Answer these first
- Would losing access to this money materially affect my life? No → leave it on the exchange, do not overcomplicate.
- Yes → read on, but accept that every consequence becomes yours.
- Can I guarantee I will still be able to find a piece of paper in five years? No → do not self-custody large amounts.
- Would I click a link in a "wallet upgrade" email? Possibly → do the phishing section first.
The trade-off, stated honestly
Exchange custody and self-custody are not "unsafe versus safe". They are two different risks. The exchange risk is the platform failing, your account being restricted, you being unable to reach your own money. The self-custody risk is you losing it, getting it wrong, or being deceived — and nobody can restore it.
The industry slogan is correct as far as it goes, but in circulation it has flattened into "self-custody is always better", which is not right. For someone who cannot remember passwords, keeps every screenshot on their phone, and clicks links reflexively, self-custody carries materially more risk than a reputable platform.
So the question is not which is safer. It is which kind of risk am I better equipped to manage.
When self-custody is worth it
I use a plain test: if this money became unreachable because of something on the platform's side, would it materially affect my life?
No — leave it. The time you spend and the mistakes you might make outweigh the risk you are avoiding.
Yes — then at least some of it should come off. Note "some". All of it means putting every egg in the basket marked "I will not make a mistake".
There is also a time dimension: short-term working balances on the platform, long-term holdings with you. The main cost of self-custody is operational friction, and things you do not touch do not incur it.
The seed phrase is the money
A seed phrase — usually twelve or twenty-four English words — is a complete backup of your wallet. Anyone holding it holds everything inside, with no need for your phone, your password or anything else. If the backup is lost but the wallet still works, move funds to a newly backed-up wallet. Losing all usable access and recovery material can make the assets permanently inaccessible.
How to store it
- On paper, or stamped into metal. Metal survives fire and water; paper does not — but paper is still far better than anything electronic.
- Two copies, in different physical places. One at home, one elsewhere. This is about fire, flood and losing things in a move.
- Verify you copied it correctly. Before adding funds, use the manufacturer’s on-device backup check or trusted-device recovery procedure. Never type a hardware-wallet recovery phrase into a computer or phone. Mis-transcribing a single letter is common, and you would otherwise discover it on the day you need it.
What never to do
- Do not photograph it. Photos sync to cloud albums, which hands it to the security of another account.
- Do not put it in notes, chat messages or draft emails. Same reason.
- Do not type it into any web page. There is no legitimate reason for a website to want your seed phrase. Anything asking is phishing, without exception.
- Do not tell anyone, including anyone claiming to be support. No genuine support function asks for it.
A question to settle in advance: if something happened to you, could your family reach these assets? Self-custody has no inheritance mechanism — there is no bank to run a probate process, and the coins simply sit on chain. That has to be arranged deliberately (telling a trusted person how to recover, or a split-backup scheme), and arranged while there is still time to.
What a hardware wallet does and does not solve
Its core function is keeping the private key away from anything connected to the internet. Your computer can be compromised and still not obtain the key, because signing happens inside the device.
What it does not solve, and these are the more frequent problems:
- You signing a malicious transaction. The device asks you to confirm, and if you confirm without reading, it signs. A great many losses happen exactly here.
- A leaked seed phrase. However secure the device, the words leaving your control ends it.
- Physical coercion. The device is with you, and so are you.
- A tampered device. Buy only from official channels. Never second-hand, and never one that arrives "already set up, seed phrase included" — that is a standard scam and the coins leave the moment they arrive.
So a hardware wallet is a worthwhile tool and one link in a chain, not a purchase that ends the problem.
Phishing deserves its own section
Phishing is the hardest to defend against, because it does not attack the technology. It attacks your state at that moment — rushed, tempted, afraid of missing out, or simply distracted. No technical control stops distraction. Only habits do.
Fake sites in search results
You search for a wallet or an exchange and the top result is a paid impostor, identical in appearance, domain differing by a character or two. Everything you type there is captured.
There is one defence and it is highly effective: bookmark the sites you use and only ever enter through the bookmark. No searching, no clicking links. This reduces exposure to fake search adverts, but bookmarks can be wrong and sites or devices can be compromised. Still verify the domain and the requested action.
"Your account has a problem, verify immediately"
By email, SMS or in-app. It manufactures urgency so you act before thinking.
Defence: never follow a link in any message claiming an account problem. Open your bookmark and log in. If there is a real problem you will see it once inside; if everything is normal, the message was fake.
Airdrops and "free claims"
An unknown token appears in your wallet, or a claim link arrives. Connect, sign, and the approval is granted.
Defence: do not interact with things that appear unbidden, and do not try to sell them — that is precisely the bait to make you connect. Treat them as not there.
Fake support in your messages
You ask a question in a public group and someone immediately messages you privately claiming to be support. Real support does not initiate private contact and does not reach you outside official channels.
Defence: only a conversation you started through an official channel counts. Ignore all inbound offers of help.
One rule across these scams: do not give a person in a chat your seed phrase, private key, password or verification code. Entering a code into a verified official login form, or restoring on trusted wallet hardware, is different. Check both the purpose and destination of the input. Support chats are not a place to hand over these secrets.
