Skip to content

Risk warning Don't invest unless you're prepared to lose all the money you invest. This is a high-risk investment and you should not expect to be protected if something goes wrong. Take 2 mins to learn more.

Custody

Crypto wallets: where your coins should actually live

The most expensive cryptocurrency loss in British history happened in Newport, and it had nothing to do with hacking, trading or a failed exchange. It was a storage decision. This is how not to repeat it.

Buy hardware wallets directly from the manufacturer. Never enter a seed phrase into any website.

Digital crypto wallet
Wallet types
6
Hardware cost
£50–150
Recovery options
None

Most people spend hours choosing an exchange and about four minutes deciding where their coins will live afterwards. That allocation is backwards, and the evidence is buried under a landfill site in Newport.

Roughly 8,000 Bitcoin sit somewhere in the Docksway site because a hard drive holding a private key was thrown out during a household clear-out in 2013. The High Court dismissed the recovery claim in January 2025, finding that Newport City Council's ownership of deposited waste provided a complete answer. Nothing was hacked. No platform failed. One copy, one location, no backup.

That is the whole subject of this page, generalised.

The one distinction that matters

Every wallet is either custodial or self-custodial, and the difference determines who can lose your money.

Custodial means a business holds the keys. That is what an exchange account is. The upside is genuine: you cannot lose a seed phrase you never had, passwords can be reset, and support exists. The downside is that you are trusting a company to remain solvent and honest. Registration under the Money Laundering Regulations does not change that — there is no Financial Services Compensation Scheme cover for cryptoassets, and if the firm fails you join the creditor queue.

Self-custody means you hold the keys. Nobody can freeze your funds, no business failure touches them, and no third party needs to approve a transaction. In exchange you accept complete and irreversible responsibility. There is no recovery, no ombudsman, and no version of this where somebody helps you.

Type Suits Strength Weakness Main risk
Exchange (custodial) Active traders, small balances Nothing to lose, recoverable password, instant trading You do not control the keys. Platform failure is your loss. Counterparty
Mobile hot wallet Everyday use, small sums Free, convenient, works with apps and payments Connected to the internet; malware and phishing are live risks Device compromise
Desktop wallet Intermediate holders More control, better key management than mobile Same online exposure, plus whatever else is on the machine Device compromise
Hardware wallet Anything you would be upset to lose Keys never leave the device; signs transactions offline Costs money, adds friction, and the seed phrase becomes everything Loss of seed phrase
Paper or metal backup Seed phrase storage Immune to hacking; metal survives fire and flood Physical theft, physical loss, and no undo Physical
Multi-signature Large holdings, shared control No single point of failure; needs several keys to move funds Genuinely complex; more ways to lock yourself out Complexity

A structure that works for most people

  • Exchange account: only what you are actively trading, or what you would shrug off losing.
  • Mobile hot wallet: spending money. Treat it like the cash in your pocket.
  • Hardware wallet: everything else. The threshold where this becomes worth it is lower than people think.
  • Seed phrase: two physical copies, two separate locations, never digital, never photographed.
  • Estate note: somebody must know these assets exist, stored separately from the phrase itself.

The seed phrase, properly explained

When you set up a self-custody wallet it gives you twelve or twenty-four ordinary English words. Those words are not a password to your wallet. They mathematically generate every private key in it. Anyone who has them has your funds, from anywhere in the world, instantly and irreversibly. Anyone who does not — including you — has nothing.

This produces two opposed failure modes that you have to solve simultaneously. Store the phrase too carelessly and it gets stolen. Store it too carefully, in one place only, and you recreate the Newport problem. The answer is redundancy without exposure: multiple physical copies, geographically separated, each individually secure.

Practical rules. Write it by hand or stamp it into metal — paper burns and dissolves, steel plates designed for this cost around £30 and survive both. Store copies in at least two locations, for instance a home safe and a trusted relative's house or a bank safe deposit box. Never photograph it, never type it into any device, never store it in a password manager or cloud notes, and never enter it into a website. Every wallet-drainer phishing site in existence is asking for exactly those words.

Hardware wallets

A hardware wallet is a small dedicated device that stores private keys in a secure element and signs transactions internally, so the keys never touch your computer. Even on a compromised machine, an attacker cannot extract them. You confirm each transaction on the device's own screen, which also defends against malware that alters a destination address in your clipboard.

Expect to pay between £50 and £150. Buy directly from the manufacturer's own website — never from a marketplace reseller, an auction site or a third party. Supply-chain tampering is documented, and the classic attack ships a device with a pre-printed "your recovery phrase" card containing a seed the attacker already controls. A genuine device always generates its seed itself, in front of you, at first setup.

Set it up yourself, verify the recovery phrase during setup, and send a small test transaction before moving anything substantial. Then practise the recovery process on a spare device or a wallet reset, so you know your backup actually works before you need it.

Inheritance, and why Wales should care

Cryptoassets form part of your estate. HMRC treats them as property for inheritance tax purposes, and they are valued at the date of death like any other asset. The difficulty is not legal — it is practical. An executor cannot access a wallet without the seed phrase, and cannot even begin if nobody knows the assets exist.

