If your bitcoin sits on an exchange, you do not have bitcoin. You have a claim against a company, denominated in bitcoin, and the company has the coins.
That distinction is invisible right up until the moment it is the only thing that matters.
What the claim is worth
Exchange failure is not a hypothetical risk that Bitcoin people invoke to sound serious. It is the empirical history of the industry.
Mt. Gox collapsed in February 2014 with something like 850,000 BTC gone, of which roughly 750,000 were customer coins and the rest the exchange's own. Repayments began in July 2024, ten years later, and only because about 200,000 of those coins turned up in an old wallet.
FTX filed for bankruptcy in November 2022. Customer assets had been lent to an affiliated trading firm. The balances on the screen were real numbers in a database; the coins backing them were not there.
Celsius, BlockFi, Voyager, the same shape. Celsius paused withdrawals on 12 June 2022 and never resumed them. In every case, users who could see a balance in an app discovered that seeing a balance and owning an asset are different things.
And failure is only one of the paths. An account can be frozen while compliance reviews run. Withdrawals can be paused during exactly the volatility that makes you want to move. An account can be closed because of where you live or what a transaction looked like to an automated system. None of these require anyone to have done anything wrong.
Self-custody removes all of it in one move. There is no company between you and the coins, so there is no company to fail, freeze, or refuse.
What you take on instead
This is the part that responsible writing has to include, and most does not.
Custody is not deleted by self-custody. It is transferred - to you. The failure modes change from someone else's insolvency to your own mistakes, and those mistakes are unusually unforgiving, because Bitcoin has no undo, no support line, and no fraud department.
Four ways people actually lose coins:
They lose the backup. Nothing dramatic: a house move, a flood, a drawer nobody thought to check, a note that seemed obvious at the time and is meaningless three years later.
They never tested the backup. They wrote twelve words down and assumed. A word was mis-transcribed, or the order was wrong, or it was a different wallet's seed. This is indistinguishable from having no backup, and it is only discovered at the worst possible moment.
They put the seed somewhere convenient. A photo, a notes app, a password manager, a cloud drive, an email to themselves. Every one of those is a copy on an internet-connected system, and there is a long history of exactly those copies being found.
They died without a plan. The coins are secure and permanently unreachable. See inheritance planning.
Those four are self-inflicted. Two more are not, and they arrive with the amount. Somebody talks the words out of you: a support account that is not support, a wallet app that was not the wallet app, a service offering to recover funds that needs your seed to do it. Or somebody who knows what you hold takes it in person. Neither is exotic, and both are why the cheapest security measure available is declining to tell people what you have.
Notice what is not on either list: sophisticated cryptographic attacks. Bitcoin's cryptography is not the weak part. Human process is.
The minimum that actually works
You do not need a vault or a multisig quorum to start. You need four things done properly.
1. A wallet where you hold the key. Software is fine to begin with. A hardware signing device is better once the amount is meaningful, because it keeps the key off a general-purpose computer and shows you what you are signing on a screen malware cannot alter.
2. The seed written down, offline, by hand. Paper as a minimum, metal if the amount justifies protecting against fire and water. Never photographed, never typed, never synced.
3. A tested restore. This is the step that separates a plan from a fact. Wipe the wallet, restore from the words you wrote, confirm the same addresses come back. Do it before there is anything meaningful in there, and do it again after any change to your setup.
4. A location that survives your actual life. Not just theft: a fire, a move, a relative doing a clear-out. And separate from the device, since the two together are the whole wallet.
Doing it in the right order
The mistake is treating this as a decision to agonise over. It is a skill to practise, and it is cheap to practise badly at small size.
Move a small amount into a non-custodial wallet, an amount you would shrug at losing. Write the seed down. Wipe the wallet. Restore it from the words. Watch the funds reappear.
That single loop teaches more than any amount of reading, and it converts the abstract fear into a procedure you have personally executed. Increase the amount when the procedure feels boring.
Where the line sits
Self-custody is right for savings. For an amount you are actively trading, the calculus is different and an exchange may genuinely be the right tool: the risk is bounded by the amount and by the time it sits there.
The honest framing is not "always self-custody". It is: know which risk you are holding. On an exchange you are holding a company's solvency and its regulator's mood. In self-custody you are holding your own process. Neither is zero. One of them you can actually control.
Next: choosing a wallet, multisig for larger amounts, and making sure it survives you.
