Almost everyone is told this and almost nobody is told what a key actually is. This page explains it in plain English: what you are really holding right now, what has happened to people who got it wrong, and the arrangement we would put in its place.
A bitcoin key is not a file, a password, or a login. It is a very long secret number. Whoever knows that number can move the bitcoin it controls, and nobody who doesn't know it can.
That is the whole system. There is no account in your name, no branch, no manager, no fraud department and no reversal. The network asks exactly one question when bitcoin moves — did whoever signed this know the key? — and if the answer is yes, it moves. It does not ask who they were or whether you meant it.
The twelve or twenty-four words you may have been told to write down are not a separate thing. Those recovery words are the key, written in a form a human can copy without making a mistake. Anyone who reads them has your bitcoin. This is why nobody legitimate will ever ask you for them, and why we never will.
Control of the key is what decides who can spend. The network records which key can move which coins — it holds no record of your name against them.
Which is why the question that matters is not “how much do I have?” but “who could move it, and what happens if something goes wrong with the one copy I've got?”
Nearly everyone is in one of three situations. Two of them have a single point of failure, and the first one isn't self-custody at all.
You do not have a key. You have a row in a company's database and their promise to honour it. The exchange holds the actual keys, pooled with everyone else's.
If the company is hacked, goes under, freezes withdrawals or is found to have been lending your coins out, you are relying on that company's legal and recovery process to get anything back. Whether you rank as an owner of the bitcoin or as one more creditor is decided by a court, and it has gone both ways.
MetaMask, or a phone or desktop app like it. You do hold a key — one key — and it lives on a device that also reads your email and browses the web.
One approval, given once, on a bad afternoon, moves everything. There is nothing behind it. This is the most common way people lose bitcoin they genuinely owned.
A real improvement, and most people stop here. The key is off the internet and you hold it. But there is still only one of it, plus one backup of the words somewhere.
Fire, flood, a failed device, a house move, a burglary, or somebody finding the words in a drawer. One event in the wrong place and it is over, in either direction.
Not obscure outfits. In each case, the largest or one of the largest exchanges of its day, holding coins for ordinary people who believed they owned bitcoin.
None of these people thought they were taking a risk. They thought they owned bitcoin.
What they actually owned was a company's promise — and Celsius froze withdrawals and went under the same year as FTX, with a shortfall of more than a billion dollars, for the same reason. An exchange is a fine place to buy bitcoin. It is not a place to keep it.
Figures rounded. Sources: Mt. Gox bankruptcy filings; FTX Trading Ltd. Chapter 11 proceedings and distribution notices; Ontario Securities Commission report into QuadrigaCX (2020); Chainalysis 2026 Crypto Crime Report. General information only, not advice.
MetaMask is the best-known example, and there are dozens like it for bitcoin — phone apps and desktop programs that let you hold and spend your own coins. They are genuinely useful, and using one means you have taken the first real step: you hold a key rather than an exchange holding it for you.
The problem is where that key lives. A software wallet keeps it on a general-purpose device — the same laptop or phone that opens attachments, installs apps and visits websites. The key is protected by that whole machine being trustworthy, every day, forever.
And the usual attack is not a break-in. It is a request. A site or a message asks you to approve something that looks routine — connect a wallet, verify an account, claim something, sign in. You approve it, because approving things is how these wallets work. That single approval can hand someone else permission to empty the wallet, and it is drained in one transaction while you are still looking at the screen. This is common enough to have a name in the industry: a drainer.
There is nothing to appeal. The network saw a valid signature from the key and did exactly what it is designed to do.
A software wallet is not a bad thing. Being the only key is the bad thing.
Held as one key out of three, a phone wallet is perfectly sensible — if it is compromised, the attacker has one key and one key moves nothing. The danger was never the software. It was that everything depended on it.
Instead of one key that can move everything, several keys exist and a rule says how many of them have to agree.
Think of a safe deposit box that takes two different keys, held by two different people in two different places, and opens only when both are turned. Except you choose how many keys exist, how many are needed, who holds them and where they live.
