Binance co-founder and former CEO Changpeng “CZ” Zhao has sparked fresh debate over cryptocurrency security after suggesting that, for many users, keeping digital assets on reputable centralized exchanges (CEXs) may be statistically safer than relying entirely on self-custody.
The comments challenge one of the cryptocurrency industry’s longest-standing principles “Not your keys, not your coins“ by arguing that real-world data paints a more nuanced picture of digital asset security.
Rethinking the Self-Custody Debate
Self-custody has long been promoted as the gold standard for protecting cryptocurrency, giving users complete control over their private keys without relying on third parties.
However, CZ argued that the conversation often overlooks a significant factor: many self-custody losses are never publicly reported.
While exchange hacks typically receive widespread media coverage and transparent disclosure, losses resulting from forgotten seed phrases, misplaced hardware wallets, phishing attacks, compromised devices, or user mistakes frequently remain private.
According to CZ, this creates an incomplete comparison between centralized exchanges and self-managed wallets.
Exchange Losses Are Visible Self-Custody Losses Often Are Not
CZ pointed out that every major exchange breach is extensively documented, scrutinized by the public, and often accompanied by detailed investigations.
Platforms such as Binance have historically compensated affected users through reserve funds or insurance mechanisms after security incidents, limiting customer losses in several high-profile cases.
By contrast, self-custody failures usually occur at the individual level.
Examples include:
- Lost or forgotten seed phrases
- Damaged or discarded hardware wallets
- Phishing attacks
- Malware stealing wallet credentials
- Incorrect wallet backups
- Sending assets to the wrong blockchain or address
Because these incidents are rarely disclosed publicly, the overall scale of self-custody losses may be significantly underestimated.
Human Error Remains the Biggest Security Risk
Rather than software vulnerabilities, many cryptocurrency losses stem from simple operational mistakes.
Security researchers estimate that millions of Bitcoin remain permanently inaccessible because users lost access to their private keys over the past decade.
Unlike centralized exchanges, self-custody provides no recovery process if access credentials are permanently lost.
For inexperienced investors, managing seed phrases, firmware updates, backups, and transaction verification introduces operational complexity that can itself become a major source of risk.
CZ suggested that this human factor deserves greater attention when evaluating different custody models.
Security Depends on the User
The comments do not suggest that centralized exchanges are inherently safer in every situation.
Instead, CZ emphasized that security depends heavily on the individual user’s knowledge, experience, and risk profile.
Large institutional investors or technically sophisticated users may benefit from advanced self-custody solutions such as:
- Multi-signature wallets
- Hardware security modules
- Multi-vendor hardware wallets
- Shamir Secret Sharing
- Multi-party computation (MPC)
Meanwhile, newer retail investors may face greater risks attempting to manage private keys without sufficient operational experience.
Finding the Right Balance
Rather than framing the discussion as a choice between exchanges and self-custody, CZ advocated for a balanced approach.
Many investors already separate assets according to their intended use.
For example:
- Long-term holdings can be secured using cold storage or multi-signature custody.
- Trading capital can remain on regulated, reputable exchanges with strong security practices.
- Smaller balances used for DeFi or everyday transactions can be managed through software wallets with appropriate safeguards.
This diversified approach reduces dependence on any single custody solution while minimizing both operational and counterparty risks.
The Custody Debate Continues to Evolve
CZ’s remarks arrive as the cryptocurrency industry continues to mature following years of exchange failures, high-profile hacks, and increasing institutional adoption.
The collapse of several centralized platforms reinforced the importance of self-custody for many investors, while recent hardware wallet vulnerabilities and phishing attacks have demonstrated that managing private keys also carries significant risks.
As institutional custody providers, regulated exchanges, and decentralized wallet technologies continue to evolve, the conversation is shifting away from absolutes toward practical risk management.
Rather than asking whether exchanges or self-custody are universally safer, the industry is increasingly recognizing that effective security depends on choosing the custody model that best matches a user’s technical expertise, investment strategy, and operational discipline.

