Guide — organisation as security
How many wallets do you actually need?
Almost everyone should have two wallets with a rule about what lives in each. Not because more wallets are safer, but because a single wallet forces a compromise between convenience and protection that always resolves the wrong way.
- 2 Wallets most people should run
- +1 Burner, if you touch new contracts
- 1 rule What each wallet is for, written down
- Inventory The document that stops a wallet being forgotten
On this page
Why one wallet fails
Here is a pattern we have watched play out enough times to consider it predictable. Someone reads that cold storage is the right answer, buys a hardware wallet, sets it up carefully, and moves everything onto it. Good so far.
Then they want to swap a token. That means finding the device, plugging it in, opening the companion app, confirming on a small screen. Fine once. Tedious the fourth time. So they leave "just a bit" in a phone wallet for convenience — a sensible, small, deliberate amount.
Six months later, "just a bit" is most of the portfolio, sitting in exactly the place the device was bought to avoid. Nobody decided this. It happened one convenient decision at a time, and the person still describes themselves as using cold storage.
The problem is not the device or the discipline. It is that a single wallet is being asked to serve two incompatible purposes: a vault you rarely open, and a wallet you use weekly. Those want opposite properties, and any single solution compromises one of them. The fix is not more discipline. It is two wallets and a rule.
The two-wallet structure
The savings wallet. A hardware wallet holding whatever you would be genuinely upset to lose. It is touched a handful of times a year: to receive a purchase, and eventually to sell. Its recovery phrase is written by hand, twice, kept in two different buildings, and verified by a wipe-and-restore before it was ever funded. It is never connected to a decentralised application. It never signs an approval. It does one thing.
The working wallet. One phone or desktop wallet holding an amount you would be annoyed but not ruined to lose. This is where you actually transact — swaps, small payments, staking if you do that, connecting to applications. Its phrase is still written down properly, but the stakes are calibrated so that a mistake here is a bad week rather than a bad decade.
That is it. Two wallets, two phrases, one clear boundary. It costs about NZ$99 for the device — a Ledger Nano S Plus from GROOV in Christchurch — and nothing for the app.
The rule that keeps them separate
Write this down, because a boundary that only exists in your intentions is not a boundary.
Funds move from the working wallet to the savings wallet, and not back. When the hot balance grows past your threshold, move the excess to cold storage. When you want to spend from savings, you are making a deliberate decision to sell — not quietly topping up your hot wallet because it was easier.
Set the threshold as a number, now. "A small amount" is not a threshold; it drifts upward invisibly. Pick a figure — NZ$500, NZ$2,000, whatever suits you — and check against it monthly. Two minutes.
The savings wallet never connects to an application. Not to a decentralised exchange, not to a mint, not to a governance vote, not to a portfolio tracker that wants a signature. If you want visibility, use a watch-only import: a BlueWallet watch-only vault shows your cold storage balances and history on your phone with no private key involved at all, which is genuinely one of the most useful features anywhere in this category.
Burner wallets
If you interact with new smart contracts at all — minting, claiming, testing something a friend recommended — a burner wallet is the cheapest insurance available and it is badly underused.
A burner is a wallet you create for one purpose and abandon afterwards. It takes about a minute: create a new wallet in your app of choice, note the phrase somewhere temporary or not at all, send it exactly what the interaction needs, and do the thing. If you sign something malicious, the loss is capped at the burner's balance.
This directly addresses the second most common cause of software wallet losses. On smart-contract chains, granting a spending allowance is a normal operation and a malicious contract asks for an unlimited one. You approve, nothing happens, and weeks later the contract empties that token. A hardware wallet does not save you — it signed exactly what you asked. What saves you is that the wallet you signed with only ever held forty dollars. Full mechanism in our drains guide.
Two refinements worth knowing. Do not reuse a burner across unrelated interactions, because an approval granted to one contract persists while you keep using the wallet. And when you are done with something valuable in a burner — an NFT you actually want to keep, for instance — move it to your working wallet, then stop using the burner.
Multiple wallets versus multiple accounts
Worth distinguishing, because they look similar in an interface and are completely different in risk.
