A peculiar thing about crypto: how you hold it determines who actually controls it — and getting this wrong is one of the most common ways people lose everything.
Keys, not coins
Crypto isn’t really “in” a wallet like cash in a purse. What you hold is a private key — a secret code that proves you own coins recorded on the blockchain. Whoever has the private key controls the coins. A “wallet” is just software or a device that stores and uses your keys.
This leads to crypto’s core security maxim: “not your keys, not your coins.”
Two ways to hold it
- Self-custody — you hold your own private keys (in a software or hardware wallet). You’re fully in control… and fully responsible. Lose the key (or its backup “seed phrase”) and your coins are gone forever — no password reset, no support line. Billions have been lost this way.
- Custodial (on an exchange) — a company holds the keys for you, like a bank. Convenient and recoverable by password — but you’re trusting that exchange. Exchanges have been hacked, frozen withdrawals, and gone bankrupt (FTX, Mt. Gox), taking customers’ funds with them.
Neither option is “safe” by default: one risks your own mistakes, the other risks someone else’s failure or fraud.
The unforgiving part
Crypto has no chargebacks and no undo. Send to the wrong address, fall for a scam, or get your keys phished, and the money is irreversibly gone. This finality is the price of having no middleman — and it’s why crypto demands far more care than a bank account.
The takeaway
Whoever holds the private keys controls the crypto — “not your keys, not your coins.” Self-custody means total control but total responsibility (lose the key, lose everything); exchanges are convenient but you’re trusting a company that could fail or be hacked. There are no undos — care is everything. (This is education, not investment advice.)