
Your 1st Lesson to Web3: Complete Guide to Wallets, Private Keys and Anti-Phishing Security | EX.IO
— EX.IO Web3 Education Series
Author: Henry YANG, PR & Marketing of EX.IO
In the traditional financial world, your assets are protected by layers of banks and custodians. In the Web3 world, the “wallet” is the sole gateway to your on-chain assets, and the “private key” is the sole credential that proves ownership. On-chain transactions are irreversible—there is no customer service that can reverse them. A single moment of carelessness can mean permanent loss of assets.

For this reason, security awareness is not optional—it is a mandatory requirement for every participant.
As a Virtual Asset Trading Platform (VATP) licensed by the Hong Kong Securities and Futures Commission (SFC), EX.IO has held Type 1 (dealing in securities) and Type 7 (providing automated trading services) licences since December 2024, and is Hong Kong’s first licensed virtual asset trading platform with a securities firm background [1][2]. We firmly believe that compliance and education must go hand in hand for the industry to develop steadily and sustainably.
This article starts from “What is a wallet” and systematically explains wallet types, the differences between hot and cold wallets, private key storage methods, and practical anti-phishing measures to help you take your first secure step into Web3.
1. What Is a Web3 Wallet? Three Key Concepts You Must Understand
Many beginners mistakenly believe that a wallet “stores coins.” In reality, crypto assets are recorded on the blockchain; the wallet only stores the keys that unlock those assets. Understanding the following three concepts is the foundation of all security practices:
Wallet Address (Address): A string of characters derived from the public key, similar to a bank account number. It can be shared publicly for receiving funds.
Private Key: An extremely long random string of characters, equivalent to a combination of “account password + seal.” Whoever controls the private key can move all assets under that address. Once a private key is leaked or lost, no institution can help you recover it.
Seed Phrase / Recovery Phrase: Usually 12 or 24 English words that serve as a human-readable backup of the private key. With the seed phrase, you can fully recover all your assets in any compatible wallet. Therefore, its confidentiality level is identical to that of the private key itself.
Basic process for setting up a self-custodial wallet: Choose a reputable wallet application (download from the official website or official app store) → Create a new wallet → The system generates a seed phrase → Copy it offline and back it up securely → Set a password / biometric authentication → Start using it. The entire process takes only a few minutes, but the quality of the “seed phrase backup” step determines the life or death of your assets.
2. What Types of Wallets Exist in the Web3 World?
2.1 Classified by “Who Controls the Private Key”: Custodial vs Self-Custodial Wallets
| Type | Who Holds the Private Key | Typical Examples | Suitable For |
| Custodial Wallet | Platform / Institution | Licensed exchange accounts (e.g. EX.IO), custody providers | Beginners, institutional investors, those who value compliance & convenience |
| Self-Custodial Wallet | The user themselves | MetaMask, hardware wallets, etc. | Users with on-chain needs who are willing to assume self-custody responsibility |
Under the custodial model, the platform holds the private keys on your behalf. The experience is similar to online banking—you can recover passwords, there is customer support, and regulated platforms must comply with requirements for asset segregation, insurance, and security audits.
Under the self-custodial model, you have complete control over your assets, but you also bear full custody responsibility. The flip side of “Not your keys, not your coins” is “Your keys, your responsibility.”
2.2 Classified by Form: Software Wallets, Hardware Wallets, Paper Wallets
- Software Wallets: Mobile apps, browser extensions (e.g. MetaMask), or desktop applications. Free and convenient, suitable for everyday small transactions, but always connected to the internet, resulting in a larger attack surface.
- Hardware Wallets: Dedicated devices that look like USB sticks (e.g. Ledger, Trezor). The private key is generated inside the device and never leaves it; signing is completed in an offline environment. Currently recognised as the highest-security self-custodial solution for individual users.
- Paper Wallets: Private keys / seed phrases printed on paper in text or QR-code form. Completely offline, but vulnerable to fire, water, and wear. Now rarely used as a primary solution and more often as a supplementary backup medium.
