruction held with your will by a solicitor, a phrase split across trusted parties, or a multisig setup where two of three keys are required and the third sits with an executor. Whatever you choose, the person who inherits needs enough context to act — a phrase with no explanation of what it opens is nearly useless to a non-technical beneficiary.

Is a paper wallet still a valid form of cold storage?

Technically yes, practically no. Paper wallets were the original cold storage method, but generating one safely requires an offline machine and a printer you trust, they encourage address reuse, and spending from one usually means importing the key into software — at which point it is no longer cold. A hardware wallet costs about the same as a good dinner and solves every one of those problems. We cover the specifics in paper wallets explained, mostly so you understand why not to use one.

Next in this cluster

Keep reading