Common loss scenarios, by handling step
The order below follows handling steps. We have no industry-wide frequency data, so it does not rank how often each loss occurs:
| Method | How it happens | Defence |
|---|---|---|
| Wrong network or wrong address | Slip, partial copy, wrong network selected | Test small to new addresses, verify the entire address and network |
| Seed phrase lost or miscopied | Written down casually, then not findable | Two copies, verify by restoring once |
| Phishing site | Fake site in search results, airdrop links | Enter only through your own bookmark |
| Signed a malicious approval | Connected to an unfamiliar site and confirmed | Read every signature request; review approvals periodically |
| Clipboard hijacking | Malware swaps the address you copied | Check after pasting, not just the first characters |
| "Support" obtained the seed phrase | Someone who approached you offering help | Nobody ever needs your seed phrase |
Note that the top two involve no attacker at all. They are handling and storage failures, which is the point: with self-custody, the main risk is you.
The clipboard row is worth expanding. Some malware watches the clipboard: you copy an address, and what pastes is the attacker's, with the first characters made deliberately similar. So check the entire address — matching ends do not rule out different characters in the middle.
A scheme that is good enough, not perfect
The usual failure of security schemes is being so elaborate that you stop following them. Multisig, split backups, geographically distributed storage — impeccable on paper, and if moving funds takes half an hour you will eventually route around them. What follows is the version I think an ordinary person can actually sustain.
Three tiers, each with its own job
- A small everyday amount on an exchange or a phone wallet. Sized so that losing it would sting without hurting. Convenience first.
- Medium-term holdings in a separate software wallet, seed phrase written down and stored properly. This one connects to nothing unfamiliar.
- Long-term holdings on a hardware wallet, seed phrase in two locations. This address only receives; it never interacts with applications.
The point is not which products you use. It is that the risks do not spread between tiers. The everyday tier getting phished leaves the others untouched; a compromised application only affects the address that interacted with it.
Three things to do every single time
- Compare the entire destination address. Obtain it through a trusted recipient channel and compare it again after pasting. With a hardware wallet, also verify the full address on the device display. Matching ends can still conceal a lookalike address.
- Send a small test to any new address. Repeated because it genuinely prevents the most expensive class of error.
- Read what you are signing. If you do not understand it, do not sign. Almost every "approval drain" happens in the moment somebody confirms with their eyes closed.
Two things to do periodically
Review and revoke approvals you no longer use. Permissions you granted an application persist; if that application is later compromised, the permission is still live. Clear out what you no longer need.
Check that the backup is correct. For a hardware wallet, use the manufacturer’s on-device backup-check feature where available. Enter the recovery phrase only on trusted hardware, not in a computer or phone wallet for a routine check. If that feature is unavailable, read the model’s recovery instructions first; do not reset a working wallet before confirming the backup.

For a full-address check, see MetaMask’s address-poisoning guidance (checked September 2026). Matching ends do not rule out substituted middle characters.
One more, less pleasant but practical: do not discuss how much you hold in public — not on social platforms, not over dinner with acquaintances. Physical security is the least discussed risk in this field and has the most serious consequences, and its first step is always somebody knowing you have it.
Questions people actually ask
Can I photograph my seed phrase and keep it on my phone?
No. Photos sync to cloud albums, which makes your assets only as safe as that account. The correct storage is an offline physical medium — paper or metal.
What does a hardware wallet protect against, and what not?
It protects against remote theft: the private key never leaves the device, so malware cannot obtain it. It does not protect against you signing a malicious transaction, a leaked seed phrase, or someone with physical access compelling you to unlock it.
How much before self-custody is worth it?
There is no universal threshold. Substitute a different question: if this money became unreachable because of something at the platform, would that materially affect your life? If yes, hold at least part of it yourself.
What is the difference between a wallet app and an exchange account?
Assets in an exchange account are a record of what the platform owes you, and the keys are held by the platform. Assets in a self-custody wallet are controlled directly by your private key. The first is convenient but depends on the platform; the second is autonomous but has nobody to fall back on.
Risk notice: crypto prices move violently and you can lose everything you put in. Self-custody means that operational mistakes or lost credentials make assets permanently unrecoverable, and no institution can assist. Nothing here is investment advice. Some jurisdictions restrict crypto assets — check the rules where you are.
What the safety advice rests on
There is no regulator to cite here, so the list is public technical specifications and vendor documentation. The storage advice is common practice, not anybody’s rule.Checked September 2026
- BIP-39: the mnemonic seed phrase specification Bitcoin Improvement ProposalsA seed phrase is not a vendor invention; it is a public specification, and this is its text.
- What is a recovery phrase Ledger AcademyWhat a recovery phrase does and the principles for keeping it safe.
- Official support: never enter your 24-word recovery phrase LedgerThe vendor's own explicit position: anything asking you to enter your recovery phrase is a scam.
- Hardware wallet guides and security learning centre TrezorAnother hardware wallet vendor's security guidance, useful as a cross-check.
- How Bitcoin works bitcoin.orgThe relationship between keys and addresses, and why whoever holds the key holds the asset.
- Ethereum block explorer EtherscanAddress balances are public, so you can confirm a transfer yourself.
- ERC-20 token standard ethereum.orgThe technical reason assets sent on the wrong chain cannot be recovered.