A crypto wallet does not actually hold your coins. It holds the keys that let you move coins that live on a blockchain. The real question behind "which wallet should I use" is who controls those keys: a custodial wallet means a company holds them for you, while self-custody (non-custodial) means you hold them yourself. That one difference decides who can move your money, who you have to trust, and what happens if something goes wrong.
What a wallet really stores
Your coins are just entries in a blockchain's ledger, tied to an address. To spend from an address you need its private key, a secret number that signs transactions. A wallet is software or hardware that keeps that key and uses it to sign.
Three terms you will see constantly:
- Public key / address. Like an account number. You can share it to receive funds.
- Private key. Like the password and signature combined. Anyone who has it controls the funds. It is never meant to be shared.
- Seed phrase (recovery phrase). Usually 12 or 24 words that can regenerate your private keys. It is your wallet. Lose it with no backup and the funds are gone; let someone copy it and they can drain you.
Because the key is the thing of value, "where is the key, and who can reach it" is the only question that really matters.
Custodial vs self-custody
| Custodial | Self-custody | |
|---|---|---|
| Who holds the keys | A company (exchange, app) | You |
| How you log in | Email, password, 2FA | Seed phrase / device |
| If you forget your login | Reset it with support | No reset — only your seed phrase recovers it |
| Who can freeze funds | The company, or a court order on it | No one (and no one can help if you're hacked) |
| Main risk | The company fails, is hacked, or restricts you | You lose your keys or get phished |
| Good for | Beginners, active trading, fiat on/off-ramps | Holding your own assets, using DeFi |
Custodial wallets
When you buy crypto on a large exchange and leave it there, that is a custodial wallet. The company holds the private keys and credits your balance in its own database. It feels like a normal online bank: you reset a forgotten password, enable two-factor authentication, and trade instantly.
The trade-off is trust. You are relying on the company to actually hold the assets, to stay solvent, and to let you withdraw. The 2022 collapse of the exchange FTX is the standard cautionary tale: customer balances showed on screen, but the coins behind them were not there. Hence the phrase "not your keys, not your coins."
Self-custody wallets
Here you generate the keys and the seed phrase, and no company can move your funds or lock you out. This is what lets you connect directly to decentralised apps, hold assets no one can freeze, and keep using your money if any single company disappears.
The cost is responsibility. There is no password reset and no support line that can recover a lost seed phrase or reverse a transaction you were tricked into signing.
Hot wallets vs cold wallets
A second split is about where the key lives, which trades convenience against exposure:
- Hot wallet. Keys sit on an internet-connected device — a browser extension like MetaMask or a phone app. Convenient for everyday use, but more exposed to malware and malicious websites.
- Cold wallet. Keys sit on a device kept offline, typically a hardware wallet such as a Ledger or Trezor. To spend, you confirm on the device itself, so a compromised computer still cannot sign without you. Best for larger amounts you hold long-term.
Many people use both: a hot wallet with small "spending money" and a cold wallet as the vault.
Smart contract wallets and account abstraction
Most wallets are externally owned accounts, controlled by a single private key. A newer option is the smart contract wallet, where a small program controls the account. Thanks to a standard on Ethereum called account abstraction (ERC-4337), these can add features a single key cannot:
- Social recovery — regain access through trusted contacts or backup devices instead of one fragile seed phrase.
- Spending limits and multi-signature — require several approvals, or cap daily transfers.
- Gas paid in other tokens, or sponsored by an app, so you are not forced to hold the native coin just to transact.
These reduce the "one wrong move and it's gone" risk of a raw private key, at the cost of a bit more complexity and reliance on the wallet's contract code.
How to choose, and how to stay safe
A practical approach:
- Starting out or mostly trading? A reputable custodial exchange is fine, but withdraw to self-custody anything you are not actively using.
- Holding meaningful value? Use self-custody, and a hardware wallet for the bulk of it.
- Using DeFi or NFTs? You need a self-custody wallet to connect to apps.
Whatever you pick:
- Write your seed phrase on paper (or steel), never in a photo, cloud note or password manager, and store copies in separate safe places.
- Treat anyone asking for your seed phrase as a scammer. No legitimate service ever needs it.
- Double-check website addresses and every transaction you sign — most losses come from approvals signed on fake sites, not from broken cryptography.
Key takeaways
- A wallet stores keys, not coins; whoever holds the private key controls the funds.
- Custodial means a company holds your keys (easy, but you must trust it); self-custody means you do (full control, full responsibility).
- "Not your keys, not your coins" — custodial balances depend on the company staying solvent and honest.
- Hot wallets are online and convenient; cold (hardware) wallets stay offline and are safest for large holdings.
- Smart contract wallets add social recovery, limits and flexible gas, softening the single-key risk.
- Your seed phrase is the wallet: back it up offline, never share it, and verify every site and transaction.
Get the weekly commit
New blockchain deep dives every week.

