Cointime

Download App
iOS & Android

Custodial vs Non-custodial Wallets: A Life-Saving Difference

If there was only one lesson to learn from the downfall of crypto exchange FTX, it would be to never keep more crypto on exchange wallets than necessary. For the sake of buying and trading, one can hardly navigate around a CEX, but crypto savings should never be stored in exchange wallets.

Although one can easily get another impression due to easy log-in and handling those big exchanges offer, the funds kept in an exchange wallet are not truly yours as the exchange has custody over the coins. They can make a business decision to block your account, freeze your funds or deny transactions and there is nothing you can do about it.

Among crypto enthusiasts, there is a famous moniker that goes by “Not your keys, not your coin,” but it sounds almost too peaceful as we witness the dire events around Alameda Research, FTX and Binance unfold.

What has happened?

In the 45th calendar week of the year 2022, a news article and a set of tweets set events in motion that can only be described as earthquakes that are shaking the entire crypto world. Let’s go through a quick chronology to get a better grasp of the situation’s gravity:

The itchy detail: In the due diligence regarding the supposed acquisition of FTX by Binance, news came to light that FTX allegedly used customer deposits to improve the balance sheet of Alemeda Research and to cover up a series of trading losses on the side of Alameda, among them a 500mn USD loan agreement with now bankrupt crypto lender Voyager Digital. So, FTC has allegedly used their customer’s funds for their sister company’s trading business. Although it is not proven (yet,) it is a proper explanation of why they had to pause withdrawals of customers’ funds.

FTT, the TFX token, is down about 90% on Nov 10th vs. Nov 5th. It’s not impossible FTX won’t be able to recover from this. Moreover, it took the crypto realm with it, with BTC and ETH each losing double-digits and a lot of private investors losing sizeable shares of their private funds, if not all of them.

Why are exchanges so unsafe to store your crypto on?

Now that we discovered that not even the big guns in the exchange business are trustworthy guardians for your crypto assets, we first should look at the difference between a custodial and a non-custodial wallet.

What does that mean: when dealing with crypto wallets, you always have one (or more) sets of keys, a private key, and a public key. Whereas the public key represents the public address of your wallet or the equivalent to your email address in your PayPal, the private key is used to sign transactions and thus, roughly equals your PayPal password or your pin in traditional banking.

In custodial wallets that exchanges like FTX, Coinbase, Binance, or Kraken are running, the exchange is holding your private key in their custody and using it to approve transactions in your name. What makes this service convenient, as you have nothing more to remember than a log-in for the exchange (and by that, not any more complicated than with every other online service), is the equivalent of granting your bank all of your passwords and pins and empowering them to send transactions on your behalf as long as you click a button. This makes it inherently dangerous, as the exchange can at any moment decide to not sign any more transactions with your private key and there is nothing you can do about it.

As this is arguably the worst case and would quickly put an exchange that performs in such a way out of business, there are much more shades of grey here: Custodial wallets can block certain transactions or specified groups of users. Remember the Canadian trucker protests in February of 2022? The Canadian Government effectively sanctioned 34 crypto wallet addresses under their Emergencies Act. Still, wallet addresses in themselves may be anonymous, but crypto exchange accounts are not (at least to government authorities), and so wallets can be tied to real persons who are on the government sanctions list. Kraken CEO Jesse Powell has confirmed they would have to comply in such a situation and is cited with the following statement: “If you’re worried about it, don’t keep your funds with any centralized/regulated custodian. We cannot protect you.”

Where to store your crypto instead?

Short answer: In a non-custodial wallet.

They provide a critical advantage to custodial wallets, as here the only custodian of your private key is you and no one else. When opening a non-custodial wallet, you are provided with a seed phrase of 12, 18 or 24 words which is used to decrypt your private key. Only with the seed phrase you can access the wallet from a different device. Popular non-custodial wallets include software solutions like Electrum Wallet for Bitcoin, Metamask for Ethereum-based tokens, or Bitpay for crypto-agnostic solutions.

The most secure version would be using a non-custodial hardware wallet, as here the private key lies encrypted on a piece of hardware that you own. You’re only able to sign transactions when the hardware device is connected to your computer, which makes it one of the most secure ways to store your crypto. Famous representatives are Ledger and Trezor.

Final Thoughts

As the disturbing events around the downfall of FTX and the freezing of customer accounts are unraveling, one always has to be crystal clear about the following facts when keeping funds in an exchange wallet:

  • You don’t have reliable access to your funds in a time of need as the exchange can always decide to halt withdrawals.
  • You can’t effectively stop them from gambling with your funds or complying with government sanctions which would leed to your funds being frozen.

