The site's referral record is not registered; the code, benefits and commercial arrangement in the account-opening guide remain unverified. That gives us an interest in you using a platform, which is exactly why this page sets out the case against platform custody in full. Full disclosure.
Custodial vs self-custody wallets: an honest trade-off table
One model can fail because a company does. The other can fail because you put a piece of paper somewhere sensible and then moved house. Almost all coverage describes the first in detail and the second in a footnote.
The short answer: neither model is safer in the abstract. Platform custody concentrates the risk in a company; self-custody concentrates it in your own record-keeping over a period of years. Choosing well means being honest about which of those you are more likely to get wrong.
Two different kinds of risk
Both models can end with you losing everything, but the routes there have almost nothing in common.
Custodial means a company holds the keys and credits your balance in their own ledger. You have an account, a login, a support channel and a password reset. What you own is a claim against that company. If they fail, you are a creditor.
Self-custody means you hold the private key, usually represented as a recovery phrase. No company is involved, no login exists, and no one can reset anything. What you own is control, conditional on continuing to possess a secret.
The important consequence is that the two failure modes are not on the same scale and cannot be traded off with a single number. One is a low-probability event with a large blast radius that you do not control. The other is a moderate-probability event, entirely within your control, that people systematically believe will not happen to them.
What the slogan gets right
"Not your keys, not your coins" is accurate on the point it makes. A balance shown in an exchange account is an entry in that company's records. The underlying assets are pooled and controlled by them, and your ability to get them out depends on the company continuing to operate, remaining solvent, and choosing to process your withdrawal.
That is not a theoretical concern. Platforms have failed, frozen withdrawals during stress, been compromised, and had assets seized or restricted by authorities. When any of those happen, the difference between "my coins" and "my claim on a company that holds coins" stops being pedantic.
The slogan is also right that this exposure is invisible in normal conditions. Nothing about the account screen tells you it is there. It only becomes real at the exact moment you cannot do anything about it.
What the slogan omits
Taking the keys does not delete the risk. It moves it onto you, and it changes its shape from a rare external event into an ongoing operational responsibility.
The unstated assumption inside the slogan is that you will store and maintain a secret correctly, without a single unrecoverable mistake, for as long as you hold the asset. For some people that assumption holds comfortably. For others it does not, and the honest version of this advice has to say so.
The asymmetry in how these two are discussed is worth naming. Exchange failures are public, dramatic and newsworthy. Self-custody failures are private and embarrassing, so they are underreported by a wide margin. Anyone forming a view from published coverage is working from a sample that heavily over-represents one side.
How platform custody fails
- Insolvency. The company runs out of assets to meet its obligations. Your claim joins a queue in a process that can take years and may not return the full amount.
- Withdrawal suspension. Withdrawals get paused during stress, maintenance, or investigation. Your funds are visible and untouchable, sometimes exactly when you most want to move them.
- Compromise. The platform's own systems are breached. Some platforms have covered such losses from reserves; that is a policy decision, not an entitlement.
- Account-level action. An account can be frozen or closed by an automated risk system or a compliance review. The decision is made by a company, and the appeal route is a support ticket.
- Credential theft. Someone gets into your account. This one is partly yours to control, through app-based two-factor and withdrawal address whitelisting.
How self-custody fails
This is the half that gets a sentence in most articles, so it gets the detail here.
- Backup loss. By a large margin the most common ending. The recovery phrase was written down and then discarded in a clear-out, lost in a house move, kept in a notebook that was thrown away, or stored in a photo library that was later wiped. No support ticket exists.
- Backup that was never really a backup. A phrase stored only on the same device that holds the wallet, or a photograph in cloud storage that is both a single point of failure and a security exposure at the same time.
- Split backups where one half is gone. A reasonable-sounding scheme, executed once and never tested, where one location turns out to be unrecoverable years later.
- Irreversible user error. Sending to a valid address on the wrong network, mistyping a destination, or approving a transaction that does something other than what was expected.
- Device compromise on a hot wallet. A software wallet's key sits on an internet-connected machine. Malware, a malicious token approval, or a convincing fake site can empty it in a single transaction.