Multiple accounts within one wallet — Account 1, Account 2, and so on in Ledger Live or MetaMask — are all derived from the same recovery phrase. They are useful organisation: separating a business balance from a personal one, keeping different assets tidy, giving one address to a counterparty without exposing your whole history. But they share a single point of failure. If that one phrase leaks, every account derived from it is gone simultaneously.
Genuinely separate wallets have independent recovery phrases. A compromise of one tells an attacker nothing about the other. That is real separation and it is what the savings-versus-working split requires: if your hardware wallet and your phone wallet were derived from the same phrase, you would have organisation without protection.
The practical rule: use accounts for tidiness, use separate wallets for anything where the point is limiting damage.
Keeping an inventory
This is the one genuine downside of multiple wallets, and it is solvable with a piece of paper.
The administrative risk of several wallets is that one gets forgotten. Over five or ten years, a wallet you used briefly and moved on from is a wallet you may not remember existing — and that is a real, common cause of long-term crypto loss, particularly for people who were active in an earlier cycle.
Keep a written inventory. Not the recovery phrases — those live separately — but a plain list: what wallets exist, what software or device each uses, roughly what is in it, where the backup is kept, and whether a passphrase was set. Store it with your important documents, and update it when something changes.
This document does double duty as your inheritance instruction. A recovery phrase with no explanation is nearly useless to a non-technical beneficiary; a phrase plus a page explaining what it opens and what to do with it is actionable. Our backup guide covers the inheritance side, and multisig is the more robust answer once amounts get serious.
Tax and record-keeping across wallets
Running several wallets makes tax records slightly more work and considerably more important, so a note on it.
Transfers between wallets you control are not disposals and generate no taxable income — moving funds from your working wallet to your hardware wallet is not a sale. But Inland Revenue treats cryptoassets as property and expects you to be able to calculate the New Zealand dollar value of your transactions, so record every movement: date, amounts, both addresses, network fee, and a clear label saying it was internal.
That labelling matters more when you have several wallets, because the on-chain picture is a series of transfers between addresses that IRD has no inherent reason to know are all yours. From 1 April 2026 the platforms either side of your wallets report to IRD under the Crypto-Asset Reporting Framework, with the first reports due by 30 June 2027 — so what they see is money leaving an exchange and, eventually, money arriving at one. Your records are what explains the middle. Full detail in our tax and CARF guide. General information, not tax advice.
From our testing notes
The people we have spoken to who are still doing this well after several years are almost never the ones with the most secure device. They are the ones who decided early what each wallet was for and wrote it down. The failure mode is never a dramatic breach — it is a slow, invisible drift of the hot balance upward until one bad signature costs far more than it should have.
Frequently asked
Questions on this topic
How many crypto wallets should I have?
Two, for most people. A hardware wallet holding whatever you consider savings, and one software wallet holding a deliberately small amount you actually spend, swap and experiment with. Add a burner wallet if you interact with new smart contracts, and add multisig if the amount would materially change your life. More than that and you start losing track, which creates its own risk.
Can I have multiple crypto wallets?
Yes, as many as you like. Wallets are not accounts registered with anyone — they are key pairs your own device generates, so there is no limit, no registration and nobody to notify. You can also have multiple accounts within a single wallet, all derived from the same recovery phrase, which is different: those share a single point of failure, so it is organisation rather than separation.
Is it bad to have multiple crypto wallets?
Only if you lose track of them. The risk of several wallets is administrative rather than technical: more recovery phrases to protect, more places to check, and a real possibility that a wallet gets forgotten entirely — which is one of the more common ways people lose crypto over long periods. Keep a written inventory of what exists and where the backups are, stored with your other important documents.
What is a burner wallet and do I need one?
A wallet created deliberately for one risky interaction and abandoned afterwards — minting from an unknown project, claiming an airdrop, connecting to an application you have not vetted. You fund it with only what the interaction needs, so a malicious signature caps your loss at the burner's balance instead of your holdings. If you interact with new smart contracts at all, yes, you need one. It takes a minute to create and it removes the largest software wallet risk.
Should I use one wallet per cryptocurrency?
No — organise by purpose, not by asset. A modern multi-chain wallet handles many assets from one recovery phrase, so splitting by coin multiplies your backup burden for no security gain. The split that actually matters is savings versus spending: what is protected by a hardware device and what sits in a hot wallet where a bad signature can reach it.
Next in this cluster