2.3 Emerging Trends: Smart Contract Wallets & MPC Wallets
The industry is working hard to eliminate the security pain point of “writing down 24 words.” Smart contract wallets(based on account abstraction) support programmable security features such as social recovery and spending limits. MPC (Multi-Party Computation) wallets split the private key into multiple shares held separately, so that a single-point leak is no longer fatal. These solutions are gradually maturing, but for most users, understanding the traditional private-key / seed-phrase model remains essential foundational knowledge.
3. Cold Wallet vs Hot Wallet: The Core Difference Is “Whether It Connects to the Internet”
The only criterion distinguishing “cold” from “hot” is whether the private key comes into contact with the internet.
| Dimension | Hot Wallet | Cold Wallet |
| Connectivity | Private key stored on internet-connected devices (phone, computer, cloud) | Private key remains fully offline (hardware device, paper, offline computer) |
| Convenience | High — sign, transfer, and interact with DApps anytime | Low — requires connecting the device and manual confirmation |
| Security | Exposed to online attack surfaces: malware, phishing, malicious approvals, etc. | Largely immune to online attacks; risk shifts to physical custody |
| Cost | Mostly free | Hardware wallets require purchase (hundreds to over a thousand HKD) |
| Typical Use | Daily small transactions, on-chain interactions — “pocket money” | Large holdings, long-term storage — the “vault” |
The industry-standard asset allocation strategy is “hot-and-cold layering”: place the vast majority of assets in a cold wallet for long-term storage, and keep only a small amount of funds in a hot wallet for daily operations. This is exactly the same logic as keeping pocket money in a current account and large sums in fixed deposits or a safe.
The custodial architecture of licensed trading platforms follows the same principle—placing client assets in cold storage at a far higher ratio than individual users can achieve, supported by multi-signature authorisation and insurance arrangements [7].
4. Private Keys & Seed Phrases: How to Store Them Securely
The seed phrase is the “last line of defence” for your on-chain assets. Please carefully observe the following rules:
What You Should Do
- Hand-copy offline with multiple backups: Neatly write down the seed phrase with pen and paper (double-check the spelling and order of every word). Make 2–3 copies and store them in different fire- and water-resistant physical locations (e.g. a home safe and a bank safe-deposit box). For large holdings, consider a metal seed phrase plate that can withstand fire and flooding.
- Verify immediately after copying: Some wallets support a “seed phrase verification” function. You can also test the recovery process with a small amount of assets first, and only transfer larger amounts after confirming the backup works.
- Consider splitting and inheritance planning: Advanced users may adopt Shamir’s Secret Sharing or store “seed phrase + passphrase” in separate locations. At the same time, you should plan an inheritance arrangement for family members to avoid assets being permanently locked if something happens to you.
- Buy hardware wallets only from official channels: Reject second-hand or devices of unknown origin. Upon receipt, verify packaging integrity and firmware authenticity. Never buy a device that comes with a pre-set seed phrase.
What You Should Never Do
- Do not take screenshots, photos, or store in the cloud: Phone photo albums often auto-sync to the cloud—taking a screenshot is equivalent to putting the key on the internet. The 2025 Android malware Crocodilus even used “emergency backup prompts” to trick users into entering their seed phrase on an already compromised device [4]—any action of entering a seed phrase on an internet-connected device is extremely dangerous.
- Do not send it to anyone: No official customer service, project team, or platform will ever ask you for your seed phrase or private key. EX.IO and any legitimate institution’s customer service will never request your seed phrase, private key, or SMS verification codes. Anyone who asks for them is 100% a scammer.
- Do not store it in plain-text files outside a password manager: Computer notepads, WeChat favourites, email drafts, cloud notes—all are routine places for hackers to look.
- Do not display it in front of others: Entering passwords, displaying QR codes, or writing down a seed phrase in public places risks being observed or recorded.
5. Anti-Phishing in Practice: Recognise Scams and Protect Your Signatures
Phishing is currently the number-one cause of on-chain asset losses. According to Scam Sniffer statistics, “Wallet Drainer” phishing caused nearly USD 500 million in losses in 2024, affecting more than 332,000 victims; in 2025 such losses fell to approximately USD 83.85 million (106,000 victims), yet the methods continue to evolve rapidly [5][6]. According to Chainalysis estimates, total on-chain scam revenue in 2024 reached at least USD 9.9 billion [7].
