cryptonist
A modern building facade of repeating glass panels seen at an angle

Exchanges

Exchange or self-custody: what you are trading

The argument is usually conducted as though one side is safe and the other is reckless, with the answer depending on who is doing the arguing. Exchanges point at people who lost a seed phrase. Self-custody advocates point at exchanges that collapsed. Both sets of examples are real, which should be the first clue that “which is safer” is the wrong question.

The trade is not safety. It is recourse against control, and the two failure modes are shaped so differently that comparing them by frequency alone is misleading.

What you hold in each case

On an exchange you do not hold coins. You hold a claim against a company that holds coins, recorded in its database. That claim is usually honoured without incident, and the arrangement buys you things that are genuinely hard to replicate alone: a password reset, an identity-verified recovery path, staff who can intervene, and in some jurisdictions a regulatory regime standing behind the arrangement.

In self-custody you hold the keys. There is no claim and no counterparty, which means there is nothing to fail at you — and correspondingly nobody to appeal to when something fails because of you.

The asymmetry that matters

Exchange failures are rare, collective and outside your control. When one happens it affects everyone at once, the cause is usually invisible from outside beforehand, and no amount of personal diligence would have prevented it. What diligence buys you is the decision about whether to be exposed at all — and what actually determines whether you are made whole is set long before the failure, mostly by whether client assets were segregated.

Self-custody failures are common, individual and preventable. A phrase stored in a synced photo album. A signature given to a contract that asked for more than it appeared to. An account imported by private key that a recovery phrase never covered. Each is avoidable with knowledge that is freely available and routinely skipped, and the full list is short enough to read in one sitting — as are the two prerequisites, what a recovery phrase actually controls and how it differs from a private key or a password.

Comparing the two by how often they happen produces the wrong conclusion, because one category is reducible by effort and the other is not. The right comparison is between a risk you can shrink through competence and a risk you can only accept or decline.

The question that actually decides it

Not “which is safer” but: if this went wrong, who could I appeal to, and would it help?

On an exchange, sometimes the honest answer is “support, and yes” — an account lockout, a forgotten password, a mistaken transfer caught in time. Those are real recoveries that self-custody cannot offer.

Sometimes the answer is “the administrators, eventually, for a fraction” — and often a fraction denominated at the price on the day everything stopped, rather than in the coins you held. If that is the realistic outcome for the amount in question, the recourse you are paying for is not worth what it costs in counterparty exposure.

In self-custody the answer is always “nobody”. That is acceptable when the failure modes are ones you can actually close, and unacceptable when they are not — which depends far more on the holder than on the technology.

It was never one pool

Treating this as a single decision about all your holdings is what makes the argument unresolvable, because the right answer genuinely differs by purpose.

Assets being actively traded belong where trading happens. The counterparty exposure is the cost of the service and it is bounded by how much is sitting there, which is a manageable trade for a working balance. If the venue also pays a return on a balance left idle, where that yield comes from decides what else the balance is exposed to.

Assets you interact with — signing into applications, minting, swapping — belong in a wallet whose compromise you could absorb, because interaction is where authorisation risk lives and no amount of care reduces it to zero.

Assets being held for years are a third thing entirely. The case for leaving them as a database entry at a company you cannot audit gets weaker the longer the horizon, and the line between hot and cold storage is the relevant threshold rather than the exchange question.

Most people run all three out of one place, usually whichever one they opened first.

What deciding deliberately looks like

The useful discipline is a decision per pool rather than one for everything, and it fits in four questions:

  1. What is this for — trading, using, or holding? That alone assigns most balances.
  2. Could I replace it? The first time the answer is no, the arrangement should already have changed. Not when you get round to it.
  3. What would I do on the day withdrawals stop? If the answer involves moving quickly, the position was already too large for the venue.
  4. Have I tested the exit? Both exits — a withdrawal from the venue, and a restore of the phrase into different software. An untested recovery path is a belief rather than a plan, on either side.

The default is a decision too

The point of all this is not that self-custody is the mature choice and an exchange balance is laziness. Plenty of people should hold on an exchange, and some who hold their own keys should not.

The point is that leaving funds wherever they happened to land is not neutrality — it is a choice, made by inaction, usually in favour of the arrangement that was most convenient on the day you signed up. That is the only version of this decision that is definitely wrong, because it is the only one nobody actually made.