Skip to content

Custody · 4 models compared

Crypto wallets for Los Angeles: custody, backups and earthquakes

Every wallet guide on the internet compares devices. Almost none of them mention that you live somewhere with wildfire seasons, earthquake risk and a genuine burglary rate — which makes a single paper backup in a desk drawer a bad plan for reasons that have nothing to do with cryptography. This is a custody guide written for this city.

Written for LA riskInheritance coveredReviewed September 2026
Cryptocurrency tokens representing digital asset custody

Custody models

4

Backup locations

2 minimum

Framing

The only question that actually matters

Choosing a crypto wallet feels like a product comparison and it is not. It is a single question about which risk you would rather carry, and once you have answered it the product almost picks itself.

The question is this: would you rather risk a company failing you, or risk failing yourself? Leave your crypto with a licensed custodian and you are exposed to that company — insolvency, an account freeze, a security breach, a support queue that does not answer. Hold your own keys and that exposure disappears entirely, replaced by a different one: you lose the recovery phrase, you fall for a phishing site, your house burns down with your only backup in it.

Neither answer is correct in general. What is definitely wrong is not choosing — buying crypto, leaving it wherever it happened to land, and never thinking about it again. That is how people end up locked out of an exchange account they cannot verify, or holding a phone with a wallet app and no idea what the twelve words were for.

We are going to be honest about something the crypto community tends not to say out loud: for a lot of people, a licensed custodian is the better choice. Self-custody demands operational discipline that most people do not have and should not pretend to. The people who lose crypto to their own mistakes vastly outnumber the people who lose it to exchange failures.

The options

Four custody models, compared

ModelWho holds the keysHow you recoverWhat can go wrongBest fit
Exchange custodyThe platform holds themAccount recovery through supportCounterparty risk — platform failure, freeze, hackSmall balances, active trading, people who fear losing keys
Mobile software walletYou hold them, on your phoneYour recovery phrase onlyPhone loss or compromise; malware; you losing the phraseEveryday amounts, spending, kiosk purchases
Hardware walletYou hold them, on a dedicated deviceYour recovery phrase onlyDevice loss plus phrase loss; physical theft; user errorLong-term holdings above roughly a few thousand dollars
Multi-signature / shared custodySplit across multiple keys or partiesDepends on the quorum you designedComplexity; losing enough keys to break quorumLarge holdings, businesses, estate planning, joint holdings

Most people end up using two of these together — a custodial account for trading and a hardware wallet for long-term holdings. That combination is sensible and we would not argue against it.

Decide

Which model suits you

Stay with a licensed custodian if…

  • Your balance is small enough that losing it would be annoying rather than serious
  • You trade actively and need assets available on the platform
  • You know, honestly, that you will not maintain a paper backup for years
  • You want account recovery to exist as an option at all

If this is you, turn on hardware-key or app-based two-factor authentication and remove SMS as a recovery method — SIM-swap attacks are the main way custodial accounts get taken.

Move to a hardware wallet if…

  • You are holding a meaningful sum for years rather than weeks
  • You want no dependence on any company continuing to exist
  • You are willing to do the backup properly, once, and then not touch it
  • You have somewhere genuinely safe to store two separated backups

Buy only from the manufacturer, never second-hand. A tampered device can arrive preloaded with a recovery phrase an attacker already knows.

Use a mobile software wallet if…

  • You need to receive from a Bitcoin ATM or a retail cash counter
  • You want to spend from crypto rather than hold it
  • The amount is what you would carry in a physical wallet
  • You want self-custody without buying hardware yet

Treat it like a wallet with cash in it, not a savings account. Keep the balance at a level you could lose without it changing your year.

Consider multi-signature if…

  • The amount is large enough that a single point of failure is unacceptable
  • You are holding on behalf of a business or a partnership
  • You are building an estate plan around digital assets
  • You want a setup where losing one key is survivable

This is meaningfully more complex to run. Do not adopt it without understanding exactly how your quorum works and testing recovery — a broken multi-sig is as final as a lost phrase.

Do it once, properly

Setting up self-custody

Six steps. Step five is the one everyone skips and the one that determines whether any of the others worked.

  1. 1

    Buy hardware only from the manufacturer

    Never second-hand, never from a marketplace reseller, never from someone at a meetup. A tampered device can arrive preloaded with a recovery phrase the attacker already has, and you would have no way to know until your funds moved.

  2. 2

    Let the device generate the phrase itself

    A legitimate device generates your recovery phrase offline, on the device, at setup. If a phrase came printed in the box, or somebody supplied one, the wallet is compromised. Stop and contact the manufacturer.

