Hot wallet, cold wallet: the custody split
Same BTC. Different keys. Wildly different operational risk.
By Solomon Ajayi · Free to read, no signup
Any custodial fintech splits its crypto holdings between HOT wallets (private keys online, can broadcast immediately, low operational friction, high security risk) and COLD wallets (keys air-gapped, requires multi-signer offline ceremony to broadcast, high operational friction, near-zero theft risk). Best practice: keep 5-15% of customer holdings hot (enough to satisfy daily withdrawals), the rest cold. As deposits accumulate or withdrawals drain hot, you REBALANCE between the two. Each rebalance is a chain transaction that hits a network fee and gets booked as an asset reclassification, not a P&L event. This lesson posts a cold-to-hot rebalance.
Hot and cold wallets hold the same coins under wildly different risk. A hot wallet keeps its keys online, so it can broadcast a withdrawal in seconds, which is exactly why a thief who breaches your systems can drain it in seconds too. A cold wallet keeps its keys air-gapped behind a multi-signer offline ceremony, which makes it nearly impossible to steal from and nearly as inconvenient to spend from. The accounting treats them as two asset accounts holding one underlying thing, split by operational risk tier rather than by what the coins are.
The hot ratio, typically five to fifteen percent of holdings, is a buffer sized to cover daily withdrawals. When withdrawals drain it too low, you rebalance from cold to hot; when deposits pile it too high, you push the excess back to cold. Either way the move is a chain transaction that costs a real network fee, so the entry has three lines: the destination wallet up by the net, the source wallet down by the gross, and a Network Fee expense for the difference. The coins simply changed custody tier, so there is no revenue and no P&L beyond that fee.
Getting the ratio wrong cuts both ways. Too little hot and a busy withdrawal day empties the buffer, forcing an emergency cold ceremony or, worse, a stampede of users unable to withdraw. Too much hot and you are carrying more theft exposure than you need, which shows up as higher insurance premiums. So the target is recalibrated regularly against actual withdrawal velocity, not set once and forgotten.
Worked example, step by step
State: 1 BTC hot, 9 BTC cold (10% hot ratio)
Standard hot/cold split. ₦750M of BTC custody, 10% online for daily ops, 90% vaulted.
| Account | Debit | Credit |
|---|---|---|
| Hot Wallet (BTC) (1900) | ₦75,000,000.00 | |
| Cold Wallet (BTC, vaulted) (1950) | ₦675,000,000.00 | |
| On-Chain Network Fees (5910) | ₦750,000,000.00 |
Hot Wallet UP ₦75,000,000 (debit). Cold Wallet UP ₦675,000,000 (debit). Two debits won't balance, so we add a token-issued liability counterpart for the bootstrap: Tokens Issued (the user wallet aggregate) UP ₦750,000,000 (credit). We post this as a state-setting entry.
Withdrawals drain hot wallet to 0.3 BTC; rebalance 2 BTC from cold
A busy day of user withdrawals dropped the hot wallet from 1 BTC to 0.3 BTC. Operations triggers a cold-to-hot rebalance: move 2 BTC from cold to hot. This requires a multi-signer ceremony, a chain broadcast, and a network fee (~0.0001 BTC ≈ ₦7,500).
| Account | Debit | Credit |
|---|---|---|
| Hot Wallet (BTC) (1900) | ₦149,992,500.00 | |
| On-Chain Network Fees (5910) | ₦7,500.00 | |
| Cold Wallet (BTC, vaulted) (1950) | ₦150,000,000.00 |
Hot Wallet UP ₦150,000,000 less the fee = ₦149,992,500 (debit). Cold Wallet DOWN ₦150,000,000 (credit). Network Fee UP ₦7,500 (debit, expense). Three lines, balanced: 149,992,500 + 7,500 = 150,000,000.
Takeaway
Hot/cold wallet accounting tracks the same underlying crypto across two operational risk tiers. The hot wallet supports daily withdrawals at low ceremony cost (and high theft risk); the cold wallet vaults the bulk at high ceremony cost (and near-zero theft risk). Every rebalance is a CHAIN TRANSACTION with a real fee, book that fee to a Network Fee expense account so your true cost of operating crypto custody is visible. Target hot ratio: 5-15%, recalibrated weekly based on actual withdrawal velocity. Below 5% and you risk a withdrawal stampede; above 15% and your theft-risk insurance premiums spike.
Practice this on a real ledger
Reading is half of it. Open this lesson in the lab to post the entries yourself against a real Postgres-backed double-entry ledger, with the validation on. Free, your sandbox is yours.