Not Your Keys, Not Your Coins: A Field Guide to Self-Custody

Self-custody trades the risk of an exchange bankruptcy for the risk of a lost seed phrase, and here is how to weigh the two.

8 min read
A small hardware wallet beside a blank steel recovery plate and a cable on a wooden desk near a closed laptop

Every argument about how to store crypto reduces to one question: who holds the private keys? Owning coins means controlling the keys that sign the transactions that move them. The ledger does not record ownership in any human sense. It records balances against addresses, and whoever can produce a valid signature for an address controls whatever sits there. That is the whole game. This piece explains what self-custody actually means, why "not your keys, not your coins" became a slogan, how a seed phrase works, and how to weigh holding your own keys against leaving coins with someone else.

What the keys control

When your coins sit on an exchange, the exchange holds the keys. You hold a claim against the company, an IOU in its database. Move to self-custody and you hold the keys yourself, which means you hold both the control and the consequences.

Controlling the keys is not abstract. To move coins you build a transaction and sign it with the private key, and the network accepts the transfer because the signature proves you hold the key without ever revealing it. Nobody has to trust your name or your identity. The math is the authorization. That is the strength of the system and the whole of its danger: there is no manager who can reverse a signed transaction or reset a forgotten secret.

Modern wallets hand you that control as words. BIP-39, a standard proposed in 2013 by developers including Marek Palatinus and Pavol Rusnak of SatoshiLabs, the company behind Trezor, encodes a wallet's master secret as 12 or 24 words drawn from a fixed list of 2,048. Pair it with BIP-32 hierarchical deterministic wallets and that single phrase derives every address and key the wallet will ever use. This is why the words are the money. Anyone who reads them can rebuild your wallet on new hardware and drain it, and it is also why a lost phone is a non-event when the phrase is safe: restore from the words, and the wallet returns intact.

There is an optional layer. A BIP-39 passphrase, sometimes called the 25th word, adds a secret you choose on top of the seed. It protects you if someone finds the paper backup, because the words alone no longer open the wallet. The cost is symmetrical. Forget the passphrase and the funds are gone, with no support line to call.

When custodians collapse

The case for holding your own keys is written in bankruptcy filings.

Mt. Gox was the dominant Bitcoin exchange of its era. It collapsed in February 2014 after disclosing that roughly 850,000 BTC, most of it customer coins, had gone missing. About 200,000 BTC turned up later. Creditors spent the next decade in Japanese insolvency proceedings before repayments began. QuadrigaCX, once Canada's largest exchange, failed in 2019 after founder Gerald Cotten died in December 2018 reportedly holding sole access to the wallets. Around 190 million Canadian dollars owed to roughly 76,000 users was frozen, and a 2020 Ontario Securities Commission review found the exchange had operated like a Ponzi scheme, with customer money misused well before Cotten died.

Then FTX. The third-largest exchange filed for bankruptcy in November 2022 with a customer shortfall of roughly 8 billion dollars, after lending customer deposits to its affiliated trading firm Alameda Research. Founder Sam Bankman-Fried was convicted of fraud in November 2023. Creditors were eventually repaid, but at the dollar value of their claims on the November 2022 petition date, which meant missing the crypto recovery that followed. The wait and the valuation cutoff made the lesson concrete: an exchange balance is a claim in a future bankruptcy, not coins in hand. The same 2022 credit cascade froze withdrawals at the lenders Celsius and Voyager for months. The common thread is one sentence. Deposited crypto was an unsecured loan to a company whose books nobody outside could see.

When self-custody breaks

Self-custody does not delete the risk. It moves it onto you, and users fail too.

Chainalysis estimated in 2020 that around 3.7 million BTC, roughly 20 percent of the supply mined by then, had not moved in five years or more and was probably lost. Much of it went to discarded drives and forgotten keys from the early years, when a coin was worth cents and nobody bothered to write anything down. The failure modes are mundane. A seed phrase never backed up before the phone died. A backup that burned or flooded with the house. A paper phrase photographed and synced to a cloud account that later got phished. Heirs who never knew the wallet existed.

