Custody identifies who can authorize a transaction
A crypto wallet manages the information needed to authorize transactions; it does not store coins in the way a physical wallet stores cash. In a custodial arrangement, a service controls the signing keys or controls a system that can initiate transfers. The customer typically authenticates to the service, while the service decides how keys are generated, stored and used. In self-custody, the user controls the signing capability directly, often through software, dedicated hardware or a multi-party setup.
This distinction changes the failure model. Custody is not a simple scale from unsafe to safe. It allocates responsibility among cryptography, people, devices, organizations and legal agreements. Two products carrying the same “custodial” or “non-custodial” label can have very different recovery paths, privileged controls and external dependencies.
Custodial systems concentrate operational and counterparty risk
A custodian can provide account recovery, transaction monitoring, access controls and professionally managed key infrastructure. The customer does not have to maintain a seed phrase or understand transaction signing. Those features reduce some user-level failure modes, but they introduce reliance on the provider.
The relevant questions include whether customer balances correspond to segregated assets, who can approve withdrawals, how signing authority is distributed, what contractual rights apply, and how the service handles outages, legal process and insolvency. Marketing terms such as “cold storage” or “insured” do not answer those questions. Coverage can be limited by event type, amount, jurisdiction or exclusions, and a technical control does not create a legal guarantee.
Custodial interfaces are also account-security surfaces. Credential theft, session compromise, support-channel impersonation and malicious recovery requests can matter even when the underlying private keys never leave secured infrastructure. Internal permissions and software updates become part of the customer’s threat model.
Self-custody replaces the provider with a key-management problem
Direct control removes the need for a custodian to authorize ordinary transfers, but it does not remove intermediaries or operational risk. Wallet software, device firmware, browser extensions, remote procedure call providers and transaction-signing interfaces can all influence what the user sees and signs. A malicious approval can be validly signed and still have an unwanted result.
NIST’s key-management guidance treats cryptographic keys as assets requiring protection throughout a lifecycle that includes generation, storage, use, backup, recovery, revocation and destruction. That framework exposes an important trade-off. A single backup can be easy to operate but creates a single point of loss or theft. Multiple devices, shares or signers can improve resilience, yet they add coordination risk and may fail if the recovery procedure has never been tested.
Recovery depends on architecture. A lost device is not necessarily fatal when an independent backup or threshold-recovery path exists. Conversely, possession of a recovery phrase can be sufficient for an attacker to recreate signing authority in many common designs. The appropriate control set therefore depends on the assets, transaction frequency, likely adversaries and acceptable recovery delay.
Hybrid arrangements need their own analysis
Some systems split authority among a user device, a service and a recovery party. Others place smart-contract controls around externally owned keys or use policy engines that limit destinations and amounts. These designs can reduce a particular single point of failure, but they also create new dependencies: contract code, signer availability, governance keys and upgrade procedures.
A neutral comparison records who can sign, who can block, how recovery works, which components can change, and what evidence supports claims about segregation or protection. The answer may differ across operating balances, long-term reserves and organizational treasury workflows. Custody is best understood as a collection of threat assumptions, not as a product endorsement or a promise that one model prevents loss.
Source: BlockchainReporter.
