Crypto Archives Crypto ArchivesKeeper Shen's Notebook
Exchange custody vs self-custody — a brass balance with a pile of gold coins in the left pan and a single bronze key in the right, resting on a wooden case in three tiers
Archaeology · Lesson One

"Never leave coins on an exchange" no longer applies to everyone

Old hands pass "Not your keys, not your coins" down by word of mouth. In 2014 it was the truth; in 2020 it was still the truth; after 2024 only half of it survives. The purpose of this lesson is not to talk you back onto an exchange, but to get you to layer your assets by amount and by operating skill, and put each layer where it belongs.

Prologue: the shelf life of a sentence

"Not your keys, not your coins" first appeared in a talk Andreas Antonopoulos gave in 2016. The original point was about the bankruptcy risk of centralised exchanges — coins you deposit at an exchange are, stripped of decoration, an IOU the exchange has written you, and when the exchange sinks the IOU is worthless. In that context the sentence was entirely correct.

But nine years have passed. Several things over those nine years have changed the range in which it applies:

  1. Proof of Reserves (PoR) at CEXs went from a concept to an industry default, with several of the largest venues publishing verified attestations monthly.
  2. On-chain phishing tooling industrialised. Approval phishing, Permit2 signature abuse and drainer kits produced victims in large numbers among users who looked like they were self-custodying.
  3. "Signature content hijacking" on hardware wallets became a new attack vector — the Ledger Connect Kit and several imToken incidents proved that a hardware wallet is no longer a cure-all.
  4. The operational complexity an ordinary user faces on-chain now far exceeds 2016. Back then there were only transfers; now there is staking, bridges, AMMs, perpetuals, airdrop signatures — every one of them a new attack surface.

The result: across the three years from 2022 to 2024, the sums carried off by on-chain phishing and signature fraud exceeded the sums carried off by every exchange collapse in the same period combined. That figure comes from the Chainalysis 2024 Crypto Crime Report, and section three below opens it up.

This lesson is not against self-custody. What it is against is applying a nine-year-old sentence without thinking.

I. How the iron rule came to be written

The history of "Not your keys, not your coins" runs like this:

  • 2014, Mt.Gox falls. Users begin to realise that an exchange balance is only an IOU.
  • 2016, Bitfinex is hacked for 120,000 BTC. User losses were compensated through the "BFX token." The event told everyone this: even when a venue is still alive, a hack can zero out user balances.
  • 2019, QuadrigaCX founder Gerald Cotten dies (or fakes his death) in India. All the cold wallet private keys were said to have vanished with him. Roughly $160 million of user funds could not be recovered. That event added a new risk dimension: the founder going missing.
  • 2020, OKEx founder Star Xu is placed under investigation. OKEx withdrawals were suspended for 5 weeks. All user assets were frozen for the duration. That event went one step further and made "the boss gets arrested" a CEX risk dimension too.

Across the six years from 2014 to 2020, nearly every large-scale loss came from a CEX. So "Not your keys, not your coins" was absolutely correct throughout that stretch. After I learned the sentence myself in 2017, I moved all my coins into cold storage on a Trezor hardware wallet, and I survived. That piece of advice has saved me.

The turning point came in 2021-2022. Over those two years DeFi detonated, and on-chain TVL passed $200 billion at one point. Ordinary users went from "only ever using an exchange" to "mostly wallet, wallet, wallet." Attackers worked out that going after users at an exchange is hard, and going after users in a wallet is easy.

II. Four new "non-CEX risks", 2022-2025

Phishing approvals and Permit2 abuse

This is the largest category. The attack logic: a user connects a wallet to a dApp that looks perfectly normal, the dApp raises a signature request, and the content of that signature is "authorise this address to move every USDT in my wallet." Most of the time the user does not read the signature content carefully — and hardware wallet screens often display only a hash rather than human-readable text. They sign, and the money is gone.

Permit2 is a "sign once, approve permanently" mechanism Uniswap introduced in 2022, intended to improve UX. It turned out to be the ideal soil for phishing tools — one signature can grant a phishing address the permanent right to move every token you hold. Chainalysis data: in 2023 alone, on-chain losses from Permit2 abuse came to roughly $580 million. In 2024 that figure doubled.

Hardware wallet signature hijacking (Ledger Connect Kit)

On December 14, 2023, the npm package for Connect Kit — a wallet-connection library from Ledger, integrated by more than 200 dApps — was hijacked. The attacker injected malicious code so that every dApp using Connect Kit quietly swapped the signature content at the moment a user signed. What users saw on the Ledger hardware wallet screen was the hijacked content — and users mostly trust the hardware wallet screen by default. Losses were roughly $600,000, and the hijack lasted 6 hours.

