Key takeaways
- Keeping crypto on an exchange means trusting that exchange's custody and security practices instead of your own.
- Moving crypto to your own wallet gives you more control, but you become fully responsible for keeping your keys or seed phrase safe.
- There's no universally correct choice — small, active balances and large, long-term holdings often call for different approaches.
- A 'hot' wallet (connected to the internet) and a 'cold' wallet (offline) trade convenience for security in opposite directions.
- Losing a seed phrase with no backup usually means losing the crypto permanently — there's no password reset.
Once you've bought some crypto, a second, less obvious decision follows the first: do you leave it where you bought it, or move it somewhere you control yourself? Both are legitimate — they just carry different kinds of risk.
What "keeping it on the exchange" actually means
When crypto sits on an exchange, the exchange holds the underlying private keys on your behalf — similar in spirit to how a bank holds your money rather than you holding physical cash. You get convenience: easy trading, no keys to lose, straightforward account recovery if you forget a password. The trade-off is that you're trusting the exchange's own security, solvency and operational practices. If an exchange is hacked, mismanaged, or becomes insolvent, customers with funds still on the platform can be affected.
What "self-custody" actually means
Moving crypto to your own wallet means you (not an exchange) hold the private keys — usually represented as a seed phrase, a sequence of words that can restore access to your funds on any compatible wallet. This removes the exchange as a point of failure for your holdings, but shifts responsibility entirely onto you. There is no password reset for a lost seed phrase. No customer support line can recover it. If it's lost or someone else obtains it, the crypto it controls is gone or stolen, permanently.
Hot wallets vs cold wallets
A "hot" wallet is connected to the internet (a phone or browser app) — convenient for regular use, but more exposed to malware, phishing and device compromise. A "cold" wallet (commonly a hardware device) stays offline except when you actively use it, trading convenience for a meaningfully smaller attack surface. Neither eliminates risk entirely; they sit at different points on the same spectrum.
| Approach | You control keys? | Main risk | Best suited to |
|---|---|---|---|
| Exchange custody | No | Exchange hack, insolvency or mismanagement | Active trading, smaller/short-term balances |
| Hot wallet | Yes | Device compromise, phishing | Regular spending/use of crypto |
| Cold wallet | Yes | Losing the physical device or seed phrase | Long-term holding, larger balances |
A reasonable way to decide
Some Australians simply split the decision by purpose: keep an amount you're actively trading or plan to use soon on the exchange, and move anything you intend to hold for the long term into your own wallet. That's not a rule — just one common, sensible pattern. If you do choose self-custody, write your seed phrase down on paper (not a screenshot or cloud note), store it somewhere secure, and never share it with anyone — no legitimate exchange or wallet provider will ever ask for it.
Neither choice is "wrong"
Plenty of long-term holders never move a single coin off an exchange, and plenty of security-conscious users self-custody everything from day one. What matters is understanding which risks you're accepting either way, rather than assuming one option is automatically safer in every situation. If you haven't yet chosen an exchange, our exchange-selection guide covers the custody and security features worth checking upfront.
This is general information, not financial or security advice tailored to your circumstances.