Skip to content
MCAP $2.93T ▼-2.94%
BTC $85,508 ▼-0.24%
ETH $2,688 ▼-0.81%
BNB $778.98 ▼-0.93%
XRP $1.500 ▼-0.03%
SOL $120.56 ▲+0.40%
DOGE $0.0936 ▼-1.73%
ADA $0.271 ▲+1.81%
TRX $0.3357 ▼-0.21%
LINK $13.92 ▼-0.03%
AVAX $11.41 ▲+4.78%
HYPE $91.60 ▼-2.29%
DOT $1.210 ▼-0.57%
Custody & security · Foundations

Crypto wallets and self-custody explained: keys, multisig, smart accounts and what Bybit taught

How private keys, seed phrases, hardware wallets, multisig, MPC and smart accounts work, what the Bybit hack and French kidnappings taught, and a costed 2-of-3 multisig setup for a small treasury.

Crypto Coin Show Editorial Desk·Updated October 2, 2026·22 min read·Educational, not investment advice

Key takeaways

  • A wallet holds keys, not coins, and whoever controls the key controls the asset. Chainalysis counted $3.41bn stolen in 2025, with personal wallet compromises making up 44% of the value taken (December 2025).
  • Bybit’s loss of 401,347 ETH, about $1.5bn, on 21 February 2025 broke no key and no contract. Attackers altered the signing interface so that trained multisig signers approved a transaction they could not see.
  • Multisig and MPC remove the single point of failure. Safe smart accounts secured $27.24bn across 63.4 million accounts at the end of Q2 2026, and Fireblocks reports more than 2,400 institutional clients on its MPC platform as of 2026.
  • Ethereum’s Pectra upgrade on 7 May 2025 switched on EIP-7702, letting ordinary accounts borrow smart-account features, but Etherscan found over 97% of early delegations were linked to scams (June 2025).
  • Physical coercion is now a measurable risk: Chainalysis recorded about $30m stolen in wrench attacks in the first half of 2026, and France logged 30 documented cases in that period after 19 in all of 2025 (August 2026).

Who this is for: Investors, founders, treasurers and policy staff who want to understand how private keys, seed phrases, hardware wallets, multisig and smart accounts fit together, and who need to decide, with concrete steps and costs, how an individual or a small company should hold digital assets without relying on an exchange.

Self-custody is the feature that makes crypto different from every other financial asset, and the one most people get wrong. A bank balance is a claim on a bank; a bitcoin or an ether at an address controlled by your own key is a claim on nobody. No counterparty can freeze it or lose it in a bankruptcy, and no counterparty will give it back if you lose the key or sign the wrong transaction.

That trade-off became expensive to ignore in 2025 and 2026. Bybit showed in February 2025 that a well-run exchange using a respected multisig product can lose $1.5bn when the screen its signers trust is lying. Kidnappings in France, including the January 2025 abduction of Ledger co-founder David Balland, showed that key holders are targets. Address poisoning took about $62m from two victims between December 2025 and January 2026, per Scam Sniffer. Meanwhile Ethereum shipped account abstraction features that make wallets easier to use and, in the wrong hands, easier to drain.

This guide explains how keys and seed phrases work, how the wallet types differ, what the last two years taught, how inheritance and institutional rules are evolving, and ends with a costed 2-of-3 multisig for a small company. For qualified custodians and what to ask one, read the companion guide Crypto custody explained.

Self-custody by the numbers

$3.41bnCrypto stolen in 2025, all sourcesChainalysis via The Block, December 2025
44%Share of 2025 stolen value from personal walletsChainalysis, December 2025
$1.5bnBybit loss from a manipulated multisig UINCC Group analysis, February 2025
63.4mSafe smart accounts, $27.24bn securedSafe Ecosystem Foundation, July 2026
$30mStolen in wrench attacks, first half of 2026Chainalysis via The Block, August 2026
2.3-3.7mBTC estimated permanently lostLedger citing analysts, 2025

Keys, addresses and what a wallet actually stores

Every crypto asset is controlled by a pair of numbers. The private key is a 256-bit secret so large that guessing it is impossible. The public key is derived from it by elliptic curve mathematics (secp256k1 on Bitcoin and Ethereum, ed25519 on Solana) in a way that cannot be reversed, and an address is a shortened, checksummed form of the public key. “Sending” coins means publishing a message that moves the balance at address A to address B, with a signature only the holder of A’s key could produce.

