Setting up your own crypto wallet takes about twenty minutes and comes down to four moves: choose the wallet type, generate the wallet, back up the recovery words offline, and use a small test amount to check that funds travel out and back. The third move decides everything that follows, because it is the only one nobody can catch up on for you.
This guide walks through each of those steps, explains the terms at the point where you first meet them, and closes with what a self-custodied wallet means in legal and tax terms in Germany.
What a Crypto Wallet Stores, and Why Your Coins Are Never Inside It
The name is misleading. A wallet is not a purse holding coins. Germany’s Federal Ministry of Finance puts it plainly in its letter of 6 March 2025: “No crypto assets are held in the wallet itself; they always remain on the blockchain” (paragraph 17). Keyring would be the more accurate translation.
What the wallet actually manages are two kinds of keys. The public key is the receiving address; the ministry compares it to an IBAN or an email address (paragraph 18). It may be known to others, because its only job is to assign balances on the blockchain. The private key is its counterpart: it produces the digital signature under every payment and is known to the holder alone.
From that follows the sentence this whole text rests on: whoever controls the private key controls the funds. The Federal Fiscal Court took the same view for tax purposes in 2023, attributing crypto assets to whoever is able to initiate transactions (judgment of 14 February 2023, IX R 3/22).
Three Terms You Need for the Rest
- Private key: the secret number used to sign a payment. Anyone who knows it can move the funds.
- Address: the public string others use to send you funds. The private key cannot be derived back from it.
- Recovery words, also called seed or recovery phrase: a list of twelve or twenty-four words from which every private key in a wallet can be regenerated. Whoever holds that list holds the wallet, regardless of the device.
There is, incidentally, no limit on how many wallets one person may have, and each blockchain generally needs its own, because address formats differ. Anyone holding Bitcoin alongside balances on other networks will therefore usually run several wallets side by side.
Custodial or Self-Custody: The One Question That Comes First
Before you install anything, you decide how your assets are held. There are exactly two options.
In the custodial model, a company holds the private key for you. Your access runs through a username, a password and a second factor. An account at a trading platform works this way. The advantage is convenience: a forgotten password can be reset, and support is reachable. The price is counterparty risk. If the company becomes insolvent, freezes withdrawals or loses control of its own keys, your funds are tied to that fate.
In self-custody, the key sits with you. Nobody can freeze your funds, but nobody can restore them either. There is no support desk to rescue you and no reset function. The recovery words are the entire contingency plan.
Both are legitimate, and both have their place. Many investors run a split approach: whatever is actively traded stays on a licensed platform, while the long-term holding moves into their own custody. Where the dividing line falls depends entirely on how firmly you have your own backup under control.

Software Wallet, Hardware Wallet or Exchange Account: Which Type Suits You
Within self-custody there are two practical designs, plus the exchange account as a third option with no keys of your own.
Software Wallet
An application on your phone, your computer or as a browser extension. The private key sits encrypted on the device. It is quick to set up, costs nothing and suits amounts whose loss would hurt without being existential. The weak point is the device itself: malware, a tampered browser extension or one careless click all strike exactly there. Which applications are common in German-speaking markets and how they differ is set out in our software wallet comparison.
Hardware Wallet
A small dedicated device that generates the private key and never releases it. Every payment is confirmed on the device itself, usually at the press of a button and with the receiving address shown on the device’s own screen. Even an infected computer cannot trigger a payment you do not approve on the device. Cost: roughly 50 to 200 euros depending on the model.
Exchange Account
No key of your own, but no setup effort either. For small amounts, and for anything due to be sold again soon, this is a legitimate route. As a permanent solution for larger holdings it carries the counterparty risk described above.
A rough rule of thumb from practice: up to a low four-figure amount, a cleanly configured software wallet is enough. Above that the device pays off, because the surcharge becomes small relative to the amount held.
Step by Step: How to Set Up a Software Wallet
The sequence is almost identical across all common applications. Take the twenty minutes in one sitting, without interruption.
