Exchange or Self-Custody? The Real Trade-off Behind 'Not Your Keys, Not Your Coins'
7 min read
7 min read
You have probably seen the warning: "not your keys, not your coins." Move your crypto off the exchange, into a wallet only you control, and it says you will finally be safe.
That advice skips half the story. In February 2025, Bybit lost about $1.4 billion in a single hack, the largest crypto theft ever recorded, straight out of what was supposed to be a secure cold wallet. And in a 2025 survey of 1,000 crypto holders, 35% said they had lost access to a wallet or account at some point, and of those, 31% never got it back. Moving your crypto off an exchange does not remove risk. It swaps one kind of risk for a completely different one, and you need to know which one you are actually taking on.
Every crypto holding is controlled by a private key, a long string of characters that proves ownership and lets you move the funds. When you buy crypto on an exchange like Indodax, Binance or Coinbase and leave it there, the exchange holds that key on your behalf. You have an entry in their database that says the coins are yours, but you never touch the key itself.
Self-custody means you hold the private key yourself, usually represented as a 12 or 24 word "seed phrase," in a hardware wallet or an app you control. No company sits between you and your coins.
Both setups fail in real ways. They just fail differently.
Keeping crypto on an exchange means trusting that company with three separate things: that it will not get hacked, that it is not lying about how much crypto it actually holds, and that it will not collapse and freeze your funds in a bankruptcy process. All three have happened, repeatedly, at scale.
Indonesia's own largest exchange was hacked in 2024. On 10 September 2024, Indodax was drained of more than $22 million across multiple blockchains in a methodical hot-wallet attack, security researchers later linked to North Korea's Lazarus Group (The Defiant, Bitget News, both retrieved 2026-08-06).
Bybit shows that even "cold storage" is not automatically safe. On 21 February 2025, attackers stole roughly $1.4 billion in ETH from a Bybit cold wallet that required multiple signers to approve any transfer. They did not break the multisig math. They tricked the human signers into approving a transaction that looked legitimate on their screens but was not, a manipulated user interface rather than a cracked key (NCC Group technical analysis, retrieved 2026-08-06). Same attacker group as Indodax.
FTX shows that "recovered" does not mean "made whole." When FTX collapsed in November 2022, customers faced an $8 billion shortfall. Distributions have since climbed toward $10 billion and many creditors are now receiving 100% to 118% of their claim. That sounds like a happy ending until you notice the catch: creditors are paid based on what their crypto was worth in dollars on the day FTX froze, in November 2022, when bitcoin traded near $16,000. Bitcoin trades near $64,500 today. Anyone who held bitcoin on FTX got their November 2022 dollar value back, roughly three years later, and missed the entire run-up in between (Bitget Academy, CryptoTimes, both retrieved 2026-08-06).
Mt. Gox shows how long "eventually" can take. Mt. Gox lost roughly 850,000 bitcoin when it collapsed in February 2014. Creditor repayments only began in 2024, and the final repayment deadline has now been pushed to 31 October 2026, twelve and a half years after the exchange went offline (Decrypt, retrieved 2026-08-06).
Take your crypto into your own wallet and the exchange-side risks disappear. A new set takes their place, and the same 2025 survey of 1,000 crypto holders puts a number on how common it is: 35% had lost access to a wallet or account, 31% of those never recovered it, and 12% lost more than $5,000 in a single incident (Oobit survey, retrieved 2026-08-06).
The leading causes were mundane, not exotic. Forgotten passwords caused 33% of lockouts, and lost two-factor authentication access caused another 20%. Only 25% of holders kept their seed phrase written on paper, and only 15% had ever actually tested that their backup worked before they needed it (Oobit, same source).
Self-custody also has a failure mode users cannot fix by being more careful: the device itself. In late July 2026, a five-year-old firmware bug in some Coldcard hardware wallets was found to generate seed phrases with far less randomness than advertised, letting attackers guess them. By early August, more than $116 million had been drained across over 5,200 addresses, in owners who had done everything "right," used a hardware wallet, wrote down their seed, and kept it offline. See our full breakdown in what to do if you made a wallet on a Coldcard.
Chainalysis and other blockchain analytics firms estimate that somewhere between 2.3 million and 3.7 million bitcoin, roughly 11% to 19% of the entire supply, is permanently inaccessible, mostly from lost keys rather than theft.
| Keeping it on an exchange | Holding it yourself | |
|---|---|---|
| Who controls the key | The exchange | You |
| What actually breaks | The company gets hacked, misrepresents its reserves, or fails | You lose access, or the device or software you trusted has a flaw |
| A real example | Bybit, Feb 2025: ~$1.4B stolen from a cold wallet despite multi-signer approval | Coldcard, 2026: a firmware bug made "random" seed phrases guessable, $116M+ stolen |
| How common | Chainalysis: ~$3.4B stolen from platforms across 2025 | Oobit survey: 35% of self-custody holders have lost wallet access at some point |
| Can you get it back | Sometimes, years later, at the dollar value frozen on the collapse date (FTX, Mt. Gox) | Rarely. 31% of those who lost access in the Oobit survey never recovered it |
Neither option is safe by default, and neither is a mistake by default either. The honest framing is that you are choosing which failure mode you are more able to prevent and survive.
An exchange concentrates risk in the platform's hands. That risk has gotten smaller in places with real rules behind it: Indonesia's OJK now requires licensed crypto platforms to keep client assets in segregated accounts, separate from the exchange's own funds, and applies bank-style capital and custody standards under the amended P2SK Law framework (Aiying License & Compliance, retrieved 2026-08-06). That reduces, but does not eliminate, the risk that a hack or a collapse leaves you unable to withdraw. It does nothing about the years-long wait that Mt. Gox and FTX customers both went through.
Self-custody removes the company from the equation entirely, but moves the entire burden of never losing a password, a seed phrase or a device onto you, with the survey data above showing how often that burden is not met.
A few practical questions to ask yourself instead of picking a side on principle:
Whichever way you hold it, start by knowing what you actually own and how it behaves. Use Explore to check an asset like Bitcoin against its volatility and worst-case drawdown before you decide how much of it belongs sitting on an exchange versus moved into your own custody.