Holding digital assets under keys controlled by the holder, without a service provider holding them. The key authorises transfers from a specific address, and nothing else in the system decides who may spend. A self-custody wallet — non-custodial in industry usage, self-hosted or unhosted in regulation — is the hardware or software that generates and stores that key. What the holder has is the ability to sign; what the ledger records is that a valid signature moved the assets, not who produced it.
What the key controls, and what it does not
A private key authorises a transfer from the address derived from it. That is the whole of the mechanism: the network validates the signature and settles the transfer, and it makes no enquiry into who signed, on whose behalf, or under what authority. Nothing is held anywhere on the holder’s behalf, so there is no provider to instruct, no account to freeze and no instruction to reverse.
The same fact runs the other way. The ledger is a complete record of transactions and a blank on persons. It shows that an address received assets on a date and sent them on another, and it says nothing about who controlled the address at either moment, what the assets were paid for, or whether the payer and the recipient were the same party. A holder in self-custody therefore has an unimpeachable record of movement and no record at all of ownership — which is the position everything downstream is built on.
The arrangements, and how they differ
Self-custody is a category, not a configuration. The arrangements below differ in what authorises a transfer, and each one changes what has to be demonstrated to an outside party.
| Arrangement | What authorises a transfer | What a single failure costs | What is demonstrable to a counterparty |
|---|---|---|---|
| Single key | One signature from one key | Loss of the key or its backup ends control | A signature or a transfer from the address, produced by one person |
| Multi-signature | A defined quorum of separate keys | One key lost, the quorum still signs | The quorum has to convene for any proof requiring a signature or a spend |
| Threshold signature (MPC) | Shares held by separate parties combine into one signature | One share lost, the threshold still signs | Output looks like a single-key signature; the internal governance is invisible from outside |
| Collaborative arrangement | Holder plus a service co-signer who cannot spend alone | Depends on which party fails | A third party can attest to its own role but not to the holder’s |
| Provider-held (for contrast) | The provider’s internal authorisation | Provider failure, not key failure | Statements, confirmations and an onboarding file, produced by the provider |
For an individual, the choice is about resilience. For an entity, it is about authority: a quorum written into the keys is the only version of a signing policy the network enforces, and it is also the only version an auditor can verify independently of the entity’s own minutes.
What it costs
Holding assets under one’s own keys carries no fee, which is why the cost of it is routinely understated. The components are procedural rather than priced:
- Key generation and backup — devices, redundant backups, and physical distribution of those backups across locations that do not fail together.
- A signing procedure — who may initiate, who must approve, and how that survives a signatory leaving, becoming unreachable or dying.
- Succession — instructions that transfer control on death or incapacity without exposing the key while the holder is alive; for an entity, the equivalent problem in corporate form.
- Recovery testing — periodic proof that a backup actually restores, which is the only way a backup is known to work before it is needed.
- The evidence file — the acquisition records, invoices, contracts and filings that the ledger does not hold, retained for as long as the position is.
None of these carry a market figure: they are set by the size of the position, the number of signatories and the jurisdiction of the holder, and they are priced by the parties engaged, not by a schedule. The last component is the one most often deferred, and it is the one that becomes urgent at the exit.
What a regulated counterparty asks for, and why it asks the holder
Self-custody is unregulated in itself. Duties attach at the edges — at the moment assets move between a self-hosted address and a licensed provider, and the provider carries them.
Where a transfer has a self-hosted address on one end, there is no institution on that end to exchange originator and beneficiary information with. Under the European Banking Authority’s Travel Rule guidelines, requests for missing information about such a transfer go directly to the provider’s own customer. The holder is the counterparty of record because there is nobody else to ask.
Above a threshold, the provider must also establish that the address is genuinely the customer’s. In the EU, under Regulation (EU) 2023/1113, a provider handling a transfer of EUR 1 000 or more to or from a self-hosted address must assess whether that address is owned or controlled by its customer. The EBA guidelines set out the accepted methods: an attended or unattended identity verification displaying the address; a predefined amount sent from and back to the address; a message digitally signed with the key corresponding to the address; or other technical means the provider is satisfied by. Where one method is not reliable enough on its own, a combination is expected.
Two consequences follow that do not appear in the rule itself.
The first is durability. Once a provider is satisfied and has documented the determination, it may treat later transfers involving the same address as verified, subject to controls that detect a change in ownership or risk. Proof of control is therefore a per-address event with a long tail: which address a large payment leaves from is settled at the point the address is first verified, not at the point the payment is made.
