Open the Ownership tab on your name, select Edit Roles, and point the Owner at a cold wallet while the Manager and ETH Address stay on your everyday hot wallet. The name keeps working as usual: records edit, funds arrive, your primary name shows. But a drained hot wallet cannot take the name away. Nobody can recover an ENS name after theft, so this split is the standard defence.
Good to know
A cold wallet is one kept offline and rarely connected to apps; a hot wallet is the one you use every day. They are ways of using a wallet, not products.
Start connected to the wallet that is currently the Owner. Once the Owner is on the cold wallet, only the cold wallet can change it back, and nobody can recover the name if you lose access to it. Test the cold wallet first by receiving a small amount, check you can sign from it, and keep it backed up the way its maker tells you to.
You need ETH on Ethereum Mainnet for gas; there is no other cost.
The ENS App handles
.ethnames, their onchain subnames and imported DNS names. For project subnames likebase.eth, use the project's own site. See What are project subnames?
The three roles
A .eth name has three roles, and they do not have to live on the same wallet. The split puts day-to-day risk and ownership risk in different places.
Role | What it does | Recommended wallet |
Owner | Holds the name's NFT. Can transfer the name, change the Manager, and use Send. | Cold wallet |
Manager | Controls the name's records: can change the ETH Address, set text records, and so on. Can hand off Manager to another wallet, but can't transfer the Owner. | Hot wallet |
ETH Address | The wallet the name points at. Funds sent to | Hot wallet |
On a wrapped name the Manager role is merged into the Owner role: there is no separate Manager field.
How to set it up
Open the Ownership tab. Go to app.ens.domains, connect the current Owner wallet, search for your name, open the Ownership tab and select Edit Roles.
Set the three roles. Select Change next to Owner and enter your cold wallet's address (an ENS name or 0x address). Do the same for Manager and ETH Address, setting both to your hot wallet. Select Save.
Approve each transaction in your wallet. Select Open Wallet and approve the first, then select Next and approve the rest, in this order: ETH Address, Manager, Owner.
Set the primary name on the hot wallet. Switch to the hot wallet and follow Set your primary name, so
yourname.ethshows across apps when you connect.
When the Owner transaction lands, the Ownership tab shows the cold wallet as Owner and the hot wallet as Manager and ETH Address. The tab labels the ETH Address row ETH record.
Common questions
Why does this setup work?
The Owner role is the one with the power to sell or transfer the name. Keeping it on a wallet that never connects to apps removes the surface that phishing and malware use. The Manager and ETH Address stay usable on the hot wallet, but neither role can transfer the name. If a phishing site tricks your hot wallet into signing something, the worst it can do is change a record or redirect funds, and you can re-edit those from the cold wallet.
What does it not protect?
Three things. Funds on the hot wallet, which face the usual hot-wallet risks, so keep balances small. The records, which a compromised Manager can change; that is annoying but reversible from the cold wallet. And you, if you connect the cold wallet to something dodgy: the protection comes from leaving it offline.
Which wallet types can I use?
Mix and match. A hardware wallet keeps keys on the device and needs every transaction approved on its screen, which makes it the usual cold-wallet choice. A multisig wallet needs approval from several wallets before a transaction confirms. A hardware wallet does not protect you from approving a malicious transaction yourself, so always check the prompt on the device screen.
Type | What it is |
Cold wallet | Kept offline. Rarely connected to apps. Best for the Owner role. |
Hot wallet | Connects to apps and signs transactions often. Best for Manager and ETH Address. Keep small amounts here. |
Hardware wallet | A physical device that holds private keys offline. The usual cold-wallet choice. |
Safe (multisig) | A smart-contract wallet that needs approvals from several wallets before a transaction confirms. Useful for shared ownership. |
My hot wallet has already been compromised. What now?
Do not wait. From a clean device, use Edit Roles or Send to move the Owner to a safe wallet before the attacker does, then work through Recover a .eth name from a compromised wallet.


