cryptotradingbook

Wallets and custody

Foundations · ~10 min read · Reviewed 2026-10-02

At a glance

1. Custodial vs. self-custody

The saying "not your keys, not your coins" puts it bluntly, but the underlying point is legal and practical. An exchange balance is an IOU from the operator. When the operator fails, that claim may be frozen for years or paid back only in part. FTX is the clearest case: in November 2022 the exchange halted withdrawals and filed for bankruptcy in the US. Customer assets had been used by its affiliated trading firm, and its founder was later convicted of fraud. Customers were creditors in a bankruptcy proceeding for roughly two years before repayments began. Earlier failures such as Mt. Gox (2014) and the lender Celsius (2022) followed a similar pattern.

ModelWho controls the keysProtects you againstLeaves you exposed to
Custodial (exchange account)The exchange holds the keys; you see a balanceAgainst losing your own keys; offers password resets and supportInsolvency, frozen withdrawals, hacks of the exchange, account closure, commingling of client funds
Self-custody (your own wallet)You hold the keys or seed phraseAgainst exchange failure and third-party freezesLosing the seed, phishing, signing malicious transactions, no one to call

Self-custody does not automatically make you safer. It swaps counterparty risk for operational risk: lost seeds, phishing and user error. Many traders end up with a mix, keeping a small trading balance on a well-regulated exchange and holding the rest in self-custody.

2. Hot vs. cold wallets

TypeExamplesWhere the keys liveSuited for
Hot walletExchange wallets, mobile and browser-extension walletsKeys on an internet-connected deviceSmall amounts you actively trade or use
Cold walletHardware wallets, air-gapped devicesKeys generated and kept offlineLarger amounts you do not move often

Exchanges use the same split internally. They keep most client assets in cold storage and a smaller share in hot wallets for withdrawals. Our profiles show the self-reported cold-storage share, and most large exchange hacks have hit the hot wallet.

3. Hardware wallets: what they do and do not do

What they do

  • Generates and stores private keys inside a secure chip that never exposes them to your computer.
  • Requires a physical button press on the device to sign every transaction.
  • Shows the destination address and amount on its own screen, so you can check them independently of your computer.

What they do not do

  • It does not stop you from approving a malicious transaction or token approval you do not understand.
  • It does not back up your seed phrase. If the device and the seed are both lost, the funds are gone.
  • It does not protect you from a tampered device. Buy directly from the manufacturer, never second-hand.
  • It does not make an exchange balance safe. Coins left on an exchange are not in your hardware wallet.

4. Seed phrases

A seed phrase (recovery phrase) is a list of usually 12 or 24 words, generated by your wallet, that encodes your private keys. Anyone who has these words can rebuild your wallet on any device and move every coin in it. You cannot change the phrase, and transfers made with it cannot be reversed. Write it down offline, store it somewhere safe from fire and theft, and never type it into a website, a chat window or a cloud note.

Remember: Your seed phrase is never shared, not with support, not with an exchange, not with a wallet maker, and not with a "recovery service". Any request for it is a scam, without exception.

5. Exchange risk and when this fails

If you do keep funds on an exchange, assess the operator first. Every profile in theexchange directory shows licences, incident history andproof of reserves. Tags make the key points visible at a glance, for example:

hack historywithdrawal issuesinsolvency historyno proof of reservesPoR assets only

Where this fails: proof of reserves is a snapshot. It often covers assets but not liabilities ("assets only"), and it does not show what happens the day after the audit. Self-custody fails through human error: seeds that are photographed, stored in email, or lost in a move. Hardware wallets cannot protect you if you approve a malicious token approval ("drainer"). Inheritance is a real gap as well: if nobody else can access your seed, your heirs cannot either.

Risk: Funds on an exchange are only as safe as the operator. In insolvency you are typically an unsecured creditor, repayment can take years, and it may be partial or valued at the price on the bankruptcy date.

Knowledge check

  1. What do you actually own when you hold a balance on a centralised exchange? (A claim against the operator, not the coins themselves. The exchange controls the keys.)
  2. What did the FTX collapse show about custodial risk? (Withdrawals can be halted overnight, client assets can be misused, and customers become creditors in a long bankruptcy.)
  3. Name one thing a hardware wallet protects against and one thing it does not. (Protects: malware stealing keys from your computer. Does not: signing a malicious transaction, losing the seed, or funds left on an exchange.)
  4. Someone from "support" asks for your seed phrase to fix an issue. What do you do? (Refuse and stop. It is always a scam, because no legitimate party ever needs your seed.)
  5. Why is proof of reserves not a guarantee? (It is a point-in-time snapshot, it often covers assets without liabilities, and it says nothing about the days after the audit.)