Skip to content
MarketClueLearn

Exchanges, Wallets, and Custody: Who Actually Controls It

Intermediate12 min readLesson 6 of 16

4 steps · one page

In short

Every digital-asset holding is controlled by whoever holds the private key, and the only question that matters is whether that is you or somebody else.

This is the highest practical risk in the pillar, and it is not price risk. Transactions cannot be reversed. A lost key is a permanent loss with no institution to appeal to. A stolen key produces a transfer the network considers perfectly valid. And multiple exchanges holding client assets have failed, with clients discovering only afterwards what their legal claim was — in several cases, an unsecured claim in an insolvency. More reported crypto losses come from this layer than from the price of anything. This article explains the custody models and where each fails. It deliberately gives no operational security instructions — specific guidance would be advice, would age badly, and is exactly the kind of content fraudsters imitate. It names no exchange, wallet, or custodian.

Blockchain basics established that a valid signature is a valid transaction — the network authenticates the key, not the person. So custody is not an administrative detail behind the investment; in this asset class custody largely is the risk.

Two models, and what each one exposes you to

Self-custody means holding the private key yourself. You can transact without permission, no third party can freeze or lose your holding, and no company failure affects it. The exposures are entirely operational and entirely yours. A key lost — hardware failure, a forgotten passphrase, a destroyed backup, a death without succession arrangements — is a permanent loss of an asset that still exists and can be seen on the ledger forever, held by nobody. A key stolen, whether by malware, deception, or physical coercion, produces transfers the network will honour. A transaction sent to a wrong address is gone. There is no support line, no chargeback, and no regulator to complain to, because there is no counterparty — which is precisely what self-custody means. Custodial holding means a third party holds the keys and credits you with a balance. This removes the operational burden and reintroduces something the design was meant to eliminate: a counterparty. Four questions determine what you actually have, and they are the same questions the stablecoin article asked of an issuer, because it is the same kind of problem. Are client assets segregated from the firm's own? Is your claim a proprietary entitlement to specific assets or a general unsecured claim on the company? Is the firm regulated, where, and does that regime cover custody of these assets? And is anything verified by independent audit rather than asserted? Several failures have turned on exactly these points, with clients who believed they owned assets discovering they were creditors of an insolvent business. The industry shorthand — "not your keys, not your coins" — is accurate but incomplete, because it implies self-custody is the safe answer. Both models carry loss modes; they are simply different ones, and the honest framing is a choice between operational risk you control and counterparty risk you do not, with no third option that removes both.

Hot, cold, and the mechanics readers should recognise

A wallet does not hold assets. It holds keys and constructs transactions; the assets are ledger entries. That sounds pedantic and it prevents a real error, because it explains why moving a wallet application does not move holdings and why the keys are the only thing that matters. Hot means connected to the internet — convenient and exposed to remote compromise. Cold means kept offline, which removes remote attack and substitutes physical risks: loss, damage, theft, and the succession problem. Custodians typically use both, with the large majority offline and a working balance hot, which is why exchange compromises have often drained a fraction of holdings rather than everything. Four mechanics worth recognising. Addresses are unforgiving: a transfer to a valid but wrong address is complete and irreversible, and sending an asset to an address on the wrong network is a common way to lose it. Transaction fees are paid in the network's native coin, so a holder of a token needs the host coin to move it — people discover this when trying to exit. An exchange balance is usually not an on-chain holding. Internal trades adjust a database; nothing touches the blockchain until a withdrawal, which is why an exchange can display balances it cannot honour. And withdrawals can be suspended. Firms have halted withdrawals during stress, sometimes permanently — an ability to see a balance is not an ability to move it, and that distinction only becomes visible at the moment it matters. On regulation. Oversight attaches to firms, not to the assets, and coverage varies enormously: whether client-asset rules apply, whether a compensation scheme exists if the firm fails, whether the firm is authorised at all in the reader's jurisdiction or merely accessible from it. This is the same jurisdictional point the FX broker article identified as the single most decision-relevant fact about an account, and it applies here with more force, because deposit-style protections that readers assume from banking generally do not extend to digital-asset custody. A firm may be registered for one purpose and unregulated for custody, which is a distinction that does not survive most marketing.