So a wallet is key-management software plus a signing engine plus an interface that shows what you are about to sign. Most security design comes from separating those parts, and the failures of 2025 came from trusting one part too much.

Seed phrases and BIP39

Bitcoin Improvement Proposal 39 (BIP39), introduced in 2013, derives every key in a wallet from one root secret encoded as 12 or 24 words drawn from a fixed list of 2,048. The words are not a password; they are the key itself, written so a human can copy it onto paper or steel. Twelve words carry 128 bits of entropy, 24 words carry 256, and the final word includes a checksum that catches most transcription errors. An optional passphrase (the “25th word”) produces an entirely different set of keys from the same words, useful as a duress or decoy layer.

Derivation paths and BIP32/44

BIP32 defines hierarchical deterministic wallets: from the seed a wallet derives a master key and then a tree of child keys, each identified by a path. BIP44 standardises the path as m / purpose’ / coin_type’ / account’ / change / index. The coin_type field is why one seed can back up Bitcoin (0), Ethereum (60), Solana (501) and hundreds of other chains, and the index generates a fresh receiving address for every payment. If a restored seed shows a zero balance in a different wallet, check the derivation path (BIP84 and BIP86 use different purpose fields for SegWit and Taproot) before assuming the coins are gone.

Hot, cold and hardware: the custody spectrum

Wallets are usually sorted by how exposed the private key is to the internet. Each step down the spectrum trades convenience for a smaller attack surface.

Wallet type Where the key lives Main threats Best suited for Typical cost
Exchange account Exchange’s custody systems Insolvency, venue hacks, account takeover, withdrawal freezes Active trading, fiat ramps Trading and withdrawal fees
Hot wallet Encrypted on an online device Malware, phishing signatures, address poisoning, device loss Daily DeFi use, small balances Free
Hardware wallet Secure element on an offline device Blind signing, seed exposure, tampered devices, coercion Long-term holdings, multisig signer keys $79 to $249 per device (2025 pricing)
Deep cold storage Air-gapped device or steel backup only Loss, fire, flood, errors when spending Assets that rarely move $20 to $200 for metal backups
Multisig (M-of-N) Several independent keys, usually on separate hardware Interface manipulation (Bybit), falling below threshold, coordination failure Treasuries, DAOs, families Hardware per signer plus gas
MPC wallet Key shares across servers and devices; no full key exists Provider dependency, policy misconfiguration, insider collusion Institutions, fintechs Subscription or per-transaction fees

A hot wallet such as MetaMask, Phantom or Rabby keeps an encrypted keystore on a laptop or phone. That is fine for the balance you would carry in a physical wallet, but the attack surface includes every browser extension, every website you connect to and every “permit” signature you approve. Scam Sniffer reported that signature phishing alone took $6.27m from 4,741 victims in January 2026.

Hardware wallets

A hardware wallet generates and stores the seed on a dedicated chip and signs internally, so the key never reaches the computer, and the device screen becomes the trust anchor. “Blind signing”, where the device shows only a hash because it cannot decode a contract call, is the weak point, and both major makers spent 2025 on it. Ledger’s Nano Gen5, announced on 23 October 2025 at $179, has a touch E Ink screen built around what Ledger calls clear signing, and launched alongside a Ledger Multisig product aimed at the same gap in team setups. Trezor’s Safe 7, announced the same week at €249, pairs an auditable TROPIC01 secure chip from Tropic Square with an EAL6+ secondary element, adds Bluetooth for the first time on a Trezor and advertises a quantum-ready architecture.

