← back to the blog

Bitcoin Opinion · September 10, 2026

By Adam Whistler

Self-Custody Culture Is Dying, and Nobody's Noticed

An old bank vault door

"Not your keys, not your coins" is one of the most-repeated sentences in Bitcoin, printed on t-shirts, tattooed on forearms, recited at conferences by people who have never once moved their own coins off an exchange. It's become a piece of furniture in the room, something everyone nods along to without checking whether it still describes the room. The idea behind it is older than Bitcoin itself, older than most of the people repeating it, and the actual numbers on how many people practice what it preaches have quietly moved in the wrong direction for the first time in the asset's history. Most holders reciting the phrase haven't noticed. That's worth sitting with.

Where the idea actually comes from

The lineage runs back to 1988, when a former Intel physicist named Timothy May began circulating something he called the Crypto Anarchist Manifesto, handing out photocopies at conferences. May's argument was blunt: computer technology was about to give ordinary people the ability to interact, trade, and negotiate without ever revealing their legal identity, and that shift would fundamentally alter the relationship between individuals and the institutions that had always mediated trust on their behalf, governments, banks, courts. In September 1992, May teamed up with Eric Hughes, a mathematician who'd spent time working with David Chaum, the cryptographer behind some of the earliest attempts at anonymous digital cash, and John Gilmore, Sun Microsystems' fifth employee, to start a small discussion group in the San Francisco Bay Area. A writer and activist named Jude Milhon, who attended those early meetings, coined the name for the group by mashing "cipher" into "cyberpunk": the cypherpunks.

Hughes set up a mailing list to grow the conversation beyond the Bay Area, and it did, fast: roughly 700 subscribers by 1994, nearly 2,000 by 1997, at its peak generating around thirty messages a day of mathematics, cryptography, and increasingly radical political argument. On March 9, 1993, Hughes published "A Cypherpunk's Manifesto" on the list, and its opening lines are the actual root of everything that gets summarized today as "self-custody culture": "Privacy is necessary for an open society in the electronic age. Privacy is not secrecy. A private matter is something one doesn't want the whole world to know, but a secret matter is something one doesn't want anyone to know. Privacy is the power to selectively reveal oneself to the world." The manifesto's practical conclusion was that privacy wouldn't be handed down by governments or corporations out of goodwill. It had to be built, in code, by the people who wanted it. Hughes's own maxim for the group became "cypherpunks write code," a rejection of the idea that political change comes from asking nicely rather than from shipping software that makes the old arrangement obsolete.

From mailing list to whitepaper

The direct line from that mailing list to Bitcoin is a documented lineage, not a loose analogy. Satoshi Nakamoto posted the Bitcoin whitepaper in 2008 on the Cryptography Mailing List, itself a descendant of the same cypherpunk milieu, and the whitepaper's own references cite cypherpunk-era cryptographic work directly. What Bitcoin actually shipped, a system where ownership is defined entirely by knowledge of a private key rather than by an entry in some institution's database, was the cypherpunk demand for individual sovereignty made technically real for the first time. Not a philosophy anymore. A working piece of software that removed the bank, the ledger clerk, and the government registry from the definition of "who owns this," and replaced all three with a number only you know. Self-custody wasn't a feature bolted onto Bitcoin after the fact. It's close to the entire point of why it exists.

The trauma that made the mantra

For Bitcoin's first several years, most people who acquired it kept it on the exchange they bought it from, largely because the cypherpunk argument for doing otherwise was abstract and the exchanges were convenient. That changed in February 2014, when Mt. Gox, at the time handling somewhere between 70% and 80% of all Bitcoin trades globally, halted withdrawals and then announced it had lost 850,000 Bitcoin, roughly 750,000 belonging to customers and 100,000 belonging to the company itself, worth somewhere between $450 and $477 million at the time. Founder Mark Karpelès was eventually convicted, in 2019, not of theft but of falsifying financial records to conceal the losses, and served no prison time. Creditors waited nearly a decade for any repayment at all; distributions finally began in July 2024, by which point Bitcoin's price had risen so dramatically that many creditors received more in dollar terms than they'd originally lost, cold comfort for a decade spent as an unsecured creditor in a Tokyo bankruptcy proceeding rather than an owner of anything.

Mt. Gox is the event that turned an abstract cypherpunk argument into a lived, collective memory, and "not your keys, not your coins" crystallized out of that memory over the years that followed. Its exact origin is unclear; it's not traceable to a single inventor the way Hughes's manifesto is. What is well documented is that Andreas Antonopoulos, without having coined it, became its most effective popularizer, repeating it across talks, books, and interviews until it became the closest thing Bitcoin culture has to scripture. The idea eventually grew an actual annual ritual around it: Proof of Keys, organized by Trace Mayer starting January 3, 2019, Bitcoin's eleventh anniversary, encouraging holders to withdraw their coins from exchanges on that day each year specifically to confirm, in practice rather than in principle, that the keys they thought were theirs actually were.

The lesson relearned, twice more

If Mt. Gox had been an isolated event, the culture around it might have faded. Instead, the lesson got reinforced twice more at painful scale. In 2019, QuadrigaCX, Canada's largest cryptocurrency exchange, lost access to roughly $190 million in customer funds when its founder, Gerald Cotten, died while reportedly the sole holder of the private keys needed to access the exchange's cold wallets. Subsequent investigation suggested a considerably messier picture than a simple tragic accident, but the structural lesson stood regardless: a custodian is only as reliable as its own internal key management, and customers have no way to audit that from outside. Then, in November 2022, FTX, one of the largest exchanges in the world, filed for bankruptcy, and the subsequent accounting was worse than almost anyone expected: the estate later confirmed that FTX held only 0.1% of the Bitcoin and 1.2% of the Ethereum its customers believed it held. Not a rounding error in a spreadsheet. A near-total absence of the assets customers had been shown on a balance in an app.