Scammers do not need to break the blockchain—they only need to trick you into “signing with your own hand.”
Common Phishing Tactics Explained
- Fake websites and lookalike domains: Spreading domains that differ from the official site by only one character (e.g. ex-1o.com) via search-engine ads or social-media comments, with pixel-perfect page clones. Once you connect your wallet and approve, assets are drained.
- Malicious approvals and Permit signatures: Fake airdrop or staking pages induce you to click “Approve / Claim.” You think you are claiming rewards; in reality you are signing an “unlimited allowance,” after which the scammer can empty your tokens at any time. Off-chain signatures (Permit) are even more stealthy—they consume no gas and leave little on-chain footprint, yet assets are still transferred after signing.
- Fake customer service and fake officials: Impersonating official staff on Discord, Telegram, or X (Twitter) who proactively DM you to “help solve a problem,” or fake platforms sending “account anomaly” or “compensation for delisting” emails/SMS, all ultimately pointing to a phishing link.
- Fake wallet apps and malicious extensions: Counterfeit wallets on app stores or third-party download sites that upload the seed phrase to a backend the moment the wallet is created.
- New composite attacks: In 2025, cases emerged of packing multiple malicious operations into a single signature using EIP-7702 features, as well as secondary phishing via fake “Revoke” websites. Even major exchanges have suffered losses of USD 1.5 billion due to multi-sig operation interfaces being tampered with—what you see on the front-end interface is not necessarily the truth, representing the highest form of attack [7].
Seven Iron Rules of Anti-Phishing
- Only access via bookmarks: Add frequently used platforms and wallet official websites to your browser bookmarks. Never click links from search ads, group messages, or private messages. Taking EX.IO as an example, our official website is www.ex.io—please recognise and bookmark it. Do not treat any other domain as our official website.
- Read every signature carefully: For any “Approve, Sign, Permit, SetApprovalForAll” pop-up, first ask yourself three questions: Whose website is this? Who is the approval target? What is the approval amount? Refuse any signature request you do not fully understand.
- Regularly revoke idle approvals: Use reputable tools to check and revoke token approvals that are no longer needed.
- Test large operations with small amounts first: Before transferring to a new address or interacting with a new contract, first send a tiny amount to verify.
- Confirm large operations on a hardware wallet whenever possible: The hardware wallet screen displays transaction details that have not been tampered with by the computer—trust the device screen, not the computer screen.
- Verify the identity of “people”: Official staff will never proactively private-message you. For account issues, only seek verification through the official app’s customer service or the official website. If you receive a “customer service call,” hang up and call back the official hotline to verify.
- Isolate risk environments: Use a dedicated “pocket-money” wallet for high-risk interactions such as airdrops and NFT minting, and keep it completely separate from the wallet that holds your main assets.
6. Beyond Self-Custody: What Can a Regulated Platform Do for You?
Self-custody gives you complete control over your assets and also requires you to assume full security responsibility. For many investors—especially institutions and professional investors—a more prudent path is: conduct daily trading and asset allocation through a licensed platform, and only use self-custody when there is a clear on-chain need.
Taking EX.IO as an example: the platform operates under the framework of the Hong Kong Securities and Futures Ordinance and the Anti-Money Laundering and Counter-Terrorist Financing Ordinance [3]; client assets are segregated from the platform’s own assets as required by regulation, protected by an institutional-grade hot-and-cold wallet layered custody architecture, and supported by multi-signature authorisation, anomaly monitoring and insurance arrangements [7]. This entrusts professional teams with private-key management, multi-signature authorisation, anomaly monitoring, and other work that individual users find difficult to perform independently.
At the same time, EX.IO is one of the virtual asset trading platforms introduced under the Hong Kong Government’s Office for Attracting Strategic Enterprises (OASES) programme [8], and continuously invests in investor education—because we believe that users who know how to protect themselves form the most solid foundation of the industry.
