Module 5 of 6 · 5 min read

Custody and Security for Stablecoin Holders

Holding stablecoins really means holding private keys, so this module covers who keeps them, how to protect a seed phrase, and the scams that drain most wallets.

The custody spectrum A horizontal spectrum from fully custodial on the left, where an exchange holds your keys, to fully self-custodied on the right, where you hold them on an offline hardware wallet. Three points sit along it: an exchange wallet, a software or hot wallet, and a hardware or cold wallet. Moving right trades convenience for control and responsibility. Fully custodialthe exchange holds your keysFully self-custodiedyou hold the keysExchangesomeone elseHot walletyou, onlineCold walletyou, offline"Not your keys, not your coins."
Exchange wallet
The exchange holds your keys
Custodial
ConvenienceVery high
Control and responsibilityVery low

Convenient and familiar. Password recovery, a support desk, and a balance that feels like a bank account. The trade is trust: you are relying on the provider not to get hacked, freeze your funds, or collapse (as Mt. Gox and FTX did).

Counterparty trustYou hold a claim, not the coins. If the provider freezes withdrawals or fails, your balance can go with it. This is exactly what "not your keys, not your coins" warns about.
Pick a point on the spectrum. As you move right, convenience falls and control (with the responsibility that comes with it) rises. Neither end is "safe" on its own, you are choosing which risk to carry.

Try the spectrum above before reading on. Move from left to right and you are trading convenience for control: on the left an exchange holds your keys for you, on the right you hold them yourself on an offline device. A stablecoin only sits still in value. It does not sit still in risk. The moment you hold one, a quiet question follows you around: who actually controls it? In crypto, controlling a coin means controlling a secret key, and that key can live on an exchange that holds it for you, or on a device that only you can touch. Where that key lives decides almost everything about how you could lose the money, and losing it here is usually final. There is no bank to call, no chargeback, no fraud department. That sounds scary, and it should, but the good news is that the rules for staying safe are short, boring, and genuinely effective once you know them.

Holding crypto means holding keys

Owning a stablecoin is really owning a private key, the secret that lets you move the coin. Custody is just the question of who holds that key, and the answers sit on a spectrum.

At one end is fully custodial: an exchange or provider holds the keys for you. It is convenient, your password is recoverable, and it feels like a normal bank account. The catch is that you are trusting that provider not to fail, freeze your funds, or get hacked.

At the other end is fully self-custodial: you hold the keys yourself, usually in a hardware wallet, a small device that keeps the keys offline where malware cannot reach them. In between sit ordinary software and mobile wallets and multi-signature setups.

The trade-off never goes away. More control means more responsibility. Less control means more trust in someone else. Neither end is "safe" in the abstract; you are choosing which risk you would rather carry.

Not your keys, not your coins

This old crypto saying, popularised by Andreas Antonopoulos, captures the whole idea. If someone else holds the private keys, you do not truly own the coins. You own a claim against a custodian, and that claim is only as good as the custodian behind it.

That is not a theoretical worry. When custodial exchanges such as Mt. Gox and FTX collapsed, customer "balances" turned into unsecured claims in a bankruptcy queue. The numbers on the screen were real right up until they were not.

Self-custody removes that middleman entirely. The price is that you become solely responsible for security and backup. So the choice is honest: hand the keys to a company and inherit its failures, or keep the keys yourself and inherit the job of protecting them.

Your seed phrase is the whole thing

A self-custody wallet is backed up by a seed phrase, usually 12 or 24 words (a BIP-39 mnemonic) that encodes your private keys. Anyone who has those words controls the funds. Nobody can restore them for you if you lose them. That single fact drives every rule that follows.

  • Keep it offline. Write it on paper or stamp it into metal. Never store it as a photo, cloud note, email, or screenshot, because a digital copy is exposed to any malware or data breach that reaches your device.
  • Keep more than one backup. Store copies in separate secure places so that a fire, flood, or theft in one location does not wipe you out completely.
  • Never type it into a website, and never share it with "support". No legitimate service will ever ask for your seed phrase. Anyone who does is trying to rob you.

Treat those words as the single most valuable secret you own, because that is exactly what they are.

How people actually lose funds

Here is the part that surprises newcomers: almost nobody loses crypto because an attacker broke the cryptography. The maths holds. People lose funds to social engineering, tricks that get you to hand over access yourself.

