Beginner8 min readCrypto Trading

Custody and Exchange Risk

In short

Assets on an exchange are a claim on that exchange, not assets you hold. Understanding what that means operationally — before you need to — is the difference between an inconvenience and a total loss.

Learning objectives

  • Explain the difference between custodial and self-custodial holding
  • Describe what proof of reserves does and does not demonstrate
  • Identify operational practices that reduce counterparty exposure
  • Recognise the social-engineering patterns that target crypto holders

The short answer

When you hold crypto on an exchange, the exchange holds the keys. Your balance is a number in their database — a claim on them, enforceable only to the extent that they remain solvent, operational and willing.

That is what "not your keys, not your coins" means. It is not ideology; it is a description of the legal and technical arrangement.

Two models

Custodial. The venue controls the keys. You get convenience: fast trading, no key management, account recovery if you lose your password. You take counterparty risk: if the venue fails, is hacked, freezes withdrawals or is subject to legal action, your access depends on events outside your control.

Self-custodial. You control the keys. You take custody risk: lose the keys and the assets are gone permanently, with no recovery mechanism and no one to appeal to.

Neither eliminates risk. They exchange one risk for another, and the right split depends on what you are doing with the assets.

A workable operational split

The common approach is boring, which is the point:

  • On the venue: only what you are actively trading. This is working capital, sized to the trading, not to your holdings.
  • In self-custody: longer-term holdings, on hardware you control, with the recovery phrase written on paper (or metal) and stored physically.

Consider also splitting across more than one venue if you trade meaningful size, so that a single venue's operational problem does not freeze all of your activity at once.

The mental model that helps: treat exchange balances the way you treat cash in a till rather than money in a vault.

Proof of reserves

Several venues publish proof-of-reserves attestations. It is worth being precise about what these show.

A typical attestation demonstrates control of certain addresses at a point in time. That is genuinely useful. What it usually does not include is a verified, complete picture of liabilities — what the venue owes to customers and to others.

Solvency is assets minus liabilities. An attestation covering only the asset side cannot establish it. Some publish liability commitments using cryptographic techniques that let individual customers verify their balance is included; that is meaningfully stronger, and still a snapshot rather than a continuous guarantee.

Treat proof of reserves as one input among several, not as an assurance.

Practices that reduce exposure

  • Hardware wallet for anything long-term.
  • Recovery phrase written on physical media, stored physically, never photographed and never in cloud storage, email or a password manager's notes field.
  • App-based or hardware two-factor authentication rather than SMS, which is vulnerable to SIM-swap attacks.
  • A withdrawal address allowlist where the venue supports it.
  • Test any new withdrawal route with a small amount first.
  • Keep the amount on any single venue proportionate to your actual trading activity.

The social-engineering rule

There is one rule here that has no exceptions, so it is worth stating in absolute terms:

No legitimate party ever needs your seed phrase or private key. Not support, not a wallet provider, not a regulator, not an auditor, not a recovery service.

Anyone who asks is attempting theft. This includes convincing websites, plausible support agents who contacted you first, and messages that arrive at exactly the moment you have a genuine problem — which is not a coincidence, because attackers watch public support channels.

This site will never ask for a seed phrase, a private key, an exchange password or an API trading key, and no tool here requires any of them.

Why this belongs in a trading course

Because it is a risk that no amount of being right about price will offset. You can have an excellent process, correct sizing and a good read on the market, and still lose everything through a custody failure.

It gets its own line in your risk assessment, separate from market risk, and it gets managed with the operational practices above rather than with analysis.

Risks and limitations

  • This lesson describes categories of risk; it does not assess any specific exchange
  • Self-custody transfers risk rather than removing it — key loss is permanent and irreversible

Common mistakes

  • Keeping the entire holding on a trading venue by default
  • Treating a proof-of-reserves attestation as a solvency guarantee
  • Storing recovery phrases in cloud storage, email or a photo library

Knowledge check

Not scored, not stored. Just a way to check your understanding.

Question 1 of 3

What does holding crypto on a custodial exchange actually mean?

Key takeaways

  • Custodial holding means you have a claim, not an asset
  • Proof of reserves shows assets at a point in time and typically not liabilities
  • Keep on-venue only what you are actively trading
  • No legitimate party ever needs your seed phrase or private key

Sources

  1. The crypto ecosystem: key elements and risksBank for International Settlements
  2. Investor alerts on crypto asset fraudU.S. Securities and Exchange Commission
AuthorLearn Then Trade Editorial TeamPlaceholder

Educational drafts produced for this site build. No individual author, track record or trading experience is claimed. Replace this record with a real, named author before launch.

Reviewer
Reviewer pending
Last reviewed
Not yet reviewed