Principle 06 — Self-custody
Holding your own keys
Why a portfolio product has an opinion about custody, how to hold keys without losing them, and what this product will never ask you for.
Why a portfolio product has an opinion about this
Bitcoin held on an exchange is not bitcoin. It is a claim on a company that says it holds bitcoin for you, settled at that company’s discretion, subject to that company’s solvency and to whichever authority can instruct it.
That is structurally the same object as the promise the first principle declines to hold. A plan that rejects issuer risk in its bond sleeve and then accepts it in its largest sleeve is not being consistent — it is just being inconsistent in a more fashionable direction.
What self-custody actually means
The seed phrase is the asset. Everything else — the hardware device, the app, the plastic — is a convenient way of using it. Whoever has the phrase has the coins, and nobody who lacks it has anything at all.
Step 01
Generate the keys on a device that has never been online
A dedicated hardware wallet from a manufacturer with a long public track record. The phrase is created on the device and is never typed into a computer or a phone.Step 02
Write the phrase down on something that survives
Paper is acceptable; stamped or engraved metal is better. It is stored somewhere a fire or a flood would not reach it, and it is never photographed, never typed, never put in a password manager, and never stored in any cloud.Step 03
Verify a receive address on the device screen
Malware substitutes addresses. The address you send to must be the one displayed on the hardware device itself, not the one shown on the computer that asked for it.Step 04
Send a small amount first, then restore from the backup
The only proof a backup works is a restore. Wipe the device, restore from the written phrase, confirm the funds are there. A backup you have never tested is a belief, not a backup.Step 05
Write down who gets it, and how
The failure that actually happens is not theft. It is that the holder dies and the phrase dies with them. Someone you trust must be able to find and use it, and that instruction should exist on paper.
How it goes wrong
Losses in self-custody are overwhelmingly not sophisticated attacks. They are ordinary mistakes, and they repeat.
- One copy, one place
- A single written phrase in a single building is one fire away from a total loss. Two copies in two locations is the minimum, and neither of them is the same building as the device.
- Photographing the phrase
- A photograph is synced, backed up, and indexed within seconds. Every phrase that has ever touched a camera roll should be considered compromised and the coins moved to a new one.
- Typing it in somewhere
- No legitimate service, wallet recovery, support agent, or airdrop will ever need your seed phrase. A request for it is a theft in progress, without exception.
- Complexity you cannot repeat
- Elaborate passphrase and multi-location schemes lose more coins than they save, because the owner is the person most likely to be defeated by them five years later. Simple and tested beats clever and untested.
What this product never does
- It never custodies anything. There is no wallet here, no balance held on your behalf, and nothing to withdraw.
- It never asks for a seed phrase, a private key, or a wallet password. There is no screen in this product that has a field for one, and there never will be.
- It cannot recover a lost phrase, for you or for anyone. Nobody can. That is the property that makes the asset worth holding.
- It reads balances only where you have chosen to tell it about them, and a read-only broker connection cannot move anything either.