Custodial vs non-custodial: who holds your money?
Custodial means a company holds the keys that control your funds, so you rely on that company. Non-custodial, or self-custody, means you alone control the keys that move the funds, so security is your responsibility. Embedded wallets are in-app wallets that aim to be non-custodial without a seed phrase.
On this page
- What do custodial and non-custodial mean?
- How do custodial, non-custodial and embedded wallets compare?
- Is money in a custodial crypto account covered by deposit insurance?
- Does self-custody mean nobody else can touch my tokens?
- What does self-custody ask of you?
- How does this work in Neovestor?
- What questions show who holds your money?
- Frequently asked questions
- Sources
Every wallet, exchange account and crypto app answers one question before any other: who holds the keys? The answer decides who can move your funds, who you depend on if something goes wrong, and which protections apply. This guide defines custodial and non-custodial in plain terms, compares them with embedded wallets, explains what deposit insurance does and does not cover, and shows where self-custody still has limits. The wider topic lives on the self-custody page.
What do custodial and non-custodial mean?
Custodial means a company holds the keys that control your funds and you rely on that company, while non-custodial, also called self-custody, means you alone control the keys that move the funds. A private key is the secret that authorizes transactions from an address on a blockchain, so whoever controls the key controls what sits at that address.
The wallet guide on ethereum.org draws the same line. It says "Wallet providers don't have custody of your funds" and that users are responsible for keeping their own keys secure. It describes a wallet as "a window to see your assets" and "a tool for interacting with your Ethereum account." It then contrasts this with exchange accounts: "you're trusting that exchange with custody over your funds."
The word "wallet" can hide this distinction. A wallet app is a window onto assets that sit on a blockchain. What matters is who holds the keys behind the window, because that party is the one who can approve a transaction.
How do custodial, non-custodial and embedded wallets compare?
The three models differ mainly in who holds the keys, who approves a transaction and what you depend on to get back in. A seed phrase is the list of words that backs up the keys of a conventional wallet. An embedded wallet is a wallet created inside an app and designed so that you use it without managing a seed phrase or private key directly, as Privy's documentation describes it.
| Custodial account | Self-custody wallet with a seed phrase | Embedded wallet | |
|---|---|---|---|
| Who controls the keys | The company | You | You, with key handling built into the app (details vary by provider) |
| Who approves a transaction | The company carries out your request | You sign it | You approve it in the app |
| What you depend on | The company's systems, terms and financial health | Your own backup and device security | Your login and the provider's service |
| If you lose access | Depends on the company's terms | Your responsibility; recovery rests on your backup | Through your login method, where the provider documents it |
| Leaving the provider | Withdraw to your own address, if the company allows it | You already hold the keys | Key export, where the provider offers it |
Embedded wallets sit between the two older models. Providers such as Privy document them as non-custodial: "Neither Privy nor your application ever sees a user's private key." That is the provider's description of its own design, so the architecture matters more than the label, and each provider's documentation is the place to check it. The trade-off is the one in the table. You gain a simpler setup, and you depend on your login and on the provider's service to use the wallet.
How do embedded wallets keep keys without a seed phrase?
Providers such as Privy document how this works. Privy's security architecture describes key sharding based on Shamir secret sharing, so that "no share in isolation provides any information or access to the wallet." A key is reconstructed only inside trusted execution environments, implemented with AWS Nitro Enclaves, by combining an enclave share with an authentication share that is accessible only with valid authentication credentials.
For recovery, Privy's cloud recovery page says that for apps on its TEE setup "your users can access their accounts on other devices using their login method." For leaving, Privy says users can export their private key, which it calls "an escape hatch to leave Privy at any time." Export is the documented way out, and it means an exported key is a secret you must then protect yourself.
Is money in a custodial crypto account covered by deposit insurance?
In the United States, not for crypto assets: the FDIC says deposit insurance covers money in a deposit account at a bank in its system in the event of a bank failure, and it lists crypto assets among the products that are not covered. That answer is about the legal protection, which is a separate question from who holds the keys.
The FDIC's guidance on banking with third-party apps adds three points. Nonbank companies, including fintechs, are never covered by deposit insurance themselves. Funds sent to a nonbank "are not eligible for FDIC insurance until the company deposits them" at a bank and meets record-keeping conditions. And coverage "does not protect against the insolvency or bankruptcy of a nonbank company."
Stablecoin law points the same way for the token itself. The US GENIUS Act (Public Law 119-27, section 4(e)) says payment stablecoins "shall not be backed by the full faith and credit of the United States" or be "subject to deposit insurance by the Federal Deposit Insurance Corporation", and it makes it unlawful to represent otherwise.