- Check the source. Download the application only from the operating system’s official app store, or from the address printed on the manufacturer’s site that you typed in yourself. Fake wallet apps are among the most common forms of fraud there are, and search results or ads are the usual entry point.
- Generate a new wallet. On first launch, choose the option for a new wallet, not the one for a recovery. The application generates the recovery words directly on the device.
- Write the words down. The application now shows twelve or twenty-four words in a fixed order. Copy them out by hand, numbered, and do not skip a single one. No screenshot, no notes app, no cloud, no email to yourself.
- Check your transcript. Most applications then quiz you on individual words. Take that seriously, and afterwards compare word for word against your transcript once more. One transposition in the order makes the backup worthless.
- Set a device lock. Assign a PIN or password for the application and switch on the device’s screen lock. That is no defence against malware, but it is one against a lost rucksack.
- Send a test amount. Transfer a small amount to the new address, then send part of it back. Only once both directions have worked is the wallet ready for use.
- Practise the recovery once. The step almost everyone skips: reset the application and restore the wallet from your handwritten list. After that you know the backup holds, rather than merely knowing it is lying around somewhere.
The Recovery Words: Twelve Words That Carry Everything
The word list follows an open standard called BIP-39. It defines a fixed vocabulary of 2,048 words that every compliant wallet draws on. That is precisely why the words are portable between manufacturers: if one provider disappears, the same wallet can be restored in a different application.
That portability is the reason the list must be treated so strictly. A password sits next to an account. This word list is the account.
Where to Keep the List
Paper is a good start and a poor finish: it burns, it yellows, and one flooded cellar is enough. Anyone securing an amount whose loss would genuinely hurt should stamp the words into a steel plate. Such plates cost a few dozen euros and survive fire and water.
For storage the rule is: at least two locations, physically separate, both under your control. A safe deposit box and your own home are a proven combination. How to put that into practice and which variants have held up is set out at length in our guide to storing your seed phrase safely.
The Passphrase as an Optional Twenty-Fifth Factor
Many wallets additionally allow a word of your own choosing, often called a passphrase. It changes the derived keys completely, is stored nowhere, and renders a found word list worthless on its own. The catch: if the passphrase is lost, the funds are lost too, even with the complete word list. For beginners that is one more source of error; for experienced users it is a sensible second wall.

Setting Up a Hardware Wallet: What Matters When You Unbox It
The sequence mirrors the software wallet, with four particulars that make the difference.
First, the source. Buy only directly from the manufacturer or from a dealer it names. Devices from the second-hand market, classified ads or third-party marketplaces are off limits, because a tampered device cannot be identified from the outside.
Second, the pre-printed card. If the device comes with a card of words already filled in, the device is compromised. A new device generates the words only during setup, and does so on the device itself. A supplied word list is the classic setup for a fraud.
Third, the display. The words appear on the device’s screen, never on the computer. If a website or a program asks you to type in your recovery words, that is an attack, without exception and no matter how genuine the page looks.
Fourth, the firmware. Install the current firmware via the manufacturer’s official application before you transfer any meaningful amount. Which models differ in German-speaking retail and what matters in the choice is summarised in the hardware wallet comparison.
After that the same rule applies as above: test amount out, part of it back, recovery practised once.
The First Transfer: Checking Test Amount, Network and Address
Most losses at the outset come not from hacks but from operating errors on the first transfer. Three checks prevent almost all of them.
The network. The same token often exists on several blockchains, and the addresses look confusingly alike. Pick the wrong network on an exchange and the funds land on a chain for which your wallet holds no key. Sometimes it can be recovered with effort, sometimes not. What remains possible in that case we wrote up in our piece on sending crypto over the wrong network.
The address. Copy the receiving address from the wallet, then compare the first and last five characters in the exchange’s input field. There is malware whose sole purpose is to swap copied addresses in the clipboard for its own. With a hardware wallet you additionally verify the address on the device’s screen.
The test amount. On the first attempt, send an amount whose loss would not trouble you, and wait for confirmation. The network fee for it is the cheapest insurance premium in the whole exercise.