In short, you don’t own the crypto you store in an exchange wallet. Period.

Comments

All Comments

Recommended for you

  • SlowMist: Beware of watering hole attacks launched by malicious attackers using WordPress plugin vulnerabilities

    SlowMist Security has issued a warning that attackers have recently been exploiting vulnerabilities in WordPress plugins to inject malicious JS code into normal websites and launch watering hole attacks. These attacks involve popping up malicious windows when users visit the site, deceiving them into executing malicious code or performing Web3 wallet signatures, thereby stealing their assets. It is recommended that sites using WordPress plugins check for vulnerabilities, update plugins in a timely manner, and avoid being attacked. When visiting any website, users should carefully identify the downloaded programs and Web3 signature content to avoid downloading malicious programs or having their assets stolen due to malicious signatures.

  • Unverified Ember Sword NFT auction contract vulnerability has caused nearly $200,000 in losses

    Certik has discovered a vulnerability in the unverified Ember Sword NFT auction contract, which has earned 60 WETH (approximately $195,000) from 159 victims who approved the contract. Certik reminds users to revoke their approval of the relevant contract on Polygon.

  • zkSync ecological lending platform xBank Finance suspected of RUG

    xBank Finance, a zkSync ecosystem lending platform, was suspected of being a RUG, and the protocol's TVL was close to zero. The project's official Twitter account has been frozen.

  • Scammers use fake USDT balances to defraud cryptocurrency users

    SlowMist has partnered with Imtoken to uncover a new cryptocurrency scam that uses offline transactions and USDT. Scammers manipulate the Ethereum RPC to falsify the USDT balance in the victim's wallet. The scammer lures the victim to change their Ethereum RPC URL to a URL controlled by them, making it appear that the victim has deposited USDT funds, but in reality, the victim is left empty-handed when attempting to trade. In addition, the scam also deceives users through small transfers to gain trust, then manipulates account balances and contract information, posing serious risks to unsuspecting users and is related to a wider range of pig slaughter scam activities.

  • Cointime April 27th News Express

    1. ETH falls below $3,100

  • HKEX: Accepts BOS HashKey, Huaxia, Harvest Bitcoin and Ethereum ETFs as eligible securities for multiple counters in the central clearing system

    On April 27th, the Hong Kong Stock Exchange issued three notices, announcing the inclusion of Bo Shi HashKey Bitcoin ETF shares and Bo Shi HashKey Ethereum ETF shares, Huaxia Bitcoin ETF shares and Huaxia Ethereum ETF shares, and Jia Shi Bitcoin Spot ETF shares and Jia Shi Ethereum Spot ETF shares as Central Clearing System multi-counterparty eligible securities. It is reported that:

  • Russia’s Central Bank and Rosfinmonitoring unveil pilot of fiat-to-crypto tracking system

    According to reports, since 2023, Russia has been trying to track cryptocurrency transactions and their sources. The Russian Central Bank and the Federal Financial Monitoring Service (Rosfinmonitoring) revealed that there is currently a system that allows private banks to track the connection between fiat-based transactions and cryptocurrency business.

  • PolkaWorld: Coretime trading on Kusama has started

    On April 27th, PolkaWorld announced that Coretime trading on Kusama has begun, marking the end of the era of parallel chains. With the approval and implementation of Kusama proposal 373, the proposal will upgrade the Kusama relay chain runtime to v1.2.0 and bring Coretime functionality. Shortly thereafter, the Kusama community approved Kusmaa proposal 375 last Friday, allowing Coretime chain to begin selling Coretime. Currently, Kusama is in the Renew Period and is selling batches of Coretime.

  • Over $155 million worth of MEME will be unlocked on May 3, accounting for 31.96% of the circulating supply

    According to Token Unlocks data, 5.31 billion MEME tokens, worth over $155 million, will be unlocked on May 3, 2024, accounting for 31.96% of the circulating supply. These tokens will be unlocked and distributed to airdrops, advisors, and investors.

  • The total open interest of BTC options is $17.83 billion, and the open interest of ETH options is $8.07 billion.

    Coinglass data shows that the nominal value of unclosed BTC option positions on the entire network is 17.83 billion US dollars, which is the lowest point since February 26; the nominal value of unclosed ETH option positions is 8.07 billion US dollars, which is the lowest point since February 25.