Bitcoin · Self-custody security

Bitcoin Self-Custody: Security Guide From Plebes to Whales

Self-inflicted loss is the one threat every holder faces, whatever the balance. This sheet sizes every defense to what you hold: pick a tier below and the page hides advice you do not need yet. Protect against loss first, theft second, and make sure someone can inherit it.

Your tier
Filter advice by holding tier

00 Which tier are you?

Tiers are set by consequence, not by a bitcoin amount. The same 1 BTC is "Everyday" for one person and "Whale" for another. When in doubt, pick the higher tier: the extra setup costs a weekend and a few hundred dollars.

Everyday Tier 1

Losing it would hurt but would not change your life. Nobody outside your household knows you hold bitcoin.

Core setup

One hardware wallet, single-sig, two metal backups in two places, a letter for your heirs.

Serious Tier 2

A meaningful share of your net worth, or an amount a burglar or a relative would find tempting.

Core setup

Tier 1 plus either a BIP39 passphrase held apart from the seed, or a 2-of-3 multisig across two vendors, with a recovery drill every year.

Whale Tier 3

Life-changing money, or you are publicly known to hold bitcoin (employer, podcast, conference talks, company treasury).

Core setup

Geographically distributed multisig (self-run or collaborative), no single person or place that can move funds, duress plan, estate attorney, quarterly signing drills.

01 Quick reference: the rules that prevent most losses

  1. Your seed is the wallet. The device is a replaceable signing tool. Anyone who reads the 12 or 24 words owns the coins; anyone who loses every copy loses the coins.
  2. Never digitize the seed. No photo, cloud note, password manager, email draft, or "validation" website. Words go on paper, then metal, and nowhere else.
  3. Test recovery before you fund. Wipe the device (or use a second one), restore from your backup, confirm the same first receive address appears. Then deposit.
  4. Two backups, two buildings. One fire, flood, or burglary should never touch every copy.
  5. Verify every address on the device screen. Your computer and phone can be lying to you. The hardware wallet's screen is the only display you trust.
  6. No one legitimate ever asks for your seed. Not support, not an exchange, not a "recovery service", not a wallet update prompt. Any request is an attack.
  7. Buy hardware from the manufacturer. Never use a device that arrives with words already printed or a PIN already set.
  8. Exchanges are for trading, not storage. Withdraw anything you do not plan to sell soon.
  9. Silence is a security control. What you do not disclose cannot be used to target you.
  10. Write down how an heir gets in. A perfectly secured wallet no one can inherit is a loss that has not happened yet.

Setup by tier at a glance

ControlEverydaySeriousWhale
Signing1 hardware wallet, single-sigSingle-sig + passphrase, or 2-of-3 multisig2-of-3 or 3-of-5 multisig, 2+ vendors, or collaborative custody
Seed backups2 copies (metal preferred), 2 buildings2+ metal copies, passphrase stored apartOne metal seed per key, each in a different location or region
Wallet configNote the wallet type and script (e.g. "native SegWit, bc1q")If multisig: output descriptor with every backupDescriptor with every key site, plus a coordinator copy
Account securityPassword manager, authenticator app, no SMS 2FAFIDO2 security keys on email and exchanges, carrier port-out PINSeparate crypto identity, dedicated signing laptop, PII removal
PhysicalBackups out of sight, fire-resistant storageBolted safe, tamper-evident bagsDistributed sites, decoy/duress wallet, alarm, professional advice
InheritanceLetter of instruction, executor knows where it isLetter + walkthrough, named technical helperEstate attorney, trust or LLC where fitting, timelock or collaborative recovery path
DrillsFull restore at setup; review yearlyFull restore yearlySigning drill quarterly, full restore yearly, rotate after staff or life changes
Setup costOne device + metal plate2 to 3 devices, 2 to 3 plates, safe3 to 5 devices, sites, legal fees, optional service subscription
The column for your selected tier is highlighted.

02 Threat model

Risk ratings escalate with the amount held and, above all, with how many people know you hold it. Loss by your own hand is the top risk at every tier.

