Exchanges
Exchange or self-custody: what you are trading
The argument is usually conducted as though one side is safe and the other is reckless, with the answer depending on who is doing the arguing. Exchanges point at people who lost a seed phrase. Self-custody advocates point at exchanges that collapsed. Both sets of examples are real, which should be the first clue that “which is safer” is the wrong question.
The trade is not safety. It is recourse against control, and the two failure modes are shaped so differently that comparing them by frequency alone is misleading.
What you hold in each case
On an exchange you do not hold coins. You hold a claim against a company that holds coins, recorded in its database. That claim is usually honoured without incident, and the arrangement buys you things that are genuinely hard to replicate alone: a password reset, an identity-verified recovery path, staff who can intervene, and in some jurisdictions a regulatory regime standing behind the arrangement.
In self-custody you hold the keys. There is no claim and no counterparty, which means there is nothing to fail at you — and correspondingly nobody to appeal to when something fails because of you.
The asymmetry that matters
Exchange failures are rare, collective and outside your control. When one happens it affects everyone at once, the cause is usually invisible from outside beforehand, and no amount of personal diligence would have prevented it. What diligence buys you is the decision about whether to be exposed at all.
Self-custody failures are common, individual and preventable. A phrase stored in a synced photo album, a signature given to a malicious contract, an account imported by private key that a recovery phrase never covered. Each is avoidable with knowledge that is freely available and routinely skipped. The failure modes are documented in what a MetaMask recovery phrase actually controls and seed phrases, private keys and passwords are not the same.
Comparing the two by how often they happen produces the wrong conclusion, because one category is reducible by effort and the other is not. The right comparison is between a risk you can shrink through competence and a risk you can only accept or decline.
The question that actually decides it
Not “which is safer” but: if this went wrong, who could I appeal to, and would it help?
On an exchange, sometimes the honest answer is “support, and yes” — an account lockout, a forgotten password, a mistaken transfer caught in time. Those are real recoveries that self-custody cannot offer.
Sometimes the answer is “the administrators, eventually, for a fraction.” If that is the realistic outcome for the amount in question, the recourse you are paying for is not worth what it costs in counterparty exposure.
In self-custody the answer is always “nobody”. That is acceptable when the failure modes are ones you can actually close, and unacceptable when they are not — which depends far more on the holder than on the technology.
The practical shape
It was never a binary, and treating it as one is what makes the argument unresolvable. Amount, time horizon and competence all move the answer.
Funds being actively traded belong where trading happens; the counterparty exposure is the cost of the service, and it is bounded by how much is sitting there. Funds being held for years are a different problem, and the case for leaving them as a database entry at a company you cannot audit gets weaker the longer the horizon.
The useful discipline is to decide deliberately for each pool rather than letting the default — wherever the money happened to land — make the decision. Most people are not choosing custody. They are just not moving anything.