4 ms·
Bitcoin n00b here. What exactly is a hot wallet/storage?
by slaxman 13y ago
Bitcoin n00b here.
What exactly is a hot wallet/storage?
- bitJericho 13y agoHot storage is a wallet that is accessible online, eg, n wallet used by the "bank" to transfer coins from their own account to a customer that wants to be paid out. A cold wallet is one where the keys are kept offline and not plugged into anything, eg, a printout, or a USB key.
- slaxman 13y agoSo, is keeping a majority of bitcoins (>98%) bitcoins in cold storage the only way to keep them safe?
- infinii 13y agoIf they secured their servers (from hacking), they could theoretically leave everything in hot storage (although it's not necessary for normal operations as others have stated).
- patio11 13y agoIn the real financial world, matching and settlement occur asynchronously from each other, on different systems. Matching is "X tried to buy Y at Z, Q tried to sell Y at Z, their orders match." Settlement is physically delivering Y to X while physically debiting Z from Q. Bitcoin developers haven't quite cottoned onto the wisdom of separating these functions architecturally. (One of many advantages is "If your matching system is compromised, you shut it down and investigate, but no money actually leaves. The settlement system is in your back office and much more protected than the matching system, because the settlement system doesn't have to talk to customers directly.") Bitcoin developers instead have developed a security pattern called hot wallet/cold wallet, where BTC which are available to the system are "hot" and BTC which are not available to the system are "cold." The idea is that, in any given day, you might only require 2% or so of your company's total reserves to go in or out. You keep the private keys to, say, 5% of it on the live system. That's your hot wallet. You keep the private keys to the remaining 95% somewhere else. That's your cold wallet. Even if your live system is rooted, you should not (the thinking goes) lose the private keys to the cold wallet. The Bitcoin community widely believes that this pattern is sufficient to prevent events like the recent Mt. Gox debacle, where the system was compromised and both the hot wallet and cold wallet were drained.
- sandGorgon 13y ago@patio11 - I dont understand. From what you wrote about matching-settlement vs hot-cold it seems there are still two systems at play there. I don't understand why there is a difference in security unless there is a time element in play (settlement at EOD). Doesn't that violate the real time nature of bitcoin then? I have built e-commerce settlement systems in the past and I thought that the big challenge with bitcoin was always the instantaneous element.
- patio11 13y agoYou're correct, injecting extra time delay between transactions and settlement is one of the reasons why that architecture is more secure. That's a feature of it, not a bug. That is not the only difference: at almost all Bitcoin exchanges, your hot wallet is on your web tier and exposed to the adversary (so successful adversaries have authority to disburse 5% of your deposits), with the matching/settlement separation, a successful adversary still has no authority to disburse any percentage of your deposits. The hot/cold system also doesn't require e.g. intelligent accounting and reconciliation of those accounts, which is a major reason why the financial system actually works. BTW: Bitcoin isn't a real-time system. The community widely believes it is, but people who actually understand what is happening would say "cough Yeah by 'real-time' we mean 'an hour later' cough."
- minimax 13y agoBitcoin developers haven't quite cottoned onto the wisdom of separating these functions architecturally. I'm not sure this is true. Any off blockchain transaction is basically an unsettled (and therefore reversible) bitcoin transaction. So for example, trades on bitcoin exchanges and payments between web wallets will have separate and distinct settlement phases. Generally bitcoin enthusiasts gloss over this though, because they don't like the idea of reversible transactions. The current maximum transaction rate for the bitcoin networks is something like seven transactions per second. So either they'll have to figure out how to increase that or move to a more conventional clearing and settlement system if bitcoin-as-a-payment-network ever takes off in real size.
- 13y ago