Self Custody Crypto: What You Are Actually Taking On

Person holding a hardware wallet device representing self custody

Written by

in

Not your keys, not your coins. It is true, it is worth understanding, and it is half of a trade that people repeat without stating the other half.

The other half is this: when you hold the keys, there is nobody to call. No password reset, no identity verification, no fraud department, no reversal. If the recovery phrase is lost, the funds are simply gone, and no amount of being able to prove they were yours changes that.

What you gain

  • No counterparty. No exchange can fail with your funds, freeze withdrawals, or be hacked in a way that reaches you.
  • No permission needed. Nobody can block a transaction, close your account or decide you need to justify a withdrawal.
  • No credit exposure. Your holdings are not on anyone’s balance sheet or lent out behind the scenes.
  • Verifiable ownership. You can confirm what you hold without trusting a statement someone else produced.

Those are real and they are the reason people do this. The history of custodians failing is long enough that the caution is earned rather than ideological.

What you take on

  1. Being the backup. There is no copy anywhere else. If your record of the recovery phrase is lost or destroyed, that is the end of it.
  2. Being the security team. Every phishing attempt, every fake support account, every convincing message is now aimed at you and there is no institution absorbing the ones you miss.
  3. Being the succession plan. If nobody can find and use your backup, your holdings die with you.
  4. Being the auditor. Verifying addresses, checking what you are signing, keeping firmware current. Nobody else is doing it.
  5. Carrying physical risk. A recovery phrase is a bearer instrument. Whoever has it, has the funds.
Notebook and pen for planning a recovery and inheritance process
The plan matters more than the device.

The failure modes, honestly ranked

If you read only the news you would think the risk is hacking. The actual distribution is close to the opposite.

FailureHow commonPreventable by
Lost or never recorded recovery phraseMost common by a wide marginDurable backup, tested, in two places
Phishing or fake supportVery commonNever entering a seed phrase anywhere, ever
Signing a malicious transactionCommon with applicationsReading what you approve, using a separate hot wallet
Backup found by someone elseLess common, total loss when it happensWhere and how you store it
Physical coercionUncommon, seriousNot advertising what you hold
Device or software defectRare, and 2026 proved not impossibleBuying direct, updating firmware, adding your own entropy

The top two rows account for most losses and both are entirely within your control. That is either reassuring or uncomfortable, depending on how organised you are.

The first move off an exchange

The transition is where a lot of avoidable losses happen, usually because people move everything at once on their first attempt.

  1. Set the wallet up completely and record the backup before sending anything.
  2. Send a small test amount. Small enough that losing it would be annoying rather than serious.
  3. Confirm it arrived and that the balance shows correctly.
  4. Then, before moving more, wipe the device or wallet and restore it from your written backup. This is the step everyone skips and it is the only thing that proves the backup works.
  5. Confirm the test amount is still there after restoring. Now you know.
  6. Only then move the rest, and consider doing it in more than one transaction.

Step four is the one that matters. A backup you have written down but never restored from is an assumption. People discover a missed word or an unreadable character years later, at the exact moment they need it to work.

The scams aimed specifically at self custody

Once you hold your own keys, you become the target rather than the exchange. The attacks are consistent and worth recognising on sight.

ApproachWhat it looks likeThe tell
Fake supportHelpful reply to a public question about a wallet problemSupport never contacts you first, and never needs your phrase
Wallet validationYour wallet needs verifying, connect or enter your phraseNo legitimate process ever needs the phrase
Recovery serviceWe can recover your lost seed phrase for a feeThis is not technically possible. It is always a scam
Fake wallet appA convincing app in a store, or a search advertCheck the developer, go to the source directly
Airdrop claimFree tokens, just connect and signYou are signing away spending permission, not claiming anything

The single rule that defeats nearly all of them: the recovery phrase is never entered anywhere, for any reason, by anyone. There is no legitimate exception and there never will be.

Who is genuinely better off not doing this

Worth saying plainly, because the culture around this topic treats custodians as a moral failing and that framing has cost people real money.

If you would not reliably maintain a backup, if you have lost important documents before, if you are managing this while unwell or under stress, or if there is nobody who could recover your holdings if something happened to you, a reputable custodian may genuinely leave you better off. An exchange failing is a possibility. A lost recovery phrase is a certainty of loss.

The right answer is the one you will actually execute. A perfect self custody setup you do not maintain is worse than an imperfect arrangement you do.

What a realistic setup looks like a year in

People imagine self custody as one decision made once. In practice it settles into a routine, and the routine is what determines whether it holds up.

  • A small hot wallet holding what you actually move, treated as spending money that could be lost
  • A hardware wallet holding the rest, plugged in occasionally and otherwise in a drawer
  • A written backup in two separate physical locations, neither of them obvious
  • A note somewhere sensible explaining to one other person that this exists
  • A habit of verifying receiving addresses on the device screen rather than on the computer

None of that is difficult and none of it is interesting, which is precisely why it gets skipped. The failures in this space are almost never sophisticated. They are ordinary carelessness compounding over time.

The thing worth rereading once a year

Setups drift. The device firmware falls behind, the backup ends up somewhere different after a house move, the person you told stops being the right person to tell, and the small hot wallet quietly stops being small.

Once a year, check four things: that firmware is current, that you can still find both backup copies, that you could still recover from them, and that the balance split between hot and cold still reflects what you would be comfortable losing. That review takes half an hour and it catches the drift that would otherwise only surface at the worst possible moment.

If you do it, do these five things

  1. Write the recovery phrase on something durable and store it offline, in more than one place, never digitally in any form.
  2. Test recovery onto a different device before moving a meaningful amount. Until you have restored from it, you have a guess.
  3. Keep a small hot wallet for anything you actually transact with, so the main store is never connected to an application.
  4. Write down, on paper, how someone would recover this if you could not. Store it where the right person will find it and the wrong person will not.
  5. Decide now that you will never enter the phrase into anything, and treat every request for it as an attack, because that is what it is.

For the mechanics of keeping keys offline, what cold storage actually means covers cold storage. For choosing between wallet types, choosing a wallet covers the decision.

Frequently asked questions

What does not your keys not your coins actually mean?

That if someone else holds the private keys, you hold a claim rather than the asset. If they fail, freeze withdrawals or are compromised, your claim is only as good as they are. It is a true statement and it is only half of the trade.

Is self custody right for everyone?

No. It suits people who will actually maintain a backup and can be trusted with something unrecoverable. Someone who loses keys regularly, or who would not have a plan if they died tomorrow, may genuinely be safer with a reputable custodian, and saying so is not a betrayal of anything.

What is the most common way people lose self custodied funds?

Losing the recovery phrase, or never recording it properly in the first place. Not hacking. The dramatic failures get written about and the boring ones are far more numerous.

Can I recover funds if I lose my seed phrase?

No. There is no reset, no support line and no identity check that recovers them. Anyone offering a recovery service for a lost seed phrase is running a scam, without exception.

What happens to my crypto when I die?

Nothing, unless you planned for it. Without a way for someone to find and use the recovery phrase it is simply gone. This is worth solving before it matters, and most people never do.

Is self custody safer than an exchange?

Against different things. It removes counterparty risk entirely and adds personal risk entirely. Which is safer depends on whether you are more likely to be failed by an institution or by your own record keeping.


This article is educational and is not financial advice. Nothing here is a recommendation to buy, sell or hold anything. You are responsible for your own security decisions.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *