First steps

From Exchange to Self-Custody

Move your bitcoin, secure the backup, and prove you can recover it.

Beginner About 20 minutes Updated Aug 17, 2026
OverviewStart here

There is a version of this that takes an afternoon and a version that takes six months. The difference is not intelligence or technical skill — it is whether you moved money before you understood what you were doing with it.

This is the whole path, start to finish: from having an account on an exchange to holding bitcoin in a wallet you control and have proven you can recover. Five stages, each with one outcome. Work through them in order.

The rule that makes this work: do not move on until you can explain the outcome of the current stage in your own words. Not recite it — explain it, to yourself, without looking. Every expensive mistake in bitcoin custody is someone who skipped that check because they were nearly sure.

A desk laid out for a setup session: hardware wallet still boxed, a seed card and pen, a laptop closed, a cup of coffee. Calm and unhurried.

Image to come

Set aside a proper block of time. This is not a thing to do between meetings.

1Understand what you own

A bitcoin wallet does not hold coins the way a physical wallet holds notes. There is nothing inside it to spill. What it actually holds is keys, and what it actually does is construct transactions and sign them.

The bitcoin itself lives on the network, as records of outputs that particular keys are allowed to spend. Your wallet is the thing that proves you are allowed. This distinction sounds academic until the first time someone tells you they "moved their bitcoin into a hardware wallet" and you realise nothing moved anywhere — the authority to spend changed hands, which is a different and much more interesting thing.

The four words everything else assumes

  • Private key — the secret that authorises a spend.
  • Recovery words — human-readable backup material that can recreate every key in the wallet.
  • Address — a destination you can share to receive bitcoin.
  • UTXO — one individual chunk of bitcoin your wallet can spend. Your balance is a pile of these, not a single number.

Outcome: you can say what your recovery words actually are, and why anyone holding them owns your bitcoin regardless of what device you bought.

2Choose the setup

There are three broad shapes, and the honest answer is that most people should start with the simplest option and move through them slowly over years — not pick the most complex one because it sounds the most secure.

Mobile Hot Wallet

Protects against
The exchange failing, freezing, or losing your account.
Trade-off
Your keys sit on an internet-connected, general-purpose device.
Advantages
Fast to start, inexpensive, and useful for learning with smaller amounts.

Cold Wallet

Protects against
Malware on your computer or phone reaching your keys.
Trade-off
A device to buy, and a backup you must store and test.
Advantages
Keys stay isolated from everyday devices while recovery remains straightforward.

Multisig Wallet

Protects against
Any single key being lost, stolen, or coerced.
Trade-off
Several backups plus the wallet configuration, and a genuinely harder recovery drill.
Advantages
Removes any one key as a single point of failure and supports geographic separation.

Multisig removes the single point of failure, which is real and valuable. It also multiplies the number of things you must back up, and adds a new category of loss: a setup that nobody — including you — can actually restore. Reach for it when you have already demonstrated you can recover a simple wallet.

Compare hardware   Compare wallet software

Outcome: you have picked one shape and can say what it protects against and what it asks of you.

3Set up and back up

This is where the wallet gets created and where the only truly irreplaceable thing — your recovery words — comes into existence. Everything here is worth doing slowly.

  • Inspect the packaging and authenticate the device using the maker's official app or process.
  • Generate a new wallet on the device. Never use words that were supplied in the box.
  • Write the recovery words offline, in order, by hand. Do not photograph them.
  • Complete the confirmation step when prompted — it catches transcription errors while they are still fixable.
  • Store the device and the backup separately, so one theft, fire, or flood cannot take both.

Close-up of a hand writing recovery words onto a numbered backup card, hardware wallet screen visible but deliberately out of focus so no real words are legible.

Image to come

By hand, in order, offline. This is the step with no undo.

A passphrase is not a casual extra password

A forgotten or mistyped BIP39 passphrase does not lock you out with an error — it silently opens a different, empty wallet. Add one only when you understand the recovery procedure and have a durable way to preserve it. If you do use one, write down that you used one.

Outcome: the wallet exists, the words are recorded somewhere durable and offline, and the device and backup are not in the same place.

4Withdraw carefully

The first withdrawal is the one that teaches you whether any of the previous stage actually worked. Treat it as a test, not a transfer.

  • Create a fresh receive address in your wallet.
  • Verify the full address on the hardware device screen, not only on the computer.
  • Send a small test withdrawal first and wait for it to confirm.
  • Confirm it arrived in your wallet before sending anything larger.
  • Understand the platform fee, the withdrawal fee, and the network fee before approving — they are three different charges.

The reason for checking the address on the device rather than the screen is specific: malware that swaps addresses in the clipboard is common, cheap, and invisible. The computer shows you what the attacker wants you to see. The device does not.

Compare Canadian purchase routes

Outcome: bitcoin has moved from a platform to a wallet you control, and you watched it arrive.

5Prove you can recover

A backup you have never tested is not a backup. It is an assumption, and you will discover whether it was correct at the worst possible moment.

After the first small transaction, and before you commit real savings, follow your device maker's documented recovery-check procedure or restore the words into a wiped spare device. Confirm the wallet fingerprint, the addresses, or the balance match what you expect. This is the single highest-value hour in the whole path.

A second, wiped hardware wallet part-way through a restore, seed card beside it, with the first device powered off in the background.

Image to come

A restore you have actually performed is worth more than any amount of care taken earlier.

Then keep it working

  • Check backups periodically for legibility and environmental damage.
  • Keep an inheritance instruction that explains the process without exposing the secret.
  • Download wallet software only from official sources, and verify releases where supported.
  • Re-evaluate single-signature versus multisig as the amount and the consequences change.

Outcome: you have restored this wallet at least once, deliberately, and know it works.

Where to go from here

Those five stages are the whole of it. Everything else on this site — multisig, passphrases, dice entropy, coin control — is refinement on top of a foundation that has to be solid first.

Read the failure modes next

These five stages describe what to do. What not to normalize describes the six ordinary habits that quietly undo them, and it is worth reading before you move an amount you would miss.

Do not guess

Stuck on a step?

If the screen in front of you does not match the guide, stop. Review the related walkthroughs or get a second set of eyes before exposing recovery words or approving a transaction.