
— EX.IO Web3 Education Series
Author: Henry YANG, PR & Marketing of EX.IO
In the traditional financial world, your assets are protected by layers of banks and custodians. In the Web3 world, the “wallet” is the sole gateway to your on-chain assets, and the “private key” is the sole credential that proves ownership. On-chain transactions are irreversible—there is no customer service that can reverse them. A single moment of carelessness can mean permanent loss of assets.

For this reason, security awareness is not optional—it is a mandatory requirement for every participant.
As a Virtual Asset Trading Platform (VATP) licensed by the Hong Kong Securities and Futures Commission (SFC), EX.IO has held Type 1 (dealing in securities) and Type 7 (providing automated trading services) licences since December 2024, and is Hong Kong’s first licensed virtual asset trading platform with a securities firm background [1][2]. We firmly believe that compliance and education must go hand in hand for the industry to develop steadily and sustainably.
This article starts from “What is a wallet” and systematically explains wallet types, the differences between hot and cold wallets, private key storage methods, and practical anti-phishing measures to help you take your first secure step into Web3.
Many beginners mistakenly believe that a wallet “stores coins.” In reality, crypto assets are recorded on the blockchain; the wallet only stores the keys that unlock those assets. Understanding the following three concepts is the foundation of all security practices:
Wallet Address (Address): A string of characters derived from the public key, similar to a bank account number. It can be shared publicly for receiving funds.
Private Key: An extremely long random string of characters, equivalent to a combination of “account password + seal.” Whoever controls the private key can move all assets under that address. Once a private key is leaked or lost, no institution can help you recover it.
Seed Phrase / Recovery Phrase: Usually 12 or 24 English words that serve as a human-readable backup of the private key. With the seed phrase, you can fully recover all your assets in any compatible wallet. Therefore, its confidentiality level is identical to that of the private key itself.
Basic process for setting up a self-custodial wallet: Choose a reputable wallet application (download from the official website or official app store) → Create a new wallet → The system generates a seed phrase → Copy it offline and back it up securely → Set a password / biometric authentication → Start using it. The entire process takes only a few minutes, but the quality of the “seed phrase backup” step determines the life or death of your assets.
2.1 Classified by “Who Controls the Private Key”: Custodial vs Self-Custodial Wallets
| Type | Who Holds the Private Key | Typical Examples | Suitable For |
| Custodial Wallet | Platform / Institution | Licensed exchange accounts (e.g. EX.IO), custody providers | Beginners, institutional investors, those who value compliance & convenience |
| Self-Custodial Wallet | The user themselves | MetaMask, hardware wallets, etc. | Users with on-chain needs who are willing to assume self-custody responsibility |
Under the custodial model, the platform holds the private keys on your behalf. The experience is similar to online banking—you can recover passwords, there is customer support, and regulated platforms must comply with requirements for asset segregation, insurance, and security audits.

Under the self-custodial model, you have complete control over your assets, but you also bear full custody responsibility. The flip side of “Not your keys, not your coins” is “Your keys, your responsibility.”
2.2 Classified by Form: Software Wallets, Hardware Wallets, Paper Wallets
2.3 Emerging Trends: Smart Contract Wallets & MPC Wallets
The industry is working hard to eliminate the security pain point of “writing down 24 words.” Smart contract wallets(based on account abstraction) support programmable security features such as social recovery and spending limits. MPC (Multi-Party Computation) wallets split the private key into multiple shares held separately, so that a single-point leak is no longer fatal. These solutions are gradually maturing, but for most users, understanding the traditional private-key / seed-phrase model remains essential foundational knowledge.
The only criterion distinguishing “cold” from “hot” is whether the private key comes into contact with the internet.
| Dimension | Hot Wallet | Cold Wallet |
| Connectivity | Private key stored on internet-connected devices (phone, computer, cloud) | Private key remains fully offline (hardware device, paper, offline computer) |
| Convenience | High — sign, transfer, and interact with DApps anytime | Low — requires connecting the device and manual confirmation |
| Security | Exposed to online attack surfaces: malware, phishing, malicious approvals, etc. | Largely immune to online attacks; risk shifts to physical custody |
| Cost | Mostly free | Hardware wallets require purchase (hundreds to over a thousand HKD) |
| Typical Use | Daily small transactions, on-chain interactions — “pocket money” | Large holdings, long-term storage — the “vault” |
The industry-standard asset allocation strategy is “hot-and-cold layering”: place the vast majority of assets in a cold wallet for long-term storage, and keep only a small amount of funds in a hot wallet for daily operations. This is exactly the same logic as keeping pocket money in a current account and large sums in fixed deposits or a safe.
The custodial architecture of licensed trading platforms follows the same principle—placing client assets in cold storage at a far higher ratio than individual users can achieve, supported by multi-signature authorisation and insurance arrangements [7].