Worked example

Worked example

Worked example (fictional). Two holders, each with $50,000 of Verex (VRX). Nadia self-custodies. Keys on an offline device, recovery phrase on paper in a safe. No counterparty, no withdrawal limits, no company that can fail. Then the safe is destroyed in a house fire and the device fails. The VRX still exists, visible on the ledger, permanently unspendable. Her loss is $50,000 and there is no one to ask. Note what did not go wrong: no fraud, no compromise, no bad decision about an asset — the loss came entirely from single-point key storage. Omar uses an exchange. He sees a balance, trades instantly, and recovers access when he forgets a password. Then the exchange suspends withdrawals, citing a liquidity review, and enters insolvency six weeks later. The balance was a database entry; the on-chain assets were pooled and partly lent out. His position resolves as an unsecured claim in an insolvency, and he receives a distribution years later at a fraction of the balance he watched on screen. Note what did not go wrong here either: VRX's price was unchanged throughout. The comparison is the point. Both lost most of $50,000. Neither loss was caused by the asset. One faced operational risk she controlled and mishandled; the other faced counterparty risk he did not control and could have investigated. The four custody questions were answerable before Omar deposited, and the single-point storage problem was visible to Nadia before the fire. Neither model is being recommended here — the point is that this layer, not the price, is where the money most often goes. (All names and figures fictional; VRX from this pillar's fictional-asset registry.)

Frequently asked

10 questions

What does custody actually mean here?

Who holds the private key. The network authenticates a key rather than a person, so whoever has the key controls the holding. That makes custody not an administrative detail but, in this asset class, most of the risk.

What is self-custody exposed to?

Entirely operational and entirely your own risks. A key lost through hardware failure, a forgotten passphrase, a destroyed backup, or a death without succession arrangements is a permanent loss of an asset that still exists on the ledger. A key stolen produces transfers the network honours. A wrong address is gone. There's no support line, chargeback, or regulator — because there's no counterparty.

What is custodial holding exposed to?

A counterparty, which the design was meant to eliminate. Four questions determine what you have: are client assets segregated from the firm's own; is your claim proprietary or a general unsecured claim on the company; is the firm regulated, where, and does that regime cover custody of these assets; and is anything independently audited rather than asserted. Several failures turned on exactly these points.

Isn't "not your keys, not your coins" the answer?

It's accurate but incomplete, because it implies self-custody is safe. Both models carry loss modes — they're just different ones. The honest framing is a choice between operational risk you control and counterparty risk you don't, with no third option that removes both.

What's the difference between a hot and cold wallet?

Hot means connected to the internet — convenient, exposed to remote compromise. Cold means offline, which removes remote attack and substitutes physical risks: loss, damage, theft, and succession. Custodians typically use both, with most holdings offline and a working balance hot.

Does a wallet hold my crypto?

No — it holds keys and constructs transactions. The assets are ledger entries. That distinction prevents a real error, because it explains why moving a wallet application doesn't move holdings and why the keys are the only thing that matters.

Is my exchange balance actually on the blockchain?

Usually not. Internal trades adjust a database, and nothing touches the blockchain until you withdraw — which is why an exchange can display balances it cannot honour.

Can an exchange stop me withdrawing?

Firms have halted withdrawals during stress, sometimes permanently. An ability to see a balance is not an ability to move it, and that distinction only becomes visible at the moment it matters.

Are crypto exchanges regulated like banks?

Generally not, and this matters more than most readers assume. Oversight attaches to firms rather than assets, and coverage varies enormously — whether client-asset rules apply, whether any compensation scheme exists, whether the firm is authorised in your jurisdiction or merely accessible from it. Deposit-style protections from banking generally do not extend to digital-asset custody, and a firm may be registered for one purpose while unregulated for custody.

So how should I store my keys?

This portal doesn't answer that, and the refusal is deliberate rather than unhelpful. Specific storage guidance would be advice, would age quickly as tools change, and is precisely the kind of content fraudsters imitate to harvest keys. What this article does is name the failure modes so a reader can recognise which ones they're exposed to.

References

Educational and informational only — not investment advice, a recommendation, or an offer to buy or sell any security. Investing involves risk, including the possible loss of principal. Worked examples use fictional companies and figures.