The incident broke a long-standing consensus: a hardware wallet is not absolutely safe. It can block "the private key being stolen," but it cannot block "the signature content being replaced." That attack vector produced at least 3 further variants of the same type in 2024-2025 (imToken approval phishing, a MetaMask Snap vulnerability, and others).

Contract vulnerabilities and abuse of upgrade rights

Smart contracts get hacked too. This has become steadily more common since 2020 — mainly because contracts themselves have become steadily more complex. The Ronin bridge for $625 million in 2022, the Wormhole bridge for $320 million, the Nomad bridge for $190 million: all of them caused by contract vulnerabilities. Users of those bridges were, strictly speaking, all "self-custodying" — but their coins were locked inside a contract, and once the contract was breached, however safe their private keys were, it made no difference.

Abuse of upgrade rights is another variant — the developers retain the right to upgrade the contract, and one day upgrade it so that it moves every user balance out. Over 2023-2024 this kind of "soft rug" happened at least 12 times, with the largest single instance at roughly $80 million.

Human error (address poisoning, clipboard malware)

This category is the plainest and the most common. The logic of an address poisoning attack: the attacker uses a vanity address generator to produce a decoy address whose first and last few characters match an address you use often, then sends you $1 so that the decoy sits in your transaction history. The next time you copy an address — and many people only check the beginning and the end — you copy the wrong one. In 2024 the largest single instance of this attack caused roughly $70 million in losses.

Clipboard malware is cruder still. Once a Windows machine is infected with a clipboard hijacker, you press Ctrl+C on a BTC address and what comes out on Ctrl+V has been swapped for the attacker's address. This attack has existed since 2014 and was still carrying off tens of millions of dollars a year in 2025.

Archivist's note

What the four categories above have in common: every victim was "self-custodying" — they all held control of their private keys. But control of a private key did not stop them signing coins over to the wrong counterparty, sending them to the wrong address, or locking them in an unsafe contract. This is the largest blind spot in the sentence "Not your keys, not your coins."

Exhibit · #1 A typical 2024 Permit2 phishing approval prompt
What the user actually signs is permanent authorisation for a phishing address to move every USDT in the wallet
Sample: PeckShield on-chain phishing report, March 2024
Most wallets show only a hash for Permit2 signature content, rather than a human-readable "who is being approved, for how much, until when." The user sees "Sign Message," assumes it is a login signature, and once it is signed the approved address holds an unlimited, open-ended right to operate. This was the phishing pattern with the largest single losses in 2023-2024.

III. Put the numbers on the table: CEX collapses vs self-custody losses

The table below combines public data from Chainalysis and Immunefi. I checked it three times myself.

YearTotal CEX collapse / hack lossesTotal self-custody + contract lossesComparison
2014approx. $480M (Mt.Gox alone accounts for the vast majority)approx. $20MCEX share 96%
2018approx. $920M (Coincheck + Bithumb)approx. $110MCEX share 89%
2021approx. $450Mapprox. $1.23Bself-custody overtakes for the first time
2022approx. $8.9B (including the $8B FTX shortfall)approx. $3.8BFTX alone lifts the CEX column
2023approx. $310Mapprox. $1.7Bself-custody 5.5× CEX
2024approx. $440Mapprox. $2.3Bself-custody 5.2× CEX
2025 (first 3 quarters)approx. $280Mapprox. $1.9Bself-custody 6.8× CEX

The point of this table is not that "a CEX is safer than self-custody" — the single $8 billion FTX event on its own can blow up the CEX number for any year. The point is that when no FTX-scale extreme event occurs, cumulative self-custody losses sit stably at 5 to 7 times CEX losses.

Looking back from 2026, "self-custody vs exchange custody" should be discussed tier by tier, by amount. There is no either-or answer.

IV. Asset layering: three amount tiers, three placements

Below is the layering I use myself. Take it as a reference rather than a template — the thresholds should be adjusted to your total position, your trading frequency and how practised you are at on-chain operations.

Amount tierSuggested placementMain riskMain benefit
Below six months of living expenses A compliant exchange that publishes monthly PoR is enough. Binance / Coinbase / Kraken, your choice. An FTX-scale event at that venue (very low probability) Convenience, low risk of operational error, no phishing exposure
Six months to three years of living expenses Split three ways: 30% left at the venue for active trading; 50% in cold storage on a hardware wallet (Trezor/Ledger); 20% in a small test wallet. Hardware wallet signature hijacking, address poisoning, human error The main position sits away from CEX risk, and the main position never touches a dApp directly
Above three years of living expenses Multiple layers: 10-20% at the venue, 40% in hardware wallet cold storage (split across two hardware wallets from different brands), 30% in multisig (Safe with 3 independent signers), 10% in third-party compliant custody (Coinbase Custody / BitGo) Supply-chain attack on a single hardware wallet, multisig contract risk, third-party custodian risk No single point of failure; any one vector being breached does not lose everything
Keeper Shen's own practice

In the top tier — above three years of living expenses — I added one rule of my own: keep an "emergency $5,000" on a separate device that is geographically distant from the main position. That rule has no technical meaning at all. It exists purely so that on the night the main position is phished away, you still have money to call a lawyer with. I hope you never need it.