7. Wallet Security Self-Checklist
- ☐ Seed phrase can be hand-copied offline; at least two copies stored in different secure locations
- ☐ Backup has been verified with a small amount of assets and can be restored normally
- ☐ Seed phrase is never stored in any screenshot, cloud, chat history, or plain-text file
- ☐ Large assets are in a cold wallet (hardware wallet); hot wallet holds only pocket-money funds
- ☐ Hardware wallet purchased from official channels, not second-hand, and has no pre-set seed phrase
- ☐ Official websites of frequently used platforms have been added to bookmarks; never click private-message or group links
- ☐ Idle token approvals have been checked and revoked using reputable tools
- ☐ Exchange account has two-factor authentication (2FA) and withdrawal whitelist enabled
- ☐ Family members are aware of the asset inheritance arrangement (balancing confidentiality and accessibility)
- ☐ Remember: anyone who asks you for your seed phrase, private key, or verification codes must be treated with extreme caution
Frequently Asked Questions (FAQ)
1. What’s the difference between a private key and a seed phrase? The private key is the sole credential that proves ownership of your assets; the seed phrase is its human-readable backup (usually 12 or 24 English words) that can restore all your assets in any compatible wallet. Its confidentiality level is identical to the private key itself.
2. How do I choose between a hot wallet and a cold wallet? The core difference is whether the private key touches the internet. Keep large, long-term holdings in a cold wallet (hardware wallet), and only pocket-money amounts for daily use in a hot wallet. Licensed platforms apply the same hot-and-cold layering to client assets.
3. How can I protect myself from crypto phishing? Access sites only via bookmarks, read every signature request carefully, never share your seed phrase or private key with anyone, regularly revoke idle approvals, and use a separate “pocket-money” wallet for high-risk interactions.
4. Can I recover a lost seed phrase? No. If a private key or seed phrase is lost, no institution can recover it for you—which is why backup quality determines asset safety. Always verify your backup with a small-amount recovery test.
Conclusion
The freedom and opportunities of Web3 are built upon the security discipline of “self-responsibility.” Understand the essence of wallets, distinguish hot from cold, guard your private keys, and see through phishing—master these four things and you will already have outrun the vast majority of security incidents. EX.IO will continue to deliver investor education series content, working with you to build a safe and compliant digital-asset worldview.
Disclaimer: This article is for educational purposes only and does not constitute any investment advice or product offer. Virtual asset prices are highly volatile and investors may lose their entire principal; past performance is not indicative of future results. Before making any investment decision, please carefully assess based on your own experience, financial situation, investment objectives and risk tolerance, and consult independent professional advice. Third-party wallets, tools and security data mentioned in the article are for illustrative purposes only and do not represent any recommendation or endorsement by EX.IO.
Footnotes
[1] SFC list of licensed virtual asset trading platforms: https://www.sfc.hk/en/Roles-and-responsibilities/Licensing-and-registration/Hong-Kong-licensed-VA-trading-platforms ; secondary media source: ChainCatcher https://www.chaincatcher.com/zh-tw/article/2157865
[2] EX.IO official press release (Franklin Templeton partnership, platform background): https://www.ex.io/support/announcements/press-release-ex-io-becomes-franklin-templetons-licensed-vatp-partner-in-hong-kong-offers-benji-to-pioneer-a-new-era-of-compliant-on-chain-financial-instruments
[3] Regulatory framework: Securities and Futures Ordinance (Cap. 571) & Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615); SFC VATP Guidelines: https://www.sfc.hk/en/Rules-and-standards/codes-and-guidelines
[4] ThreatFabric analysis of Android malware Crocodilus (March 2025)
[5] Scam Sniffer wallet-drainer statistics 2024/2025; secondary: Odaily https://www.odaily.news/en/post/5208221
[6] Tangem wallet-drainer explainer (secondary): https://tangem.com/tr/learning-hub/post/what-are-wallet-drainers/
[7] Chainalysis 2025 Crypto Crime Report; secondary: Odaily https://www.odaily.news/en/post/5208221
[8] OASES official announcement — wording now “one of the platforms introduced under OASES”, pending official list confirmation.