ThreatHow it happensEverydayWhalePrimary defense
Self-inflicted lossLost or illegible seed, words out of order, forgotten passphrase, lost multisig config, backup burned or floodedCriticalCriticalMetal backups in 2+ places, recovery drill, descriptor backup
Phishing & fake supportLookalike wallet apps and sites, "support" DMs, fake firmware update pages that ask for the seedHighHighSeed never typed into a computer or phone; bookmarks for official sites only
Malware & clipboard hijackClipper malware swaps a copied address for the attacker's; keyloggers take exchange loginsHighHighConfirm the full address on the hardware screen before signing
Address poisoningAttacker sends dust from an address matching the first and last characters of one you used, hoping you copy it from historyMediumHighNever copy addresses from transaction history; use saved, verified contacts
Custodian failureMt. Gox (2014, about 850,000 BTC), FTX (bankrupt Nov 2022), frozen withdrawals, hacksHigh if on exchangeHigh if on exchangeWithdraw to self-custody; keep only a trading float on platforms
SIM swap & account takeoverCarrier moves your number to the attacker, who resets email and exchange passwordsMediumHighFIDO2 keys, no SMS recovery, carrier port-out PIN or number lock
Supply chainTampered or counterfeit devices; the 2020 Ledger customer database leak (about 272,000 home addresses) was followed by fake replacement devices mailed to customersMediumHighBuy direct, check tamper evidence, generate the seed on the device yourself
Blind signingSigners approve what a compromised interface shows them. Bybit lost about $1.5B in ETH (Feb 2025) when multisig signers approved a transaction the web UI misrepresentedLowCriticalRead amount, address, and change on each device screen; second coordinator on a separate machine
Burglary & device theftThief takes the safe; seed card stored in the device boxMediumHighPIN on device, seed stored away from device, no single site holds a quorum
Wrench attack & kidnappingCoercion in person. Jameson Lopp's public list of physical bitcoin attacks grows every year; Ledger co-founder David Balland was kidnapped in France in January 2025LowCriticalSilence, geographic multisig, duress wallet, timelocks you cannot bypass
Insider & familySomeone who knows where the backups are, or holds enough keysMediumHighNo one person holds a signing quorum; tamper-evident seals
Heirs locked outDeath or incapacity with no instructions, or instructions no one can followCriticalCriticalLetter of instruction, tested by a non-technical reader
Seizure & regulationAccount freezes, capital controls, forced disclosure in some jurisdictionsLowMediumSelf-custody, legal counsel, keys in more than one jurisdiction
Quantum (future)A large quantum computer could derive keys from exposed public keys (reused addresses, old P2PK outputs)LowLow todayAvoid address reuse; follow the post-quantum custody migration work

What protocol-level attacks mean for you

A 51% attack can reorder recent transactions; it cannot spend coins from your keys. Treat deep confirmations (6+ blocks) as settlement for large incoming payments. Breaking secp256k1 or SHA-256 with classical computers is not a practical threat.

Custodian and counterparty risk

Every custodian adds its insolvency, hack, and policy risk to yours. If you use one, prefer segregated, audited custody, read the withdrawal terms, and keep it below the amount you can afford to have frozen for years. The custody responsibility matrix shows what stays your job in each model, and institutional custody covers the qualified-custodian side.

03 Wallet setups compared

Every setup trades theft resistance against loss resistance. Adding keys removes single points of theft but adds things you must back up. Choose the simplest setup that removes the threats in your tier.

SetupSingle point of failureTo recover you needComplexityFits
Exchange accountThe company, your login, its jurisdictionThe company's cooperationNoneTrading float only
Phone or desktop hot walletThe device's malware exposure; the one seed12 or 24 wordsLowSpending money
Hardware wallet, single-sigThe one seed backup12 or 24 words (plus script type)LowTier 1
Single-sig + BIP39 passphraseForgetting the passphrase; no error on a typoWords + exact passphraseMediumTier 2
SLIP-39 Shamir backup (Trezor)One signing device at spend timeM of N shares (e.g. 2 of 3)MediumTier 2 backup distribution
2-of-3 self-run multisigThe wallet config, if not backed up2 seeds + output descriptor (or all 3 xpubs)HighTier 2 Tier 3
Collaborative multisigProvider cannot spend alone; you still hold a quorumYour keys + config (provider keeps a copy)MediumTier 3
Timelocked recovery path (miniscript)Coins must be refreshed before the timelock maturesPrimary key now, or recovery key after the delayHighTier 3 inheritance
Collaborative custody examples: Unchained (2-of-3, Unchained holds one key), Casa (2-of-3 or 3-of-5, Casa holds one key). Timelocked wallets: Liana by Wizardsardine. Relative timelocks top out at 65,535 blocks, about 455 days.

Everyday: single-sig hardware wallet Tier 1

  • Buy direct from the maker (see tools). Generate the seed on the device, never import one.
  • Choose native SegWit (bc1q…) or Taproot (bc1p…) addresses; write the choice on the backup.
  • Set a PIN of 6+ digits. Most devices wipe after a set number of wrong entries, which is why the seed backup matters more than the device.
  • Use a Bitcoin-only companion app (Sparrow, the vendor's app) on a clean machine; connect through your own node when you can.

Serious: passphrase or first multisig Tier 2

  • Passphrase route: seed words in one place, passphrase in another. A thief with only the words sees an empty or decoy wallet.
  • Multisig route: 2-of-3 with devices from 2 or 3 vendors, coordinated in Sparrow, Nunchuk, or Specter.
  • Losing any one key is survivable; losing the descriptor with one key missing is not.

Whale: distributed multisig Tier 3

  • Single-sig is a single point of coercion and loss at this size. Use 2-of-3 or 3-of-5 across vendors and sites.
  • No location, and no person, should hold enough keys to sign. That also makes "I cannot move it today" true under duress.
  • Collaborative custody (Unchained, Casa, Swan Vault) adds a professional co-signer, key-replacement support, and inheritance help without handing over control.
  • Airgapped signing (PSBT by QR or microSD) on a laptop used for nothing else.

04 Seed, passphrase & backup management

Your 12 or 24 words are your bitcoin. The facts below explain why backups fail and which failures are silent. For what each word turns into, see how 12 words become an address.

2,048words in the BIP39 English list; the first 4 letters identify each word
128 bitsentropy in 12 words (24 words: 256 bits); 12 is already beyond brute force
Last wordcarries a checksum, so random words usually fail validation; 1 in 16 random 12-word lists pass
No erroron a wrong passphrase: every passphrase opens a valid, empty wallet
For all tiers: never store the seed digitally, and never type it into an internet-connected device. The only legitimate place to enter it is a hardware wallet during recovery.

Writing the backup

  • Number every word (1 to 24). Order errors are the most common unrecoverable mistake.
  • Record the metadata that recovery needs: wallet type, script (bc1q/bc1p), and for multisig the descriptor. The seed alone does not say where the coins are.
  • Paper first, then transfer to metal. Check each word against the device's display twice.
  • Stamp or etch rather than rely on loose letter tiles, which can scatter if the holder is crushed or opened.

BIP39 passphrase ("25th word")

  • Case, spaces, and punctuation all matter. Correct horse and correct horse are different wallets.
  • Everyday: usually skip it. Forgetting it is permanent, and a solid PIN plus separated backups covers your risk.
  • Serious: worthwhile if the passphrase is on metal, stored in a different place from the words, and in your inheritance letter's instructions.
  • Whale: one layer among several; a small-balance wallet with no passphrase doubles as a duress decoy.

Multisig backup: the descriptor Tier 2+

A multisig address is built from all cosigners' public keys. With 2 of 3 seeds but no record of the third public key, you cannot rebuild the address and the coins are stuck.

  • Export the output descriptor (or wallet config file) from your coordinator.
  • Store a copy with every seed backup. It reveals balances but cannot spend, so it can live alongside a seed.
  • Standard multisig path: m/48'/0'/0'/2' (P2WSH).

Derivation paths to note on the backup

ScriptPathAddress
Legacym/44'/0'/0'1…
Nested SegWitm/49'/0'/0'3…
Native SegWitm/84'/0'/0'bc1q…
Taprootm/86'/0'/0'bc1p…

Wallets scan 20 unused addresses by default (the gap limit). A restored wallet that shows zero is often on the wrong path, not empty.

