Naar hoofdinhoud
Live markt
Block #9

Security

Holding your own crypto

Self-custody means you control the private keys to your crypto, not a company. That brings full control and full responsibility: there is no forgot-password button and no support desk to reverse a mistake. Below we walk through the practical steps, from choosing a wallet to storing your recovery phrase and actually testing the backup. It covers technology and security, not investment advice.

Dani OosterhuisWritten by Redacteur payments, GroningenUpdated Checked by the editorial desk

Step 1: match the wallet type to the amount

A software wallet on your phone or laptop is free and quick to set up, but the keys live on an internet-connected device. A hardware wallet keeps keys inside a separate device that signs transactions without ever exposing them. For balances held long term, many users choose hardware for exactly that reason.

Only use wallets with a long track record and open source code, and buy hardware from the manufacturer or an official reseller. Second-hand or marketplace units can be tampered with before they reach you.

  • Small amounts, daily use: software wallet with PIN and biometrics
  • Larger long-term balances: hardware wallet from an official seller only

Step 2: record the recovery phrase properly

On setup you receive a recovery phrase, usually twelve or twenty-four words. Those words are the asset: whoever holds them can move everything. Write them on paper or stamp them into metal, in order, and store them in at least two physically separate places.

Never photograph them, never screenshot them and never store them in cloud notes or a password manager that syncs online. Never type the phrase into a website; a legitimate wallet never asks for it in normal use.

Step 3: test the backup and start small

Move a small amount first, then restore the wallet from the recovery phrase on another device or after a reset. Only once that works do you know your backup is valid. This is the most skipped step and the most common route to permanent loss.

For every transfer, verify the first and last characters of the receiving address on the device screen itself, not only in the browser. Malware that swaps clipboard addresses is a well-documented attack.

  • Test transaction before the large transfer
  • Practise recovery on a second device
  • Verify the address on the hardware screen, not the browser

Steps 4 and 5: maintenance and inheritance

Update firmware through official software and keep track of the networks and tokens you use. Periodically revoke the approvals you granted to smart contracts; stale, unlimited approvals are a common source of theft.

Consider too what happens if you are no longer around. A sealed instruction with a notary, or a split backup held by trusted people, prevents assets being lost forever without giving any single person the ability to take everything.

Frequently asked questions

What if I lose my recovery phrase?

Without the phrase and without a working device, the assets are permanently unreachable. No central party can restore access; that is the essence of self-custody.

Do I need hardware for small amounts?

Not necessarily. Many people keep a small balance in a software wallet for day-to-day use and larger holdings on hardware, much like not carrying all your savings in your wallet.

Can I keep the phrase in a password manager?

It is discouraged once the manager syncs to the cloud, because the risk shifts to that account. Offline paper or metal backups remain standard practice.

Can I send from an exchange straight to my wallet?

Yes, as long as you pick the same network as the address your wallet shows. Send a small test first; transfers to the wrong network are usually unrecoverable.

Read next

Newsletter

Bitcoin for breakfast, Brussels for lunch

One short email with what actually matters: prices, regulation and the banks that move. No hype, no noise.

  • Daily at 07:00
  • 2 minute read
  • No spam

Free. Unsubscribe in one click.