01

What a wallet holds

A crypto wallet is not a box that stores coins inside a device. The asset record remains on the blockchain, while the wallet manages keys that prove authority over an address. Separating the displayed balance from the power to authorize a transaction clarifies the roles of wallets, exchanges, and networks.

02

Custody and self-custody

With a custodian, a service provider controls the keys and the user accesses an account. With self-custody, the user controls both the keys and recovery process. Custody may offer convenience and account support but adds dependence on the operator; self-custody offers control while placing loss and phishing risk on the user.

03

What a recovery phrase controls

A recovery phrase can recreate the wallet and is therefore a critical secret. Storing it in a photo, cloud note, or email can expose the assets independently of an account password. It should not be entered into unsolicited websites, and the offline backup and recovery process should be tested carefully.

04

Review before signing

Connecting a wallet or signing a request is not always a simple login. The request may approve token spending, transfer an asset, or call a smart contract. Verify the domain, network, permissions, and amount. Compare the beginning and end of a pasted address and use a small test before a large transfer.

05

Exchange dependencies

For an exchange account, review more than login security. Asset segregation, withdrawal policies, reserve disclosures, incident procedures, and supported networks affect whether funds can be moved when needed. A balance shown in an account is not the same as direct authority over an on-chain address.

06

Choose a custody model

No custody model is best for every user. Consider the amount, frequency of use, recovery ability, and whether shared control is necessary. Design the recovery path before searching for yield, and rehearse it with a small amount rather than discovering the process during an emergency.