A cold wallet stores private keys completely disconnected from the internet, usually on a physical device (hardware wallet) such as a Ledger or Trezor, or even on a simple piece of paper with the recovery seed phrase written on it.
Why it's more secure
Since it's never connected to the internet while the keys are generated and stored, an attacker can't steal the funds remotely through malware or phishing: they would need physical access to the device and, usually, an additional PIN or password as well.
When to use one
It's recommended for amounts you won't move often (medium- to long-term savings), unlike a hot wallet, which is more practical for daily use but more exposed to online risks.
The risk becomes physical
The main danger with a cold wallet isn't hacking, but the physical loss or destruction of the device or the recovery seed phrase: without it, the funds are unrecoverable. That's why it's recommended to keep copies of the seed phrase in several secure locations.