Backup media

MediumSurvivesFails toVerdict
PaperShort-term, dry storageFire (ignites around 230°C), water, fading inkSetup and transfer only
Aluminum tilesWater, corrosion in dry storageHouse fires (aluminum melts at 660°C; fires can exceed that)Avoid for primary backups
BrassWater, moderate heatHot, long fires (melts near 900°C)Acceptable
Stainless steel (304/316), stamped or etchedFire (melts around 1,400°C), water, corrosion, crushingDeliberate destruction, theftRecommended
Titanium, stampedFire (melts around 1,670°C), corrosionTheftRecommended; costs more
Jameson Lopp's metal storage stress tests rate specific products under heat, crushing, and corrosion.

Where to keep copies

LocationStrengthWeaknessUse for
Home safe (bolted)Instant access, you control itBurglary, fire, coercion at homePrimary copy, or one multisig key
Bank safe deposit boxPhysical security, fire protectionBank hours, no FDIC insurance on contents, can be sealed at death or frozenOne copy or one key, never a quorum
Trusted family or friendGeographic separation, helps heirsTheir home security, their discretion, relationship changesSealed, tamper-evident copy, or one key
Estate attorneyContinuity at deathStaff turnover; you must trust the firmInstructions or a sealed key, not a full single-sig seed
Second property or other regionSurvives a local disasterHarder to checkTier 3 key sites

05 Sending and receiving safely

Before every send

  • Compare the full address on the device screen with the recipient's, from a second channel (call, in person) for large amounts.
  • Check amount, fee, and change address on the device; change should return to your own wallet.
  • Send a small test first when the address is new; bitcoin transactions cannot be reversed.

Receiving

  • Generate the receive address on the hardware wallet and confirm it on its screen before sharing.
  • Use a fresh address each time. Reuse links your payments and exposes the public key.
  • Label incoming coins by source (exchange, salary, private sale) in your wallet software.

Privacy & coin control Tier 2+

  • Use coin control (Sparrow, Electrum) to choose which coins you spend so you do not merge identified and unlinked coins.
  • Consolidate small coins when fees are low; each input raises future fees.
  • Run your own node or connect through a trusted Electrum server so a third party does not learn your addresses.

06 Operational security & privacy

Every link between your identity, your address, and your holdings is a way for someone to find and target you. Remove them in order of cost.

The shield of silence All tiers

  • No posts about buys, sells, balances, or wallet screenshots.
  • Do not discuss holdings with strangers or casual acquaintances.
  • Unbox hardware wallets off camera; the box and device are signals.

Accounts & devices All tiers

  • Unique passwords in a manager (Bitwarden, 1Password).
  • Authenticator app or security key instead of SMS 2FA on exchanges and email.
  • On public Wi-Fi, use a VPN (Mullvad, ProtonVPN) or wait.
  • Think about where hardware wallets are shipped; an office or P.O. box avoids tying "bitcoin buyer" to your home.

Harden identity Tier 2+

  • FIDO2 security keys (two, one as spare) on email, password manager, and exchanges.
  • Ask your carrier for a port-out PIN or number lock; remove the phone number as a recovery method where you can.
  • Separate email for crypto accounts (Proton Mail, Tuta).
  • End-to-end encrypted messaging (Signal) for anything about your setup.

Whale footprint reduction Tier 3

  • Pseudonyms for all crypto activity; separate "crypto" and everyday identities.
  • Remove PII from data brokers (DeleteMe, Optery).
  • Mail forwarding for crypto deliveries (Traveling Mailbox, PhysicalAddress.com).
  • A dedicated, minimal laptop used only for signing and coordination.
  • Legal structures (LLC, trust) that keep your name off asset records where lawful.
  • A policy for family and staff on what is never discussed, including with people outside the security plan.

07 Physical security & duress

Keys and devices All tiers

  • Store the device and the seed in different places. A device alone is protected by its PIN; a seed alone is the whole wallet.
  • Keep the home copy in a fire-resistant box or safe, out of sight.
  • Keep one copy off-site: a trusted relative's home or a safe deposit box.