The most conservative pattern is deep cold storage: a seed generated on an air-gapped device, stamped on steel, with the device wiped afterwards. Its failure mode is loss, not hacking. Ledger, citing analysts including Chainalysis, estimated in 2025 that 2.3 million to 3.7 million BTC are permanently lost, roughly 11% to 18% of the 21 million cap.

Multisig and MPC: removing the single point of failure

A single key fails in both directions: lose it or leak it and the funds are gone. Multisig and MPC both require more than one party to approve a transaction, but enforce it in different places.

Multisig: on-chain policy

In a multisig, N independent keys are registered and any M must sign. On Bitcoin this is native to the scripting system, and Casa and Unchained build collaborative custody on it. On Ethereum and compatible chains multisig lives in a smart contract, and Safe (formerly Gnosis Safe) dominates. The contract stores the owner list and threshold and executes only when the threshold is met, so anyone can audit the policy and the account survives any single device failing. Safe’s Q2 2026 report, published 29 July 2026, counted 63.4 million accounts, nearly 130 million transactions in the quarter and $27.24bn of total value locked. Safe also launched Safenet Beta on 2 April 2026, a validator network that checks transactions against predefined policies and had verified more than 500,000 by late July, a direct response to Bybit.

MPC: off-chain threshold signing

MPC keeps a single standard key pair as far as the chain is concerned, but the private key is never assembled. It exists as shares held by different parties (the client’s device, the provider’s servers, a backup) who run a protocol to produce a valid signature without any of them seeing the whole key. Fireblocks, which reports more than 2,400 institutional clients, over 80 banks in production and 550 million wallets created as of 2026, wraps its MPC-CMP signing in a policy engine so that a transfer above a threshold needs approval from named officers. Coinbase is a hybrid: Coinbase Prime handles trading while Coinbase Custody Trust Company, a New York-chartered trust, holds assets in segregated cold storage as a qualified custodian, which is why most US spot Bitcoin ETFs launched in January 2024 named it (see How spot Bitcoin ETFs work).

The trade-offs: multisig is transparent and chain-native but costs more gas, works per chain and exposes the policy publicly. MPC is chain-agnostic, cheap and private, but depends on the provider’s software, which makes vendor due diligence part of the security model.

Smart accounts, passkeys and EIP-7702

Account abstraction makes an Ethereum account programmable, so that who can spend, and under what conditions, is code rather than a single fixed key.

ERC-4337

ERC-4337 went live on mainnet on 1 March 2023 without a protocol change. Users submit UserOperations to an alternative mempool, bundlers package them into normal transactions, a singleton EntryPoint contract validates and executes them, and optional paymasters sponsor gas or accept stablecoins. Because validation lives in the account contract, a wallet can accept a passkey (a WebAuthn credential in a phone’s secure enclave) instead of a seed phrase, enforce daily limits or require a second device above a threshold. Alchemy reported more than 40 million smart accounts deployed by the end of 2024 and over 100 million UserOperations processed.

EIP-7702 after Pectra

Pectra activated on 7 May 2025 and included EIP-7702, which lets an ordinary externally owned account delegate to a contract through a new type 4 “set code” transaction. The account keeps its address but behaves like a smart account, so a user can batch an approve-and-swap, pay gas in USDC or add a session key. A malicious delegation, though, hands control to attacker code. Etherscan reported in June 2025 that over 97% of early delegations were linked to “sweeper” contracts targeting users whose seeds had already leaked. The feature is sound; a prompt to sign a type 4 transaction deserves the scrutiny you would give to handing over your seed.

Smart accounts also enable social recovery: guardians (friends, a hardware device, a lawyer, an institutional service) who can jointly rotate the signing key after a delay if you lose it, a quorum that cannot spend but can restore access. The design questions are who the guardians are and whether the owner can veto during the delay.

