Onpode
Cover art for Why users face an irreducible choice between control and ease of use in crypto

Why users face an irreducible choice between control and ease of use in crypto

August 5, 2026 · 10 min

Eliza Ward & Brian Reed

Crypto self-custody and custodial exchanges have produced nearly identical aggregate losses — roughly 1.57 million Bitcoin lost to self-custody errors versus 1.51 million lost through exchange failures. Users aren't choosing the safer option; they're choosing which catastrophe to risk, and fear of the most recent disaster drives the decision every time.

Cryptocurrency custody is fundamentally a question of who controls the private keys — the cryptographic secrets that authorize movement of assets on a blockchain. Whoever holds those keys controls the assets; this single fact drives the entire self-custody versus custodial debate.

0:0010:21
Get the next episode on Crypto

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Crypto

About this episode

Crypto custody has one irreducible tension: whoever holds the private key controls the asset, and every design choice is just a different way of deciding who that is. This episode starts with the Bybit breach of February 2025 — $1.5 billion moved while the team of authorized signers believed they had rejected the transaction — and uses it as a lens for why the custody debate keeps producing the same result regardless of which direction users run. The episode traces the panic cycle: Mt. Gox created the self-custody argument, FTX seemed to prove it, and then the Coldcard hardware wallet crisis in July 2026 reversed two years of migration in a matter of weeks. On-chain flow data showed users moving back to exchanges every single day after that failure. The most striking detail: Willy Woo's figures put permanent self-custody losses at roughly 1.57 million Bitcoin, exchange losses at roughly 1.51 million — nearly the same number. Fear drove both migrations, and the aggregate damage converged anyway. The episode also works through why hybrid approaches like multisig and MPC, while theoretically sound, introduce their own failure modes — and what the arrival of MiCA and proposed SEC custody rules means for users already mid-panic. It's a genuinely uncomfortable listen, not because it tells you what to do, but because it explains clearly why there may be no choice that removes the risk — only choices about which version of it you're willing to live with.

Frequently asked

Is self-custody crypto safer than keeping funds on an exchange?

Self-custody and custodial exchanges have produced nearly equal losses historically. On-chain data cited by analyst Willy Woo estimates roughly 1.57 million Bitcoin permanently lost to self-custody errors versus approximately 1.51 million lost through exchange failures. Neither model is objectively safer — they carry different but comparably sized risks.

What caused the $1.5 billion Bybit hack in February 2025?

The February 2025 Bybit breach moved approximately $1.5 billion despite the exchange using institutional multisig custody — a setup requiring multiple signers to authorize transactions. The signers believed they had rejected the transaction, but the blockchain recorded their signatures as valid. Complexity in the signing interface created a gap between perceived and actual authorization.

What is a crypto private key and why does losing it mean permanent loss?

A crypto private key is the sole cryptographic secret that authorizes transactions from a wallet. There is no recovery mechanism — no locksmith, no password reset. A seed phrase of 12 to 24 words is simply a human-readable copy of that key. If either is lost or compromised, the associated funds are permanently inaccessible.

Do users actually move Bitcoin between self-custody and exchanges after major crypto crises?

Yes. After the FTX collapse in November 2022, on-chain data showed a sustained migration of Bitcoin off exchanges into self-custody wallets that lasted roughly two years. After a Coldcard hardware wallet crisis on July 31, 2026, net on-chain flows reversed back toward exchange addresses every single day following that date.

Does multisig or MPC custody eliminate crypto security risk?

Multisig and MPC custody reduce single-point-of-failure risk but introduce new ones. The Bybit breach in February 2025 exploited a best-practice multisig setup: authorized signers believed they were rejecting a transaction while the blockchain executed it. Added signing complexity created a new failure mode rather than eliminating the underlying vulnerability.

Grounded in 12 sources
Raising the bar: Assessing historical cryptocurrency exchange practices in light of the EU’s MiCA and DORA regulation · sciencedirect.com
Custody Rule Modernization: A Model Framework for ... · sec.gov
The collapse of FTX · assets.kpmg.com
What Is Cold Storage in Crypto? | Banxa · banxa.com
The Darkest Days in Crypto History: 5 Market Crashes That Changed the Industry Forever - Bitcoin Foundation · bitcoinfoundation.org
Institutional Crypto Custody: A Guide for Asset Managers | BitGo · bitgo.com
Custodial vs. Non-Custodial Wallets: Where is Your Crypto Held? | BitGo · bitgo.com
What Is a Self-Custody Wallet? How Do I Take Control of ... · bitpay.com
What is a CEX? Centralized Exchange Defined - Chainalysis · chainalysis.com
Self-Custody Wallet Guide: From Personal to Enterprise · cobo.com
Mt. Gox to FTX: a writeup of the major crypto custody collapses · coinsnews.com
What Is Self-Custody in Crypto? Custodial vs. Self-Custodial Wallets - Crypto.com US · crypto.com
Read transcript

Eliza Ward: Brian, hey — I need to ask you something before we even start, because I read the Bybit timeline again this morning and I'm still stuck on one thing.

Brian Reed: Yeah, what are you stuck on?

Eliza Ward: If private keys are the thing — the cryptographic secret that controls everything, whoever holds them controls the assets, that's the whole deal — then how does one point five billion dollars move in February 2025 through a wallet where the key holders thought they'd said no?

Brian Reed: That's the episode. And I want to actually walk into the scene before we explain the mechanism, because the mechanism is almost secondary to the image of what happened. A team of signers. A multisig setup — meaning no single person could move the money alone, which is the institutional best practice. They go through the process. Nothing looks wrong to them. They believe they've rejected the transaction.

Eliza Ward: And the money was already gone.

Brian Reed: Gone. Because from the blockchain's perspective, the signatures were valid. This wasn't a stolen seed phrase — no one broke in through a back door. It was a best-practice institutional custody setup that failed on its own terms, while the people inside it thought they were in control.

Eliza Ward: So the question isn't really which custody model is safer. It's whether that question even — wait, no — it's whether complexity itself became the failure mode.

Brian Reed: Right — and that's what I want to sit with. Because one point five billion dollars moved while the people who were supposed to stop it thought they had. That image is where today starts.

Eliza Ward: And Bybit isn't even the first time a supposedly safe model collapsed like that. Because before Bybit there was FTX — November 2022, the exchange goes insolvent, users who held assets there lose access. Not hacked, not stolen. Just — counterparty failed.

Brian Reed: And KPMG documented what happened next — a major migration, Bitcoin moving off exchanges into self-custody wallets. People pulled their keys back.

Eliza Ward: For two years. That trend held for two years.

Brian Reed: Right — and then Coldcard. July 31, 2026, the hardware wallet crisis hits. And on-chain flow data showed net transfers going the other direction, back to exchange addresses, every single day after that date. So they ran from exchanges to hardware wallets, and then ran back?

Eliza Ward: That's exactly it. And look — Mt. Gox is the original version of this story. Exchange insolvency, mismanagement, permanent loss. That's what created the whole self-custody argument in the first place. The cypherpunk logic was: don't trust intermediaries, hold your own keys. FTX looked like proof. And then Coldcard looked like proof of the opposite.

Brian Reed: So the users aren't threat-modeling — they're just pattern-matching to the most recent disaster.

Eliza Ward: Right. And here's where Willy Woo's numbers become the actual punchline. His on-chain figures put self-custody errors at roughly 1.57 million Bitcoin in permanent losses. Exchange losses — roughly 1.51 million. Those are nearly identical.

Brian Reed: Wait — so the flight direction doesn't even matter? You flee to self-custody after FTX, you flee back to exchanges after Coldcard, and the aggregate losses on both sides are basically the same number?

Eliza Ward: That's — yeah. And that reframes the whole question. It's not which model is safer. It's that users are choosing which catastrophe they can tolerate, while believing each time that the direction they're running is the safe one.

Brian Reed: And that — the identical numbers — that's where I want to actually slow down and make the thing click. Because I think the reason people keep running in the wrong direction is they don't have a clean mental model of what key control actually means. Like, forget blockchain for a second. Private keys are the only key to a safe that has no locksmith. There is no locksmith. If you lose that key, the safe stays locked forever. If you hand the key to someone else, you are trusting them completely — not partially, not with a backup — completely.

Eliza Ward: So self-custody is: you keep the key. And a seed phrase — the twelve to twenty-four words — that's literally just a human-readable copy of the key.

Brian Reed: Exactly. And if that copy — that Post-it note, that screenshot, whatever — if it's compromised, you don't get a second chance. A Ledger or a Trezor, MetaMask on your laptop, those are just different ways of holding the same key. The tool changes; the exposure doesn't.

