Crypto winter teaches tough lessons about custody and taking control

CointelegraphPublished on 2022-09-02Last updated on 2022-09-02

Abstract

Many agree that digital assets should be held in hard wallets, but recent actions in the EU and the U.S. may make that more difficult, not easier.

The crypto winter has pumped new life into the adage “Not your keys, not your coins,” particularly after the collapse of some high-profile enterprises like the Celsius Network, whose funds were frozen in June. Just last week, Ledger CEO Pascal Gauthier hammered home the point further, warning: “Don’t trust your coins and your private keys to anyone because you don’t know what they’re going to do with it.”

The basic idea behind the adage, familiar to many crypto veterans, is that if you don’t personally hold your private keys (i.e., passwords) in an offline “cold wallet,” then you don’t really control your digital assets. But, Gauthier was also framing the issue in a larger context as the world moves from Web2 to Web3:

“A lot of people are still in Web2 [...] because they want to stay in the matrix where they’re being controlled, because it’s easier, it’s you know just click yes yes yes and then someone else is going to deal with your problems.”

But, giving away control won’t set you free. “Taking responsibility is how you become free.”

Admittedly, Gauthier has a self-interest here — Ledger is one of the world’s largest cold-wallet providers. Then, too, he may have been stating the obvious. In May, Coinbase acknowledged in an SEC 10-Q filing that if it ever went bankrupt, customers that entrusted their digital assets to the exchange “could be treated as our general unsecured creditors,” i.e., could find themselves standing at the back of the creditors’ line in bankruptcy proceedings.

“It doesn’t matter that the exchange’s contract with you says you ‘own’ the currency,” Georgetown University law professor Adam Levitin told Barron's at the time, “That’s not determinative of what will happen in bankruptcy.”

But, Gauthier’s statement raises other questions, too. This notion of seizing “control” of one’s keys and coins could become more complicated given recent regulatory proposals in Europe, as well as a key government agency interpretation in the United States. Moreover, as the world transitions from Web2 to Web3, is it really so certain that centralized solutions like Coinbase and others might still not have an important role to play with regard to custody and, yes, even privacy?

Learning the hard way

Generally speaking, it appears that consumers still do not understand the potential risks when they turn their crypto private keys over to centralized platforms and exchanges.

“It’s been made abundantly clear that even the most seemingly trustworthy custodians can still make grave missteps with user funds,” Nick Saponaro, CEO at the Divi Project, told Cointelegraph. “The promise of self-sovereign ownership of your money is immediately obliterated when users hand over their private keys to any third-party, regardless of that third-party's genuine intent.”

“All crypto users should learn and be responsible for the security of their own coins by storing them securely on hardware wallets,” Bobby Ong, co-founder and chief operating officer at CoinGecko, told Cointelegraph.“However, this is not a popular move because for most crypto users, it is probably more convenient to store them on centralized exchanges.”

Still, a centralized exchange (CEX) can be useful at times and maybe we should expect to live in a hybrid cryptoverse for a while, with both cold and hot wallets, centralized and decentralized exchanges (DEXs).

“There is a case for using centralized exchanges for sending funds to others to not doxx your crypto addresses,” said Ong. “This is because when you send a transaction to someone else, they will know your address and can see your balance, historical transactions, and all future transactions.”

Indeed, Ong tweeted recently: “The basic advice now is to have multiple wallets for various purposes and to fund these wallets using centralized exchanges. This works well but it’s not good enough. If you use FTX or Binance, Uncle Sam and Changpeng Zao will know all your wallets and they can profile you instead.”

Continued Ong, “To get full privacy for your new wallet, a service like Tornado Cash is needed. Granted, it’s probably more expensive, slow and tedious,” but having such an option would ensure privacy and make crypto behave more like cash, he added.

Justin d’Anethan, institutional sales director at Amber Group, agreed that trade-offs remain. “You can’t do as many sophisticated trades from a private wallet as you can on a centralized platform, or at least not as easily and efficiently,” he told Cointelegraph. Large, sophisticated traders will always need to have some of their holdings on exchanges to optimize returns. In his personal case:

“I hold a chunk of my core holdings in private wallets, but I definitely hold some assets on centralized platforms for yield generation, some rebalancing, etc.”