The seed phrase is the “last line of defence” for your on-chain assets. Please carefully observe the following rules:
What You Should Do
What You Should Never Do
Phishing is currently the number-one cause of on-chain asset losses. According to Scam Sniffer statistics, “Wallet Drainer” phishing caused nearly USD 500 million in losses in 2024, affecting more than 332,000 victims; in 2025 such losses fell to approximately USD 83.85 million (106,000 victims), yet the methods continue to evolve rapidly [5][6]. According to Chainalysis estimates, total on-chain scam revenue in 2024 reached at least USD 9.9 billion [7].
Scammers do not need to break the blockchain—they only need to trick you into “signing with your own hand.”
Common Phishing Tactics Explained
Seven Iron Rules of Anti-Phishing
Self-custody gives you complete control over your assets and also requires you to assume full security responsibility. For many investors—especially institutions and professional investors—a more prudent path is: conduct daily trading and asset allocation through a licensed platform, and only use self-custody when there is a clear on-chain need.
Taking EX.IO as an example: the platform operates under the framework of the Hong Kong Securities and Futures Ordinance and the Anti-Money Laundering and Counter-Terrorist Financing Ordinance [3]; client assets are segregated from the platform’s own assets as required by regulation, protected by an institutional-grade hot-and-cold wallet layered custody architecture, and supported by multi-signature authorisation, anomaly monitoring and insurance arrangements [7]. This entrusts professional teams with private-key management, multi-signature authorisation, anomaly monitoring, and other work that individual users find difficult to perform independently.
At the same time, EX.IO is one of the virtual asset trading platforms introduced under the Hong Kong Government’s Office for Attracting Strategic Enterprises (OASES) programme [8], and continuously invests in investor education—because we believe that users who know how to protect themselves form the most solid foundation of the industry.
1. What’s the difference between a private key and a seed phrase? The private key is the sole credential that proves ownership of your assets; the seed phrase is its human-readable backup (usually 12 or 24 English words) that can restore all your assets in any compatible wallet. Its confidentiality level is identical to the private key itself.
2. How do I choose between a hot wallet and a cold wallet? The core difference is whether the private key touches the internet. Keep large, long-term holdings in a cold wallet (hardware wallet), and only pocket-money amounts for daily use in a hot wallet. Licensed platforms apply the same hot-and-cold layering to client assets.
3. How can I protect myself from crypto phishing? Access sites only via bookmarks, read every signature request carefully, never share your seed phrase or private key with anyone, regularly revoke idle approvals, and use a separate “pocket-money” wallet for high-risk interactions.
4. Can I recover a lost seed phrase? No. If a private key or seed phrase is lost, no institution can recover it for you—which is why backup quality determines asset safety. Always verify your backup with a small-amount recovery test.
The freedom and opportunities of Web3 are built upon the security discipline of “self-responsibility.” Understand the essence of wallets, distinguish hot from cold, guard your private keys, and see through phishing—master these four things and you will already have outrun the vast majority of security incidents. EX.IO will continue to deliver investor education series content, working with you to build a safe and compliant digital-asset worldview.
Disclaimer: This article is for educational purposes only and does not constitute any investment advice or product offer. Virtual asset prices are highly volatile and investors may lose their entire principal; past performance is not indicative of future results. Before making any investment decision, please carefully assess based on your own experience, financial situation, investment objectives and risk tolerance, and consult independent professional advice. Third-party wallets, tools and security data mentioned in the article are for illustrative purposes only and do not represent any recommendation or endorsement by EX.IO.
[1] SFC list of licensed virtual asset trading platforms: https://www.sfc.hk/en/Roles-and-responsibilities/Licensing-and-registration/Hong-Kong-licensed-VA-trading-platforms ; secondary media source: ChainCatcher https://www.chaincatcher.com/zh-tw/article/2157865
[2] EX.IO official press release (Franklin Templeton partnership, platform background): https://www.ex.io/support/announcements/press-release-ex-io-becomes-franklin-templetons-licensed-vatp-partner-in-hong-kong-offers-benji-to-pioneer-a-new-era-of-compliant-on-chain-financial-instruments
[3] Regulatory framework: Securities and Futures Ordinance (Cap. 571) & Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615); SFC VATP Guidelines: https://www.sfc.hk/en/Rules-and-standards/codes-and-guidelines
[4] ThreatFabric analysis of Android malware Crocodilus (March 2025)
[5] Scam Sniffer wallet-drainer statistics 2024/2025; secondary: Odaily https://www.odaily.news/en/post/5208221
[6] Tangem wallet-drainer explainer (secondary): https://tangem.com/tr/learning-hub/post/what-are-wallet-drainers/
[7] Chainalysis 2025 Crypto Crime Report; secondary: Odaily https://www.odaily.news/en/post/5208221
[8] OASES official announcement — wording now “one of the platforms introduced under OASES”, pending official list confirmation.