What Is Permitted in Germany: BaFin, MiCAR and Self-Custody
One question comes up regularly: do you need a permit for your own wallet? No. In its guidance notice on crypto-asset services under MiCAR, the Federal Financial Supervisory Authority states clearly that “the custody and administration of one’s own crypto assets by the holder” is not covered, because such custody is not provided “for clients”. What requires authorisation is the service to third parties, not the handling of your own assets.
The flip side is this: anyone who holds assets for you has, since 30 December 2024, needed authorisation as a crypto-asset service provider under the European regulation on markets in crypto-assets. For a provider based in Germany, that status can be traced through the supervisor’s databases. It is the single most important check before funds are left sitting on a platform.
For you as a user, that yields a simple division of labour: for the custodied part of your holdings you check the provider’s authorisation, and for the self-custodied part you check your own backup. For neither is there a third party that steps in when things go wrong.
Tax: What the Tax Office Wants to Know About Your Wallet
The wallet itself triggers no tax. It becomes relevant as evidence. Crypto assets held privately count as “other economic goods”, and a gain on sale is taxable under section 22 number 2 in conjunction with section 23 paragraph 1 sentence 1 number 2 of the Income Tax Act if no more than one year lies between acquisition and disposal. The Federal Ministry of Finance letter of 6 March 2025 records this at paragraph 53 and also names the exemption threshold there: if the total gain from all private disposal transactions in a calendar year stays below 1,000 euros, it remains tax free. Until 2023 that threshold stood at 600 euros.
Three points bear directly on the wallet:
- The assessment is wallet-based. Under paragraph 62 a wallet-based view applies, and once a method for the order of use has been chosen it must be retained within a wallet until all holdings of that trading designation there have been sold. Anyone spreading holdings across several wallets must therefore track them separately.
- Reallocations belong in the records. The record-keeping duties at paragraph 103 expressly name documentation of the chosen order of use per wallet, as well as documentation of reallocations between wallets. A transfer between two of your own wallets is not in itself an acquisition, since the letter understands that term to mean acquisition for consideration from third parties (paragraph 54). It must be documented all the same, because otherwise neither the acquisition date nor the acquisition cost can be evidenced later.
- Addresses and cut-off date holdings can be requested. Paragraph 104 lists what the tax office may demand in an individual case: information on the source of funds, wallet holdings at cut-off dates such as 31 December, the wallet addresses used, and transaction hash values.
In practice that means: on the day you set it up, create a short overview listing the wallet, its purpose and the setup date, and export the transaction list once a year. That costs minutes in day-to-day running and saves days in hindsight.
Five Mistakes That Cost the Most When Setting Up
- Backing up the words digitally. Screenshot, cloud password manager, a chat message to yourself: every one of these variants shifts the security of the wallet onto someone else’s account.
- Never testing the recovery. An unverified backup is an assumption. The test takes five minutes and is the only proof.
- Sending the full amount the first time. Without a test transfer, the first attempt carries the entire risk of the wrong network and a swapped address.
- Approving permissions unread. Connecting a wallet to applications in the browser means signing permissions. Read what appears on the device screen, and abort if it says something other than what you expected.
- Putting everything in one wallet. A separate wallet for day-to-day experimenting and one for the holding limits any damage to the part that is in motion anyway.
Setting Up a Crypto Wallet: What to Take Away
- Decide on the custody model first. Work out which part of your holdings should stay custodied and which moves into your own control. For the custodied part you check the provider’s authorisation, and our overview of regulated crypto exchanges is the starting point for that.
- Back up the recovery words before any funds move. By hand, in two separate locations, and in metal for larger amounts. Anyone wanting a dedicated device for it will find the differences between models in the hardware wallet comparison.
- Test the route with a test amount and document it. Network, address, return path, plus a note recording the wallet and setup date for your tax file. Which application suits everyday use is shown in the software wallet comparison.
(As of September 23, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)





Be the first to comment