Wallets & Safety

Self-Custody Without Losing Everything: The Wallet Setup Exchanges Hope You Skip

How to move crypto off an exchange and into your own hands without turning a security upgrade into a total loss.

By Firoz Khan|28 July 2026|Updated 20 September 2026|10 min read

ShareXFacebookLinkedIn

Every exchange has a financial incentive for you to leave your crypto sitting in their custody. It keeps you inside their ecosystem, generates trading fees, and means they hold the asset if their platform ever fails, not you. 'Not your keys, not your coins' isn't a slogan, it's a description of what happens legally when an exchange goes under: customer crypto has repeatedly ended up tangled in insolvency proceedings rather than returned promptly. Self-custody fixes that problem and creates a different one: if you lose your keys, there is no customer support line, no password reset, and no one who can get your money back. Here's how to do it without that happening to you.

Hot wallets vs cold wallets

A hot wallet is software connected to the internet, an app on your phone or a browser extension. It's convenient for smaller amounts and frequent use, but it's also reachable by malware, phishing sites and malicious browser extensions, all of which exist specifically to drain hot wallets. A cold wallet, in practice a hardware wallet, keeps your private keys on a physical device that never exposes them to an internet-connected computer, even when you're confirming a transaction. The sensible split most experienced holders use is a hot wallet for spending money you're comfortable losing, and a cold wallet for anything you'd genuinely mind losing. Treat the hot wallet like the cash in your pocket and the cold wallet like the money in a safe.

The seed phrase is the whole system

When you set up a wallet, you're given a set of 12 or 24 words, your seed phrase. This single string of words can regenerate every private key and recover every asset in that wallet on any compatible device, which means it is functionally identical to your funds. Anyone who sees it can take everything, instantly and irreversibly, and there is no support desk that can freeze the transaction. Never type it into a website, never store it in a password manager, cloud drive, email draft, or photo on your phone, and never let anyone on a call, in a message, or claiming to be support ask you for it. Legitimate wallet providers and exchanges never ask for your seed phrase, full stop, which is exactly why every phishing attempt pretends to be one of them.

Newsletter

Get the best of our crypto and money content every week

Straight to your inbox, once a week.

By subscribing you agree to receive our weekly newsletter and to our Privacy Policy. No spam, unsubscribe anytime.

Writing it down properly

Write your seed phrase on paper or, better, stamp it into metal, and store it somewhere a fire, flood or nosy houseguest can't reach. A single paper copy in a drawer is fragile: it fails silently and you often won't discover the failure until you need it. Consider two copies in two separate physical locations, and be honest with yourself about who else might stumble across it. A phrase found by the wrong person is just as catastrophic as one lost to fire, so security and redundancy have to be balanced, not treated as the same problem.

Hardware wallets: what they actually buy you

A hardware wallet keeps your private key inside a dedicated chip that never transmits the key itself, even to the device you plug it into. Transactions are signed on the hardware wallet's own screen, so malware on your laptop can display one transaction while a hidden one is actually being signed, and a genuine hardware wallet stops that by making you verify the real destination address on its own separate display. This is the main reason hardware wallets matter more than the brand name on the box: the isolated signing and the independent screen, not extra software features.

Test your recovery before you need it

The single biggest cause of self-custody losses isn't hacking, it's people locking themselves out of their own wallet through a recovery process they never tested. Before you move meaningful funds onto a new wallet, deliberately wipe the device (or use a second, spare device) and restore it from your written seed phrase alone, with no other notes to fall back on. If that restore works cleanly, you know your written record is accurate and complete. If it doesn't, you've just found the gap while it costs you nothing, rather than finding it the day you actually need to recover.

How people actually lose crypto

The realistic loss scenarios aren't exotic. A seed phrase photographed and synced to a cloud account that later gets compromised. A phrase transcribed with one word wrong, discovered only when recovery is attempted for real. A phishing site that looks identical to a wallet's official interface, prompting a 'connect wallet' action that quietly requests a draining approval. A hardware wallet bought second-hand or from an unofficial reseller with a pre-loaded seed phrase, so funds sent to it are visible to whoever set it up. And simple hardware failure or loss with no backup at all. Every one of these is preventable with the steps above, and every one of them happens to people who assumed it wouldn't happen to them.

Where people get this wrong

The most common failure isn't a hack, it's overconfidence about memory and paper. People assume they'll remember where they wrote a seed phrase down, or that a single copy will survive years untouched, and both assumptions fail more often than you'd expect. Buy hardware wallets only direct from the manufacturer or an authorised retailer, never a marketplace listing, generate the seed phrase yourself on the device rather than accepting one that comes pre-printed, and treat moving to self-custody as a process with a recovery test at the end, not a one-off action you do once and forget about.

A reminder

The FCA risk warning still applies to higher-risk crypto content. Always assess how much risk you are willing to take before buying.

ShareXFacebookLinkedIn

Related reading