A crypto exchange can fail you while your password is correct. A hardware wallet can fail you while the hardware works perfectly.
Those are different failure classes, which is why “which is safer?” is the wrong way to frame the choice.
For meaningful long-term holdings, I would not make one exchange the entire custody plan. I also would not move a full balance into self-custody until the owner has proved the backup, transaction-verification and recovery process with small amounts.
The practical answer is usually to give each system a narrower job.
Failure drill one: the exchange shows your balance but will not send it
Imagine the market price is unchanged and the account still shows the assets. The problem is access: a withdrawal is held for security review, identity verification, funding-source risk or another account restriction.
Nothing about your investment thesis has to be wrong for that to matter.
Coinbase documents circumstances in which sending can be restricted while an account is under review. Kraken likewise states that it may restrict features or hold crypto withdrawals for security, compliance or scam-prevention reasons. These controls can be legitimate protections and still create a liquidity problem for the customer.
This is the exchange failure you are accepting: another entity controls the signing process and the conditions under which an on-chain withdrawal leaves the platform.
That dependency buys useful things in return—fiat access, order books, account recovery, fraud controls, records and customer support. The mistake is treating convenience as if it removed counterparty risk.
Failure drill two: the hardware wallet is fine, but recovery is not
Now reverse the custody model.
The exchange is no longer required to sign. The owner controls the hardware signer and recovery material. Then the device disappears, or the recovery phrase has been photographed, or a passphrase cannot be reproduced exactly.
The SEC’s December 2025 retail custody bulletin makes the trade-off explicit: self-custody gives the owner control of the private keys and also sole responsibility for protecting them. Loss or theft of the relevant key material can mean permanent loss of access.
This is the self-custody failure you are accepting: there may be no institution capable of restoring the system after your own recovery process fails.
A hardware wallet therefore does not replace “risk” with “safety.” It replaces exchange dependency with owner-operated controls.
The two systems fail in opposite directions
| If this happens… | Exchange account | Hardware-wallet self-custody |
|---|---|---|
| Password or login problem | Recovery process may exist | Device PIN may be reset only by restoring from valid recovery material |
| Platform stops withdrawals | You depend on the platform and its legal/operational process | Not relevant if your signer and network remain usable |
| Recovery phrase is stolen | Usually not your custody model | Potentially catastrophic |
| You approve the wrong on-chain transaction | Platform controls which withdrawals it signs | The signed transaction may be irreversible |
| You need to trade immediately | Assets are already near the market | You normally have to transfer them to a venue or use another execution route |
| Provider becomes insolvent or unavailable | Customer access may depend on legal claims and recovery process | Keys can remain usable independently if the wallet and recovery standards are portable |
The table is not a scorecard. It shows why a person can rationally prefer an exchange for one balance and self-custody for another.
The strongest design is usually a three-layer system
Instead of asking one wallet or one exchange to do everything, separate the jobs.
Exchange: access and liquidity
Keep the amount needed for planned buying, selling or fiat conversion near the market. The relevant question is not a fixed percentage; it is whether losing access to that working balance for days or weeks would create a material problem.
Operational wallet: interaction
Use a separate hot wallet for routine payments, dApps, approvals and experiments. That keeps contract risk away from the keys protecting long-term savings.
Hardware wallet: deliberate savings
Use self-custody for assets that are not needed for routine trading once recovery has actually been tested. The savings signer should have a narrow job and should not become the default wallet for every unfamiliar contract.
This architecture is less elegant than “not your keys, not your coins” or “just use a reputable exchange.” It is more realistic because different tools are good at different failures.
Do not migrate a full balance as your first self-custody test
The dangerous moment is often the transition itself.
A hurried withdrawal can fail through the wrong network, a substituted address, bad recovery material or a wallet that has never successfully sent funds back out. The safer sequence is deliberately boring:
- Initialise the hardware wallet through verified official software.
- Record and protect the recovery material offline.
- Complete the manufacturer’s recovery check.
- Generate a receive address and verify it on the signer.
- Send a small amount from the exchange.
- Wait for confirmation.
- Send part of that amount back out.
- Prove recovery safely before scaling the balance.
- Move the remaining amount in stages rather than one emotional transaction.
A test transfer proves the address path. A recovery drill proves something different: that the wallet still exists after the original device does not.
When more exchange custody is reasonable
Keeping more on an exchange can be rational when the funds are genuinely working inventory, the balance is small relative to the consequence of operational mistakes, or the owner has not yet built a reliable self-custody recovery process.
It can also be rational for a user who values institutional access controls more than bearer-asset finality and understands the counterparty being accepted.
The key is to call that dependency what it is rather than treating a familiar login as risk-free custody.
When more self-custody is reasonable
The case strengthens as the holding period lengthens, the balance becomes more consequential, dependence on one account becomes unacceptable and the owner can demonstrate—not merely describe—the recovery process.
Self-custody is not improved by ideology. It is improved by competence, separation of duties and tested recovery.
The line I would use
If loss of the exchange balance would materially hurt, the exchange balance is too large for a single counterparty. If you cannot restore the hardware wallet from its documented backup, the self-custody balance is too large for your current process.
Those two sentences can both be true at the same time.
For the device side, start with What Is a Hardware Wallet? and the hardware wallet setup checklist. For exchange selection, use the crypto exchange framework. For staged withdrawals, see How to Move Crypto Off an Exchange Safely.