The common ones are worth recognising on sight:

  • Phishing approval requests. A fake site prompts you to sign a transaction that quietly grants a contract permission to drain your tokens later.
  • Fake bridge or "exploit" sites and bogus airdrops that lure you into connecting a wallet you should have left alone.
  • Impersonation of support staff asking for your seed phrase or recovery words.
  • Address poisoning, where a lookalike address is planted in your history so you copy it by mistake and pay a stranger.

The habits that stop most of this are unglamorous but they work: use a hardware wallet for any meaningful balance, verify URLs and contract addresses carefully, read what you are actually signing before you sign it, revoke stale token approvals, keep a small separate wallet for day-to-day activity, never share the seed phrase, and slow down. Manufactured urgency ("act now or lose your airdrop") is a scammer's main tool, so a pause is a defence.

The one move that caps the damage

If you remember a single practical idea from this module, make it the hot/cold split. Keep only what you actively need in an online "hot" wallet, and hold the bulk in offline "cold" storage. That way, the most common attacks can only reach the small pile.

Worked example: a hot/cold split in action

A user holds 20,000 USDC. Instead of leaving it all in one place, they split it.

  • 1,000 USDC stays in a mobile hot wallet for day-to-day payments and on-chain activity. They treat that as the amount they could afford to lose to a bad approval.
  • 19,000 USDC moves to a hardware wallet. Its 24-word seed is stamped on metal and stored in two separate locations, and never photographed.

One day the hot wallet is drained by a phishing approval. The loss is capped at $1,000, because the other $19,000 lives in cold storage whose keys never touched an internet-connected device. A single structural decision put roughly 95% of the balance out of reach of the most common attack. Notice that the user did not have to be a security expert. They just had to divide the money before anything went wrong.

If you do use a custodian, judge it on four things

Custody is not a moral test, and a well-run custodian is a reasonable choice for funds you use often. If you go that route, evaluate the provider on four points:

  • Security record. Has it been breached, and how are funds stored? Cold storage kept offline is far safer than hot wallets sitting online.
  • Reserves. Does it actually hold customer assets one-for-one, ideally with a proof-of-reserves, or does it quietly lend them out?
  • Jurisdiction and regulation. Is it licensed, where, and what protection do you have if it fails?
  • Operational transparency. Audits, insurance, and a track record of paying withdrawals reliably.

No custodian is risk-free, so the realistic goal is to pick a well-run, well-regulated one and keep only what you need there for active use. The rest belongs in self-custody.

Why self-custody transactions cannot be undone

On an exchange account, the provider can sometimes freeze, reverse, or recover a transaction because it controls the ledger and the keys. A self-custodied on-chain transfer is different: once it is confirmed, it is final. There is no admin who can claw it back, no support desk that can reverse a mistake, and no way to recover funds sent to a scammer or a wrong address.

This is the same irreversibility that makes stablecoin payments fast and cheap, viewed from the security side. It is a feature and a hazard at once, which is exactly why "verify before you sign" and "check the address" are not fussy advice. They are the only line of defence, because there is no second one.

Quick knowledge check

What does "not your keys, not your coins" mean? If a custodian holds your private keys, you own only a claim against that custodian rather than the coins themselves. If it fails, as FTX did, that claim can leave you an unsecured creditor waiting in a bankruptcy queue.

Why must a seed phrase never be stored digitally? A photo, cloud note, screenshot, or email is exposed to any malware or data breach, and whoever obtains the phrase gains irreversible control of the funds. Offline paper or metal keeps it off any device an attacker can reach.

What single practice caps most self-custody loss? A hot/cold split: keep only small day-to-day funds in an online hot wallet and hold the bulk in a hardware wallet with offline seed backups, so a phishing drain can only reach the small amount.

Sources

  • ethereum.org, "Security", the custody spectrum from custodial to self-custodial and how hardware wallets keep keys offline.
  • Bitcoin BIPs, "BIP-0039", the 12- or 24-word mnemonic (seed phrase) standard, and that anyone with the phrase controls the funds.
  • U.S. SEC, "Press Release 2022-219: SEC Charges Samuel Bankman-Fried", how the failure of a custodial exchange turns customer balances into bankruptcy claims.
  • FBI (Internet Crime Complaint Center, IC3), "Cryptocurrency fraud losses", on losses driven by scams and social engineering rather than broken cryptography.

CoinUnited Academy is an education initiative by CoinUnited.io.

This is an educational credential. It is not a licence, not authorisation to give financial advice, and not a guarantee of trading skill or profit.

© 2026 CoinUnited Academy · CoinUnited.io