Cointime

Download App
iOS & Android

Crypto Custody — Becoming Your Own Bank

Validated Project

In the last few years, cryptocurrencies have gone from being a niche technology to something far more mainstream. Big brands have experimented with NFTs, Web3 Play2Earn gaming has become more well-known and it’s become easier than ever to add coins and tokens to your savings portfolio thanks to centralized exchanges such as Binance and Coinbase. Even mainstream “TradFi” companies such as Revolut offer the option to buy cryptocurrencies. However, that convenience comes at a price.

Centralized Exchanges and Custodial Wallets

When you buy coins or tokens on a centralized exchange, those tokens are held in the exchange’s wallet. This means you have to trust that the exchange:

  • has the coins they claim they do,
  • will allow you to withdraw those coins when you want them,
  • is storing your holdings securely and won’t get hacked.

Those risks aren’t just limited to CeFi (Centralized Finance) companies, either. If you’re dealing with DeFi (Decentralized Finance) smart contracts that require you to lock up funds for any length of time, there’s the risk of the contract being hacked by a malicious third party.

One look at Web3IsGoingGreat, our own blog on The Role of Cover Protocols in Mitigating Risks, is enough to show that custodial risk is too great to ignore. The recent high-profile collapses of platforms and exchanges such as Celsius and FTX highlight how important it is for long-term investors to take ownership of their crypto.

Self-Custody for Your Crypto

While it makes sense for day traders to keep their cryptocurrencies on the exchanges they use for trading, if you plan to hold a currency for a long time, it’s worth considering self-custody options. The cryptocurrency community has a saying — Not Your Keys, Not Your Crypto (NYKNYC).

Cryptocurrencies use a combination of public keys (shared) and private keys (only the owner of the currency knows). If you are not in possession of the private keys for the wallet in which the coins/tokens are stored, then those assets are not yours — at least in the sense that you cannot access them.

Self-custody begins with withdrawing the assets from the exchange and holding them in a wallet for which you have the the keys. Those wallets can be:

Hot wallets are incredibly convenient, but that convenience brings some security risks. Metamask is a browser extension that makes it easy to use DApps and Web3 services and manage multiple tokens and assets all in one place. Electrum is a desktop application that gives you instant access to your Bitcoin. Some other hot wallets run on your mobile phone. What all of these things have in common is that all you need is access to the device and your wallet password, and you can transact using that wallet.

If you’re running a hot wallet and the device gets hacked, and the attacker gains access to the wallet’s keys, you could lose all funds in the wallet. To combat that risk, many people use cold wallets for long-term storage.

Cold wallets are devices that store the keys offline. It’s possible to configure Electrum to work in this way, but most cold wallets are physical devices that look a lot like USB memory sticks. For example, Ledger and Trezor offer apps to view and manage your wallet. However, you can’t send cryptocurrencies from the wallet without “signing” the transaction using the physical device. This adds an extra layer of security at the cost of convenience. If you’re away from home and want to sell some Ethereum or send some Chainlink to a friend, you can’t do so if you aren’t carrying your hardware wallet.

It’s possible to purchase a Ledger Nano S for around $100. If your cryptocurrency holdings are worth more than a couple of hundred US dollars and you plan on keeping them for a long time, it’s well worth making that purchase for peace of mind.

Securing Your Cryptocurrency Wallets

Most modern cryptocurrency wallets use a recovery phrase (typically 12–24 words) rather than a collection of random letters and numbers. If you lose your wallet, you can recover it by entering that phrase into any hardware or software wallet that supports the same standard.

In addition to the recovery phrase, some wallets may use an “extra word” for added security and a password to unlock the wallet. When you go through the wallet creation process, note these details. If you forget them, there’s a risk you could lose access to the wallet.

Always keep in mind that anyone who knows the recovery phrase can create a copy of your wallet. Follow these golden rules when storing your coins and transacting with cryptocurrencies:

  1. Keep the wallet and recovery details separate, ideally out of public view.
  2. Do not re-use passwords for exchanges or wallets on other services.
  3. Never store your keys/recovery phrase online or on a computer connected to the internet.
  4. Never enter your wallet’s recovery details into a website, or share them with a third party, even if that third party claims to be from “Trezor Support”.
  5. If you have the luxury of doing so, keep a spare computer that isn’t used for day-to-day browsing to manage your cryptocurrencies.
  6. Do not install untrusted applications on your computer.
  7. Do not connect your Metamask wallet to a website or DApp unless you can trust it.
  8. When sending cryptocurrencies from your wallet, always verify the address you’re sending it to by checking several characters at the beginning and end of the address. Don’t just trust the address you paste from your clipboard.
  9. If your cryptocurrency holdings are large enough to make it worthwhile, test your wallet recovery procedure by attempting to recover your hardware wallet to a backup wallet while the first wallet is still working.
  10. Never reuse addresses. Most modern wallets automatically generate new addresses for each deposit request. Take advantage of this feature.

Some hardware wallet manufacturers offer steel plates to stamp your recovery phrase onto. The idea of these plates is to create a backup of your keys that will last a lifetime. Ink fades, and notepads can be mistakenly discarded. They’re also likely to be destroyed if you experience a fire, flood, or another disaster. Steel plates will survive such events, so if the worst happens, you’d still be able to recover your cryptocurrency and get back on your feet.

If you take a systematic approach to protect your self-custodied cryptocurrencies and invest in protection against custodial risk, you’ll be prepared for any eventuality.

