Crypto Custody Security: Exchange Controls, Self-Custody, and User Risks
Summary
The document surveys crypto custody security by comparing exchange-held accounts, delayed-withdrawal vaults, and self-custody wallets. It describes common safeguards such as offline storage, key-splitting methods, account monitoring, encryption, withdrawal whitelists, and hardware-based two-factor authentication. It also distinguishes exchange crime coverage and insured fiat deposits from direct insurance for cryptocurrency losses, and notes that self-custody transfers recovery responsibility to the user.
The article identifies social engineering, SIM swapping, account freezes, exchange outages, and bankruptcy proceedings as residual risks. It recommends checking platform controls and considering how to distribute holdings between custodial services and personal wallets. Its comparison includes Coinbase, Bitget, Kraken, and OSL, but much of the platform-specific material consists of claims and promotional comparisons rather than independently verified evidence. Security features, regulation, insurance, and asset counts can change, and no exchange or wallet arrangement removes all loss risk.
Key ideas
- Custodial exchange accounts offer convenience while leaving control of private keys with the platform.
- Vault-style storage can add approval steps and withdrawal delays, while self-custody makes the user responsible for recovery credentials.
- Hardware authentication and preapproved withdrawal addresses can reduce risks associated with account compromise.
- Insurance coverage may apply to some exchange or fiat losses without covering stolen cryptocurrency.
- Social engineering, SIM swapping, outages, account freezes, and insolvency remain possible risks.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.