- Death or incapacity. If nobody else can find and use the recovery phrase, the funds end with you. This is not an edge case; it is the default outcome of self-custody without a succession plan.
The comparison nobody likes making
Ask which is more likely for you personally over the next ten years: a specific major platform failing while you happen to hold funds there, or you losing track of a piece of paper across a decade of house moves, device changes and life events. Both are real. Only one of them has a base rate you can actually estimate from your own history.
The running cost of holding your own keys
Self-custody is usually presented as a one-time setup. It is closer to a small ongoing obligation, and the obligations are what people underestimate.
A backup that survives real events. Not just theft, but fire, water, and the ordinary entropy of moving house. Paper in a drawer fails several of those.
A backup you can still find in five years. The failure is rarely dramatic. It is that the location made sense at the time and does not any more.
A recovery you have actually rehearsed. An untested backup is a belief, not a backup. Restoring from the phrase onto a different device, once, converts it into something you know.
A succession arrangement, if anyone else would need access. Someone can find the phrase, knows what it is for, and can use it — while it stays secure in the meantime. It is genuinely difficult and it is the part almost everyone skips.
Ongoing care on every transaction. Each transfer is final. The habit of checking the network, verifying the address, and sending a small test first is the cost of not having an intermediary.
The trade-off table
| Dimension | Platform custody | Self-custody |
|---|---|---|
| Who can lose it | The company, an attacker, or a compliance decision | You, an attacker on your device, or nobody finding your backup |
| Recovery if credentials lost | Identity verification and a support process | None. The phrase is the only route |
| Reversibility of a mistake | Sometimes, within the platform | Never, once on-chain |
| Ongoing effort | Keep two-factor and whitelisting on | Maintain a backup for as long as you hold |
| Cost to move funds | Withdrawal fee set by the platform | Network fee only |
| Access after your death | Estate process exists | Only if you built one |
| Exposure you cannot control | Company solvency and policy | None |
| Exposure you must control | Account security | Everything |
Which model fits which situation
The useful question is not which model is better but which failure you are better positioned to avoid. Three inputs do most of the work.
Amount
Below the level where a total loss would genuinely hurt, the friction of self-custody tends to cost more than the platform risk it removes. Above the level where a loss would change your year, the calculation reverses.
There is no universal threshold, and anyone quoting one is guessing about your finances. The honest version of the test is personal: name the number that would materially hurt to lose, and treat that as the line.
Frequency
Assets you actively trade have to be somewhere they can be traded. Moving funds back and forth between trades pays a withdrawal fee and a network fee each way and multiplies the number of chances to make an irreversible mistake.
Assets you intend not to touch for years have no such requirement. Nothing about holding needs a platform, so the platform risk is being carried for no benefit.
Technical comfort
This is a legitimate input, not something to be embarrassed about. Self-custody failures cluster around setup and backup rather than exotic attacks, which means the risk is highest exactly for people who are least sure what they are doing.
The sensible path if you are in that group is not to avoid self-custody permanently. It is to do the first move with an amount you could lose entirely without it mattering, and to practise a full restore before trusting it with anything real.
The split most people end up at
For anyone whose answers point in different directions — a meaningful balance, but also regular activity — one wallet cannot serve both jobs. The common resolution is to split by purpose rather than choosing a side.
The long-term holding goes into self-custody, ideally with keys that never touch an internet-connected device. A working balance stays on the platform, sized so that losing it entirely would be annoying rather than serious.
The honest costs are that you now maintain two systems, two sets of habits and two ways to get it wrong, and that every movement between them pays fees both ways. It only makes sense if the working balance is genuinely small relative to the holding.
Our custody decision guide walks the same five inputs and returns the model plus the specific trade-off it puts on you.
A third option most comparisons skip
The custodial/self-custody framing presents a binary, but control does not have to sit entirely in one place. Multi-signature and threshold arrangements require more than one key to authorise a transaction — two of three, three of five — and the keys can be held in different places or by different people.