Corporate entities, especially, may not want to handle the operational side of a trade, including investment and custody, and they may also want to interact with a recognized and established centralized entity that can perform due diligence. Also, corporations may want to have an identifiable and liquid entity to sue “in the event of an error,” added d’Anethan.

On the retail side, setting up a private wallet can still be daunting, which may explain why so many entrust private keys to CEXs and the like, even if it isn’t always the best way. As d’Anethan told Cointelegraph:

“You might not know how — or have the motivation — to buy a private wallet, set it up to hold your private key and bear the risk of losing it. So, the path of least resistance wins.”

Do regulators still not “get it?”

Elsewhere, self-hosted wallet providers may soon face tough regulations in Europe if and when the EU’s Transfer of Funds Regulation (TFR) proposal takes hold. It could overturn this whole notion about taking control of one’s private keys and coins.

“Effectively, it would amount to a ‘de facto’ ban on self-hosted wallets by enforcing to connect personal identities with self-hosted wallets,” wrote Philipp Sandner and Agata Ferreira.

Mikolaj Barczentewicz, associate professor at the United Kingdom’s University of Surrey, told Cointelegraph:

“The TFR proposal doesn’t ban self-custodied wallets, but it does incentivize service providers to treat them as ‘high risk’ for money laundering.[…] It may become practically very difficult to transact using self-hosted wallets.”

Defenders of the TFR might respond that it’s not regulators’ fault that businesses are not better at risk-based analysis and at distinguishing situations of genuinely high risk of criminality, but “I don’t think that answer works,” continued Barczentewicz. “It shows a lack of understanding — or care — for the fact that regulations need to be designed to be workable in the real world. The EU is basically saying to businesses: ‘You figure it out.’”

However, the biggest threat to self-custodied wallets in Barczentewicz’s view “is something like the scenario we’ve been watching in reaction to Tornado Cash being sanctioned by the U.S.: Businesses are afraid and engaging in over-compliance, doing more than the law requires.”

As reported, on Aug. 8, the United States Department of the Treasury’s Office of Foreign Assets Control (OFAC) issued legal sanctions against digital currency mixer Tornado Cash for its role in laundering over $455 million worth of cryptocurrency stolen by the North Korean-linked hacking organization Lazarus Group.

According to data analytics firm Chainalysis, the obligations of non-custodial crypto wallet providers are now unclear under OFAC’s recent designation: “An extreme interpretation could mean that non-custodial wallet providers might also need to block transfers to the sanctioned addresses, though this would be unprecedented.”

At a minimum, government actions like these suggest that cold-wallet solutions to help crypto users take control of their private keys could become more problematic — not less — at least in the immediate future.

An education imperative?

Overall, does the crypto industry face an education challenge here i.e., to explain the importance of cold storage and individual “responsibility” to both individuals and policymakers?

“I think we have to be honest with ourselves,” answered Saponaro. “Yes, education can help some individuals avoid the pitfalls we’ve witnessed in recent months, but most people will not read every article, watch every video or take the time to educate themselves.” Developers have a responsibility to develop products that guide users “into learning by doing.”

“The crypto community, including in the EU, can still do much more to educate policymakers,” added Barczentewicz. “But this education cannot be limited to just explaining how crypto works. It is a mistake to think that once policymakers ‘get it,’ they will come up with sensible rules on their own.”

The crypto community needs to be proactive in proposing detailed technical and regulatory notions of how to fight crime and malfeasance without giving up key benefits of crypto, like self-custody, he said. “It is not enough just to mention buzzwords like ‘zero knowledge proofs’ and then expect the policymakers to do the hard work.”

Is taking “control” really important?

What about Gauthier’s larger point that people simply have to learn to take "responsibility" for their assets — digital and otherwise — because “taking responsibility is how you become free?”

“Crypto is a game-changer because we now have full control of our money without the need to trust any third-party,” said Ong. That said, some people “may choose to pass on the responsibility and trust a third-party custodian who may be better equipped to store their coins safely — and that is acceptable too,” he told Cointelegraph.

“In the crypto space, you typically have very binary opinions about how things can grow from here. I think the truth is somewhat in the middle,” said d’Anethan, adding:

“One is delusional if one thinks every individual and corporate is going full DeFi tomorrow. But, one would also be delusional if one thinks the growing digital world will forever stay within the Web2 infrastructure.”

