Custody risk: what “not your keys” means

Custody Risk: What ‘Not Your Keys, Not Your Coins’ Actually Means

We remember the sinking feeling clearly. It was a grey November morning in London, and our group chat was pinging relentlessly. A colleague had a substantial six-figure sum locked on FTX, a platform many of us had casually recommended to friends looking for yield. As the withdrawal queue froze and the balance sheets evaporated, the abstract crypto mantra “not your keys, not your coins” transformed from a tedious, repetitive cliché into a gut-wrenching, personal financial disaster. For thousands of British retail investors, that was the precise moment the theory of custody risk became a painful reality.

The Day We Realised ‘Not Your Keys’ Wasn’t Just a Cliché

The collapse of FTX wasn’t just a blip on a chart; it was a systemic failure of trust that wiped out an estimated £7 billion in customer funds globally. Here in the UK, we watched friends and family realise that the sleek interface they trusted was nothing more than a facade. The Financial Conduct Authority (FCA) had been sounding the alarm for years, warning that crypto is largely unregulated in the UK. Yet, the speed at which a multi-billion-dollar empire turned into a black hole for creditors shocked even the most cynical among us. It proved that regulatory registration alone—FTX was once on the FCA register via a subsidiary—offers no guarantee against catastrophic mismanagement or outright fraud.

The Illusion of Safety on Centralised Platforms

We naturally gravitate toward centralised exchanges because they feel like banking apps. They offer a clean UX, customer support chatbots, and the illusion that our assets are sitting in a segregated account with our name on it. The reality is far murkier. When you deposit Bitcoin onto a platform like the now-defunct FTX, you are not depositing into a custodial safe deposit box in your name. You are transferring legal title of your coins to the exchange. What you see on the screen is an IOU, a liability on their internal database. If that company goes bust, you don’t get your Bitcoin back automatically; you become an unsecured creditor in a complex insolvency process, often queuing behind lawyers and institutional lenders.

When Terms of Service Override Your Ownership

We rarely read the fine print, but the devil of custody risk lives in the Terms of Service. Most centralised platforms explicitly state that they can freeze your account, halt withdrawals, or commingle your assets with those of other users. In the UK, while the FCA mandates that firms must be registered for anti-money laundering purposes, it does not mean your capital is protected under the Financial Services Compensation Scheme (FSCS). If the exchange rehypothecates your coins—lending them out to risky trading firms to generate yield—and those loans go sour, your “ownership” is legally subordinated to the platform’s survival. FTX’s terms explicitly stated that digital assets belonged to users, yet in bankruptcy court, those assets were effectively treated as property of the estate.

Understanding Custody: IOUs vs. Actual Bitcoin

To truly grasp the danger, we need to distinguish between a database entry and a Unspent Transaction Output (UTXO). When you buy Bitcoin on an exchange and leave it there, the exchange’s database simply increments a number in your account column. No movement occurs on the Bitcoin blockchain. You don’t possess a UTXO; you possess a promise. In contrast, when you withdraw to a self-custodial wallet, a transaction is broadcast, miners confirm it, and a UTXO is cryptographically assigned to your private key. This is the difference between holding a gold certificate from a shaky bank and holding the physical bullion in your hand. Following the trust deficit created by FTX, major exchanges like Gemini and Kraken scrambled to restore confidence, heavily promoting their proof-of-reserves audits to show that on-chain assets covered customer liabilities.

How Exchange Balance Sheets Really Work

An exchange’s balance sheet is a black box. A customer liability is simply an internal record. A solvent, honest platform will hold customer assets 1:1 in cold storage. A fraudulent or over-leveraged one will treat those deposits as its own working capital. We saw this with FTX, where customer funds were allegedly lent to Alameda Research, a sister trading firm, to cover bad bets. When the market discovered the hole, both entities imploded simultaneously. The balance sheet wasn’t just illiquid; it was insolvent, revealing that the “1:1 backed” claim was a fabrication.

Why Proof-of-Reserves Became a Buzzword

In the aftermath, “Proof-of-Reserves” (PoR) became the industry’s favourite marketing term. Kraken, for example, has long championed its PoR audits using Merkle tree cryptography, allowing users to cryptographically verify that their specific balance was included in the total liability sum without revealing individual data. It’s a powerful tool, but we must remain critical. A PoR audit proves that a custodian possesses a certain amount of assets at a snapshot in time. It does not prove that the liabilities haven’t been understated or that the private keys aren’t being borrowed from another entity just for the audit. It’s a necessary improvement, but it is not a substitute for holding your own keys.

