Wallet and Key Custody
A crypto wallet does not store coins; it stores the private keys that prove you can spend them. Key custody is the set of choices for generating, backing up, and authorizing the use of those keys, ranging from a single device holding one key to schemes that split signing authority across several devices or people, each trading convenience against the risk of loss or theft.
itIdentity, access, and cryptography | OpenSkills.info
Recommended first:web3-application-integration
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Wallet and Key Custody
A crypto wallet has never held a single coin. What it actually holds is a private key - a very large secret number - while the coins just sit on the ledger, waiting for whoever can produce the matching signature. This is, if you sit with it for more than four seconds, a faintly terrifying design. There is no helpdesk. There is no "forgot password" link. There is only the number, and whoever has it.
Before this scheme, wallets generated a fresh random key for every address, which meant a fresh backup for every address, which meant backups nobody actually managed correctly. The fix was the seed phrase: twelve to twenty-four ordinary words that deterministically regrow an entire tree of keys. Lose the device, keep the words, and everything comes back exactly as it was. This is either the most elegant idea in the whole field, or the reason sticky notes with twelve mysterious words on them keep turning up in places they really should not. Possibly both.
Three ideas are worth keeping after this tab closes. A key is proof, not property, so whoever holds it controls the funds completely and irreversibly. One seed backs up everything, so losing that one phrase is catastrophic, and protecting it is the entire job. And custody is not one choice but a spectrum: a single key, a hardware device, a multisig threshold of several keys, a multi-party computation scheme where several parties jointly compute one signature without ever assembling the full key, or a custodian who holds it on someone else's behalf - every point on that spectrum trades convenience for risk in a different place.
Here is the part that will surprise you: adding more signers does not make a wallet unfoolable, only harder to fool. A threshold scheme checks that enough people signed. It cannot check whether what they signed was what they believed they were approving. In February 2025, a multisig holding well over a billion dollars was emptied, not because its cryptography broke, but because a compromised developer machine let an attacker disguise the transaction those signers were approving. Everyone did their job correctly and still approved the wrong thing. The lesson is not that multisig is broken. It is that the interface a signer trusts is part of the custody model, whether or not anyone said so out loud.
So, what to read where. The cheatsheet carries the exact derivation math and the comparison tables, for a dense-facts kind of reader. The practice reference has runnable commands, for anyone who would rather do than read. Field Notes carries the uncomfortable judgment calls nobody puts on a landing page. And the quiz will cheerfully report whether any of this actually stuck. None of it will stop a seed phrase from ending up on a sticky note somewhere. But at least the risk being taken will be an informed one.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki
Supports
- Hierarchical deterministic (HD) wallet derivation from one seed via HMAC-SHA512
- Master key and chain code generation
- Normal vs. hardened derivation and the index ranges each uses
- Why hardened derivation is required to prevent a leaked non-hardened child key plus the parent extended public key from exposing the parent private key
- Created date 2012-02-11
- https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki
Supports
- Entropy-to-mnemonic conversion (checksum, 2048-word list, 11-bit groups)
- Mnemonic sizing table (128-256 bits of entropy to 12-24 words)
- Mnemonic-to-seed conversion via PBKDF2-HMAC-SHA512 with 2048 rounds and the "mnemonic" + passphrase salt
- A different wordlist or passphrase producing a completely different seed
- Created date 2013-09-10
- https://github.com/bitcoin/bips/blob/master/bip-0044.mediawiki
Supports
- The m/purpose'/coin_type'/account'/change/address_index path structure
- What each path level means (coin type, account, change, address index)
- Hardened derivation used at purpose, coin_type, and account levels
- The address gap limit of 20 consecutive unused addresses, and the requirement that software warn a user about to exceed it
- Assigned date 2014-04-24
- https://ethereum.org/en/wallets/
Supports
- Wallet categories (hardware, mobile, browser extension, browser, desktop)
- A wallet as a key-management tool rather than a store of funds
