← All field notes
CustodyField note / custody-vs-self-custody-decision-guide

Custody vs. Self-Custody: A Decision Guide

‘Not your keys’ identifies one risk. It does not complete the decision. The better question is who can act, who can recover, and which failure you are equipped to survive.

Crypto custody determines who can authorize a transfer and what happens when access, infrastructure, or an institution fails. Self-custody puts key control with the holder. Third-party custody puts control or safeguarding obligations with an intermediary. Hybrid arrangements distribute authority across people, devices, contracts, and service providers.

None is automatically safest. Each protects against some failures by accepting exposure to others.

The five questions behind custody

1. Who can move the asset?

In basic self-custody, control follows possession of the private key or signing capability. In an exchange or custodial account, the user generally instructs an intermediary, which controls the keys and decides whether a withdrawal is processed.

Multisignature and multiparty-computation systems can divide authority. A transaction may require several keys or coordinated signing shares. This reduces dependence on one secret, but adds policy, software, coordination, and recovery complexity.

2. Who can stop a transfer?

Some tokens contain issuer-controlled freeze or blacklist functions. Some custodians enforce withdrawal holds, approval policies, or legal orders. Some smart accounts can impose spending limits or recovery delays.

“Self-custody” describes control of the account key. It does not guarantee that an issuer, contract administrator, network participant, or application has no power over the asset.

3. What happens when credentials are lost?

Third-party accounts may offer identity-based recovery. That convenience creates an authentication surface attackers may exploit.

Basic self-custody may offer no recovery beyond a seed phrase or backup. More sophisticated arrangements can add guardians, time locks, multiple devices, or institutional recovery processes. Every recovery path is also a potential attack path.

4. What happens when a person or company cannot act?

Custody design should account for death, incapacity, employee departure, device loss, business continuity, and organizational shutdown—not just theft.

The SEC’s December 2025 broker-dealer custody statement emphasizes advance procedures for blockchain malfunctions, attacks, forks, airdrops, legal orders, and the custodian’s own failure. Individual holders do not need a broker-dealer manual, but they need the same category of thinking: foreseeable failure and a tested response.

5. What evidence exists that safeguards work?

For a third party, inspect legal entity, jurisdiction, registrations where applicable, segregation terms, insurance limitations, security disclosures, incident history, audit evidence, withdrawal controls, and insolvency treatment.

For self-custody, evidence is operational: verified device sourcing, secure backups, tested restoration, protected signing, transaction review, address verification, succession planning, and a response plan.

A practical decision matrix

Self-custody may fit when

  • The holder understands keys, addresses, networks, and transaction finality.
  • Backups and recovery have been tested without exposing secrets.
  • The value and use case justify the operating burden.
  • No required transaction depends on an institution holding or reporting the asset.
  • Succession or business-continuity plans exist.

Third-party custody may fit when

  • Regulated or contractual custody is required.
  • A team needs approvals, reporting, policy enforcement, or role separation.
  • Identity-based recovery is more important than direct key control.
  • The custodian’s legal and operational protections are stronger than the holder can create.
  • The holder has evaluated insolvency, access, transfer, and jurisdiction risk.

A hybrid may fit when

  • No single person or provider should control movement.
  • The holder needs policy controls without giving one intermediary unilateral authority.
  • Recovery must survive loss of one device, person, or service.
  • The team can maintain the added technical and procedural complexity.

Match the model to the use

Do not make one custody decision for every asset and purpose. A small transaction balance, long-term reserve, organization treasury, trading account, and tokenized security may justify different controls.

A useful architecture can separate:

  • Spending: limited value, frequent access, narrower controls
  • Operations: team approvals, policy limits, documented recovery
  • Reserve: infrequent movement, stronger isolation, succession readiness
  • Institutional obligations: custody and reporting matched to legal requirements

The preflight

Before moving meaningful value, write down:

  1. Who can sign or request a transfer?
  2. Who can freeze, reverse, or block it?
  3. Which network and contract hold the asset?
  4. How is recovery triggered and verified?
  5. What happens if a device, person, custodian, or issuer disappears?
  6. Has restoration been tested with a safe process?
  7. Does another person know how to execute the continuity plan?

If those answers exist only in one person’s memory, the custody system is incomplete.

Sources and scope

This guide applies failure-planning themes from current SEC crypto-custody statements and fraud warnings from the CFTC. It does not evaluate a specific custodian or wallet. This is general education, not financial, investment, legal, tax, or security advice.

Evidence ledger

Sources used in this field note

  1. Statement on the Custody of Crypto Asset Securities by Broker-DealersU.S. Securities and Exchange Commission ↗
  2. Out of the Gray Zone: Custody of Crypto Assets with State Trust CompaniesU.S. Securities and Exchange Commission ↗
  3. Digital Asset FraudsCommodity Futures Trading Commission ↗
Scope note

This material is educational and general. It is not financial, investment, legal, or tax advice.