South Africa's Bitcoin specialists. Compliant by design.
Custody & Security · By James Caw · Updated July 2026 · 12 min read

Bitcoin Self-Custody in South Africa: What It Means and How to Do It Properly

Bitcoin on an exchange is a promise from a company. Bitcoin in self-custody is property held directly in your hands. The difference sounds academic until withdrawals freeze, which has happened often enough, including here at home, that the oldest warning in the industry is still the single most useful one: not your keys, not your coins. Here is how South Africans learn to hold their own keys the right way.

Key takeaway

Whoever holds the private keys owns the Bitcoin. Exchanges have failed from Mt Gox in 2014 to FTX in 2022, while the protocol itself has never been cracked. Buy your hardware wallet directly from the manufacturer, keep the seed phrase off every screen, test the recovery before funding the wallet and write down where your heirs can find it all.

What self-custody actually means

Bitcoin is a bearer asset. The private key, a 256-bit number that your wallet presents as a seed phrase of 12 to 24 words, is not a password to an account somewhere. It is the asset. Anyone who holds those words in the correct order can spend the Bitcoin from anywhere on earth without asking a bank, an exchange or me. Anyone who does not hold them, including you after a careless house move, cannot. The phrase everyone quotes, not your keys, not your coins, is just this fact wearing its work clothes.

That single fact drives every decision that follows.

When your Bitcoin sits on an exchange, the exchange holds the keys and you hold an entry in their database. In legal terms you are an unsecured creditor of a private company. The balance in the app looks like yours. It behaves like theirs the moment anything goes wrong, because possession of the keys is the only fact the Bitcoin network recognises.

Self-custody is not one thing either. It runs from a simple wallet app on your phone, which is fine for spending money, through a single hardware wallet and up to a full multisignature vault where no single key can move funds on its own. The right level depends on the size of the holding and on how much sleep the number would cost you if it were ever to vanish without warning.

The exchange failures that keep teaching the lesson

Mt Gox handled around 70% of all Bitcoin transactions at its peak. By early 2014 roughly 850,000 BTC had vanished through a mix of weak security and internal rot. Creditors waited more than a decade for partial repayments and many of them had long stopped believing the money existed. Bitfinex lost nearly 120,000 BTC in 2016 despite running a multisig arrangement with a specialist third party. FTX collapsed in November 2022 without being hacked in any technical sense. The client money was simply not there. The pattern has not retired either: Bybit suffered one of the largest single-exchange hacks on record in 2025.

South Africa has its own entry in that ledger. In March 2021 the local exchange iCE3X suspended trading after reporting discrepancies in its Bitcoin and Litecoin balances, then went into liquidation while clients queued behind the lawyers. Nobody here needed to follow the Tokyo court reports to learn the lesson. It was taught in rand.

None of this is an argument that Bitcoin failed.

The protocol processed every one of those collapses without missing a block, a distinction I set out in what has and has not been hacked. Companies holding coins on behalf of other people failed, which is a very old kind of failure wearing new branding. I put the two models side by side in self-custody versus exchange custody. The short version is that an exchange is a reasonable place to buy Bitcoin and a poor place to leave it.

There is a local layer to the argument as well. South Africans already live with exchange control, with banks that freeze first and ask questions later and with a rand that has lost roughly 70% against the dollar in twenty years. A properly self-custodied Bitcoin position is the one part of your balance sheet where no third party sits between you and your asset. That is a structural statement, not an invitation to hide anything. My clients declare their holdings and follow the rules. The keys being yours and the taxman being paid are two separate things entirely.

Buying and setting up a hardware wallet properly

A hardware wallet is a small offline device that keeps your private key away from whatever malware your laptop has collected over the years. Expect to pay between R2,000 and R10,000. Buy it directly from the manufacturer or a certified reseller, even when that costs more and takes longer. Never buy a second-hand unit and never buy through marketplace platforms like eBay or Takealot, because hardware supply chains get intercepted. A tampered device can arrive with malware installed or its keys already copied by whoever repackaged it. Check that the seals are intact and run whatever verification checks the manufacturer offers before trusting it with a cent.

On brands: I have set up and supported Trezor, Ledger, Coldcard, BitBox and Keystone units over the years and all of them are respectable. The brand counts for far less than the sourcing and the backup discipline that follows it.

Then comes the seed phrase, which is where most people fail. During setup the device will present your 12 to 24 words. Write them on paper and number them so the sequence survives. From that moment those words must never touch anything with a network connection. Do not photograph them. Do not type them into a computer to keep in a file. Do not save them in a cloud note, a password manager or an email draft to yourself. A seed phrase that has been seen by a screen is no longer secure and every rand the wallet will ever hold is at risk. Thieves do not need your device. They need those words.

Paper has its own enemies. It burns, it fades and anyone in George can confirm that it also floods. For any holding you would mind losing, stamp the words into a stainless steel plate. A steel backup shrugs off fire and flood and costs about as much as a tank of petrol.

Most hardware wallets also offer a passphrase, an optional 25th word that opens a hidden wallet on top of the same seed. Used well it is a genuine security layer. The passphrase is useless to a thief without the accompanying seed words, so it can even live in plain sight. Used carelessly it is a trapdoor, because a lost passphrase makes that hidden wallet permanently unrecoverable with no support line to phone. If you use one, back it up separately from the seed and make sure your estate plan knows it exists.

