Skip to main content
Back to blog

Custody and self-custody: who can act on your funds?

Keys, recovery, exports and permissions: what custody changes when you make a payment or leave an app.

A hand holds a key in front of another key locked inside a glass box.
On this page

Imagine a payment app becoming unavailable on the morning you need to repay a friend. Yesterday鈥檚 balance may still exist. But who can access it, through which tool, and without waiting for which company? This hypothetical situation makes custody and self-custody concrete.

A balance and the power to move it

A custodial service holds assets or the means of accessing them on your behalf. With a self-custody wallet, you control the keys that authorize transactions. The app鈥檚 name tells only part of the story: almost identical interfaces can give their users very different powers. [1]

That distinction matters during ordinary use and when a service closes, suspends withdrawals or requires access to be restored. A useful comparison examines what you can do in those situations, who can help and which dependencies remain.

A familiar login does not explain the whole setup

Embedded wallets can put a familiar login in front of the technical steps. Privy protects key shares across separate environments and temporarily assembles them for signing; its infrastructure checks the wallet鈥檚 authorization and policies. Protecting keys this way does not, by itself, establish whom the product has authorized to act. [2]

You still need to examine the service鈥檚 configuration: who can sign, which actions can be delegated and what needs your approval. Assuming every wallet created through Google login is controlled exclusively by its user skips this essential step.

An exit you can actually use

Exporting a key may let you use another tool, but conditions matter. Privy distinguishes client-created wallets from server-created wallets. A quorum combining user and application can require both approvals to export; for a smart wallet, the export provides the signer鈥檚 key. An exit promise should explain the process actually available. [3]

Return to our unavailable app: knowing that funds remain recorded on a blockchain does not make them accessible. Understand the recovery process and its requirements before an outage. Never send a private key to support to ask them to check that process.

Other powers remain

Controlling a wallet does not remove the token issuer鈥檚 powers. Circle鈥檚 published contracts include functions to pause activity and block addresses. Tokens can therefore face restrictions even when held in a wallet controlled by their owner. [4]

Spending permissions also matter. ERC-20 allows a third party to transfer tokens up to an approved amount. A transfer without a fresh confirmation may rely on an earlier authorization. Reading and limiting those permissions is part of controlling funds. [5]

Compare three situations: making a payment, losing access and leaving the service. For each, identify who must act and what remains possible without them. That gives you more useful information than treating either custody label as a general guarantee.

Read more: Understanding wallets

Sources

Friends first. Enjoy the good times.