Bitcoin VerityOpen comparator

Level 6 · Use and security

Custody and self-custody: who actually holds the keys?

The difference between a balance held by a custodian and bitcoin controlled with your own keys, including the risks of both options.

Article
53
Reading time
11 minutes
Reviewed
8 September 2026

In a nutshell

With custodial storage, a service signs withdrawals and the user has a claim against that service. With self-custody, the user's own wallet signs. The first option delegates some responsibility to a custodian; the second removes that intermediary but makes the user fully responsible for the keys and recovery.

01

A service balance is not the same as your own UTXO

An exchange or custodial wallet can show a bitcoin balance in its internal ledger without assigning a separate blockchain output to every customer. The custodian controls the keys to pooled addresses and decides when to sign a withdrawal. The user has a contractual claim against the service, not direct cryptographic control over particular outputs.

Only a withdrawal to an address whose keys the user controls creates self-custodial ownership. The blockchain does not know an account holder's name or the service's terms; nodes see only a valid transaction and the conditions for spending its outputs later.

02

What a custodian provides

A custodian can simplify sign-in, buying, selling, account recovery and customer support. It can also pause withdrawals, request more verification, or fail technically, legally or financially. Two-factor authentication protects the account, but it does not change the fact that the service holds the final on-chain signing keys.

Risk therefore cannot be judged from an application's appearance alone. Relevant factors include the legal entity, custody model, withdrawal terms, incident history, reserve transparency and protections in the applicable jurisdiction. Neither regulation nor an audit guarantees immediate access in every circumstance.

  • a custodian reduces the user's technical workload
  • the user accepts counterparty risk and the service's rules
  • an internal balance becomes on-chain holdings only after a valid withdrawal
03

What self-custody provides

With self-custody, a device or software controlled by the user creates the signature. No exchange needs to approve an ordinary spend. This removes one counterparty, not every risk: malware, a fraudulent address, a bad backup, physical theft or an exposed seed can cause irreversible loss.

Self-custody is therefore a process, not a single product. It includes obtaining a trustworthy wallet, generating and protecting keys, verifying a receiving address, testing a small transaction, making a backup and planning recovery. As the value rises, the appropriate safeguards and number of independent checks may change.

04

One model need not cover everything

A user can keep a small spending amount in a mobile wallet, funds intended for trading with a service, and a longer-term reserve separately. This limits the consequences of one account, device or backup failing. A more complex arrangement can, however, create its own mistakes and forgotten procedures.

A sensible decision depends on value, frequency of use, the ability to store a backup safely and the consequences of loss. A slogan is no substitute for a practical test. Until a user can restore the wallet and safely send a small amount, moving substantial value into a new setup is unwise.

Level 6 · Use and security

Terms to know

Custody
An arrangement in which a service or another custodian controls keys on the user's behalf.
Self-custody
An arrangement in which the user controls the keys needed to sign a transaction.
Counterparty risk
The possibility that another party fails to honour an obligation, restricts access or fails outright.

Common misconception

If an app shows my bitcoin balance, I always have full control of the bitcoin.

A more accurate explanation

With a custodial service, the custodian controls the on-chain keys. The user can request a withdrawal, but execution depends on the service until the bitcoin reaches an address controlled by the user.

A more accurate explanation

Is self-custody automatically safer?

Not for every person or every procedure. It removes the risk of one custodian, but an unprepared user can create greater risk through a poor backup, an exposed seed or a mistaken payment. Security depends on the whole process.

53

Key takeaways

  1. 01A custodial balance is a claim against a service; self-custody is direct control of signing keys.
  2. 02Two-factor authentication protects an account but does not change who holds the on-chain keys.
  3. 03Self-custody removes a counterparty while transferring recovery responsibility to the user.
  4. 04The right model depends on the value, its use and a security procedure the user can actually perform.

A child-friendly recap

In very simple terms

At an exchange, the service holds the keys and you trust it to release the bitcoin. In your own wallet, you hold the keys and do not need its permission. You must also protect the backup and know how to restore the wallet.

Reviewed: 8 September 2026

Sources and further reading

Sources support particular facts and definitions; listing one does not mean the editors endorse every view of its author.

01
Bitcoin.org: what you need to knowBitcoin.org
bitcoin.org
02
Bitcoin.org: securing your walletBitcoin.org
bitcoin.org
03
Bitcoin Developer Guide: walletsBitcoin Developer Guide
developer.bitcoin.org

Educational material, not an investment recommendation.