The Anatomy of a Crypto Wallet: Public and Private Keys

Moving into self-custody requires understanding the basic mechanics of a wallet. A crypto wallet doesn’t actually “store” your Bitcoin in the way a leather wallet stores banknotes. It stores the cryptographic keys that allow you to move coins on the blockchain. Think of your public key as your sort code and account number—you can freely share it to receive funds. Your private key, however, is the PIN that authorises the spending of those funds. If someone obtains your private key, they have total, irreversible control over your wealth. To make this secure but user-friendly, the industry adopted the 24-word seed phrase, which is essentially a human-readable representation of your master private key.

Seed Phrases: The Master Key to Your Wealth

Those 24 seemingly random words generated when you set up a hardware wallet or a non-custodial app are the single point of failure and recovery for your entire portfolio. From that seed phrase, all your private and public keys are mathematically derived. This means that if your hardware device is destroyed, you can simply buy a new one, input the 24 words, and regenerate your entire wallet. However, this also means that anyone who finds those words can do the exact same thing. We cannot stress this enough: your seed phrase must never be typed into a computer, saved in a cloud drive, or photographed on a mobile phone. It exists purely offline, etched in physical reality.

Real-World Wallet Security Risks in the UK

The threat landscape for British Bitcoin holders is evolving rapidly. It’s not just about sophisticated cyber-attacks from North Korean hacking cells; often, the danger is closer to home. Action Fraud, the UK’s national reporting centre for fraud and cybercrime, has reported a dramatic surge in crypto-related scams. The City of London Police, who lead the national response to economic crime, are constantly dealing with cases where victims have been socially engineered out of their seed phrases or targeted physically. We need to defend against both the digital spectre and the physical intruder.

Digital Threats: SIM Swaps and Dusting Attacks

One of the most prevalent digital attacks in the UK is the SIM swap. A criminal gathers your personal details, often through social media scraping or phishing, and convinces your mobile network provider to transfer your phone number to a SIM card they control. Once they have your number, they can bypass two-factor authentication (2FA) on your email and exchange accounts, often draining your funds in minutes. We always recommend using an authenticator app or a hardware security key rather than SMS-based 2FA. Dusting attacks are another subtle threat. A scammer sends a tiny, traceable amount of crypto to your wallet, hoping you won’t notice. They then track the dust through the blockchain to de-anonymise your spending patterns and potentially target you with phishing or physical threats.

Physical Threats: The £5 Wrench Attack and Home Safety

The “£5 Wrench Attack” is a dark piece of crypto humour that describes a scenario where a criminal simply beats you with a cheap wrench until you hand over your hardware wallet and PIN. While the term is a meme, the threat of physical coercion is real, especially if you publicly flaunt wealth. There have been documented cases in the UK of home invasions specifically targeting known crypto investors. We advise maintaining strict operational security (OpSec). Never boast about your stack, keep your hardware wallet hidden but accessible, and consider using a “decoy” wallet with a small amount of funds that you could plausibly surrender under duress, keeping your main stash secured behind a hidden passphrase.

Self-Custody: Finding Your Sweet Spot on the Risk Curve

Self-custody isn’t a binary switch where you go from “reckless” to “perfectly safe” overnight. It’s a spectrum of risk, and moving along it requires honest self-assessment. We don’t recommend that a complete beginner move a life-changing sum to a single-signature hot wallet on an old Android phone. Conversely, an advanced user keeping everything on a centralised exchange is unnecessarily exposed to counterparty risk. The sweet spot shifts depending on your technical skill, the amount held, and the UK tax year, which often triggers a mass movement of assets as investors realise gains and consolidate their cold storage for the long winter ahead.

Hot Wallets, Cold Storage, and Multi-Sig: A Comparison

We view the custody spectrum in three broad categories. A hot wallet (connected to the internet) is like a current account: convenient for daily spending but disastrous for holding savings. Cold storage (a hardware wallet generating keys offline) is your savings account, safe from remote hackers but susceptible to physical theft or loss. Multi-signature (multi-sig) setups distribute trust, requiring, for example, 2 out of 3 keys to move funds. You might hold one key, a trusted family member holds another, and a solicitor holds a third. This eliminates the single-point-of-failure of the seed phrase but introduces complexity. We often use a multi-sig setup for business holdings while keeping personal savings in a geographically distributed cold storage setup.

