openskills.info
Course Preview

Wallet and Key Custody

A crypto wallet does not store coins; it stores the private keys that prove you can spend them. Key custody is the set of choices for generating, backing up, and authorizing the use of those keys, ranging from a single device holding one key to schemes that split signing authority across several devices or people, each trading convenience against the risk of loss or theft.

itIdentity, access, and cryptography

Recommended first:web3-application-integration

Don't Panic - Wallet and Key Custody

A crypto wallet has never held a single coin. What it actually holds is a private key - a very large secret number - while the coins just sit on the ledger, waiting for whoever can produce the matching signature. This is, if you sit with it for more than four seconds, a faintly terrifying design. There is no helpdesk. There is no "forgot password" link. There is only the number, and whoever has it.

Before this scheme, wallets generated a fresh random key for every address, which meant a fresh backup for every address, which meant backups nobody actually managed correctly. The fix was the seed phrase: twelve to twenty-four ordinary words that deterministically regrow an entire tree of keys. Lose the device, keep the words, and everything comes back exactly as it was. This is either the most elegant idea in the whole field, or the reason sticky notes with twelve mysterious words on them keep turning up in places they really should not. Possibly both.

Three ideas are worth keeping after this tab closes. A key is proof, not property, so whoever holds it controls the funds completely and irreversibly. One seed backs up everything, so losing that one phrase is catastrophic, and protecting it is the entire job. And custody is not one choice but a spectrum: a single key, a hardware device, a multisig threshold of several keys, a multi-party computation scheme where several parties jointly compute one signature without ever assembling the full key, or a custodian who holds it on someone else's behalf - every point on that spectrum trades convenience for risk in a different place.

Here is the part that will surprise you: adding more signers does not make a wallet unfoolable, only harder to fool. A threshold scheme checks that enough people signed. It cannot check whether what they signed was what they believed they were approving. In February 2025, a multisig holding well over a billion dollars was emptied, not because its cryptography broke, but because a compromised developer machine let an attacker disguise the transaction those signers were approving. Everyone did their job correctly and still approved the wrong thing. The lesson is not that multisig is broken. It is that the interface a signer trusts is part of the custody model, whether or not anyone said so out loud.

So, what to read where. The cheatsheet carries the exact derivation math and the comparison tables, for a dense-facts kind of reader. The practice reference has runnable commands, for anyone who would rather do than read. Field Notes carries the uncomfortable judgment calls nobody puts on a landing page. And the quiz will cheerfully report whether any of this actually stuck. None of it will stop a seed phrase from ending up on a sticky note somewhere. But at least the risk being taken will be an informed one.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources