What you actually own on an exchange
When your Bitcoin sits on an exchange, you do not hold Bitcoin. You hold a promise from a company that says they hold Bitcoin for you. Most of the time that promise is honored. The problem is what happens the rest of the time.
The SEC's investor materials put it plainly: third-party custodians control access to the private keys, and if a custodian is hacked, shuts down, or goes bankrupt, customers may lose access to their assets. History has repeatedly demonstrated this is not theoretical.
The phrase to remember
Not your keys, not your coins. If someone else controls the keys, you own a claim, not an asset.
What a wallet actually is
A wallet does not store Bitcoin. Bitcoin lives on the network. A wallet stores the keys that prove the coins are yours and let you move them.
Those keys come from a seed phrase, usually 12 or 24 words in a specific order. Whoever has those words controls the coins. Not a password you can reset. Not a username. The words are the ownership.
| Type | What it is | Strength | Main risk |
|---|---|---|---|
| Hot wallet | App connected to the internet | Convenient for small amounts and learning | Exposed to hacks and phishing |
| Cold wallet | Offline device, usually hardware | Strong protection from online attacks | Device or backup can be lost, damaged, or stolen |
Seed phrase rules, no exceptions
These are not suggestions and every one of them exists because people lost everything learning it the hard way.
- Write it on paper or stamp it into metal. Never type it into anything.
- Never photograph it. A screenshot in your camera roll syncs to the cloud automatically.
- Never store it in email, notes apps, Google Drive, iCloud, or a password manager.
- Never enter it into a website, ever, for any reason.
- Never share it with anyone, including support staff. Anyone asking is stealing.
- Store backups in separate secure locations, protected from fire and water.
That fifth one deserves emphasis. No legitimate company will ever need your seed phrase. Not to verify you, not to fix an error, not to process a withdrawal. The request itself is the theft attempt.
How to actually do it, slowly
Buy a hardware wallet directly from the manufacturer, never from a marketplace reseller, because tampered devices are a real attack. Coldcard, Trezor, and Ledger are common options.
Then go slow, in this order:
- Inspect the packaging and follow the manufacturer's setup exactly.
- Generate the seed phrase offline, on the device.
- Write it down by hand. Check every word twice.
- Send a small test amount, something you could afford to lose.
- Verify it arrived.
- Wipe the device and restore it from your written phrase. This is the step everyone skips.
- Verify the test amount is still there. Now you know your backup works.
- Only then move meaningful value.
Step six is the whole point. An untested backup is a guess, and you find out whether the guess was right at the worst possible moment.
The tradeoff, stated honestly
Self-custody means nobody can freeze your account, block your withdrawal, or lose your coins in their bankruptcy. It also means nobody can recover your mistake. No support line, no password reset, no reversal.
That is not a reason to avoid it. It is a reason to go slow, test small, and build the process before value is on the line. Control and responsibility are the same coin.
Take action today
- Research one hardware wallet and write down its cost.
- Find the manufacturer's official store, not a marketplace listing.
- Watch the manufacturer's own setup tutorial start to finish.
- Decide where two separate backup locations would be.
- Write down the test amount you will use first.
What is next
You have stability, an asset, and control of it. Level 2 shifts to cash flow: assets that pay you while you hold them.