Inheritance Planning for Bitcoin: Why It’s Not Optional

One of the most overlooked aspects of “being your own bank” is death. If you pass away without a clear inheritance plan, your private keys die with you, and your family’s wealth is permanently locked in the blockchain. In the UK, inheritance tax applies to crypto assets, so your estate must be able to access them. We have worked with solicitors to design a system where sealed, tamper-evident envelopes containing partial seed phrases or hardware wallet locations are held by executors, combined with a legally binding letter of wishes explaining how to reconstruct the wallet. It’s a morbid but necessary layer of the custody journey.

How We Manage Our Own Keys (And Sleep Soundly)

Our team’s methodology is paranoid by design, refined through years of watching others lose everything. We do not rely on a single piece of paper hidden in a sock drawer. We assume that fire, flood, or theft is a constant possibility, especially considering the damp British climate and the risk of flooding in certain counties. Our process is built around redundancy, encryption, and physical durability, ensuring that even if our primary location is compromised, we can recover our sovereignty without panic.

Our Redundancy Checklist for Peace of Mind

We don’t trust luck; we trust a checklist. Here is the exact protocol we follow internally to mitigate custody risk:

  • Steel Backup: We stamp seed phrases onto high-grade stainless steel plates. Unlike paper, these plates survive house fires (temperatures up to 1,400°C) and flooding, which are realistic threats in UK homes.
  • Geographic Distribution: We never store the complete seed phrase in one location. We often split the 24 words using Shamir’s Secret Sharing or keep a multi-sig signer in a secure deposit box in a different city from our home office.
  • Passphrase Implementation: We attach a strong, memorised “25th word” passphrase to our seeds. Even if a steel plate is unearthed by a builder, the wallet remains empty without the passphrase, giving us time to sweep funds to a new wallet.
  • Test Transactions: Before sending a large amount to a fresh cold storage address, we always send a minimal test transaction and verify receipt, then reset the hardware wallet and restore it from the seed phrase to prove we can recover it before the final deposit.

Taking custody of your Bitcoin is a profound responsibility that shifts the burden of security from a corporate entity to yourself. Yet, it is the only path to true financial sovereignty—a state where no terms of service or corrupt CEO can unilaterally confiscate your life savings. The technical barrier has never been lower, and the tools available today are remarkably intuitive. We urge you not to be intimidated. Start small today with a modest test transaction to a personal wallet. Once you feel the tangible reality of controlling a UTXO that only you can move, you will understand that the effort of self-custody is the price of liberty.

Frequently Asked Questions

Is my crypto protected by the FSCS if a UK exchange fails?

No. The Financial Conduct Authority (FCA) regulates crypto firms primarily for anti-money laundering purposes, but crypto assets are not covered by the Financial Services Compensation Scheme (FSCS). If a UK-registered exchange goes bankrupt, you are an unsecured creditor and may only recover a fraction of your funds after the insolvency process concludes.

What should I do if I fall victim to a crypto scam in the UK?

You must act immediately. Report the incident to Action Fraud, the UK’s national reporting centre, either online or by calling 0300 123 2040. If you are in immediate danger or have suffered a physical theft, contact your local police force. The City of London Police often takes the lead on complex, high-value crypto investigations, but swift action is critical to freezing any assets on-chain.

Can I just memorise my 24-word seed phrase instead of writing it down?

We strongly advise against relying solely on memory. Human memory is fallible, especially under stress, illness, or after an accident. A sudden head injury or neurological event could permanently lock you out of your wealth. You should always have a physical, durable backup like a steel plate, combined with a strong passphrase stored in your memory or a separate location.

Are hardware wallets completely immune to hacks?

No device is 100% immune, but a high-quality hardware wallet is the most secure option for the average user. The device keeps your private keys isolated inside a secure chip, never exposing them to your internet-connected computer. The primary risk is not the device being hacked remotely, but you being tricked into signing a malicious smart contract or physically losing your seed phrase backup.

How do Kraken and Gemini handle custody differently from FTX?

Kraken and Gemini have historically prioritised security and regulatory compliance, offering proof-of-reserves audits that use cryptographic Merkle trees to verify customer balances without exposing private data. Unlike FTX, which allegedly commingled customer funds with a high-risk trading firm, these exchanges maintain a clearer separation of assets. However, they are still custodians, meaning you rely on their internal controls; they do not offer the same sovereignty as withdrawing to your own cold storage.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *