Go Back

Keys, Wallets and What Owning Crypto Really Means

Keys, Wallets and What Owning Crypto Really Means

Nuwan Liyanage

Nuwan Liyanage

Make Catenaa preferred on (opens in a new tab)

There is no coin to hold. What you own is a very large secret number, and who keeps that number decides everything else.

In Summary

Crypto is not stored anywhere. Your balance is an entry on a shared ledger, and your key authorises changes to it.

A private key produces a public key, which produces an address. Each step works in one direction only.

Guessing a private key is not realistic. The number of possibilities sits close to the count of atoms in the observable universe.

Digital signatures prove you hold a key without revealing it. The secret never leaves your device.

A seed phrase of twelve or twenty-four words encodes an entire wallet. Whoever reads it controls everything.

Custodial means a company holds your keys. You then own a claim on that firm rather than the coins.

Custodial failures are well documented, from Mt. Gox in 2014 to the $1.5 billion Bybit theft in 2025.

Self-custody is not automatically safer. Attacks on personal wallets reached 44% of all stolen value by 2024.

Mistakes are permanent either way. Roughly 1.1 million coins linked to Satoshi have never moved.

In February 2014, the world’s largest bitcoin exchange stopped answering.

Mt. Gox had handled most global bitcoin trading at its peak. Then roughly 850,000 coins went missing, and the company filed for bankruptcy.

Twelve years later, the case remains open. Creditors now have until 31 October 2026, after a third deadline extension. About 19,500 people have received something. Many are still waiting.

That collapse gave crypto its most repeated warning: not your keys, not your coins. To weigh that warning properly, you first need to know what a key actually is.

There Is No Coin

Start by dropping a mental picture.

No bitcoin file sits on a hard drive anywhere. Nothing gets stored, downloaded or moved the way a photo does.

Part 02 described the blockchain as one shared record. Your balance is simply a line in that record. So what do you own? You own the ability to authorise a change to that line.

That ability is a number. A very large, very secret number.

Concept Check

One Number, Two Halves

Every crypto account begins with a private key.

Picture a number somewhere between one and roughly a hundred trillion trillion trillion trillion trillion trillion. Software picks one at random.

From that private key, mathematics produces a public key. That public key in turn produces your address. Critically, each step runs one way only. Going forwards is easy, whereas working backwards is not feasible.

Genuine cryptography. The address was derived using the secp256k1 curve and verified against a standard test vector. Values are truncated for display.

Share the address freely, because that is how people pay you. Guard the private key absolutely, since it is the only thing that can spend.

Concept Check

Proving Ownership Without Revealing Anything

Here is the elegant part.

Spending requires proving you hold the private key. Yet revealing that key would let anybody drain your funds. Digital signatures solve the puzzle. Your wallet combines the payment details with your private key, producing a signature.

Anyone can then check that signature against your public key. It either matches or it does not. The key itself never leaves your device. Only the proof travels.

The trick that makes it all work. You prove control of a secret without ever exposing it. Every crypto payment you make relies on this exchange.
Concept Check

Twelve Words That Contain Everything

Modern wallets do not ask you to save a 64-character key. Instead they hand you a list of ordinary words, usually twelve or twenty-four. That list is your seed phrase.

Those words encode one master number. From it, the wallet derives every key and address you will ever need. The phrase therefore is the wallet. Copy it, and you copy total control.

Lose it, and no support desk can help you. No reset link exists, because no company holds a record.

One backup covers everything. This design is why wallets ask you to write the words down once, then never type them into a website.
Concept Check

Who Is Actually Holding Your Keys?

Now the practical question.

Buy crypto on an exchange, and the exchange normally keeps the keys. Your balance is a database entry at that firm. Arrangements like that are called custodial. Legally, you hold a claim on a company, rather than the coins themselves.

Self-custody flips the relationship. You hold the keys, and no firm sits between you and the ledger. Neither option wins outright. Each simply moves the risk somewhere different.

A middle path exists as well. Multi-signature setups need several keys before funds can move, so losing one key does not lose the balance.

Families and businesses use that design regularly. It adds resilience, though it also adds complexity.

A trade-off, not a ranking. Green lines mark advantages and red lines mark exposures. Many holders split their balance across more than one quadrant.
Concept Check

What Mt. Gox Taught, and Others Repeated

Custodial risk is far from theoretical.

Mt. Gox lost roughly 850,000 coins in 2014. FTX then collapsed in November 2022, owing billions to its customers. February 2025 brought the largest single theft yet. Attackers drained about $1.5 billion from the exchange Bybit.

The FBI attributed that raid to North Korean actors. Across the whole of 2025, Chainalysis counted $3.4 billion stolen.

Notice the pattern running through all three. In each case, a large pool of other people’s keys sat in one place.

Concentrated losses. Chainalysis figures. The 2025 total was dominated by a single February breach, while attacks on ordinary holders grew steadily in the background.

Not one failure mode, but three. Custodial risk is not only about hackers. It also covers insolvency, mismanagement and the misuse of client assets.

Self-Custody Is Not Automatically Safer

Now the balancing point, which crypto marketing tends to skip. Holding your own keys removes company risk. However, it adds personal risk in its place.

Chainalysis found that personal wallet compromises climbed sharply. They reached 44% of all stolen value by 2024. During 2025, the firm logged 158,000 such cases, affecting more than 80,000 victims.

Self-custody also has no undo button. A mistyped address or a lost phrase is normally permanent.

How Personal Wallets Actually Get Lost

The word “hacked” hides what usually happens. Very few people lose coins because someone broke the mathematics. Keys themselves are rarely cracked. Instead, the seed phrase gets handed over. Sometimes willingly, and nearly always by mistake.

A convincing fake app asks you to restore your wallet. You type the twelve words, and the funds leave within seconds. Sometimes a friendly stranger messages you after you post a problem publicly. That helpful person asks for your recovery phrase.

Photographs cause trouble too. A phrase saved in a cloud photo library travels wherever that account travels. Chainalysis noted a further shift during 2025. Attackers hit many more people for smaller sums each.

Individual losses totalled $713 million that year, down from $1.5 billion. Even so, the number of cases climbed. So the weak point is rarely mathematical. It is usually social, and it targets attention rather than encryption.

That is worth sitting with. The strongest part of this system is the maths, and the weakest part is us.

Coins That Can Never Move

Permanence carries a visible cost. Large quantities of bitcoin have not moved in over a decade. Some owners died, while others lost phrases or threw away drives.

Roughly 1.1 million coins linked to Satoshi Nakamoto sit untouched across about 22,000 addresses. Nobody can recover any of it. The same rule that stops thieves also stops rescuers.

Important facts and figures

What Ownership Really Means

Return to the phrase Mt. Gox left behind.

Not your keys, not your coins is accurate, yet incomplete. It describes a trade, not a rule. Custody hands you convenience and a safety net, along with somebody else’s failure risk.

Self-custody hands you control and finality, along with total responsibility. Most importantly, understand which one you have chosen. Plenty of people believe they own coins when they actually own a promise.

Part 04 leaves Bitcoin behind. Ethereum turned the ledger into a computer, which opened doors that Satoshi never designed for.

This article explains how the technology works. It is not financial, legal or security advice, and it does not recommend any wallet, exchange or custody arrangement. Anyone making decisions about meaningful sums should seek qualified independent advice.