Eliza Ward: Wait — so what does the custodial side actually look like in that analogy?

Brian Reed: You hand the key to a bank manager. They can let you back in if you forget your PIN. They can recover your account. But — they can also go bankrupt. They can get robbed. Mt. Gox. FTX. The bank burns down. Two different failure modes, not two different safety levels.

Eliza Ward: Okay but it gets uncomfortable here. Picture someone — say, a freelancer, forty-eight years old — she reads about self-sovereignty, moves half her Bitcoin off Kraken into MetaMask on her laptop, writes the seed phrase on a Post-it. Still on her monitor. Eight months later she hasn't touched it. She wanted censorship resistance — the guarantee that no third party can freeze her assets. She got operational exposure instead.

Brian Reed: And that's — I mean, that's actually the case CZ made. Binance's own founder cited Willy Woo's figures and said: for users who don't have the discipline to manage keys, handing them to a reputable exchange might actually reduce expected loss. Which is a wild thing for an exchange founder to frame as a risk-reduction argument, but the numbers kind of support it.

Eliza Ward: So the cypherpunk rationale — cut out the intermediary, no counterparty risk — that only holds if you can actually execute the key management. Otherwise you're just creating a different counterparty. Yourself.

Brian Reed: Right. And the part that makes all of this thornier — and we're going to get into this — is what happens when you layer regulation on top of users who are already making fear-driven choices. The Coldcard reversal and what it means for hybrid custody and emerging rules, that becomes genuinely complicated.

Eliza Ward: But here's what the regulation piece actually does to that fear cycle — it doesn't fix it, it just adds a third thing to be scared of. MiCA, DORA, the SEC's proposed custody rules — those impose capital requirements, disclosure obligations on custodial providers. Which sounds like protection, but it also means compliance costs, new points of regulatory exposure. So now you've got users bouncing between two failure modes, and a third layer that could reshape either one mid-swing.

Brian Reed: And the timing on that is — I mean, MiCA is live in the EU right now. These aren't proposed. So the rules land exactly when users are mid-panic from Coldcard, moving assets back to exchanges, and suddenly those exchanges are under new compliance structures they're still figuring out.

Eliza Ward: Wait — so the regulated exchange they're fleeing to is itself in transition.

Brian Reed: Right. And that's where the Coldcard reversal stops being a behavioral curiosity and becomes actually unsettling. Because July 31, 2026 — every day after that date, net flows going back to exchanges. Not slowly. Every. Day. That's not people updating their threat model after careful consideration. That's — imagine someone who moved to self-custody after FTX specifically because they read about counterparty risk, understood it, built a whole rationale around it, and then in August 2026 just... moved their Bitcoin back anyway because Coldcard failed.

Eliza Ward: Their two-year conviction reversed by a single crisis in a different category.

Brian Reed: A different category. FTX was counterparty risk — the institution failed. Coldcard was operational risk — the device or its security model failed. Those are actually distinct threats, right? A rational threat model treats them separately. But users treated them as interchangeable proof that whichever side they were on was wrong.

Eliza Ward: Which is exactly — actually, no, here's the sharper version — that's why hybrid models, multisig, MPC, collaborative custody, sound like the answer but maybe aren't. Adding signatures didn't save Bybit. It created a gap between what the signers believed they were authorizing and what the blockchain actually executed. More complexity, new failure mode.

Brian Reed: So the users who can't stick to a simple custody choice are being pointed toward models that require even more technical sophistication to execute safely. And if they can't thread that needle — and most can't — the regulated custodial exchange is where they land by default. Which is where Willy Woo's numbers just sit there. 1.57 million Bitcoin, 1.51 million. Almost identical. Fear drove the choice both times, and the losses converged anyway.

Eliza Ward: And they converged. 1.57, 1.51. You could flip a coin.

Brian Reed: Yeah. And we started this whole thing with Bybit — a room full of people who believed they'd said no, and the money was already gone. Self-custody done exactly right, best-practice multisig, and it still failed. The numbers on both sides just... sit there equally. You're not picking safe. You're picking which version of gone you'd recognize as yours.

Eliza Ward: And most people pick based on whichever one they read about last.

Why users face an irreducible choice between control and ease of use in crypto · Onpode