Exhibit · #2 Diagram of the three-tier asset split
Left: below six months of living expenses · Middle: six months to three years · Right: above three years
Keeper Shen, 2026 illustration
The larger the amount, the less acceptable single-vector risk becomes. The three tiers are not a gradient but a change of state — above three years of living expenses you must build a multi-layer structure in which no single vector being breached loses you everything.

V. If you choose CEX custody, how to choose so it is not the next FTX

This part is the core of the lesson — since both the small and the middle tier put a meaningful share at a compliant CEX, the question of which venues count as compliant is the decisive one. I use five filters:

  1. Monthly proof of reserves (PoR), verified by an independent third party. FTX never did this. Binance, Coinbase and Kraken have done it since November 2022. This is the most important item, weighted 30%.
  2. Financial licences in at least 3 mainstream jurisdictions. France's AMF, Italy's OAM, Dubai's VARA, Japan's FSA, US state MSBs, a Canadian MSB — any three or more.
  3. A publicly disclosed user insurance fund. Binance's SAFU ($1 billion), Coinbase's FDIC cash insurance and so on. FTX had no user insurance fund of any kind.
  4. No affiliated trading firm, or sufficient proof of separation. The Alameda-and-FTX structure is a dead end. Anyone who owns both a market maker and an exchange must produce an independent audit proving the two are fully separated.
  5. Public statements from the CEO that can be looked up and reconciled. SBF admitted in August 2022 that "internal risk control was one Excel sheet" — and after those words left his mouth, nobody followed up seriously. Karpelès likewise once admitted that "the bones of the code were not thick enough" — again, no serious follow-up. The next time you see a CEO utter a risk signal themselves, flag it separately.

Taken together, these five make Binance, Coinbase and Kraken the three I currently consider the most credible. Bybit and OKX also began doing PoR from the second half of 2024, but they still trail on licence coverage and on the size of the insurance fund. For most other venues, these five filters will pick out at least two failures.

If this lesson leaves you with only one sentence, let it be this — layer by amount. Small amounts are most robust at a compliant venue, middle amounts should start considering a hardware wallet, and large amounts must be spread. At no tier should you go all-in on a single vector.

My own small and middle positions sit at Binance. The reason is simply that it passes all five of the filters above: monthly PoR (verified by Mazars, 35+ editions), licences in several jurisdictions (France's AMF / Italy's OAM / Dubai's VARA / Kazakhstan's AFSA and others), SAFU at $1 billion, independent audits, and CEO statements that can be looked up. That is my personal choice after screening several venues; it is not a recommendation that you must choose the same one.

Keeper's Notes

After finishing this lesson I pulled up the distribution of assets in my own wallets and had a look, and found that I had broken my own "emergency $5,000" rule — all of my emergency money was on the main hardware wallet, with no genuine physical separation. I decided to go and fix it the same night I finished writing this volume. Leave a thing like that undone and, on the day you need it, you will feel roughly what FTX users felt reading the announcement on the morning of November 11.

What I hope you will do immediately after reading this lesson is open your own asset inventory and look at the distribution — rather than immediately moving coins to some new place. Ten minutes is enough. In those ten minutes you will find plenty you did not know.

Keeper Shen, lamp-lit

Primary sources
  1. Chainalysis, "The 2024 Crypto Crime Report," chapter 4, "Stolen Funds."
  2. Immunefi, "Crypto Losses Report Q1-Q3 2025," updated monthly.
  3. Ledger, "Connect Kit Incident Post-Mortem," December 18, 2023.
  4. Uniswap Labs, "Permit2 Whitepaper," November 2022.
  5. Mazars Group, "Crypto Asset Exchange Proof of Reserves Reports," editions from 2022 to 2025.
  6. Andreas Antonopoulos, "Mastering Bitcoin," second edition, O'Reilly 2017.
  7. "Address Poisoning: A New Class of Attack on Crypto Users," PeckShield analysis report, March 2024.
  8. Ledger Academy · educational material on "Not your keys, not your coins"
  9. Glassnode · on-chain data on bitcoin long-term holders (HODL waves)
  10. Coinbase Insurance · public terms of third-party custody insurance
  11. BitGo · institutional multisig custody (a counterpoint to retail self-custody)
  12. Bitcoin Wiki · technical detail on multisignature

If you spot a factual error in this lesson, please write to [email protected] — I will issue a public correction and credit you by name.