The second is divergence. The duty is not uniform. Transfers involving self-hosted addresses are a listed risk-increasing factor in the EU framework, feeding monitoring and, where the provider judges it necessary, refusal of later transfers involving the same address. In the United States, the proposal that would have imposed reporting and recordkeeping on transactions involving unhosted wallets — issued in December 2020 — was withdrawn by the Treasury in August 2024, leaving firm-level policy rather than a federal rule in place. What a holder is asked for is set as much by the provider’s own risk appetite as by legislation.
The EU framework itself is written as provisional. Article 37 of Regulation (EU) 2023/1113 required the Commission, after consulting the EBA, to report by 1 July 2026 on the risks posed by transfers to and from self-hosted addresses and on whether specific measures — including restrictions — are needed, and to propose amendments if appropriate. The verification regime a holder meets today is the interim one.
Proof of control, in practice
The signed-message method assumes the wallet can produce a signature for that address in a form the counterparty’s tooling verifies. That assumption does not always hold. The original Bitcoin message-signing convention was built around the oldest address type; the generic format intended to cover modern script types, BIP-322, remains a draft and support across wallets and verifiers is uneven. A holder using a current address type may find that the address cannot sign in a format the other side accepts, or that the signature verifies in one tool and not another.
The fallback is the transfer method — a small amount sent from the address and returned. That is not a form field. It is a real spend from the exact address, which for a cold or multi-signature arrangement means convening the signers and running the full procedure to prove a point rather than to move a position. Where the arrangement is a threshold scheme, the resulting signature is indistinguishable from a single-key signature, which satisfies the provider and evidences nothing about the entity’s internal authority — a separate question that has to be answered on paper.
What goes wrong
The key or its backup is lost. The ability to authorise a transfer ends, and nothing in the protocol restores it. The assets remain visible at the address indefinitely.
The backup exists but only one person can find it. Control survives the holder’s absence in theory and not in fact, and the gap is only discoverable at the moment the absence occurs.
The address has a history the holder cannot document. Assets acquired years ago through a service that has since closed, or moved through an intermediary later designated, leave a permanent public trail and no counterparty willing to attest to it. The trail cannot be edited, and the explanation has to come from the holder’s own records.
A signature cannot be produced in the required form. The position is intact and the proof is not, and the transfer waits on a procedure nobody scheduled.
The payout is directed to an account in a different name. The party proven to control the address and the party receiving the proceeds are then not the same, and the chain the provider is required to evidence breaks at the last step.
Self-custody removes the record, not only the intermediary
The argument for self-custody is stated as the removal of a counterparty. What is removed with it is the counterparty’s bookkeeping.
A position held with a provider generates documentation as a by-product of being held: an onboarding file, periodic statements, confirmations for every movement, and a name attached to each of them. None of it is requested; it accrues. When a bank, an auditor or a buyer later asks where a holding came from, the answer is retrieved rather than reconstructed.
Self-custody generates none of it. The holding is easier to control and harder to account for, and the account has to be assembled after the fact from records the ledger never held — the acquisition confirmations from whatever service the assets were originally bought through, the invoices for anything sold to earn them, the filings that reported them, the resolutions that authorised the arrangement. Those records age badly. Services close, exports expire, staff leave, and the counterparty that could have confirmed a transaction stops existing while the transaction stays on the chain forever.
The work is therefore not created by the exit. It is created at the moment assets move into self-custody, and it is deferred until somebody asks. The holder who treats the transfer into self-custody as the point at which the evidence file opens — rather than the point at which the record stops — is the one who can move a large position through a regulated counterparty on the timetable of the transaction rather than the timetable of the enquiry.
Terms it is confused with
Non-custodial is the same thing, named from the product side rather than the holder’s.
Self-hosted address and unhosted wallet are the regulator’s terms for the same arrangement; unhosted is the older of the two and still appears in United States material.
Cold storage describes how a key is kept — offline, on a device that never touches a network — not who holds it. A provider can hold customer keys in cold storage, and that is not self-custody.
A position held with a provider is a contractual claim against that provider, ranking with its other obligations and depending on its solvency; see issuer claim. Self-custody replaces that claim with the ability to sign, which is not a claim against anyone.
The term applies to digital assets. Physical metal held under an allocated arrangement with a named vault operator is a different structure, evidenced by a register naming the counterparty against numbered bars rather than by control of a key.
Conversion of a self-custodied position into national currency, and the record that conversion produces, is set out under off-ramp; where the payment runs against an invoice or order reference instead, see payment gateway. Where the proceeds are applied to physical metal, the sequence from payment through screening to allocation by serial number is set out on Buy Physical Gold with Crypto.