What 2025 and 2026 taught about wallet security

Bybit, February 2025: the screen was lying

On 21 February 2025 Bybit moved funds from an Ethereum cold wallet to a warm wallet, a routine operation on a Safe multisig with hardware-wallet signers. The transaction drained 401,347 ETH, worth $1.4bn to $1.5bn at the time, the largest theft in crypto history. Post-mortems by Sygnia, Verichains and NCC Group agreed on the mechanism. A Safe{Wallet} developer machine was compromised, giving attackers access to the infrastructure serving app.safe.global. JavaScript injected two days earlier activated only for Bybit’s signers: when one opened a legitimate transfer, it swapped in a delegatecall to an attacker contract, captured the signature, then restored the display so the next signer saw the original proposal. Once executed, the delegatecall overwrote the proxy’s implementation slot and the attacker owned the wallet. Safe’s contracts were not at fault. The theft was attributed to North Korea’s Lazarus Group; by 4 March 2025 Bybit’s CEO said 77% of funds remained traceable, 20% had gone dark and 3% was frozen, with most ETH swapped to bitcoin through THORChain.

The lesson: hardware multisig protects keys, but if signers cannot read what they are signing on the device itself, the interface is the single point of failure. The fixes that followed were devices that decode Safe transactions and show the real target and calldata, independent verification of the transaction hash, signers on separate machines, whitelists for routine flows, and the Safenet policy layer. Chainalysis noted that Bybit alone was about 44% of the $3.41bn stolen in 2025, and that North Korean actors took a record $2.02bn for the year.

Wrench attacks: when the attacker holds the hammer

The “$5 wrench attack” was the old joke that no cryptography survives a beating. In 2025 it stopped being a joke. On 21 January 2025 David Balland, a Ledger co-founder, and his partner were kidnapped from their home in central France; Balland was mutilated before police freed him. In May 2025 armed men tried to abduct the daughter and grandchild of Paymium chief executive Pierre Noizat in Paris. By 20 June 2025 The Block counted France’s tenth wrench attack of the year, and by April 2026 French prosecutors had charged 88 suspects. Chainalysis reported in August 2026 that about $30m was stolen in wrench attacks worldwide in the first half of 2026, that France recorded 30 documented cases against 19 in all of 2025, that 52% of 2026 incidents were kidnappings and 37% home invasions, and that attackers increasingly target relatives.

The response is operational, not cryptographic: do not be able to move everything alone from home. A multisig with one key in a bank vault, time-locked vaults, a decoy wallet under a BIP39 passphrase and a low public profile change a kidnapper’s calculation.

Address poisoning

Address poisoning exploits the habit of copying a destination from transaction history. An attacker generates a vanity address whose first and last characters match one you have used, then sends a dust or zero-value transfer from it so it appears in your history. A 2025 USENIX study cited by Etherscan found 17.4 million poisoning attempts against 1.3 million Ethereum users between July 2022 and June 2024, with $79.3m of confirmed losses. The attack got cheaper after Ethereum’s Fusaka upgrade in December 2025 cut gas costs: stablecoin dust reached 11% of all Ethereum transactions, one victim lost about $50m in December 2025 and another $12.2m in January 2026, per Scam Sniffer data reported on 9 February 2026. The defence is an address book, verification of the full address on a hardware screen, and a small test transaction before any large one.

Self-custody versus exchange custody

Each option fails in a different way. An exchange account carries counterparty risk: FTX customers learned in November 2022 that assets held by an insolvent platform become part of a bankruptcy estate, a lesson behind the segregation rules covered in SEC vs CFTC crypto regulation. Self-custody removes counterparty risk and replaces it with operational risk: you are now the security team and the estate executor, and the 44% of 2025 theft that came from personal wallets measures how often individuals fail at that job. A sensible split follows purpose: trading capital on a regulated exchange with withdrawal whitelists and hardware two-factor authentication, working balances for DeFi or staking in a hot wallet funded only for the task, and long-term holdings behind a hardware wallet or, once the amount would be painful to lose or dangerous to be known to hold, a multisig.