The attacks rarely touch the cryptography. They target the person. Fake wallet apps and fake support staff ask you to 'validate' your seed phrase, though no legitimate wallet or support channel ever asks for the words. Clipboard malware swaps a copied address for the attacker's in the gap between copy and paste. Malicious token approvals in DeFi drain a wallet whose owner signed away access without reading the prompt. Address-poisoning dust plants a lookalike address in your transaction history, betting you copy it by mistake. And holdings large enough to be known about become a personal-safety question, what the community calls the five-dollar-wrench attack: no exploit required, just a threat and a person who knows you hold coins.

Put the two lists side by side and a pattern shows up. Exchange failures are systemic and out of your hands: you can pick a better venue, but you cannot audit its books or stop it lending your deposits to a sister fund. Self-custody failures are personal and mostly preventable, which is small comfort at three in the morning when the phrase is nowhere to be found, but it does mean the odds are yours to change.

The custody spectrum

Custody is a spectrum, not a switch. At one end sits the exchange, where you hold an IOU and the company holds the keys, convenient and instantly tradable right up until the company cannot pay. Next come hot wallets, software on an internet-connected phone, desktop or browser extension. Here you control the keys, a real step up, but they live on a general-purpose machine alongside every browser tab and download that machine might catch.

Hardware wallets pull the keys offline into a dedicated device that signs transactions without exposing the secret to the connected computer. The first, the Trezor One, shipped in 2014, followed by devices such as the Ledger Nano S in 2016. Past that sit multisignature setups. A 2-of-3 multisig splits control across three independently stored keys and requires any two to sign. Lose one key to a fire or a thief and the funds are still spendable with the other two, while a single stolen key steals nothing. That removes the single point of failure a lone seed phrase always is. Institutions go further again, leaning on regulated custodians with insurance and audits. Plenty of individuals borrow from both ends at once: a small hot-wallet float for daily spending, a hardware wallet or multisig for the core position that rarely moves.

Guarding the seed phrase

Most defensive practice is boring, which is the point. Write the seed phrase on paper or stamp it into metal, and never photograph it or type it into any website or app except a wallet you are deliberately restoring. Verify a receiving address on the hardware wallet's own screen rather than trusting the computer's display, which malware can quietly rewrite. Before moving a large sum, send a small test transaction and confirm it arrives.

The rest is maintenance and honesty about failure. Keep firmware current and buy devices only from the manufacturer, never a third-party reseller who could have tampered with them first. For serious size, consider a passphrase or a 2-of-3 multisig. Test the recovery from your backup before you trust it with real money, because a backup you have never restored is a guess, not a plan. And leave heirs a way to find and use it, or your security becomes indistinguishable from loss.

Weighing the trade-off

Neither side is safe in the abstract. Custodians fail through fraud and insolvency, and the record is long and specific. Self-custodians fail through lost phrases, ruined backups and a signature handed to the wrong prompt. The right mix depends on your skills, the sum at stake and your threat model, not on a slogan shouted from either camp. A few hundred dollars of spending money on a reputable exchange is a different question from a life-changing position.

So treat it as a skill with a checkpoint. Before you trust any setup with meaningful size, wipe the device or open a fresh wallet, restore purely from your written backup, and watch the balance reappear. If it does not, you found out while it was still a drill.

Sources

  • Keys, seed phrases and what custody actually means (BIP-32/BIP-39) · Bitcoin wallet protocol documentation
  • When custodians fail: the exchange-collapse record (Mt. Gox, QuadrigaCX, FTX) · Court filings and public reporting
  • When self-custody fails: loss statistics and defensive practice · Chainalysis research and standard wallet-security practice

Disclosure

Our stories are produced with a combination of human writers and AI tools, and every article is reviewed by a human editor before publication. Read more in our editorial policy. This article is for informational purposes only and is not financial, investment, or legal advice. Crypto assets are volatile and you can lose money — always do your own research.