The most common arrangement is three keys, any two of which can spend. Written down it looks like “2 of 3”. Here is what that actually buys you:
A device dies, a backup is destroyed in a fire, one is simply misplaced. The other two still open it. You still spend normally, and you replace the missing key. Losing one becomes a job to do rather than a catastrophe.
A burglar takes the device off your desk. Someone finds a backup. Your phone is compromised by the same approval that emptied a single-key wallet. One key on its own moves nothing. What a thief may have learned is that you hold bitcoin, which is why we also plan for where the keys are kept and who knows about them.
Because the keys are already separated and written down, the people you nominate can be given what they need to reach the bitcoin together — without any one of them being able to take it alone. That is what Tier 2 builds on.
The design is decided with you on the call, against what you hold and who else is involved. Two shapes cover almost everybody.
The balance point. Enough redundancy that no single loss or theft matters, few enough keys that you can actually keep track of them and explain the arrangement to someone else.
More redundancy and more separation: two keys can be lost entirely and the bitcoin is still reachable. The cost is more devices, more locations and more to document.
It sounds twice as safe and it isn't. There is no spare. Lose either key along with its backups and the bitcoin is frozen for good, with no way back. You have swapped the risk of theft for the risk of loss, and loss is the more common ending.
Convenient, and it doubles your exposure. A thief now has two chances instead of one, and only needs to succeed at either. Redundancy that any single key can use on its own is not redundancy.
We work with bitcoin and nothing else. That is not loyalty. It is that bitcoin enforces the arrangement described on this page as a rule of the network itself, and we would rather do one custody model properly than several partly.
Splitting a wallet across several keys is written into bitcoin’s own rules. Every computer on the network enforces it, and the arrangement is fixed the day it is created. Nobody can quietly change how many keys are needed, or add one later.
Almost everywhere else, the same idea is a program somebody wrote and installed on the network. It runs on one chain at a time, it can be rewritten afterwards, and it is only ever as sound as the code behind it.
So you can spread your keys across devices from different manufacturers, have each device confirm the arrangement on its own screen, and still recover everything using software from someone else entirely.
Other networks can do multi-signature as well. There it is generally a contract deployed on one chain, which is only as sound as its code and can often be changed later by whoever controls it. That is a different security model, not a worthless one — it is simply not the one we have built this practice around.
Every one of those is something you can check for yourself, which is the entire point. We would rather narrow what we do than sell you a version of it we cannot stand behind.
Other things you own may well be worth protecting. They need a different kind of plan, and we will say so on the call rather than stretch this one to cover them.
Then you are already ahead of most people, and you almost certainly do not need to start again. Most current hardware devices can take part in a multi-signature wallet, so if yours is compatible it simply joins your quorum as one of the keys. A Ledger, a Trezor, a Coldcard, a Jade — tell us what you have on the call and we will confirm it before anything is ordered.
Two honest caveats. If the device has been used as a single-key wallet already, we will talk through whether to bring that key across or start it fresh — there are reasons to prefer a clean start, and it is your call. And any device that came to you pre-configured, second-hand, or with recovery words already printed on a card should be treated as compromised and retired, no matter how it looks.
Anything we do order for you is bought sealed from the manufacturer and shipped straight to your door. It never passes through our hands, so we never have physical access to it — and you verify the device is genuine yourself before a key is created on it.
Everything else we do — the succession plan, the private node — is built on top of these. This is the part that shouldn't wait.
While it sits there you are not holding bitcoin, you are holding a claim against a company. Every exchange failure on this page began exactly there.
The single highest-value change most people can makeWhether that key is in a phone app or on one hardware device, one loss or one bad approval ends it. More than one key, and no single event can.
This is Tier 1, and every engagement starts hereYou create every key yourself. We never see, hold or copy one.
We will never ask for your balances, your addresses, your recovery words or a device PIN — not on the call, not afterwards, not ever. If we could recover your bitcoin, then so could someone else, and that is the whole problem we are here to remove.
A free 15 to 20 minute call, with no obligation and no sales pitch. Pick a time and James rings you. We look at what you hold today and where the single points of failure are in it. Bring nothing sensitive. You will come off the call knowing where you stand, even if that is the last you hear from us.