Custodial vs Non-Custodial: Why You Shouldn't Have to Choose

Hardware wallets had a brutal summer. Exchanges had a brutal decade. The custody debate keeps asking you to pick a side. We built TARA so you don't have to.

Custodial vs Non-Custodial: Why You Shouldn't Have to Choose

On the last day of July, people who had done everything right started losing their Bitcoin.

They held their own keys. 

They kept them on Coldcard hardware wallets, devices built for exactly one job: keeping crypto safe offline.

They never typed their seed phrase into a website. 

Never photographed it. 

Never told a soul.

By the first week of August, more than $130 million was gone.

Reports traced it to how affected Coldcard devices generated seed phrases in the first place: a bug, reportedly sitting in the code since 2021, made those twelve or twenty-four words predictable enough to brute-force.

Attackers never needed to touch anyone's device. They ran the math from a distance and walked into wallet after wallet.

Days later, in mid-August, Trezor disclosed that a breach at its shipping partner exposed personal details of nearly 14,000 customers, including names, phone numbers, and home addresses.

The devices themselves are fine. The problem is the paper trail: a list, now in someone else's hands, of people who own crypto and where they live.

Ledger customers know that story too well.

In 2020, a breach of Ledger's marketing database ended with 272,000 names, home addresses, and phone numbers dumped on a public forum, fueling years of phishing campaigns and even physical threats.

This January it happened again, this time through a third-party e-commerce provider.

Three companies. Three different failures.

One uncomfortable conclusion: the standard package of self-custody has sharp edges that have nothing to do with you doing anything wrong.

What custodial and non-custodial actually mean

Strip away the jargon and the two models are simple.

A custodial account means a company holds your assets for you. You trust it to keep them safe, to stay solvent, and to hand them back when you ask.

Convenient, familiar, and entirely dependent on the company behind it.

A non-custodial wallet, also called self-custody, means you hold the keys yourself. No company can move, freeze, or lose your crypto.

Every action starts with you. And every risk a company would normally absorb lands on you instead.

The crypto industry has spent more than a decade telling you to pick one.

Both sides have fine print

 The custodial fine print is written in bankruptcy filings.

When FTX collapsed, customers made the painful discovery that the crypto they "held" was actually held by the exchange. Withdrawals froze. Balances became claims in a court case.

TL;DR: the company is the single point of failure.

The self-custody fine print showed up twice this summer.

The Coldcard exploit broke the assumption that a seed phrase generated by a trusted device is unguessable.

Those twelve words are only as strong as the code that produced them, and you have no way to audit that code from the outside.

The Trezor and Ledger leaks broke the second assumption: self-custody is not always fully private.

A hardware wallet is a physical product. It ships to your door. Somewhere, a database remembers your name, your address, and the fact that you bought a crypto safe.

You can hold your keys perfectly and still end up on a target list.

The lesson is not to pick the other side

Every time an exchange collapses, the self-custody camp says told you so. Every time a wallet fails, the custodial camp returns the favor.

Both are right about the other side's weaknesses. Neither has fixed their own.

Because these were never failures of custody or self-custody as ideas.

They were failures of packaging. A master secret printed on paper, security resting on one unaudited line of code, purchase records that turn customers into targets, and platforms that blur who actually holds what until the day it matters.

How TARA removes the choice

We built TARA as one app with two accounts, on deliberately different foundations, so you get what each model does best and always know which one you're using.

The Vault is self-custody without the sharpest edges.

Instead of a seed phrase, it uses MPC, short for multi-party computation: your private key is never created as a single object, anywhere.

Separate key shares, generated in separate places, cooperate to sign transactions without ever being assembled into one key.

There is no master secret to generate badly, no twelve words to guess, steal, or photograph.

Access is your passkey and biometrics, and if you lose your phone, you recover your Vault on a new device.

And because the Vault is software inside TARA, not a gadget in the mail, owning one doesn't leave a shipping record that ties your name and home address to your crypto.

TARA cannot access, move, or freeze what's in your Vault.

Not as a policy. As architecture.

The Smart Account is custodial on purpose.

Regulated companies manage it, opening one requires identity verification, and in exchange you get what custody is actually for: assets held in institutional custody, fiat transfers, rewards on dollar balances for eligible users, and a Visa card that works with Apple Pay and Google Pay anywhere Visa is accepted.

Remember that TARA is not a bank. Custodial services and card issuance are provided by regulated companies under their own terms.

Between the two accounts sits a boundary you can always see.

The app tells you which side you're on, and nothing moves between them unless you move it.

You were never the problem

The Coldcard victims didn't fail. Neither did the 14,000 people now reading Trezor's phishing warnings.

They were handed a false choice and picked a side, because picking a side used to be the only option.

It isn't anymore.

TARA is opening in friends and family mode, with public access to follow. If you want both of your accounts in one app, join the waitlist at tara.com.

Hold what you own. Spend what you need. Decide where everything lives.

Money on your side.