> ## Content Index
> Fetch the complete content index at: https://blog.tara.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Custodial vs Non-Custodial: Why You Shouldn't Have to Choose
- URL: https://blog.tara.com/custodial-vs-non-custodial/
- Published: 2026-08-19T09:29:45.000Z
- Updated: 2026-08-19T09:36:43.000Z
- Description: Hardware wallets had a brutal summer. Exchanges had a brutal decade. The custody debate keeps asking you to pick a side. We built TARA so you don't have to.
- Author: Tara
- Tags: Article

On the last day of July, people who had done everything right started losing their Bitcoin.

They held their own keys. 

They kept them on Coldcard hardware wallets, devices built for exactly one job: keeping crypto safe offline.

They never typed their seed phrase into a website. 

Never photographed it. 

Never told a soul.

By the first week of August, [more than $130 million was gone](https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/?ref=blog.tara.com).

> COLDCARD Mk3 Security Advisory  
>  
> If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.   
>  
> Mk4, Q and Mk5 are not affected based on our early analysis.  
>  
> Read the advisory and migrate carefully:[https://t.co/3vgPHOjMS7](https://t.co/3vgPHOjMS7?ref=blog.tara.com)
> 
> — COLDCARD (@COLDCARDwallet) [July 30, 2026](https://x.com/COLDCARDwallet/status/2082961993070247948?ref%5Fsrc=twsrc%5Etfw&ref=blog.tara.com)

Reports traced it to how affected Coldcard devices generated seed phrases in the first place: a bug, reportedly sitting in the code since 2021, made those twelve or twenty-four words predictable enough to brute-force.

Attackers never needed to touch anyone's device. They ran the math from a distance and walked into wallet after wallet.

Days later, in mid-August, [Trezor disclosed](https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/?ref=blog.tara.com) that a breach at its shipping partner exposed personal details of nearly 14,000 customers, including names, phone numbers, and home addresses.

The devices themselves are fine. The problem is the paper trail: a list, now in someone else's hands, of people who own crypto and where they live.

> We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
> 
> — Trezor (@Trezor) [August 13, 2026](https://x.com/Trezor/status/2087885428313543059?ref%5Fsrc=twsrc%5Etfw&ref=blog.tara.com)

Ledger customers know that story too well.

In 2020, a breach of Ledger's marketing database ended with [272,000 names, home addresses, and phone numbers dumped on a public forum](https://fullycrypto.com/ledger-data-breaches-a-timeline?ref=blog.tara.com), fueling years of phishing campaigns and even physical threats.

> A researcher participating in our bounty program made us aware of a potential data breach in our marketing database.  
>  
> We immediately investigated and fixed it.   
>  
> Your payment information and crypto funds are safe.   
>  
> More details: [https://t.co/dpnI2tdfmO](https://t.co/dpnI2tdfmO?ref=blog.tara.com)
> 
> — Ledger (@Ledger) [July 29, 2020](https://x.com/Ledger/status/1288372785098764288?ref%5Fsrc=twsrc%5Etfw&ref=blog.tara.com)

[This January it happened again](https://www.theblock.co/post/384275/ledger-customers-data-leak-payment-processor?ref=blog.tara.com), this time through a third-party e-commerce provider.

Three companies. Three different failures.

One uncomfortable conclusion: the standard package of self-custody has sharp edges that have nothing to do with you doing anything wrong.

## **What custodial and non-custodial actually mean**

Strip away the jargon and the two models are simple.

A **custodial** account means a company holds your assets for you. You trust it to keep them safe, to stay solvent, and to hand them back when you ask.

Convenient, familiar, and entirely dependent on the company behind it.

A **non-custodial** wallet, also called self-custody, means you hold the keys yourself. No company can move, freeze, or lose your crypto.

Every action starts with you. And every risk a company would normally absorb lands on you instead.

The crypto industry has spent more than a decade telling you to pick one.

## **Both sides have fine print**

 The custodial fine print is written in bankruptcy filings.

When FTX collapsed, customers made the painful discovery that the crypto they "held" was actually held by the exchange. Withdrawals froze. Balances became claims in a court case.

TL;DR: the company is the single point of failure.

The self-custody fine print showed up twice this summer.

The Coldcard exploit broke the assumption that a seed phrase generated by a trusted device is unguessable.

Those twelve words are only as strong as the code that produced them, and you have no way to audit that code from the outside.

The Trezor and Ledger leaks broke the second assumption: self-custody is not always fully private.

A hardware wallet is a physical product. It ships to your door. Somewhere, a database remembers your name, your address, and the fact that you bought a crypto safe.

You can hold your keys perfectly and still end up on a target list.

## **The lesson is not to pick the other side**

Every time an exchange collapses, the self-custody camp says told you so. Every time a wallet fails, the custodial camp returns the favor.

Both are right about the other side's weaknesses. Neither has fixed their own.

Because these were never failures of custody or self-custody as ideas.

They were failures of packaging. A master secret printed on paper, security resting on one unaudited line of code, purchase records that turn customers into targets, and platforms that blur who actually holds what until the day it matters.

## **How TARA removes the choice**

We built **TARA** as [one app with two accounts](https://blog.tara.com/what-is-tara/), on deliberately different foundations, so you get what each model does best and always know which one you're using.

The **Vault** is self-custody without the sharpest edges.

Instead of a seed phrase, it uses [**MPC**, short for **multi-party computation**](https://blog.tara.com/how-vault-and-smart-account-work/): your private key is never created as a single object, anywhere.

Separate key shares, generated in separate places, cooperate to sign transactions without ever being assembled into one key.

There is no master secret to generate badly, no twelve words to guess, steal, or photograph.

Access is your passkey and biometrics, and if you lose your phone, you recover your Vault on a new device.

And because the Vault is software inside TARA, not a gadget in the mail, owning one doesn't leave a shipping record that ties your name and home address to your crypto.

TARA cannot access, move, or freeze what's in your Vault.

Not as a policy. As architecture.

The **Smart Account** is custodial on purpose.

Regulated companies manage it, opening one requires identity verification, and in exchange you get what custody is actually for: assets held in institutional custody, fiat transfers, rewards on dollar balances for eligible users, and a Visa card that works with **Apple Pay** and **Google Pay** anywhere Visa is accepted.

![](https://storage.ghost.io/c/ed/70/ed70c633-dcdf-4f47-9fa2-c01f4ae99514/content/images/2026/08/tap-to-pay-1.png)

Remember that **TARA** is not a bank. Custodial services and card issuance are provided by regulated companies under their own terms.

Between the two accounts sits a boundary you can always see.

The app tells you which side you're on, and nothing moves between them unless you move it.

## **You were never the problem**

The Coldcard victims didn't fail. Neither did the 14,000 people now reading Trezor's phishing warnings.

They were handed a false choice and picked a side, because picking a side used to be the only option.

It isn't anymore.

TARA is opening in friends and family mode, with public access to follow. If you want both of your accounts in one app, **join the waitlist** at [**tara.com**](https://tara.com/?ref=blog.tara.com).

Hold what you own. Spend what you need. Decide where everything lives.

**Money on your side.**