  3. 3

    Write it by hand, on paper or metal

    Never typed into anything. Never photographed. Never in cloud storage, email, notes apps or a password manager. Every one of those creates a copy on a device connected to the internet, which defeats the entire point of the exercise.

  4. 4

    Verify the words and the order

    Most devices make you confirm a subset. Do it carefully — a single transposed word means the backup does not work, and you will find that out at the worst possible moment.

  5. 5

    Test the restore before you trust it

    Send a small amount. Then deliberately wipe the device and restore it from your written phrase. This is the only way to know your backup is real. Skipping this step is how people discover a transcription error two years too late.

  6. 6

    Store two copies, geographically separated

    Detailed in the next section, because in this city it deserves one.

LA-specific

A backup plan for earthquake and wildfire country

This is the section that makes this guide different from every generic wallet article, and it is the one we would most want a friend here to read.

Generic advice says "write down your recovery phrase and keep it somewhere safe". In Los Angeles that advice is incomplete in a way that matters, because the realistic threat model here includes several events that destroy an entire location at once.

Wildfire is the obvious one, and it is not hypothetical — large parts of this county sit in or beside high-risk terrain, and evacuation notice is sometimes measured in minutes. Earthquake is the structural one: a building can become inaccessible or unsafe for weeks even without collapsing, and a safe you cannot reach is functionally the same as a safe that burned. Burglary is the mundane one, and a piece of paper labeled with twelve words is the most valuable thing in most homes that hold crypto.

So the rule is two copies, in two places, far enough apart that one event cannot take both. A fireproof safe at home plus a bank safe deposit box in a different part of the county. Or a home safe plus a trusted family member in another city — San Diego, Phoenix, wherever your people are. The specific combination matters less than the separation.

Two upgrades worth considering. A metal backup plate — stamped or engraved steel — costs a modest amount and survives heat that destroys paper, which directly addresses the wildfire case. And if the amount justifies the complexity, a multi-signature setup distributes the problem instead of duplicating it, so that no single backup is catastrophic to lose.

One thing not to do, however tempting: do not solve this with cloud storage. An encrypted file in a cloud drive feels like a clever answer and it is a bad one, because it converts a physical-security problem into a remote-attack problem — and remote attackers are far more numerous than house fires.

Do

  • Two copies, two separated locations
  • Paper at minimum; metal if the amount justifies it
  • A bank safe deposit box as one of the two
  • Test the restore before trusting the backup
  • Check both copies still exist once a year

Never

  • Photograph the phrase
  • Type it into any device or website
  • Store it in cloud storage, email or notes
  • Put it in a password manager entry
  • Write it in a will — wills become public record
  • Tell anyone the words over the phone

The nervous part

Your first transfer off an exchange

The first withdrawal from a custodian to your own wallet is the moment people make expensive irreversible mistakes, and it is entirely avoidable with one habit: send a small amount first.

Copy the receiving address from your wallet — always copy, never type, and always check the first and last several characters after pasting. Send a small test amount. Wait for it to appear in your wallet, not just to leave the exchange. Only then send the rest. The test costs a network fee measured in cents or a few dollars and it verifies the entire path.

Two specific traps are worth naming. Network mismatch: many assets exist on multiple networks, and sending on the wrong one usually means the funds are gone. Make sure the network selected on the exchange matches the network your wallet is expecting. Clipboard malware: some malware silently replaces a copied crypto address with the attacker's. This is exactly why you verify the pasted address character by character at both ends rather than trusting the paste.

Also expect a hold. Most platforms restrict withdrawals for a period after you add a new payment method, change a password or update two-factor authentication — and ACH-funded purchases carry their own settlement hold. None of that means something is wrong. It does mean that if you have a deadline, do the account housekeeping a week early. Our cash-out guide lists the common holds.

Uncomfortable but necessary

What happens to your crypto if you die

Self-custodied crypto with no succession plan is very likely lost forever. This is genuinely different from every other asset you own, and it is worth understanding precisely why.

An executor can reach a bank account through probate, because a bank is an institution with records and a legal obligation to respond to a court. There is no equivalent for a hardware wallet in a drawer. If the recovery phrase existed only in your memory, or in a location nobody else knows about, the assets remain on the blockchain permanently, visible and unreachable. No court order, no exchange, no law firm and no family member can change that.

What a plan looks like: a written record of what exists and where — which assets, which wallets, which platforms — held somewhere your executor can access on death but nobody can access before. Instructions clear enough that a non-technical person could follow them. Explicit reference in your estate documents to the existence of digital assets and to where the access information is held. And, crucially, never the recovery phrase in the will itself, because a probated will becomes a public record.