- Self-custody versus custodial-exchange distinction
- Seed-phrase backup guidance
- https://ethereum.org/en/developers/docs/accounts/
Supports
- Externally owned account (EOA) versus contract account distinction
- Private key to public key derivation via ECDSA
- Public key to address derivation via Keccak-256 hashing
- Private keys needing to stay private to retain account control
- https://github.com/satoshilabs/slips/blob/master/slip-0039.md
Supports
- Shamir's secret sharing applied to a wallet master secret
- Group and member threshold notation (for example 2-of-4, 3-of-5)
- Fewer than the threshold number of shares revealing no information about the secret
- Published by SatoshiLabs in 2017
- https://docs.safe.global/advanced/smart-account-concepts
Supports
- Safe's owners list and threshold mechanics
- Threshold as the minimum number of owner confirmations required before execution
- Owners and threshold both changeable by existing owners
- https://eips.ethereum.org/EIPS/eip-4337
Supports
- UserOperation as a pseudo-transaction object
- Bundlers collecting UserOperations into one on-chain transaction
- The singleton EntryPoint contract's verification and execution loops
- Programmable smart contract wallet validation (social recovery, session keys, custom multisig) without consensus-layer changes
- Mainnet deployment March 1, 2023
- https://www.fireblocks.com/what-is-mpc/
Supports
- MPC key-share generation and distributed signing without reconstructing the full private key
- Multisig (on-chain, visible threshold) versus MPC (off-chain computation) structural difference
- Chain-agnostic nature of MPC across ECDSA/EdDSA chains
- https://www.ledger.com/academy/glossary/secure-element-se
Supports
- Definition of a secure element as a tamper-resistant chip
- Private keys and entropy generated and staying inside the secure element
- Secure element defenses against fault attacks, side-channel attacks, and cold-boot attacks
- https://www.trezor.io/learn/a/what-is-a-hardware-wallet
Supports
- Private key signing occurring inside the device, isolated from a connected computer
- Hardware wallets protecting against online threats (malware, phishing) while remaining exposed to physical-access threats
- Trezor's open-source firmware claim
- https://trezor.io/blog/news/a-decade-of-pioneering-10-years-since-trezors-first-hardware-wallet-revolution
Supports
- Trezor One launching July 29, 2014, as the first dedicated hardware wallet
- https://trezor.io/trezor-safe-5
Supports
- Trezor Safe 5 carrying an EAL6+ certified secure element chip
- Trezor's open-source firmware pairing with that certified secure element on current models
- https://nextbillion.net/news/mt-gox-files-for-bankruptcy-protection-says-850000-bitcoin-lost
Supports
- Mt. Gox filing for bankruptcy protection on February 28, 2014
- 850,000 BTC reported missing
- https://www.theregister.com/2017/11/10/parity_280m_ethereum_wallet_lockdown_hack/
Supports
- The November 6, 2017 Parity multisig library self-destruct
- A user taking ownership of, then destroying, the shared library contract
- Roughly 280 million dollars in ether made permanently inaccessible
- https://eprint.iacr.org/2019/114
Supports
- Gennaro and Goldfeder's paper "Fast Multiparty Threshold ECDSA with Fast Trustless Setup", published at ACM CCS 2018
- A practical, efficient threshold-ECDSA signing protocol underpinning later MPC wallet custody products
- https://forkast.news/quadrigacx-ceo-dies-customers-cant-get-funds-what-you-need-to-know/
Supports
- QuadrigaCX founder Gerald Cotten holding sole control of customer keys and dying without sharing access
- Roughly 190 million dollars in customer funds becoming inaccessible
- The exchange filing for creditor protection in February 2019
- https://forklog.com/en/ronin-sidechain-developers-reveal-further-details-of-625-million-hack/
Supports
- The March 23, 2022 Ronin bridge hack
- Roughly 625 million dollars (173,600 ETH and 25.5 million USDC) drained via compromised validator signatures
- A spear-phishing attack on a Sky Mavis employee granting access to company infrastructure and validators
- The Axie DAO allowlist grant given in November 2021, the gasless-transaction practice it supported discontinued in December 2021, and access not revoked afterward
- https://forklog.com/en/ledger-to-publish-recover-protocol-code-amid-negative-user-reaction/
Supports
- Ledger Recover announced May 16, 2023, as an optional encrypted seed-backup service split across three custodians
- Community backlash over the tension with "a key never leaves the device"
- Ledger postponing the launch about a week later
- https://thehackernews.com/2023/12/crypto-hardware-wallet-ledgers-supply.html
Supports
- The December 14-15, 2023 compromise of the @ledgerhq/connect-kit npm package
- Root cause as a phished former employee's npm account access