Inheritance and estate planning

A key that only you know dies with you. A will becomes public in probate, so it must never contain a seed phrase, and a sealed letter with a lawyer creates a single human point of trust. Better structures use the technology: a 2-of-3 multisig with one key held by an heir or executor means nobody can spend while you are alive, but the estate can recover with the second key holder’s help. Casa and Unchained offer inheritance services built on this pattern on Bitcoin, and smart accounts can encode a dead man’s switch that grants a recovery address access after a period of inactivity. The paperwork matters as much as the cryptography: heirs need an inventory of chains, wallets and exchanges, plain-language instructions, derivation paths and passphrases, and a named technically competent person to call.

Institutional self-custody versus qualified custodians

For regulated firms the law constrains the choice, and it moved in 2025 and 2026. In January 2025 the SEC rescinded Staff Accounting Bulletin 121, which had forced custodians to carry client crypto as a liability, and in March 2025 the OCC confirmed that national banks may custody crypto. On 1 October 2026 the SEC voted to propose a custody rule for investment advisers and funds (file S7-2026-35) that would allow an adviser to self-custody a crypto asset only when no qualified custodian is available for it, with quarterly reassessment, at least two authorised individuals approving any transfer and fund board oversight. It would also admit state-chartered trust companies as qualified custodians for crypto if their regulator authorises the activity and they segregate client assets. Comments run 60 days from Federal Register publication; CCS covered the vote in SEC proposes crypto custody rule for investment advisers.

Outside the adviser context, corporates and DAOs face no mandate and choose between a qualified custodian for size and audit comfort, an MPC platform for flexibility, and a Safe multisig for transparency and low cost. Many bitcoin treasury companies use a custodian for the bulk and self-custody for a working float, and most DAO treasuries sit in Safe accounts with elected signers.

How we got here: a timeline

BIP39 proposed. Mnemonic seed phrases turn a 256-bit key into 24 words and make one backup cover every address.

ERC-4337 goes live. The EntryPoint contract launches on Ethereum mainnet, enabling smart accounts without a protocol change.

SAB 121 rescinded. The SEC removes the accounting rule that kept banks out of crypto custody.

Ledger co-founder kidnapped. David Balland and his partner are abducted in France and held for a crypto ransom.

Bybit loses $1.5bn. A compromised Safe{Wallet} frontend tricks hardware-wallet signers into approving a malicious delegatecall.

Pectra activates EIP-7702. Ordinary accounts can delegate to smart-account code; Etherscan soon finds over 97% of delegations tied to scams.

Next-generation hardware wallets. Ledger announces the Nano Gen5 ($179) and Ledger Multisig; Trezor announces the Safe 7 (€249) with an auditable secure chip.

Chainalysis tallies 2025. $3.41bn stolen, 44% from personal wallets, $2.02bn by North Korean actors; Fusaka cuts gas and dust attacks surge.

Safenet Beta launches. Safe adds a validator network that checks transactions against policies before execution.

SEC proposes adviser custody rule. Self-custody permitted only where no qualified custodian exists; state trust companies admitted for crypto.

Worked example: a 2-of-3 multisig for a small company treasury

Assume a ten-person software company holds $600,000 of treasury on Ethereum, $450,000 in USDC and about 50 ETH, currently in the founder’s MetaMask. The goals: no single person can move funds, losing one key does not lose the treasury, and the setup survives the founder being unavailable. Assumptions: Ethereum mainnet, Safe as the multisig, October 2025 hardware prices, and post-Fusaka gas where a simple Safe execution costs a few dollars in quiet conditions.