What may be best is to have both centralized and decentralized platforms, “so that the user base can gradually shift where it sees the most value — however long that takes,” he said.

Trending Cryptos

Related Reads

GPT-5.6 Countdown: Abandon the Illusion of a Single API, Computational Iteration Can't Outpace a Single Page of Compliance

In mid-June, three seemingly independent industry events—the compliance-driven throttling of Fable 5, the open-sourcing of GLM-5.2, and the leaked release timeline for GPT-5.6—are pushing the global AI industry toward a watershed moment. These shifts signal a fundamental restructuring of the industry's underlying logic. First, **"usability" has substantially overtaken "advanced capabilities"** as the primary weight, pushing the global large language model (LLM) supply chain into a "dual-track" phase of controlled closed-source and local open-source coexistence. Second, **the competitive moats of closed-source giants are shifting**. Their technical focus is moving from "language intelligence" toward "spatial intelligence (world models)"—a domain heavily reliant on computing power. Third, faced with常态化 transnational compliance risks, **a "model-agnostic" decoupled design has become a survival necessity for application-layer developers to maintain business continuity.** The article details how Anthropic's Fable 5, despite its advanced engineering feats, was restricted for non-U.S. citizens within 72 hours of launch, highlighting how geopolitical compliance can instantly limit even the most advanced models. In response, the open-source camp, exemplified by Zhipu AI's MIT-licensed GLM-5.2, is gaining market share by offering stable performance improvements and significant cost advantages (up to 70% savings for enterprises), while achieving full adaptation with domestic semiconductor platforms. Meanwhile, closed-source leaders like OpenAI are pivoting. The anticipated GPT-5.6 reportedly shifts focus from language to spatial intelligence and world models, aiming to rebuild a generational gap in areas like 3D understanding, simulation, and industrial design that demand immense compute. The core conclusion is that the LLM supply chain's logic has changed. Enterprises must now evaluate infrastructure based on a composite of technical performance and policy compliance. For developers, complete reliance on a single closed-source API poses unacceptable risk. Implementing a truly model-agnostic architecture—enabling swift switches to compliant, locally deployable open-source alternatives—is no longer just good practice but a fundamental baseline for business continuity.

marsbit55m ago

GPT-5.6 Countdown: Abandon the Illusion of a Single API, Computational Iteration Can't Outpace a Single Page of Compliance

marsbit55m ago

Is the 'Token Subsidy War' Among AI Giants Almost Over?

The article discusses the ongoing "token subsidy war" among AI giants like OpenAI and Anthropic, questioning whether it's nearing its end. It reveals that current AI subscription prices are heavily subsidized, with some plans offering tokens at up to 70 times the actual cost to attract and retain heavy users, especially developers and enterprises. This strategy mirrors past internet-era subsidy battles, but with a key difference: AI tokens lack "lock-in" effects. Unlike ride-hailing or food delivery apps, users can easily switch between AI providers as APIs become standardized, making it difficult for companies to raise prices post-subsidy. The piece highlights a structural asymmetry in the competition. Giants like Google, with massive advertising revenue, can afford to subsidize tokens indefinitely, akin to using "tokens as a weapon." In contrast, venture-backed companies like OpenAI and Anthropic face pressure to become profitable, especially as they approach IPO. The article cites Google Ventures founder Bill Maris, who suggests Google could slash token prices by 80%, putting immense pressure on competitors. Two potential endgames are presented: the "internet service" model (subsidize, monopolize, then raise prices) and the "utility" model (tokens become a standardized, low-margin commodity like electricity). Given the low switching costs, the latter seems more likely. The competition may not have a single winner but could instead accelerate AI's evolution into a foundational, infrastructure-level technology, akin to a public utility. For now, users continue to benefit from heavily subsidized token costs.

marsbit1h ago

Is the 'Token Subsidy War' Among AI Giants Almost Over?