- Malicious code live for roughly five hours before Ledger published a fixed version
- Over 600,000 dollars stolen across multiple dApps
- https://nvd.nist.gov/vuln/detail/CVE-2023-39910
Supports
- CVE-2023-39910 affecting Libbitcoin Explorer's bx seed command
- Root cause as a Mersenne Twister PRNG seeded with 32 bits of system time
- A valid BIP-39 checksum giving no signal about the quality of the underlying entropy
- https://safefoundation.org/blog/safe-ecosystem-foundation-statement
Supports
- The February 2025 Bybit incident traced to a compromised Safe developer machine used to propose a disguised malicious transaction
- No vulnerability found in the Safe smart contracts or the source code of the frontend and services
- Safe fully rebuilding and reconfiguring its infrastructure and rotating credentials afterward
- https://www.theblock.co/post/342667/crypto-exchange-bybit-hacked-as-over-1-billion-worth-of-eth-leaves-wallets
Supports
- The February 21, 2025 date and the over 1.4 billion dollar amount stolen from Bybit's Ethereum cold wallet
- Bybit CEO Ben Zhou's own account that signers saw a masked interface showing the correct address and a Safe URL, while the actual signing message changed the ETH cold wallet's smart contract logic
- https://getfoundry.sh/reference/cli/cast/wallet
Supports
- The cast wallet subcommand list (new-mnemonic, private-key, address, sign, verify, derive, import, list)
- cast wallet private-key deriving a key from a mnemonic via --mnemonic and --mnemonic-index
- cast wallet address, sign, and verify usage for single-key operations
- https://github.com/safe-global/safe-cli
Supports
- safe-cli's unattended-mode send-ether command syntax, including supplying one --private-key flag per signer
- https://github.com/sindresorhus/awesome
Supports
- Starting point used to discover topic-specific awesome lists for the Awesome Links section
- https://github.com/igorbarinov/awesome-bitcoin
Supports
- Curated Bitcoin wallet and key-management tools, used to select Awesome Links entries (Electrum, Sparrow, the BIP39 mnemonic converter, HD Wallet Scanner, PaperVault)
- https://iancoleman.io/bip39/
Supports
- An open-source BIP-39/BIP-32/BIP-44/BIP-49/BIP-84 mnemonic and address derivation tool
- Its own warning against entering a real mnemonic on a networked device
- Offline-use instructions
- https://sparrowwallet.com/
Supports
- Sparrow's single-sig and multisig support across common script types
- Hardware wallet support in USB and airgapped modes
- A transaction editor exposing PSBT contents before signing
- https://electrum.org/
Supports
- Electrum as a long-running Bitcoin HD wallet
- https://github.com/alexk111/HD-Wallet-Scanner
Supports
- A tool for finding every address an HD wallet has used, including addresses past a wallet's default address-gap limit
- https://github.com/boazeb/papervault
Supports
- Offline paper-based secret storage combining AES-256-GCM encryption with Shamir's secret sharing
- https://www.ledger.com/
Supports
- Ledger as a hardware wallet vendor using a secure element
- https://trezor.io/
Supports
- Trezor as an open-source-firmware hardware wallet vendor
- https://keyst.one/
Supports
- Keystone as a fully air-gapped, QR-code-only, open-source hardware wallet with no USB, Bluetooth, WiFi, or NFC connectivity
- https://www.gridplus.io/
Supports
- GridPlus Lattice1's secure-enclave chip design
- A large on-device touchscreen for reviewing full transaction data before signing
- https://safe.global/
Supports
- Safe as an open-source multisig smart contract wallet
- https://www.fireblocks.com/
Supports
- Fireblocks as an MPC-based institutional custody and wallet infrastructure provider
- https://www.turnkey.com/
Supports
- Turnkey's non-custodial wallet infrastructure for developers
- Signing performed inside hardware-isolated secure enclaves (TEEs)
- https://www.bitgo.com/
Supports
- BitGo as an institutional digital asset custodian founded in 2013
- BitGo's federal banking charter status
- https://www.anchorage.com/
Supports
- Anchorage Digital as the first federally chartered digital asset bank in the United States, chartered January 13, 2021
- Qualified, federally regulated custody for institutions
- https://metamask.io/
Supports
- MetaMask as a self-custody browser-extension wallet storing keys locally on-device
- https://github.com/RabbyHub/Rabby
Supports
- Rabby as an open-source browser wallet for the DeFi ecosystem
- https://github.com/RabbyHub/web3-security-engine-core
Supports
- Rabby's security engine evaluating transactions and signature requests against a rule set before signing and reporting which rules matched
- https://www.privy.io/
Supports
- Privy's embedded wallet infrastructure for application developers
- Hardware-isolated key management
- Both custodial and non-custodial wallet configurations offered