What this fixes is precisely the weakness that makes self-custody frightening. A single lost backup no longer loses the funds, because the remaining keys still meet the threshold. A single stolen key no longer drains the wallet, because one signature is not enough.
What it costs is complexity, and the complexity is not trivial. You now have several backups to maintain instead of one, and a setup whose recovery procedure you need to understand well enough to execute under stress. Some arrangements involve a third party holding one key, which reintroduces a counterparty, though a much weaker one than full custody.
The honest assessment is that this is the right answer for a meaningful number of people and that it is under-recommended because it is harder to explain than either pole.
Making the first move
Most self-custody failures happen on the first attempt, when someone moves a serious amount to a wallet they set up an hour earlier. The sequence that avoids this takes about a week of elapsed time, most of which is waiting.
- Set the wallet up and record the recovery phrase. Write it by hand. Do not photograph it, and do not type it into anything that syncs.
- Send a small amount. Small enough that losing it entirely is irrelevant. Confirm it arrives.
- Wipe the wallet and restore it from the phrase alone. This is the step people skip and it is the only one that proves the backup works.
- Send a second small amount out again to confirm you can also spend, not just receive.
- Only then move the real amount, and move it in stages rather than all at once if the total is large.
What neither model stops
There is a whole category of loss that neither side prevents, and it accounts for more retail losses than everything above put together: you being persuaded, and then completing the operation yourself.
Two-factor does not stop you logging in and sending funds to a "safe address" on instruction. Whitelisting does not stop you adding that address yourself and waiting out the cooling-off period. A hardware wallet asks you to confirm on screen, but if you already believe the story, you press confirm.
The common structure is that the other party gets you to start the conversation somewhere else — a fake support number in a search result, a helpful stranger in a group, a call about suspicious activity. Then, with you already anxious, they ask you to complete an operation that is technically entirely normal.
What reduces it is not a custody model but two habits: re-check anything involving money from an entry point you saved yourself, and never transfer while being hurried.
What to verify either way
If you are using platform custody: turn on app-based two-factor rather than SMS, enable withdrawal address whitelisting, set an anti-phishing code if offered, and store the two-factor backup codes somewhere you will find them. Read what the platform publishes about how it holds assets and what protection, if any, it claims.
If you are using self-custody: confirm which recovery standard your wallet uses and whether the phrase would restore into a different wallet from another vendor, since vendor lock-in on a recovery phrase is a real and checkable difference. The relevant specification is BIP-39. Then do a full restore onto a second device before funding it properly.
Either way: write down what happens to this if you are not around, and whether the person who would need it could actually follow those instructions. If the answer is no, that is the highest-value thing on this page to fix.
Questions
Is self-custody safer than leaving crypto on an exchange?
It removes one category of risk and adds another. Self-custody eliminates the risk that a company fails, freezes withdrawals or is hacked. In exchange it makes you solely responsible for a secret that cannot be reset, with no recovery process if it is lost. Which is safer depends entirely on which of those two failures you are more likely to experience.
Is it true that if you don't hold the keys you don't own the coins?
As a description of the legal and technical position, yes: a balance on a platform is a claim against that company rather than direct control of an asset. What the slogan omits is that holding keys transfers the failure risk to you rather than removing it, under the assumption that you will store and maintain a secret correctly for as long as you hold the asset.
What actually goes wrong with self-custody?
Overwhelmingly it is backup failure rather than attack: recovery phrases discarded, lost in a house move, stored in a photo library that was later wiped, or split between locations where one half went missing. Second most common is irreversible user error, such as sending to a valid address on the wrong network.
How much crypto is too much to leave on an exchange?
There is no universal figure. A useful test is to ask what amount would materially hurt to lose in a company failure, and to treat that as the threshold above which platform risk stops being a reasonable trade for convenience. For amounts you actively trade, the friction of self-custody usually costs more than the risk it removes.
Does a hardware wallet remove the recovery phrase problem?
No. A hardware wallet protects the key from an internet-connected device; the recovery phrase still exists, still has to be backed up, and losing it still loses the funds if the device fails or is lost. The device changes where the key is exposed, not whether you own the backup problem.