So custody and protection are separate questions. Holding your own keys does not add deposit insurance, and, per the FDIC, crypto assets held in a custodial account are not covered by it either. What changes is who you rely on and what you have to manage yourself. Apps that call themselves neobanks raise the same question: which company holds the money behind the app? What a stablecoin neobank is covers that in detail.
Does self-custody mean nobody else can touch my tokens?
No. Self-custody means no company holds the keys to your wallet, but the token itself can carry rules set by its issuer. On Solana a token can be created with built-in issuer powers, and xStocks, the tokenized stocks issued by Backed, are a documented example.
The Solana Foundation's case study of xStocks says the tokens use the Permanent Delegate extension, "an authority designated by the token issuer (in this case, Backed) with ongoing rights to transfer or burn tokens", and the Pausable extension, which "lets the issuer pause all interactions with the token in case of emergencies." Solana's documentation says a permanent delegate "can authorize transfers and burns for any token account for that mint", and that token account owners cannot revoke it. The case study adds that a permanent delegate is often a regulatory requirement so that assets can be seized under a lawful court order, and that pausing covers emergencies, regulatory requirements and security incidents.
Keys and token rules are separate layers. Your keys decide who can approve your own transactions. The token's design decides what its issuer can do on top of that. How xStocks work explains these powers for tokenized stocks, and the issuer's terms are where the rest is written down.
What does self-custody ask of you?
Self-custody asks you to protect the keys and check each transaction yourself, because no company sits between you and the network to undo a mistake. Etherscan puts it as "no undo buttons in crypto", and its advice for transfers is to "always verify the destination address before sending funds."
Three habits follow from that:
- Protect whatever gives access to the keys: the seed phrase for a conventional wallet, or the login for an embedded one.
- Check the address and the network before you send, because a transfer cannot be recalled.
- Read what you approve before you confirm, because your signature is what moves the funds.
The trade runs in both directions. With a custodial account the company carries the work of securing the keys, and you carry the reliance on the company. With self-custody you carry the work, and no company stands between you and the network.
How does this work in Neovestor?
In Neovestor, your wallets are self-custodial: only you can approve transactions, and Neovestor can't access your keys. When you sign in, the app creates a Solana wallet and an Ethereum-compatible wallet, which is the one used on Base. Neovestor's backend never derives or exports your keys, and it never signs as you.
Every money action follows the same steps: quote, review screen, confirmation with Face ID or passcode, your signature, broadcast, then status tracking until the transaction is final. By default a quote expires after about 30 seconds. The only thing Neovestor's backend may sign is the network fee payer signature, and only after its Transaction Guard has checked the exact transaction you approved.
Each asset screen names the asset's issuer or counterparty, links its terms and shows jurisdiction restrictions, so you can read the rules that sit on top of the token. If you delete your Neovestor profile, the app warns that your funds remain in your wallet and offers export or withdrawal first.
What questions show who holds your money?
A few plain questions reveal the custody model of any app or wallet:
- Who holds the keys that control the funds, according to the app's own terms?
- Who approves a transaction, and what do you see before you approve it?
- How do you get back in if you lose your device or your login?
- Can you take the funds elsewhere, for example by withdrawing to your own address or exporting a key?
- Which company issues the asset, and what powers do its rules give it?
- What protection applies, and what does the provider say it does not cover?
To see the mechanics of leaving a custodial account, read how to move USDC from an exchange to self-custody. The self-custody overview collects the related guides.
Frequently asked questions
Is an exchange account custodial?
Generally yes. Ethereum.org says that with an exchange account you are trusting that exchange with custody over your funds. The account terms of each company say who holds the keys and what you can withdraw.
What is a private key?
A private key is the secret that authorizes transactions from an address on a blockchain. Whoever controls it controls the funds at that address, which is why custody comes down to who holds the keys.
Does non-custodial mean no risk?
No. The risk moves rather than disappears. A custodial account relies on a company, while a non-custodial wallet puts the job of keeping the keys secure, and of checking every transaction, on you.
Can I move funds from a custodial account to my own wallet?
Where a company allows withdrawals to an outside address, yes. You choose the network your wallet uses, paste the address copied from that wallet and check both on the confirmation screen. Steps and limits vary by company.
What happens if I lose access to a non-custodial wallet?
In a conventional self-custody wallet the user is responsible for keeping the keys secure, so the way back in is the backup you made. Embedded wallets work differently: providers such as Privy document that, for apps on Privy's TEE setup, users can reach their accounts on other devices using their login method.
Who controls the keys in Neovestor?
Only you can approve transactions, and Neovestor can't access your keys. The app creates a Solana wallet and an Ethereum-compatible wallet when you sign in, and every money action needs your confirmation with Face ID or passcode.