marsbit1h ago

Beyond the Stadium: The Profitable Games Surrounding the World Cup

"Beyond the Pitch: The Profit Game Around the World Cup" The FIFA World Cup transcends being a sporting spectacle, evolving into a massive global arena for speculation and profit-seeking. The 2026 tournament has amplified this dynamic, creating a multi-layered ecosystem of financial opportunism alongside the football. **Prediction markets** have surged into the mainstream. Platforms like Polymarket and Kalshi saw trading volumes for World Cup contracts soar, attracting new users with their financial trading model and high-profile, chain-based wealth stories that overshadow traditional sports betting in terms of growth and narrative. However, **traditional sportsbooks** remain the dominant force, leveraging established user habits, legal markets, and comprehensive product offerings to handle the vast majority of speculative wagers, with projections suggesting record-breaking betting volumes. Capital markets also react. **"Concept stocks"** in countries like South Korea and Japan experience volatile price swings based on team performance and anticipated fan spending on items like chicken, beer, and viewing parties, effectively becoming a stock market reflecting fan sentiment. The **ticket resale market** has become a sophisticated arena for arbitrage. Prices fluctuate wildly based on team draws and star power, with sellers sometimes listing tickets they don't yet own in a practice akin to short-selling, while FIFA's own "Right to Buy" tokens add another layer of speculative trading. **Collectibles and merchandise** offer another avenue. Panini sticker albums, with their inherent scarcity and nostalgic value, can become high-value collectibles. Limited-edition or locally themed jerseys command significant premiums on secondary markets, and even counterfeit vendors profit from fans' desire for affordable match-day identity. The **cryptocurrency** space has seen a frenzy of speculative, unauthorized World Cup-themed meme coins on chains like Solana. These tokens, often exploiting team names and player imagery, experience extreme pump-and-dump cycles, creating stories of massive gains for a few early entrants and steep losses for many others. Finally, an entire industry thrives on **providing information and tools** to other speculators. Developers create platforms like SeatSidekick to track ticket inventory and prices, while paid Telegram groups and subscriptions sell betting tips and predictions, monetizing the widespread desire for an informational edge. In essence, the World Cup has become a compressed, global laboratory for speculation. While the games determine champions on the field, a parallel, complex network of financial transactions—spanning prediction contracts, bets, stocks, tickets, collectibles, crypto, and information services—settles its own scores in the global market.

marsbit1h ago

Beyond the Stadium: The Profitable Games Surrounding the World Cup

marsbit1h ago

How Does Codex Use a Computer? Three Entry Points and Permission Boundaries

This article explains the three primary methods for Codex to interact with a computer, each with distinct use cases, permission boundaries, and trust levels. **1. Computer Use:** This offers the broadest access, allowing Codex to visually control and interact with the graphical user interface of authorized macOS/Windows apps, system settings, and even iOS simulators. It's ideal for tasks lacking APIs or structured tools, such as operating legacy software or multi-app workflows. However, it's the slowest method and has the widest permission scope, requiring careful supervision for sensitive actions. **2. Chrome Extension:** This grants Codex access to the user's logged-in Chrome browser state, including cookies, profiles, and open tabs. It's best for tasks requiring user identity across websites like Gmail, LinkedIn, Salesforce, or internal dashboards. Its key advantage is multi-tab control for complex workflows. While more powerful for browser-based tasks than Computer Use, it carries higher sensitivity as actions are performed under the user's identity. **3. In-App Browser:** This is a browser isolated within the Codex thread, separate from the user's personal browsing data. It excels in web development and debugging scenarios—previewing local servers, testing responsive layouts, or annotating designs directly on the page. Its isolation is a strength for development but a limitation for tasks requiring login sessions. The core principle is to choose the narrowest, safest, and most structured interface for the task. Use plugins or MCPs first, resort to visual control (Computer Use) only for GUI-dependent tasks, employ the Chrome extension for identity-reliant browser work, and prefer the In-App Browser for isolated development. **Appshots** are clarified as a fourth, complementary tool for *inputting* context—capturing a screenshot of a window to point Codex to something—rather than a method for Codex to *act*. Together, this layered approach highlights a key to AI agent productization: not granting unlimited permissions, but constraining them within clear boundaries for specific tasks while preserving user oversight.