The Newport case is the extreme version of a problem that is going to become ordinary. A generation that bought crypto in their twenties and thirties is now in their forties, and estates containing wallets nobody can open are already reaching solicitors. In Cardiff you can find a firm that has dealt with one. In much of mid, west and north Wales you cannot, which makes planning ahead more important rather than less.

A workable approach: keep a written record of what you hold and roughly where — which exchanges, which wallet types, which devices — stored with your will or somewhere your executor will find it. Keep the seed phrase itself entirely separate, with access arranged through a mechanism you have actually thought about. Tell the person who will administer your estate that the assets exist. And take proper legal advice if the sums are meaningful; this is one area where a generic template is genuinely inadequate.

Moving coins off an exchange, without losing them

Four steps, in order, every time. Add the destination address to your exchange's allowlist and expect a security hold of up to 24 hours on a newly added address — that delay is protecting you. Send a small test amount first and confirm it arrives. Only then send the balance. And verify the address on the hardware wallet's own screen rather than trusting what your computer displays, because clipboard-hijacking malware exists specifically to swap addresses at the moment you paste.

Be aware of the compliance side too. Under the Travel Rule, in force since September 2023, firms must collect and transmit originator and beneficiary information on cryptoasset transfers, with customer due diligence triggered at a flat £800 threshold since 30 June 2026. You may be asked who controls the destination wallet. Answer honestly — and keep the record, because when you eventually sell, the receiving platform will ask where the coins came from. Our cashing-out guide covers why that matters.

Wallet-specific fraud

Three patterns account for most self-custody losses. Fake wallet applications, published in app stores with convincing branding, which harvest the seed phrase at setup. Phishing sites impersonating a wallet's own support or a "validation" process, asking you to enter your phrase. And malicious token approvals, where you sign a transaction that grants a contract permission to move your assets — common in DeFi and rarely understood by the person signing.

Download wallet software only from the developer's official site or a link you have verified independently. Never enter a seed phrase anywhere. Review what you are actually approving before signing, and periodically revoke old approvals. And remember that Welsh police forces recorded more than ten thousand fraud reports in a single year — our scams page covers the wider picture.

Custody is the decision that actually matters

Choose a platform sensibly, then decide deliberately where the coins will live and test the backup before you need it.

Questions

Wallet and custody questions

Should I leave my crypto on the exchange?

For small amounts you are actively trading, it is a reasonable trade-off. For anything you would be genuinely upset to lose, no. Registration under the Money Laundering Regulations does not bring your balance inside the Financial Services Compensation Scheme — if the platform fails, you are an unsecured creditor.

The rough rule of thumb most experienced holders use: if losing it would change your year, it should not live on someone else's server.

What is a seed phrase and why does everyone go on about it?

A sequence of twelve or twenty-four ordinary English words that mathematically generates every private key in your wallet. It is the money. Anyone with those words has your funds; anyone without them, including you, has nothing.

That is why the advice is repetitive. Losing it is unrecoverable, and there is no support line, no password reset and no ombudsman.

Where should I store a seed phrase?

Written or stamped physically, in at least two geographically separate locations, never photographed and never typed into any device. A fireproof safe at home plus a second copy with a trusted family member or in a bank safe deposit box is a common arrangement.

Never store it in a password manager, cloud notes, email drafts or a photo library. Never type it into a website, however official-looking. No legitimate service will ever ask for it.

Are hardware wallets worth the money?

For anything above a few hundred pounds, generally yes. A hardware wallet keeps private keys on a dedicated device that signs transactions offline, so malware on your computer cannot extract them. They typically cost between £50 and £150.

Buy directly from the manufacturer. Devices bought through marketplace resellers have been tampered with in documented cases, sometimes shipping with a pre-generated seed phrase the attacker already holds.

What happens to my crypto if I die?

Nothing, unless you have planned for it — which is the problem. Cryptoassets form part of your estate for inheritance tax purposes, but an executor cannot access a wallet without the seed phrase, and a solicitor cannot help if nobody knows the assets exist.

A practical approach is to record the existence and location of your holdings in a document your executor can find, kept separately from the seed phrase itself, and to discuss it with whoever will administer your estate. Take proper advice for anything substantial.

Is a wallet on my phone safe enough?

For spending money, yes. For savings, no. A mobile wallet is connected to the internet, sits on a device that also runs a browser and a messaging app, and is vulnerable to phishing, malicious approvals and device theft.

The sensible structure is a small hot wallet for day-to-day use and a hardware wallet for the bulk, in the same way you would carry cash in a pocket and keep the rest in a bank.

What is the Newport lesson exactly?

In 2013 a hard drive holding the private key to roughly 8,000 Bitcoin was discarded during a household clear-out and ended up at the Docksway landfill site in Newport. Every attempt to recover it failed, and in January 2025 the High Court dismissed the claim, finding the council's ownership argument provided a complete answer.

Nothing was hacked and no exchange failed. One copy of one key, in one place, with no backup. That is the lesson, and it applies to almost every self-custodied wallet in Wales today.