

Self Custody, A Primer
On June 12, 2022, several hundred thousand people opened an app and found that the withdraw button had stopped working. The balances were still on the screen, the same numbers as the day before, but there was no longer any way to touch them.
Seven months later a bankruptcy judge in Manhattan ruled on who had owned that money. The terms of service those customers clicked through at signup transferred title to their Earn deposits over to Celsius the moment they made them. Roughly 600,000 Earn account holders found out that the coins had belonged to the company the whole time, and all they actually owned was a claim against a bankrupt estate, standing in line behind everyone else Celsius owed.[1]
Picture a parking lot. You hand your keys to a guy in a vest, he drives your car somewhere you can't see, and he hands you a numbered stub. While he has the keys he can move the car, park it next to a leaking dumpster, or let his cousin borrow it for the afternoon. Keys work the same for everyone who holds them. Whoever has them drives, and the stub in your pocket is nothing but a promise that the car comes back.
A custodial account runs on two separate ledgers. The blockchain keeps one, recording that a quantity of coin belongs to an address and can be moved only by a signature from whoever holds that address's key. The exchange keeps the other, recording what the exchange owes you. Your balance lives on the second ledger, and the blockchain has never heard of you.
Subpoenas, freezes, tax summonses and court orders all land on the exchange's ledger, because there is a company behind it and a company can be ordered to comply. Federal rules already treat exchanges as money services businesses, so they collect your identity and log what you do long before anyone comes asking for it.[2]
In 2016 the IRS wanted to know who had been trading, so it served a summons on Coinbase. In November 2017 a federal court in California ordered the company to hand over names, birth dates, addresses, taxpayer identification numbers and transaction records for roughly 14,000 accounts.[3] Most of those account holders found out afterward, if they found out at all.
It works the same outside crypto. Payment processors cut off WikiLeaks without a court ordering anything. Cypriot savers with more than €100,000 in the bank had part of it taken to recapitalize that bank, and learned about it from the news.
Crypto people have a saying for this: not your keys, not your crypto. A private key is just a number, big enough that nobody is going to guess it. Your address gets derived from that number by math that only runs one direction. Owning crypto means being able to produce a signature the network accepts. The seed phrase you write down is the number your keys grow from, put into words so you can copy it by hand without a typo.
Hold that number yourself and there's no company in the middle to serve. Anyone who wants your coins has to come to you, and where you keep it becomes your problem.
A key on your phone is available whenever you want it and exposed to whatever else gets onto your phone. Cold storage keeps it on a device that never touches the internet. You build the transaction on your phone, hand it across to the device, the device signs it, you hand the signature back, and the key itself never moves. The seed phrase is the backup for all of it, which is why people stamp it into metal. That survives a house fire and surrenders to anyone who cracks the safe you keep it in. A passphrase is an extra word or phrase, kept in your head on top of the seed, so a stolen phrase by itself opens an empty wallet. Multisig spreads signing across several keys in several places, so no single theft, fire, or funeral moves the coins, and neither do you without a bit of planning. Each of these trades convenience against the number of ways things can go wrong.
Taxes work the same either way. The IRS has treated virtual currency as property since 2014, so selling it, trading it, or spending it is a taxable event you report, and where the key sits makes no difference.[4]
The blockchain is public and permanent. In February 2022 the government recovered about 95,000 bitcoin taken in a 2016 exchange theft, after the thieves had run the coins through thousands of transactions to bury them. The haul was worth $3.6 billion the day it was seized.[5] Holding your own keys puts the car in your hands, but it still has plates and still drives on public roads.
In 2020 a company selling cold-storage hardware had its customer database hacked. Names, phone numbers and home addresses for a quarter of a million people were published on a hacker forum. Every one of them had announced, by buying the hardware, that they owned crypto.[6] The hardware did its job. Keep the fact that you own it to yourself. And if someone with a badge does turn up, the courts still haven't settled whether you can be made to produce a passphrase.[7]
In 2013 a man in Wales threw out an old hard drive during a clear-out at home, not realizing it held the keys to around 8,000 bitcoin, and it went to a municipal landfill with the rest of the rubbish. He has spent more than a decade asking the council for permission to dig for it. They keep saying no.[8] The coins are still sitting there on the blockchain where anyone can look them up, and nobody will ever move them again. There is no support line for that.
BRIJ starts out custodial. Self-custody takes knowledge and discipline, and someone's first day, with no undo available, is a rough place to learn either one. So we hold the keys at the start and teach the rest.
Custodial now is not custodial forever. We're building toward a day when holding your own keys is ordinary and nobody has to be brave about it.
A stub is a promise about a thing you can't see. Keys are just keys, and whoever holds them drives.