  1. Define the policy. Three signers, two required. Signer A is the CEO, signer B the finance lead, signer C a backup key held offline in a bank safe deposit box, its location known to the company’s lawyer. Payments above $25,000 need a logged written request before anyone signs.
  2. Buy hardware from the manufacturers. Two Ledger Nano Gen5 at $179 and one Trezor Safe 7 at €249 (about $270), so one vendor bug cannot compromise all three. Never use a second-hand device.
  3. Initialise each device separately. Each signer generates a seed on the device, never typing it into a computer, and stamps it on steel. Signer C’s device and backup are sealed and deposited in the bank box.
  4. Deploy the Safe. From a clean browser profile on a dedicated laptop, create a Safe with the three hardware addresses as owners and a threshold of 2. Record the Safe address, owner addresses and chain internally.
  5. Test before funding. Send $100 of USDC in, then propose a $50 transfer out. Both signing devices must display destination and amount in readable form; if either shows only a hash, stop and fix the setup. Confirm the hash in the Safe interface matches the device and an independent hash tool.
  6. Fund in stages. Move the $600,000 in three transfers, checking the balance after each. Add regular payees to an address book and agree that no address is ever copied from transaction history.
  7. Write the runbook. One page: how to propose, who signs, how to verify, what to do if a device is lost, where the backups are.
Cost line One-off Annual Notes
Three hardware wallets $630 $0 Two Ledger Nano Gen5, one Trezor Safe 7, 2025 list prices
Steel seed backups $120 $0 One per signer
Safe deployment gas $10 to $40 $0 Mainnet, varies with congestion
Bank safe deposit box $0 $60 to $150 Holds signer C device and sealed seed
Transaction gas $0 $100 to $500 50 to 100 payments a year at $2 to $5 each
Total About $800 $160 to $650 Roughly 0.1% of a $600,000 treasury in year one

Failure drills, run quarterly. Drill 1, lost device: signer B wipes their Ledger, restores from steel onto a fresh device and confirms the address matches the Safe owner; if the backup is suspect, A and C sign a swapOwner transaction to replace B’s key. Drill 2, departing signer: A and C rotate the leaver’s owner key the same day and treat the old key as burned. Drill 3, compromised interface: a signer is shown a transaction whose on-device calldata does not match the proposal and must refuse, record it and pause all signing until the frontend is verified from a second machine. Drill 4, address poisoning: finance proposes a payment copied from history rather than the address book, and the second signer must catch it on the device screen. Drill 5, key person unavailable: with A unreachable, B and C execute payroll, which also tests retrieving the box. Each drill takes under an hour.

How to evaluate a wallet or custody setup: a checklist

  • Where does the private key exist in full? An internet-connected device is the attack surface; a hardware secure element, or an MPC scheme where no full key is ever assembled, is the good answer.
  • Can the signer read the transaction on a trusted screen? Bybit’s signers could not. The device must show destination, amount and, for contract calls, the decoded target and function. Blind signing of anything but a simple transfer should be off.
  • How many keys does it take to spend, and who holds them? One key is a single point of failure. For a treasury, two of three independent keys held by different people in different places is the baseline.
  • How many keys can be lost before the funds are lost? A 2-of-3 tolerates one loss. Ask whether backups are tested and survive fire, flood and a house search.
  • Is the interface independently verifiable? Can you compute the Safe transaction hash with a second tool or run the frontend locally? Does the provider offer a policy layer such as Safenet or a Fireblocks-style approval engine?
  • Who knows you hold it? Wrench attacks target visible wealth. Public addresses linked to identities, social posts and leaked customer databases all raise risk.
  • Who can recover the funds if you cannot? A seed in a safe is not a plan unless someone knows it exists and how to use it. Test the inheritance path with the people involved.

Risks and open questions

The largest unresolved risk is the interface. Every gain in hardware security pushes attackers toward the layer between the human and the device: the website, the extension, the app, the clipboard. Clear signing helps only when the signer reads the screen, and people habituate to prompts. Policy layers such as Safenet and institutional MPC engines move the check from a human to a rule, which is more reliable but creates a dependency on the rule’s author and the validator set. Whether these layers can be decentralised without becoming as opaque as the custodians they replace is open for 2027.

Account abstraction widens the gap between what a wallet can do and what a user understands. EIP-7702 delegations, session keys, permit signatures and intents all let one approval authorise a long sequence of actions, and the 97% scam share of early 7702 delegations shows what happens when a feature arrives before wallets have warnings for it.