Test the recovery before the money moves

An untested backup is a guess. Before any meaningful amount lands in the wallet, prove that the guess is a fact. Save the wallet's first receive address somewhere convenient. Wipe the device or delete the app entirely. Then restore the wallet from nothing except the words you wrote down. If the restored wallet produces the same receive address, your backup is proven accurate. If it does not, you have just discovered a catastrophic error while it was still free to fix.

Send a small test transaction before the large one, because Bitcoin payments are irreversible and a R200 mistake is a lesson while a R2 million mistake is a life event. When you handle addresses, copy and paste or scan the QR code. Never retype an address by hand. Clipboard malware is a real category of theft, so check the first and last few characters against what the wallet shows before pressing send. Once the test lands, confirm it on a block explorer and move the balance.

I have never met anyone who regretted testing a recovery.

When one hardware wallet is no longer enough

A single hardware wallet has one honest weakness: it concentrates everything in one key. If the device and its seed plate live in the same safe, one burglary or one fire takes both in an afternoon. For smaller holdings that risk is manageable with discipline and geography. Past a certain size the structure itself should carry the discipline for you, which is what multisignature custody does. I cover the mechanics in multi-signature Bitcoin custody. The principle fits in a sentence: several keys, stored apart, with no single one able to move funds.

The SimplB Vault is that principle in managed form, a 2-of-3 multisig where any two keys can move Bitcoin and no single party can ever act alone. You hold two keys on devices from separate manufacturers, a Trezor and a Ledger, each with its own steel backup plate. I hold the third key on an air-gapped Coldcard purely for recovery and inheritance support. You generate your own keys with me guiding every step and I never see or touch them. The recovery process is tested before a single sat moves. The two wallets and two plates end up in four separate secure locations planned around your life, following a rule institutional custody has used for years: no two seed backups are ever stored together. Losing any one key, whether to fire, theft or simple misplacement, never loses the Bitcoin. You replace the lost key and rotate the vault at leisure rather than in a panic.

I do five Vault setups a month, by consultation, because doing them properly takes time.

Self-custody that survives you

Bitcoin held properly can outlive its owner or it can die with him. The difference is documentation. Your will should never contain the seed words themselves, since a will becomes a public document during estate administration. It should contain directions: where the backups are stored, that a passphrase exists if one does and who to contact for help. Multisig estates need one more item that almost everyone forgets, the wallet configuration file, the map that tells recovery software which keys make up the wallet. Without it a full set of seed words can still leave an executor stuck.

The Vault builds the inheritance path in from day one. Your executor does not need to be technical and does not need to track down every device you ever owned. Retrieving any single one of your seed backups is enough, because my Coldcard recovery key co-signs alongside it to reach the 2-of-3 threshold and release the Bitcoin on your estate's instruction. I walk through the estate process in what happens to your Bitcoin when you die in South Africa, including what executors actually face.

Millions of coins are already lost forever. Your family does not need to add to the statistic.

Where guided self-custody fits

My position is easy to state. Once your Bitcoin is worth more than the cash you would happily leave on a car seat, the keys belong with you and the setup deserves to be done once, properly. I offer guided self-custody from R10,000. You perform every sensitive step with your own hands while I watch for the silent mistakes: the unverified backup, the address never checked, the seed word written out of order. Onboarding is FICA-compliant through CAEP Asset Managers (FSP 33933), so holding your own keys and staying a compliant taxpayer were never in tension.

The mistakes in self-custody are front-loaded. Almost everything that goes wrong goes wrong early, in the setup itself, in the backup that was never tested, in the photo taken for convenience. That is exactly the stretch where guidance earns its keep. After that the discipline becomes boring, which in custody is the highest compliment available.

Frequently asked questions

What is the safest way to store Bitcoin in South Africa?

For meaningful holdings, a 2-of-3 multisig vault with keys stored in separate locations. It removes the single point of failure that a lone hardware wallet carries while keeping every transaction under your control. For smaller amounts, a hardware wallet bought directly from the manufacturer, backed up on steel and tested by restoring from the seed, does the job well.

Can I lose Bitcoin in self-custody?

Yes, though the risk sits with your own key management rather than anyone else's balance sheet. A lost seed phrase with no backup means the Bitcoin is gone for good. The fix is process: written and numbered seed words, a steel backup stored away from the device and a recovery test done before any real money moves.

Is it safe to buy a hardware wallet on Takealot or eBay?

No. Buy directly from the manufacturer or a certified reseller even if it costs more. Marketplace and second-hand devices can be intercepted and tampered with, arriving with malware installed or the keys already copied. Check that the seals are intact when the device arrives and run the manufacturer's verification checks before using it.

How do I move Bitcoin off an exchange safely?

Set up the receiving wallet first and prove the backup works by wiping and restoring it before anything moves. Send a small test amount, verify it arrives at an address you checked character by character and only then transfer the balance. The withdrawal itself is the easy part. The preparation is the actual work.

Does SimplB take custody of my Bitcoin?

No. In the Vault I hold one key of three on an air-gapped Coldcard, used only for recovery and inheritance support. Your two keys meet the signing threshold on their own, so you can always transact without me. I cannot move your Bitcoin alone and the structure ensures nobody else can either.

Self-custody, without the school fees

SimplB helps South Africans buy, secure and structure Bitcoin compliantly, as a Juristic Representative of CAEP Asset Managers (FSP 33933).

Book a discovery call