Веерх ↑

Non-custodial wallet

Learn how self-custody wallets work, how they differ from custodial wallets, what recovery phrases mean

A non-custodial wallet, also called a self-custody wallet, is a crypto wallet in which the user controls the private keys or recovery credentials needed to access and move their blockchain assets. The wallet provider may supply the app, interface, or hardware, but it does not normally hold the keys or approve transactions on the user’s behalf.

In practical terms, this means the user can sign and send transactions directly through the wallet. It also means that responsibility for securing the recovery phrase, private keys, devices, and transaction approvals stays primarily with the user.

Core concept: key control

Crypto assets are recorded on a blockchain. A wallet does not physically store coins or tokens; instead, it manages the cryptographic credentials that let a user prove control over assets associated with blockchain addresses.

The central distinction is simple:

  • In a non-custodial wallet, the user controls the private keys or recovery phrase.
  • In a custodial wallet, a third-party provider controls the private keys on the user’s behalf.

Private keys are used to sign transactions. A valid signature tells the blockchain network that the transaction has been authorised by the party who controls the relevant address.

Because the provider does not normally control the private keys in a non-custodial setup, it cannot generally initiate transfers from the wallet as part of normal wallet operation. However, users should understand the permissions they grant to connected apps, smart contracts, or third-party services, because those permissions can create separate risks.

How a non-custodial wallet works

The exact experience depends on the wallet type, but a typical flow includes the following stages.

Wallet creation

When a user creates a wallet, the wallet software generates cryptographic key material. This is commonly represented by a recovery phrase, often a sequence of words that can be used to restore access to the wallet.

The recovery phrase is extremely sensitive. Anyone who gains access to it may be able to restore the wallet elsewhere and control the associated assets.

Address generation

The wallet derives one or more public blockchain addresses from the underlying key material. A public address can be shared with others to receive assets, much like an account identifier.

Receiving assets does not require sharing a private key, recovery phrase, password, or one-time verification code.

Transaction signing

When the user wants to send crypto, the wallet prepares a transaction with details such as:

  • The recipient’s blockchain address
  • The asset and amount to send
  • Network fees
  • The network on which the transaction will be processed

The user reviews and approves the transaction. The wallet then signs it using the private key and broadcasts it to the blockchain network.

Blockchain confirmation

After the transaction is broadcast, network validators process it according to the rules of that blockchain. Once confirmed, the transaction is usually difficult or impossible to reverse.

This is why users should carefully review the recipient address, asset, network, amount, and any smart-contract permissions before confirming a transaction.

Recovery phrase and backups

A recovery phrase, sometimes called a seed phrase or secret recovery phrase, is a backup mechanism for a non-custodial wallet. It can restore the wallet and its associated private keys on another compatible device or wallet application.

Users should treat it like the master key to their funds.

Best practices include:

  • Keep the recovery phrase private and offline.
  • Store it in a secure location that only you can access.
  • Never share it with support agents, websites, social-media accounts, or anyone claiming to represent a wallet provider.
  • Do not enter it into a form, chat, browser extension, or website unless you are certain it is part of a trusted wallet-recovery process.
  • Keep a secure backup plan in case your device is lost, damaged, replaced, or inaccessible.

If a user loses both access to their wallet and the recovery credentials, the wallet provider may be unable to restore the assets. This is one of the most important trade-offs of self-custody.

Non-custodial vs custodial wallets

Feature Non-custodial wallet Custodial wallet
Control of private keys Controlled by the user Controlled by a provider or custodian
Transaction approval User signs transactions directly Provider processes or approves transactions on the user’s behalf
Recovery User relies on a recovery phrase, private-key backup, or wallet-specific recovery method Provider may offer account recovery through its support and identity-verification processes
Responsibility for security Primarily rests with the user Shared with, and often substantially handled by, the provider
Access to blockchain apps Often supports direct interaction with decentralised applications and smart contracts May offer more limited or provider-mediated access
Main trade-off Greater control and autonomy, with greater responsibility Greater convenience and recovery support, with reliance on a third party

Neither approach is universally better. The appropriate choice depends on the user’s experience, security habits, need for recovery support, product requirements, and tolerance for taking direct responsibility for crypto assets.