The private key for every Bitcoin wallet on Earth is on this website, even Satoshi's. But even if you try for a million years, you'll never find a funded one.

Try the key collider now

The reversal nobody quite named

Given that history, you'd expect self-custody's share of total Bitcoin supply to have only climbed. For most of Bitcoin's existence, it did. Then something changed, and the change hasn't been widely named for what it is. Spot Bitcoin ETFs, live in the US since January 2024, use a mechanism called in-kind creation that lets large holders exchange actual Bitcoin directly for ETF shares without triggering a taxable sale, a useful tax feature that has a side effect nobody advertises loudly: it moves real, previously self-custodied coins out of private wallets and into a fund's custodial wrapper. By late 2025, reporting cited by Bloomberg noted that Bitcoin held in self-custody wallets had declined for the first time in roughly fifteen years. The exact current percentage depends heavily on which analytics firm you ask and how they classify a wallet, one August 2026 industry estimate put self-custody at 45.6% of supply with exchanges and custodians at 36.1%, while a separate River Financial report from the same month put self-custody considerably higher, at roughly 65.9%. That's a wide disagreement, and I'd rather name it than pretend one of those numbers is obviously right. What both data sources agree on is the direction: for the first time since Bitcoin existed, the trend line on self-custody turned downward rather than up, and it's turned downward specifically because of the wrapper that's made Bitcoin easiest for institutions to buy.

There's a genuine irony sitting in that fact that the cypherpunks who wrote the founding argument would have recognized immediately. The entire point of "not your keys, not your coins" was to route around exactly the kind of institution that now holds a growing share of the actual supply: BlackRock's IBIT alone held net assets in the tens of billions of dollars by mid-2026, and every one of those shares represents real Bitcoin sitting in a regulated custodian's wallet, not the shareholder's own. Nobody's being deceived here the way FTX's customers were; ETF custody is audited, regulated, and disclosed in exactly the way Mt. Gox's internal Bitcoin holdings never were. But it's still, structurally, the same basic arrangement the founding mantra warned against: trusting someone else's key to represent your ownership. The institutions embracing Bitcoin most enthusiastically right now are, in aggregate, moving the asset further from the cypherpunk ideal it was built to embody, and almost nobody framing it that way in the coverage of "record ETF inflows."

Self-custody isn't risk-free either

It would be dishonest to write all of this as a simple story of virtuous self-custody losing ground to convenient custodial risk, because self-custody carries its own well-documented failure mode, and it's a large one. Chainalysis estimates that somewhere between 3.7 and 3.8 million Bitcoin, close to 20% of everything ever mined, is permanently inaccessible: lost hardware, forgotten passwords, discarded hard drives, seed phrases that died with the person who wrote them down and told no one else. Unlike an exchange collapse, there's no bankruptcy court, no creditor process, no eventual partial recovery. The coins simply sit on the chain forever, visible, verifiable, and permanently out of reach. And self-custody's tooling isn't immune to its own security failures either: a wave of hardware wallet exploits in August 2026 caused an estimated $116 to $130 million in losses, a reminder that "hold your own keys" solves the custodian-risk problem while introducing a different, entirely personal one that most holders are considerably less equipped to manage well than a regulated custodian with a dedicated security team.

The honest version of the argument isn't "self-custody good, custody bad." It's that the two approaches trade one category of risk for a different one, and the cypherpunk case for self-custody was never really a claim that holding your own keys is safer in some actuarial sense. It was a claim that it's safer in a specific, narrower way: nobody else can lose it for you, freeze it, or simply not have it when you come to collect, the exact three things that happened at Mt. Gox, QuadrigaCX, and FTX respectively. That protection is real and it's not nothing. It's also a protection an increasing share of Bitcoin holders are quietly opting out of, in exchange for tax efficiency, convenience, and the reasonable assumption that a regulated ETF custodian isn't going to repeat Sam Bankman-Fried's mistakes.

Does the cypherpunk dream survive this?

I don't think the answer is a clean yes or no, and I'd be suspicious of anyone offering one. The cypherpunk argument was always bigger than any single custody arrangement, it was a claim about what kind of power cryptography could hand back to individuals, and Bitcoin itself, the actual protocol, the actual math, hasn't moved an inch from that founding design. Anyone who wants to hold their own keys still can, with exactly the same guarantees Hughes and May were arguing for in 1993. What's changed is that a growing share of the people who own Bitcoin's economic exposure have decided, rationally, given their own circumstances, that the guarantee isn't worth the operational burden of claiming it themselves. That's not a betrayal of the founding ideology so much as a market answering a question the ideology never quite settled: sovereignty is valuable, but so is convenience, and most people, most of the time, will trade some of the first for enough of the second. The cypherpunks built a tool that makes true ownership possible for anyone willing to accept the responsibility that comes with it. They didn't, and couldn't, make everyone want to.

For more on the practical side of actually holding your own keys, see keeping your private key safe, and for the other side of the custody question, see cold wallets versus hot wallets and the Mt. Gox, Terra, and FTX collapses in full. For a related, less obvious shift in who actually holds the keys, see how social platforms became financial infrastructure.