Self-Custody vs Exchange Custody: What Every South African Bitcoin Holder Should Understand
When you buy Bitcoin on an exchange and leave it there, you do not hold Bitcoin. You hold a claim against the exchange. The exchange holds the Bitcoin. This distinction is not a technicality. It is the foundational principle of Bitcoin ownership and the starting point for thinking clearly about custody.
Key takeaway
The history of exchange failures makes the point concrete. Mt Gox collapsed in early 2014 with roughly 850,000 Bitcoin belonging to customers, and FTX wiped out client assets in November 2022 without being hacked in any technical sense. In both cases clients believed they held Bitcoin when what they held was a claim against an entity that failed. Self-custody removes that counterparty risk and hands you the full weight of responsibility. Collaborative 2-of-3 multisig sits between the two, removing the single point of failure that both pure self-custody and exchange custody carry.
The one distinction the whole decision rests on
Two questions decide everything that follows. Who holds the keys, and what happens to your Bitcoin the day the party holding them fails. Exchange custody and self-custody give opposite answers, and the honest comparison is not about which is safer in the abstract but about which set of risks fits the money in front of you.
An exchange holds the keys. You hold a login and a balance that behaves like yours right up until it does not. Self-custody puts the keys in your hands, which removes the exchange from the picture entirely and replaces its risk with your own discipline. Neither of these is free. One asks you to trust a company. The other asks you to trust yourself, your backups and your future memory. Most South Africans I meet have never framed the choice that plainly, because the exchange app makes leaving the coins there feel like the default rather than a decision.
It is a decision. A quiet one, but the most consequential you will make about the asset.
What exchange custody actually is
When Bitcoin sits on an exchange the exchange is the custodian. You have an account, a balance and access credentials, and you can log in whenever you like to watch the number. The private keys, though, are held by the exchange, and your access depends on that exchange staying operational, solvent, honest and legally reachable. In law you are an unsecured creditor of a private company. The balance in the app is a promise, not a coin.
For a small position or a short horizon that promise is a reasonable one to accept. A licensed South African exchange operates inside the FSCA framework, with client asset segregation rules meant to keep your Bitcoin separate from the exchange's own balance sheet, and that separation is a real protection an unlicensed operator cannot offer. The trouble is that segregation on paper and segregation in practice are only the same thing while the operator is honest and solvent. Counterparty risk is the name for the gap between those two states, and it grows quietly as the holding grows, because a licensed, well run exchange is still a single company carrying your savings on its infrastructure, under its governance, at the mercy of its worst decision.
South Africans carry an extra layer here. Bitcoin left on a foreign exchange sits in a cross-border posture that brushes against SARB capital flow rules, while the same Bitcoin in your own local custody keeps a cleaner exchange control story. It is the difference between an asset you can point to and one held offshore that you have to explain.
The failures that keep making the argument
Mt Gox is the case that taught a generation. At its peak it was handling the large majority of all Bitcoin trades on earth, and by early 2014 roughly 850,000 coins belonging to customers had vanished through a mix of weak security and internal rot. Creditors waited more than a decade for partial repayment, and plenty of them had long since stopped believing the money existed.
FTX rewrote the same lesson in November 2022. It was not hacked in any technical sense. The client money was simply not where clients thought it was, spent and lent away behind a slick interface that showed everyone a balance. Both were claims that evaporated, and in both cases the people who lost had done nothing wrong except leave their coins on a platform that looked too big to fold. South Africa has its own entry in that ledger, the local exchange that suspended withdrawals in 2021 after finding holes in its own books and turned its customers into creditors in a liquidation overnight.
None of this is Bitcoin failing.
The protocol processed every one of those collapses without missing a block, a distinction I set out in what has and has not been hacked. Companies holding coins for other people failed, which is a very old kind of failure wearing new branding. The lesson is not that exchanges are evil. It is that an exchange is a fine place to buy Bitcoin and a poor place to leave it.
What self-custody hands you, for better and worse
Self-custody means you hold the private keys yourself, usually on a hardware wallet, a small offline device that keeps the keys away from anything with a network connection. The device signs a transaction when you want to spend, but the keys never leave it in a form anyone could intercept. There is no exchange to fail, no custodian to freeze your account and no support line that could be socially engineered into handing over your balance. The Bitcoin is yours in the most direct sense the technology allows.
The price of that directness is that the responsibility is now entirely yours. Lose the device without a backup, or lose the recovery seed, and the Bitcoin can be gone with no institution to phone and no reversal possible. The seed phrase, the sequence of words your wallet generates at setup, is both the ultimate backup and the ultimate vulnerability, because whoever holds those words holds the coins and whoever loses them loses the coins. Done with care, tested backups and geography between them, self-custody is the most robust ownership Bitcoin offers. Done carelessly it invents risks that leaving the coins on a licensed exchange never would. I set out how to do it without paying the usual school fees in my guide to Bitcoin self-custody in South Africa, from sourcing the device to testing the recovery before a cent moves.
The point of comparing the two is not to crown a winner. It is to notice that self-custody does not remove risk. It relocates it, from a company's balance sheet to your own habits, and for many holders that trade is worth making the moment the number gets serious.