Safes, seals, ratings Tier 2+

  • UL 72 Class 350: interior stays below 350°F in a fire test; fine for metal and paper. Class 125 protects electronics and media.
  • TL-15 / TL-30: resists 15 or 30 minutes of attack with common tools. Bolt it to the floor.
  • Tamper-evident bags with recorded serial numbers show whether a backup was opened.

Home fortress Tier 3

  • Reinforced doors and frames, window film, professionally monitored alarm with cellular backup.
  • Cameras with off-site recording (PoE systems such as UniFi Protect).
  • A safe room or reinforced area; a professional security assessment of home and travel habits.
  • Personal defense training focused on awareness and de-escalation.

Duress plan Tier 3

  • Life before bitcoin. Comply and de-escalate.
  • Decoy wallet with a plausible balance you can surrender.
  • Device features: Coldcard Trick PINs (duress wallet, wipe, brick); passphrase-hidden wallets on Trezor and others.
  • Make "I can't" true: with keys in other cities, or a timelock, you cannot move the main stash on demand, and a credible attacker learns that fast.
  • Study real cases: Lopp's list of physical bitcoin attacks.

08 Inheritance & succession

Without a plan, your bitcoin is lost at your death or incapacity. The plan has to work for someone who is grieving and not technical.

Letter of instruction All tiers

  • What exists: wallet types, rough amounts, which exchanges.
  • Where things are: devices, backups, descriptor, passphrase location.
  • How to recover, step by step, and who to call for trusted help.
  • A list of scams: nobody legitimate will ask them to type the seed online.
  • Tell your executor that the letter exists and where it is.

Never put the seed in a will. In the US, a probated will becomes a public court record.

Make it followable Tier 2+

  • Have a non-technical person read the letter and walk through a recovery on a test wallet.
  • Record a video walkthrough stored with the letter.
  • Name a crypto-literate helper ("coach") who holds no keys, so help does not create a new theft path.

Comprehensive protocol Tier 3

  1. Legal: crypto-aware estate attorney; trust or entity where it fits.
  2. Technical: multisig where heirs plus a professional co-signer reach quorum after your death, or a timelocked recovery path (Liana, miniscript) that heirs' keys unlock after a delay you keep resetting.
  3. Guided recovery: collaborative custody providers (Unchained, Casa) offer inheritance protocols that verify the death and assist heirs.
  4. Review after marriage, divorce, births, or moving.

09 Drills, updates & adaptation

Universal practice: before trusting any new wallet or backup method with real money, run a small amount through the whole lifecycle: set up, back up, receive, sign a send, then fully restore from the backup on a wiped or second device and confirm the balance. This catches most user errors while they are still cheap.
ActivityEverydaySeriousWhale
Full restore from backupAt setupYearlyYearly, per key
Signing drillWhen you spendTwice a yearQuarterly, every key
Backup site checkYearlyYearlyTwice a year, seals checked
Firmware updatesAfter security releases, from the official appWait a week unless urgent; verify signaturesTest on one key first; stagger vendors
Threat reviewAfter life changesYearlyYearly and after any disclosure or staff change
Timelock refreshn/an/aBefore the recovery path matures

10 Common mistakes

11 Tools, services & resources

Inclusion is not endorsement. Check recent security disclosures before buying. For a full wallet comparison see the Bitcoin wallet cheatsheet; if access is already at risk, see the seed phrase recovery guide, the hacked-wallet rescue guide, or wallet recovery forensics.

Hardware wallets and signing devices
Metal seed storage
Wallet and multisig coordinator software
Collaborative custody and inheritance services
Privacy and account security
Learning

12 Self-custody checklist

Progress is saved in this browser only. The tier filter at the top hides items above your tier.

Some items are hidden by your tier filter. Choose "Show all" to see them.

Done: 0 of 0

OPSEC & physical

Wallet & backups

Inheritance

Maintenance

David Veksler is a Principal AI Engineer in Denver. He leads agentic AI engineering at Antech, a Mars company, and builds AI platforms for regulated financial firms. This page was produced by a governed, multi-agent Claude Code pipeline with a git audit trail. How it's built Case studies