Types of non-custodial wallets

Non-custodial wallets can take several forms.

Mobile wallets

Mobile wallets are apps installed on a smartphone. They make it convenient to manage assets, scan QR codes, connect to decentralised applications, and approve transactions on the go.

They are convenient but depend on device security. Users should protect the phone with a strong passcode, keep the operating system updated, and avoid installing untrusted apps or profiles.

Browser-extension wallets

Browser-extension wallets run inside a web browser and are commonly used to connect to decentralised applications, exchanges, NFT marketplaces, and DeFi services.

They offer convenience but require extra caution. Fake extensions, malicious websites, phishing prompts, and harmful smart-contract approvals can put assets at risk.

Desktop wallets

Desktop wallets run on a computer and may offer more detailed portfolio or transaction-management features. Their security depends on the computer’s operating-system hygiene, malware protection, wallet password, and recovery-phrase handling.

Hardware wallets

Hardware wallets are dedicated devices designed to keep private keys isolated from internet-connected devices. Transactions are prepared on a computer or phone but are typically reviewed and approved directly on the hardware device.

This can reduce exposure to some online threats, but users must still protect the recovery phrase, verify transaction details on the device screen, and purchase hardware only from trusted sources.

Smart-contract wallets

Some wallets use smart contracts instead of relying only on a single externally owned account. Depending on their design, they may support features such as multi-signature approvals, transaction limits, social recovery, spending controls, or recovery guardians.

These features can improve usability and recovery options, but they also introduce dependency on the wallet’s smart-contract design, supported networks, and implementation security.

Security risks to understand

Non-custodial wallets provide control, but no wallet setup is completely risk-free.

Lost recovery credentials

If you lose your recovery phrase, private key, and device access, recovery may not be possible. Unlike a traditional bank account, there may be no provider with the ability to reset access.

Phishing and impersonation

Scammers may create fake wallet websites, fake support accounts, fraudulent browser extensions, or messages asking for a recovery phrase. Legitimate wallet providers should not need your recovery phrase to provide standard support.

Malware and compromised devices

Malware can attempt to steal credentials, alter copied wallet addresses, capture screens, or manipulate transaction details. Keeping devices updated and using trusted software reduces, but does not eliminate, these risks.

Incorrect addresses or networks

Crypto transfers can be irreversible. Sending the wrong asset, entering the wrong address, or choosing an incompatible network can result in loss of funds or complex recovery procedures.

Malicious smart-contract approvals

When connecting a wallet to decentralised applications, users may be asked to sign messages or approve token allowances. Some approvals can give a smart contract permission to move tokens under certain conditions.

Users should review requested permissions, avoid unknown applications, and periodically revoke approvals they no longer need.

Non-custodial wallets and card products

A crypto card product may support a non-custodial wallet while still requiring separate processes for card issuance, collateral management, payments, compliance, and risk controls.

For example, a user may control their wallet’s private keys, but a secured card programme may require collateral to be transferred, locked, pledged, or otherwise managed under separate product terms before a credit line can be issued. The wallet itself remains a self-custody tool, while the card programme may involve additional contractual and operational arrangements.

Product documentation should distinguish clearly between:

  • Assets held in the user’s non-custodial wallet
  • Assets deposited or committed as collateral
  • Available spending capacity on the card
  • Assets or balances held with any third-party service provider

This distinction helps users understand what they control directly, what may be subject to collateral or programme rules, and which transactions can be reversed, paused, or processed through a card-payment system.

Spend your
crypto.
Don’t sell it
Join the members who figured it out.

Cookies preferences

✕

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

Necessary

Necessary
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

Advertisement

Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.