Skip to content

Security

Wallets, Custody, and Private-Key Security

A practical guide to securing digital assets: self-custody versus third-party custody, seed phrases, address and network checks, hardware practices, phishing awareness, and the irreversibility of on-chain transactions. Published by the Law Office of David S. Harris.

Unlike a bank account, a blockchain wallet does not have a password reset button. If you lose the keys that control your tokens, or if someone else gains access to them, there is usually no customer service line that can help. Understanding wallet security is therefore one of the most important steps before holding any digital asset. This article covers the core concepts and practices. It is general guidance, not a guarantee of safety.

Who controls the keys

Self-custody versus third-party custody

The fundamental distinction in digital-asset storage is who holds the private keys. In self-custody, you hold the keys yourself, using a software wallet, a hardware wallet, or a paper backup. You have full control, but you also bear full responsibility. If you lose your keys or your seed phrase, your assets may be permanently inaccessible. If someone steals them, your assets may be permanently gone.

In third-party custody, an exchange or custodian holds the keys on your behalf. This is more convenient and can reduce the risk of user-side key loss, but it introduces counterparty risk: you depend on the custodian's security, solvency, and integrity. If the custodian is hacked, becomes insolvent, or freezes your account, you may lose access. A common principle is: not your keys, not your coins. The right choice depends on your needs, the amount involved, and your tolerance for each type of risk.

The root of control

Seed phrases and private keys

A private key is a cryptographic secret that authorizes transactions from a specific address. A seed phrase, typically 12 or 24 words, is a human-readable representation that can regenerate all the private keys in a wallet. Anyone who has the seed phrase has full control of the associated assets.

This means the seed phrase is the single most sensitive piece of information in self-custody. It should never be stored on a device connected to the internet, never photographed, never entered into a website that is not your trusted wallet software, and never shared with anyone. Write it down on durable material, store it in a secure location, and consider redundant copies in separate physical locations.

Before you send

Address and network checks

Blockchain transactions are generally irreversible. One of the most common causes of loss is sending tokens to the wrong address or using the wrong network. Before any transfer, verify:

  • The destination address is correct. Check the first several and last several characters. If possible, send a small test transaction first.
  • The network matches. Tokens sent on one network generally cannot be recovered if sent to an address on a different network. Confirm the sender, the receiver, and the platform all use the same network.
  • The contract address is legitimate. Malicious actors create counterfeit tokens with similar names. Verify token contract addresses through official sources, not through links in unsolicited messages.

For more on the technical infrastructure that underpins transfers, see our technology overview.

Layered defense

Hardware and security practices

For meaningful holdings, a hardware wallet is widely recommended. A hardware wallet stores private keys on a dedicated device that is not exposed to the internet, requiring physical interaction to authorize transactions. This significantly reduces the risk of key theft through malware or phishing.

Beyond hardware, a layered approach to security includes:

  • Using strong, unique passwords for every account, managed through a reputable password manager.
  • Enabling two-factor authentication on all exchange and custodian accounts, preferably using an authenticator app or hardware key rather than SMS.
  • Keeping software updated on all devices, including operating systems, browsers, and wallet applications.
  • Using a dedicated, clean device for significant transactions when possible.
  • Diversifying custody rather than keeping everything in one wallet or on one exchange.
  • Maintaining offline backups of seed phrases and recovery information in secure, physically separated locations.

The human attack surface

Phishing and impersonation

The most common attacks do not target cryptography; they target people. Phishing emails, fake websites, social-engineering calls, and impersonation accounts on social media are all designed to trick you into revealing your seed phrase, authorizing a malicious transaction, or sending funds to a fraudulent address.

Be deeply skeptical of unsolicited messages, urgent requests, offers that seem too good to be true, and any communication asking for your seed phrase or private key. Legitimate services will never ask for your seed phrase. Verify website URLs carefully, bookmark official sites, and be cautious with links in emails and messages.

The defining property

Irreversibility

The most important thing to internalize is that blockchain transactions are, with very limited exceptions, irreversible. Once a transaction is confirmed on the network, it cannot be undone. There is no central authority that can reverse a mistaken transfer, no fraud department that can claw back stolen funds, and no chargeback mechanism.

This irreversibility is a feature of the system, not a bug. It eliminates certain types of intermediary risk and censorship. But it also means that mistakes and thefts are final. Every security practice described above exists because of this single property.

A summary checklist

Key safety practices

  • Never share your seed phrase with anyone, ever. No legitimate service will ask for it.
  • Store seed phrases offline on durable material in secure, separate physical locations.
  • Verify every address and network before sending. Send a small test transaction first for large amounts.
  • Use a hardware wallet for meaningful holdings.
  • Enable two-factor authentication on all exchange and custodian accounts.
  • Be skeptical of all unsolicited contact. Verify independently through official channels.
  • Keep software updated on all devices used for digital-asset activity.
  • Diversify custody so a single failure does not result in total loss.
  • Assume transactions are irreversible. Take the time to verify before confirming.

Further reading

Where to learn more

For onboarding and access considerations, see our guide to digital-asset access and jurisdictional fit. For legal and regulatory context, see our disclosures page.

Begin the conversation

Need guidance on custody arrangements?

If you are an eligible private client or institution deciding between self-custody and third-party custody and would like legal consultation regarding XAU₮/USDT holding, risk, and jurisdictional considerations, the Law Office of David S. Harris offers legal consultation. An enquiry is a consultation request only and does not create an attorney-client relationship.

Made with AI in Macaly