Physical security has no cryptographic answer. The French experience, including an alleged breach of tax records that exposed high-net-worth holders, suggests leaked data is the upstream problem, which makes data security at exchanges and tax authorities part of crypto security. Finally, the post-quantum question hangs over all elliptic-curve signatures: no practical attack exists, but migration will mean moving funds to new address types, impossible for lost keys.

What to watch next

  • SEC custody proposal comment period, closing about 60 days after Federal Register publication (late 2026). The final shape of the “no qualified custodian available” exception will decide how advisers hold newer tokens in 2027.
  • Chainalysis 2027 Crypto Crime Report, expected early 2027. It will confirm whether 2026 became the worst year on record for wrench attacks and whether personal wallet compromises stayed near 44% of stolen value.
  • French prosecutions of the 88 suspects charged in April 2026, with trials running into 2027. Sentencing will test whether enforcement changes the risk calculation for coercion attacks.
  • Hardware wallet post-quantum roadmaps in 2027. The first firmware shipping a standardised post-quantum algorithm will matter for long-term cold storage planning.

Glossary

Private key
A 256-bit secret that authorises spending from an address. Anyone who has it controls the funds.
Seed phrase (BIP39)
Twelve or twenty-four words encoding the root secret from which all of a wallet’s keys are derived. It is the key, not a password for it.
Derivation path (BIP32/44)
The route from a seed to a specific key, written like m/44’/60’/0’/0/0. Different paths give different addresses from the same seed.
Blind signing
Approving a transaction the device cannot decode, so the signer sees only a hash.
Clear signing
Device-level decoding so the signer can read the real destination, amount and contract action before approving.
Multisig
An arrangement where M of N registered keys must sign. On Ethereum it is implemented by a contract such as Safe.
MPC
Multi-party computation: a key split into shares held by several parties who jointly sign without reconstructing the full key.
Smart account
An account whose spending rules are defined by code, enabling passkeys, limits, batching and social recovery (ERC-4337, EIP-7702).
Address poisoning
A scam that plants lookalike addresses in a victim’s history so they copy the wrong one when sending.
Wrench attack
Physical coercion, including kidnapping or home invasion, to force a key holder to transfer crypto.

Why it matters

Self-custody is what makes a crypto asset bearer property rather than a claim, and every other debate in the industry, from ETFs to stablecoins to DAO treasuries, assumes someone has solved the problem of holding keys safely. The record of 2025 and 2026 says the problem is better understood rather than solved. The technology for eliminating single points of failure exists and is cheap; what failed at Bybit, in the French kidnappings and in the address poisoning cases was process, interfaces and discipline, not mathematics. That shifts the question from “which wallet” to “which failure modes have I removed and which have I accepted”. A reader who can answer that, and has rehearsed losing a key and refusing a transaction that does not match the screen, is better placed than most institutions were in February 2025.

Sources

  1. Safe Ecosystem Foundation: Safe Q2 2026 Quarterly Report, July 29, 2026
  2. NCC Group: In-depth technical analysis of the Bybit hack, February 2025
  3. BleepingComputer: Lazarus hacked Bybit via breached Safe{Wallet} developer machine, February 26, 2025
  4. The Block: Bybit CEO says 20% from $1.4 billion theft has gone dark, March 4, 2025
  5. The Block: Crypto hacks hit $3.4 billion in 2025, attacks on individual wallets rise: Chainalysis, December 18, 2025
  6. The Block: More than $30 million stolen in violent crypto attacks in 2026: Chainalysis, August 6, 2026
  7. The Block: France hit by 10th crypto wrench attack of 2025, June 20, 2025
  8. La Libre: Kidnapping en France, David Balland a ete mutile, January 25, 2025
  9. Etherscan: What you need to know about EIP-7702 smart accounts, June 2025
  10. Alchemy: What is account abstraction, 2025
  11. Etherscan: Address poisoning attacks are rising on Ethereum, March 9, 2026
  12. Cointelegraph: Over $62M lost to address poisoning since December: Scam Sniffer, February 9, 2026
  13. Cointelegraph: Ledger and Trezor 2025 hardware wallets released: what’s new, October 23, 2025
  14. Genfinity: SEC proposes crypto custody rule for investment advisers and funds, October 2, 2026
  15. Stablecoin Insider: Fireblocks review 2026, June 29, 2026
  16. CryptoSlate: Bitcoin’s self-custody culture created an inheritance time bomb, February 28, 2026
  17. Crypto Coin Show: SEC proposes crypto custody rule for investment advisers, October 1, 2026