Comments

All Comments

Recommended for you

  • Measuring Exchange Quality And ‘Fake Volume’

    A framework to assess the quality of centralized exchanges (CEX's)

  • A whale sold 224 WBTC worth $14.4 million in the past three hours

    According to on-chain analyst @ai_9684xtpa, address 0x486...1505e sold 224 WBTC tokens worth $14.4 million through Cowswap in the past three hours, making a profit of $830,000 (selling at an average price of $64,203). The seller had bought 371 WBTC tokens at an average price of $60,504 between November 2023 and April 2024, and still holds 280 WBTC tokens.

  • CryptoQuant CEO: BTC needs to remain above $80,000 for miners to remain profitable after halving

    Bitcoin mining revenue significantly decreased in May due to the impact of the fourth Bitcoin halving event. On May 1st, the total revenue from block rewards and transaction fees reached a new low of only $26.3 million.CryptoQuant CEO Ki Young Ju calculated that, based on current conditions, Bitcoin needs to stay above $80,000 for miners to remain profitable after the halving. However, most miners have taken proactive measures to upgrade their mining equipment to lower long-term operating costs and remain competitive.

  • BTC returns to above 65,000 USDT, up 2.08% in 24 hours

    OKX market shows that BTC has returned to above 65000 USDT, now reporting 65102 USDT, with a 24-hour increase of 2.08%.

  • Hundre Finance attackers have withdrawn 162.2 ETH worth of crypto assets from Curve

    According to PeckShield monitoring, the attacker of Hundre Finance withdrew 784,000 3Crv from Curve and exchanged it for 273 ETH. In addition, they also exchanged 305.6 WOO, 39 PAXG, 200,000 FRAX, and 100,000 DAI, totaling 162.2 ETH. The attacker then bridged 1,034 ETH (2.17 million USD), 842.8K DAI, 1.11 million USDT, 1.27 million USDC, and 457.3 FRAX from Optimism to Ethereum. They also exchanged a total of 480,000 USDC for 142.6 WETH, 306 WOO, and 39 PAXG. They also exchanged 1.11 million USDT for 500.3 thousand USD worth of DAI and 613.8 thousand USD worth of FRAX. Additionally, on April 15, 2023, approximately 786,000 USD worth of USDC was added to Curve3Pool.

  • LayerZero co-founder: "Self-reporting of witch activities" is not aimed at individuals, but at industrial witch studios

    Bryan Pellegrino, co-founder and CEO of LayerZero, stated on social media that the "Self-Report Sybil Activity" is not targeting individual users, but rather large industrial witch farms (studios).Earlier, LayerZero Labs launched the "Self-Report Sybil Activity" plan, which allows witch addresses to self-report related addresses on a designated page and receive an expected allocation of 15%, without answering any questions. The deadline is May 17th, 19:59:59.

  • Argentina’s House of Representatives Passes Bill to Regularize Cryptocurrency Taxation

    The Argentine Chamber of Deputies has passed a cryptocurrency tax normalization bill aimed at advancing a series of important government reforms. The bill introduces the possibility of regularizing previously undeclared cryptocurrency assets, up to a maximum of $100,000, without paying government collection fees. However, if the value of cryptocurrency assets exceeds this limit, the government will apply preferential tax rates based on the taxpayer's declaration date.

  • GNUS on Fantom was attacked, with a loss of about $1.27 million

    According to Beosin's monitoring, GNUS on Fantom was attacked, resulting in a loss of approximately $1.27 million. GNUS stated on the X platform that due to recent vulnerabilities, hackers were able to mint fake GNUS tokens on Fantom, transfer them to Ethereum and Polygon through the Axelar Bridge, and sell them to existing liquidity pools. We will take a snapshot of the blocks before the exploit. To ensure fairness, please do not purchase GNUS tokens after the exploit, as we will issue new tokens.

  • Pandu Financial Group received the first round of strategic equity investment of tens of millions of Hong Kong dollars, led by Longling Capital

    Pando Financial Group announced it has received tens of millions of Hong Kong dollars in strategic equity investment led by Longling Investment. Pando Financial Group stated that it plans to use the newly injected funds for key growth areas, including market expansion, innovative product development, key talent recruitment, and technology upgrades, aiming to accelerate the layout of opportunities in the era of virtual assets through these strategic initiatives. Currently, the group's asset management scale has reached $500 million. Pando Asset, a subsidiary of Pando Financial Group, established its headquarters in Zurich in 2022 and issued the Pando 6 spot virtual asset fund (Bitcoin/Ethereum spot ETPs) on the Swiss Exchange. Another subsidiary of Pando Financial Group, Pando Limited, obtained licenses from the Securities and Futures Commission in Hong Kong, including Type 1 (securities trading), Type 4 (advising on securities), and Type 9 (asset management), as well as public fund qualifications, and was approved to manage investment portfolios with more than 10% invested in virtual assets and issued several excellent performance actively managed ETF products.

  • Hong Kong Monetary Authority launches industry consultation on “renaming virtual banks as licensed digital banks”

    Hong Kong virtual banks released their annual reports for 2023 last week. The eight virtual banks collectively lost about 2.99 billion yuan last year, a decrease of about 12% compared to the total loss of about 3.4 billion yuan in 2022. In response to the occasional feeling of "unreality" brought about by the term "virtual" in recent years, the Hong Kong Monetary Authority has initiated a consultation on renaming with the eight virtual banks, the Hong Kong Bankers Association, the Hong Kong Restricted Licensed Banks and Deposit-taking Companies Association, with the aim of renaming virtual banks as licensed digital banks, for a period of one month. It is reported that in the Asian region, similar banks have different names in different places. South Korea and Singapore issue licenses under the name of "digital bank", with Singapore further dividing them into digital full banks (DFB) and digital wholesale banks (DWB).