The middle path most larger holders end up wanting
Framed as a straight choice, self-custody and exchange custody each ask you to accept a single point of failure. One careless key loss wipes a self-custodied holding. One exchange collapse wipes a custodial one. For a growing position that is an uncomfortable pair of options, which is why a third arrangement exists and why it suits most of the larger holdings I work with.
Collaborative multisig splits control across several keys so that no single one can move anything alone. In a 2-of-3 setup three keys exist and any two must co-sign for a transaction to be valid. You hold keys, a regulated provider holds one, and the maths does the governing. The provider cannot move your Bitcoin without you, you can move it without depending on the provider day to day, and the spare key is a recovery path for the day one of the others is lost or destroyed. It keeps you in self-custody while removing the lone-key fragility that makes people nervous about holding everything themselves. I explain the mechanics properly in multi-signature Bitcoin custody, and how I run it as a managed service on the Vault page.
For Bitcoin held through a company or a trust this stops being a nicety and becomes the whole point. A board cannot responsibly leave its treasury where one director could move it in an afternoon, and pure self-custody by a single individual is exactly that risk wearing a lanyard. Multisig documents the keyholders, forces two parties onto every transaction by design rather than policy and survives the day a signatory leaves. The governance questions that stall most boards on this asset answer themselves once the structure is in place, which I get into in holding Bitcoin in a company or trust.
Which one is actually right for you
The answer turns on the size of the holding, the horizon you are holding for, the entity the Bitcoin sits in and how much operational discipline you can honestly promise to keep up. There is no universal winner, only a fit.
For a small position over a short horizon, a licensed local exchange is a sensible starting point, and the licensing genuinely counts here. For a growing position you intend to hold for years, and especially for anyone who has decided to treat Bitcoin as a long-term savings vehicle rather than a trade, the custody question earns real attention long before it feels urgent. My own rule is plain enough to say over coffee. Once the Bitcoin is worth more than the cash you would happily leave on a car seat, the keys belong with you, and past the point where a single lost key would ruin your year, the structure should carry the discipline for you rather than resting on your memory.
Self-custody is the most direct ownership on offer and it rewards people who are willing to be methodical. Collaborative multisig is where I steer most serious South African holdings, because it keeps the direct ownership while removing the one mistake that ends the story. Exchange custody earns its place at the buying stage and while a position is small, and loses it as the stakes rise.
Decide the custody before you build the position
The most expensive mistake I see is not choosing wrong. It is not choosing at all, buying the Bitcoin and treating where it lives as a problem for later.
Later tends to arrive as a headline. The real risk in the whole picture is rarely that Bitcoin falls in value, since anyone holding it for years has made peace with the swings. The risk is that the coins become inaccessible or lost through a custody failure nobody planned for, on an exchange that folded or a seed phrase that was never backed up. The custody arrangement deserves to be as deliberate as the decision to buy in the first place, and for a larger or more complex holding that means settling it before the position is built rather than retrofitting a fix once the number is large enough to keep you awake. If you would like to work out which model fits your situation and your entity, you can start a custody conversation with me and we will build it around your life rather than a template.
Frequently asked questions
What is the difference between self-custody and exchange custody?
Exchange custody means the exchange holds the private keys and you hold a login and a balance. You depend on that exchange staying operational and solvent, which makes you an unsecured creditor of a private company. Self-custody means you hold the keys yourself, usually on a hardware wallet, without depending on anyone. Bitcoin on an exchange is a claim against the exchange. Bitcoin in self-custody is a directly held bearer asset that no third party sits between you and.
What is a hardware wallet and how does it protect Bitcoin?
A hardware wallet is a small offline device that stores your private keys away from anything with a network connection. When you send Bitcoin, the device signs the transaction internally without ever exposing the keys. That removes the counterparty risk of an exchange and the malware exposure of a software wallet on a laptop. The one real weakness is losing the device together with the backup seed phrase, which is why tested backups kept in separate secure locations matter more than the brand of device.
What is 2-of-3 multisig and why does it matter for South African holders?
A 2-of-3 multisig wallet uses three keys and needs any two of them to co-sign before Bitcoin can move, so no single key can act alone. Its value is that it removes the single point of failure both pure self-custody and exchange custody carry, where one lost key or one failed exchange ends the story. A collaborative arrangement lets you hold keys while a regulated provider holds one, keeping you in self-custody while adding a recovery path and governance that suit larger holdings, companies and trusts.
Is it safe to leave Bitcoin on a South African exchange?
A licensed South African exchange operating inside the FSCA framework with client asset segregation offers more protection than an unlicensed one, and for a small amount or while you set up proper custody it is a reasonable place to start. For a larger or long-term holding, exchange custody carries counterparty risk that grows with the position. My working rule is that Bitcoin becomes more worth holding in your own custody as the number climbs. You can book a call to work out the right arrangement for your situation.
Secure your Bitcoin properly.
SimplB helps South Africans buy, secure and structure Bitcoin compliantly, as a Juristic Representative of CAEP Asset Managers (FSP 33933).
Book a discovery call