marsbit3h ago

How Does Codex Use a Computer? Three Entry Points and Permission Boundaries

marsbit3h ago

Trading

Spot
Futures

Hot Articles

What is $BITCOIN

DIGITAL GOLD ($BITCOIN): A Comprehensive Analysis Introduction to DIGITAL GOLD ($BITCOIN) DIGITAL GOLD ($BITCOIN) is a blockchain-based project operating on the Solana network, which aims to combine the characteristics of traditional precious metals with the innovation of decentralized technologies. While it shares a name with Bitcoin, often referred to as “digital gold” due to its perception as a store of value, DIGITAL GOLD is a separate token designed to create a unique ecosystem within the Web3 landscape. Its goal is to position itself as a viable alternative digital asset, although specifics regarding its applications and functionalities are still developing. What is DIGITAL GOLD ($BITCOIN)? DIGITAL GOLD ($BITCOIN) is a cryptocurrency token explicitly designed for use on the Solana blockchain. In contrast to Bitcoin, which provides a widely recognized value storage role, this token appears to focus on broader applications and characteristics. Notable aspects include: Blockchain Infrastructure: The token is built on the Solana blockchain, known for its capacity to handle high-speed and low-cost transactions. Supply Dynamics: DIGITAL GOLD has a maximum supply capped at 100 quadrillion tokens (100P $BITCOIN), although details regarding its circulating supply are currently undisclosed. Utility: While precise functionalities are not explicitly outlined, there are indications that the token could be utilized for various applications, potentially involving decentralized applications (dApps) or asset tokenization strategies. Who is the Creator of DIGITAL GOLD ($BITCOIN)? At present, the identity of the creators and development team behind DIGITAL GOLD ($BITCOIN) remains unknown. This situation is typical among many innovative projects within the blockchain space, particularly those aligning with decentralized finance and meme coin phenomena. While such anonymity may foster a community-driven culture, it intensifies concerns about governance and accountability. Who are the Investors of DIGITAL GOLD ($BITCOIN)? The available information indicates that DIGITAL GOLD ($BITCOIN) does not have any known institutional backers or prominent venture capital investments. The project seems to operate on a peer-to-peer model focused on community support and adoption rather than traditional funding routes. Its activity and liquidity are primarily situated on decentralized exchanges (DEXs), such as PumpSwap, rather than established centralized trading platforms, further highlighting its grassroots approach. How DIGITAL GOLD ($BITCOIN) Works The operational mechanics of DIGITAL GOLD ($BITCOIN) can be elaborated on based on its blockchain design and network attributes: Consensus Mechanism: By leveraging Solana’s unique proof-of-history (PoH) combined with a proof-of-stake (PoS) model, the project ensures efficient transaction validation contributing to the network's high performance. Tokenomics: While specific deflationary mechanisms have not been extensively detailed, the vast maximum token supply implies that it may cater to microtransactions or niche use cases that are still to be defined. Interoperability: There exists the potential for integration with Solana’s broader ecosystem, including various decentralized finance (DeFi) platforms. However, the details regarding specific integrations remain unspecified. Timeline of Key Events Here is a timeline that highlights significant milestones concerning DIGITAL GOLD ($BITCOIN): 2023: The initial deployment of the token occurs on the Solana blockchain, marked by its contract address. 2024: DIGITAL GOLD gains visibility as it becomes available for trading on decentralized exchanges like PumpSwap, allowing users to trade it against SOL. 2025: The project witnesses sporadic trading activity and potential interest in community-led engagements, although no noteworthy partnerships or technical advancements have been documented as of yet. Critical Analysis Strengths Scalability: The underlying Solana infrastructure supports high transaction volumes, which could enhance the utility of $BITCOIN in various transaction scenarios. Accessibility: The potential low trading price per token could attract retail investors, facilitating wider participation due to fractional ownership opportunities. Risks Lack of Transparency: The absence of publicly known backers, developers, or an audit process may yield skepticism regarding the project's sustainability and trustworthiness. Market Volatility: The trading activity is heavily reliant on speculative behavior, which can result in significant price volatility and uncertainty for investors. Conclusion DIGITAL GOLD ($BITCOIN) emerges as an intriguing yet ambiguous project within the rapidly evolving Solana ecosystem. While it attempts to leverage the “digital gold” narrative, its departure from Bitcoin's established role as a store of value underscores the need for a clearer differentiation of its intended utility and governance structure. Future acceptance and adoption will likely depend on addressing the current opacity and defining its operational and economic strategies more explicitly. Note: This report encompasses synthesised information available as of October 2023, and developments may have transpired beyond the research period.

411 Total ViewsPublished 2025.05.13Updated 2025.05.13

What is $BITCOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of BTC (BTC) are presented below.

活动图片