Hot Wallet Compromise
Pronunciation: HOT WAW-lit KOM-pruh-myz
Also known as: Online wallet compromise, Hot wallet breach
Definition
A hot wallet compromise occurs when an attacker gains unauthorized control over an internet-connected wallet, its signing keys, approval workflow, or supporting infrastructure. It is more specific than a general private key compromise because the incident may also involve API credentials, wallet software, policy engines, administrators, or compromised transaction instructions. Operationally, teams should limit balances, separate duties, use allowlists and transaction limits, and monitor signing behavior.
Overview
A hot wallet compromise occurs when an attacker gains unauthorized control over an internet-connected wallet, its signing keys, approval workflow, or supporting infrastructure.
Hot Wallet Compromise is closely connected to Private Key Compromise, Multi-Party Computation Wallet, and Malicious Signature. It is more specific than a general private key compromise because the incident may also involve API credentials, wallet software, policy engines, administrators, or compromised transaction instructions.
Operational implementation should limit balances, separate duties, use allowlists and transaction limits, monitor signing behavior, isolate key material, require independent approval, sweep excess funds, and maintain emergency freeze and migration procedures.
The principal failure modes include key theft, malicious insiders, poisoned dependencies, cloud credential compromise, policy bypass, unauthorized signing, and delayed detection of outbound transfers.
Useful measures include value at risk, unauthorized-signing attempts, time to freeze, hot-wallet exposure ratio, and recovery amount after compromise.
Operationally, teams should limit balances, separate duties, use allowlists and transaction limits, and monitor signing behavior. Key risks include key theft, malicious insiders, poisoned dependencies, and cloud credential compromise.
A production treatment of Hot Wallet Compromise should test hot wallet compromise occurs when an attacker gains unauthorized control over an internet-connected wallet, its signing keys, approval workflow, or supporting infrastructure within the relevant asset, decision, or service state. The Hot Wallet Compromise context record for its signing keys, approval workflow, and supporting infrastructure should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Hot Wallet Compromise should determine whether safeguards addressing its signing keys, approval workflow, and supporting infrastructure changed exposure in practice, not merely whether a document or setting existed.
Key Takeaway
A hot wallet compromise occurs when an attacker gains unauthorized control over an internet-connected wallet, its signing keys, approval workflow, or supporting infrastructure.
Sources
- Recommendation for Key Management, NIST SP 800-57 Part 1 Rev. 5 — NIST (2026-08-03)
- Incident Response Recommendations and Considerations, NIST SP 800-61 Rev. 3 — NIST (2026-08-03)
- NIST Workshop on Multi-Party Threshold Schemes 2026 — NIST (2026-08-03)