Skip to content
Glossary

Cold storage

Holding private keys on a device or medium that has never been, and is not, connected to a network.

Why it matters

Cold storage protects keys from remote compromise. It does not protect against approving a malicious transaction, which is a separate control — the Bybit incident involved a cold wallet whose keys were never extracted.

What you can check

Cold storage describes where a key is held, not how a transaction is approved. The question that matters is what the signer sees before approving, and whether the approval path is reachable from an internet-connected machine. An offline key can still authorise a transfer if the request that reaches it has been altered upstream.

Where it showed up

Records in the Incident Tracker that turn on this: Bybit cold wallet compromise.

Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.