Disclosure: This guide is for education only and is not investment, legal or tax advice.

Frequently asked questions

What is the difference between a private key and a seed phrase?

A private key is the 256-bit secret that signs transactions for one address. A seed phrase (BIP39) is a set of 12 or 24 words encoding a root secret from which a wallet derives thousands of private keys across many chains. Backing up the seed phrase backs up every key the wallet will ever create, which is why it must be protected as carefully as the funds themselves.

Is a hardware wallet enough to keep crypto safe?

A hardware wallet protects the key from malware on your computer, which removes the most common attack. It does not protect against phishing for your seed phrase, approving a transaction you did not read, address poisoning, or physical coercion. For larger holdings most security specialists add a second layer such as a multisig or a BIP39 passphrase, and rehearse recovery from the backup.

What actually went wrong in the Bybit hack?

On 21 February 2025 attackers linked to North Korea compromised a Safe{Wallet} developer machine and injected code into the Safe web interface that targeted Bybit's signers. The signers saw a routine transfer on screen but their hardware wallets signed a delegatecall that handed control of the multisig to the attackers. About 401,000 ETH, roughly $1.5bn, was drained. The keys and the Safe contracts were never broken.

What is the difference between multisig and MPC?

Multisig registers several separate keys on-chain and requires a threshold of them to sign, so the policy is public and enforced by the blockchain. MPC splits one key into shares held by different parties who jointly produce a single signature without ever assembling the key, so the policy lives in the provider's software. Multisig suits DAOs and small treasuries; MPC suits institutions that need many chains and fast operations.

What does EIP-7702 change for ordinary wallet users?

Since Ethereum's Pectra upgrade on 7 May 2025, a normal account can delegate to smart-account code through a type 4 transaction, enabling batched actions, gas paid in stablecoins and passkey signing while keeping the same address. The risk is that a malicious delegation gives an attacker control of the account; Etherscan found over 97% of early delegations were tied to scams, so any request to sign a type 4 transaction needs scrutiny.

How much does a 2-of-3 multisig cost to set up for a small company?

Using 2025 list prices, three hardware wallets cost about $630, steel backups about $120, and Safe deployment gas on Ethereum mainnet roughly $10 to $40. Ongoing costs are a bank safe deposit box for the backup key and gas for each payment, usually a few hundred dollars a year. For a treasury of several hundred thousand dollars that is well under 0.2% in year one.

How should I plan for heirs to access my crypto?

Never put a seed phrase in a will, which becomes public in probate. Use a structure where heirs or an executor hold one key of a multisig or a sealed backup, keep an inventory of accounts and chains, write plain-language instructions, record derivation paths and passphrases, and name a technically competent helper. Services from Casa and Unchained, and recovery modules in smart accounts, formalise this pattern.

Can a registered investment adviser self-custody crypto?

Under the rule the SEC proposed on 1 October 2026, an adviser could hold a crypto asset itself only when no qualified custodian is available for it, with quarterly reassessment, at least two people approving each transfer and fund board oversight. The proposal would also allow state-chartered trust companies to act as qualified custodians for crypto. It is a proposal with a 60-day comment period, not yet final.

This explainer is reviewed and updated as the rules and the market change. Last reviewed October 2, 2026. It is educational content and not financial, legal or tax advice.

Keep learning