Bitcoin
Self-Custody vs Exchange Custody: The Real Trade-offs of Holding Bitcoin
Keeping bitcoin on an exchange is convenient. Keeping it in a wallet you control is more work. The difference between the two arrangements goes well beyond user experience, and understanding it is one of the most practically important things a bitcoin holder can learn. What custody actually means In traditional finance, custody means a licensed … Continued
Key takeaways
- In traditional finance, custody means a licensed institution holds assets on behalf of a client.
- Exchange custody has genuine advantages that are worth naming honestly.
- The arguments for self-custody centre on counterparty risk and censorship resistance.
- The collapse of FTX in November 2022 was the most visible demonstration in crypto history of exchange counterparty risk.
- The custody decision depends on the size of the holding, the intended holding period, and the holder’s technical comfort and security discipline.
Keeping bitcoin on an exchange is convenient. Keeping it in a wallet you control is more work. The difference between the two arrangements goes well beyond user experience, and understanding it is one of the most practically important things a bitcoin holder can learn.
What custody actually means
In traditional finance, custody means a licensed institution holds assets on behalf of a client. In crypto, it means something more specific: whoever controls the private keys controls the coins. A private key is a secret piece of cryptographic data that authorises transactions. If you do not hold your own private key, someone else does — and that someone else controls your bitcoin, regardless of what your account balance shows on screen.
This is the meaning behind the phrase “not your keys, not your coins.” It is not mere slogan. When you deposit bitcoin to an exchange, the exchange takes custody of the private keys and issues you a promise to return the equivalent value. What you actually hold is a liability of the exchange, not bitcoin itself. For most practical purposes the distinction is invisible — until the exchange has a problem.
Our private key glossary entry explains the cryptographic mechanics. Our wallets guide covers how different types of wallet handle key storage in plain language.
The case for exchange custody
Exchange custody has genuine advantages that are worth naming honestly. It is frictionless: buying, selling and transferring bitcoin on an exchange requires no technical knowledge of keys or wallet addresses. The account is recoverable if you forget a password, which self-custody is not. Regulated exchanges in major jurisdictions now operate under capital requirements, insurance arrangements and audit obligations that did not exist in 2013.
For small amounts, or for active traders who move in and out of positions regularly, exchange custody is often the practical choice. The risk-adjusted case for going through the complexity of self-custody weakens considerably when the balance is small relative to the effort and the failure modes of hardware wallets are also considered.
Major regulated exchanges — those operating under licences in the US, UK, EU or other mature regulatory frameworks — present a meaningfully different risk profile than unregulated offshore platforms. The distinction matters when assessing counterparty risk.
The case for self-custody
The arguments for self-custody centre on counterparty risk and censorship resistance. Counterparty risk is the possibility that the exchange fails, is hacked, freezes withdrawals, or is seized by a government. The history of crypto is populated by exchanges that failed and left customers without recourse: Mt. Gox in 2014, QuadrigaCX in 2019, and FTX in November 2022 are the most prominent. Each represented billions of dollars in customer funds that became inaccessible or were lost entirely.
Self-custody eliminates exchange counterparty risk at the cost of introducing personal key-management risk. If you lose your seed phrase — the 12 or 24 words that can regenerate your private key — your bitcoin is gone permanently. There is no password reset, no customer service call, no court order that can retrieve it. The responsibility is total.
Hardware wallets (cold storage devices that sign transactions without exposing the private key to an internet-connected computer) are the standard recommendation for meaningful self-custody balances. Manufacturers including Ledger and Trezor produce the most widely used devices. The tradeoff is that each introduces its own supply-chain and firmware risk alongside the key-management risk the holder already carries.
The FTX lesson and what changed after it
The collapse of FTX in November 2022 was the most visible demonstration in crypto history of exchange counterparty risk. FTX, at the time one of the largest and most professionally presented exchanges, misappropriated customer funds. The failure prompted a significant shift in on-chain data: net withdrawals from centralised exchanges rose sharply as users moved coins to self-custody wallets, a pattern visible in blockchain analytics from providers such as Glassnode.
In regulatory terms, FTX accelerated the push for proof-of-reserve requirements — regular attestations by exchanges that customer balances are backed one-to-one by actual assets. Several exchanges now publish on-chain proof-of-reserve reports, though the standards and third-party verification of those reports vary. Our regulation coverage tracks how proof-of-reserve requirements are evolving in different jurisdictions.
The episode also reinforced that jurisdictional regulation matters. US-regulated exchanges operate under SEC, CFTC and FinCEN oversight; exchanges registered in the EU now face MiCA requirements; offshore unregulated platforms carry a different risk profile. The choice of where to custody assets is partly a choice of which regulatory framework backstops the arrangement.
A practical framework for deciding
The custody decision depends on the size of the holding, the intended holding period, and the holder’s technical comfort and security discipline. A rough framework: for small, actively traded balances, exchange custody at a regulated platform is reasonable; for larger balances held over a long time horizon, some form of self-custody or cold storage is worth the added complexity; for very large balances, a multi-signature arrangement or institutional custody solution adds another layer of protection against single-point failures.
No arrangement is risk-free. Exchange custody carries counterparty risk. Self-custody carries key-loss and hardware risk. Institutional custody carries counterparty and regulatory risk. Understanding which risks you are accepting, and being honest about your own ability to manage a seed phrase or hardware wallet, is the starting point for making a sensible choice.
Our wallets guide walks through each option in more detail. The live bitcoin price page includes exchange-vs-self-custody context in the About section.
Not financial advice. This article is educational and informational only. Cryptocurrency custody decisions carry real financial and technical risks. We do not endorse any specific exchange, hardware wallet manufacturer or custody provider. Conduct your own due diligence and consult a qualified financial adviser before making any decision about where to hold digital assets.
Frequently asked questions
What does “not your keys, not your coins” mean?
It means that if you do not control your own private keys — that is, if an exchange holds them on your behalf — you do not have direct ownership of your bitcoin. You hold an IOU from the exchange, which introduces counterparty risk.
What is a seed phrase?
A seed phrase (also called a recovery phrase or mnemonic) is a sequence of 12 or 24 randomly generated words that can regenerate your private key. Losing it means losing access to your bitcoin permanently. See our seed phrase glossary entry for the full explanation.
Is a hardware wallet completely safe?
Hardware wallets significantly reduce the risk of a remote hack because the private key never touches an internet-connected device. They do not eliminate risk: physical loss, damage, supply-chain attacks and user error are all real failure modes. Backup seed phrases kept securely offline address most of these.
Did FTX change the standard advice on custody?
FTX reinforced the pre-existing argument for self-custody. On-chain data showed a notable shift toward exchange withdrawals after the collapse. Regulatory responses have pushed for proof-of-reserve standards, but the fundamental counterparty risk of exchange custody has not changed — only the regulatory pressure on exchanges has increased.