For larger holdings, a multi-signature arrangement or a professional custodian solves this more elegantly than any paper plan, by making access a matter of institutional process rather than of secret knowledge. Either way, this is a conversation for a California attorney with digital-asset experience — the specialist bar here has grown considerably, partly because these questions are now arriving in probate regularly. Our local firms guide covers the categories of professional worth finding.

Reality check

How people actually lose crypto

Not to sophisticated cryptographic attacks. To these, in roughly this order of frequency.

Entering the recovery phrase on a phishing site

A convincing fake wallet or exchange page asks you to "restore" or "validate" your wallet. Nothing legitimate ever asks for your phrase in a browser.

Losing the only backup

One piece of paper, one location, one flood, fire, move or spring clean. The single most common self-inflicted loss.

A transcription error, discovered too late

One wrong or transposed word, never tested. The backup was worthless from the moment it was written and nobody knew.

Sending to the wrong address or network

Typed instead of copied, or the right address on the wrong chain. Irreversible in both cases, which is why you always test small.

A fake wallet app from an app store

A convincing clone with a slightly wrong publisher name. Download only via the developer's official site link.

SIM-swap on a custodial account

An attacker ports your number and resets your account through SMS recovery. Remove SMS as a recovery method and use hardware or app-based 2FA.

Trusting a "support" agent who contacted you

No real support team ever initiates contact by direct message, and none ever needs your phrase or remote access to your screen.

Handing keys to a "manager"

Anyone offering to trade on your behalf if you give them wallet access is stealing from you. There is no version of this that ends well.

Dying without a plan

The loss you never experience yourself. Also the most preventable, and the one people put off longest.

The single rule that prevents most of these

Your recovery phrase is typed into exactly one thing, ever: a wallet you are deliberately restoring, on a device you control, having navigated there yourself. Not a website, not a support chat, not an app someone recommended, not a form, not a phone call. If anything or anyone asks for those words in any other context, it is theft — including at a crypto kiosk, where you should only ever provide a receiving address. See our safety guide and report attempts to the FTC.

Questions we actually get

Wallet and custody questions

Do I need a crypto wallet to buy crypto in Los Angeles?

Not to buy on an exchange — the platform holds the assets for you. You do need one to use a Bitcoin ATM, because the machine sends coins to an address you supply, and you need one if you want genuine control of your holdings rather than a claim against a company. Set it up before you visit a kiosk, at home, calmly, where you can record the recovery phrase properly.

Is a hardware wallet worth it?

Above roughly a few thousand dollars held for the long term, in our view yes. A hardware wallet keeps your private keys on a device that never exposes them to an internet-connected computer, which eliminates the largest category of remote theft. Below that amount, the device cost and the added complexity are harder to justify — a well-secured mobile wallet or a reputable custodian is a reasonable choice.

What is a recovery phrase and why does it matter so much?

Twelve or twenty-four words that mathematically regenerate your entire wallet. Anyone with those words has your crypto, permanently, from anywhere. Losing them without another backup means the assets are gone with no appeal to anyone. Write them on paper or metal, never type them into a phone or computer, never photograph them, and never enter them into a website — the only legitimate place they are ever typed is a wallet you are deliberately restoring.

Should I leave my crypto on an exchange?

It depends on amount and purpose, and both answers are defensible. Custody with a licensed platform removes the risk that you lose your own keys — which is a real and common way people lose crypto — and adds the risk that the platform fails, freezes your account or is compromised. Federal deposit insurance does not cover crypto holdings. Our rough rule: trading balances and small amounts can stay; long-term savings you would be upset to lose should move to self-custody.

How do I back up a wallet safely in Los Angeles specifically?

Assume a single-location disaster. Wildfire, earthquake and burglary are all realistic in this metro, and a paper backup in a desk drawer survives none of them. Use at least two geographically separated locations — a fireproof safe at home plus a bank safe deposit box, or a trusted family member in another city. Consider a metal backup plate for heat resistance. Never store the phrase in cloud storage, email or a password manager note.

What happens to my crypto if I die?

Without planning, it is very likely lost. Keys that only you know die with you, and no court, exchange or family member can recover them. This is genuinely different from a bank account, which an executor can access through probate. You need a documented plan — where the assets are, how to reach them, and who is authorised — held securely and referenced in your estate documents. A California attorney with digital-asset experience is the right person for this.

Is a wallet app from an app store safe?

Reputable ones are, and fake ones are a persistent problem. Download only from the developer's official website link, check the publisher name carefully, and be suspicious of any app with few reviews or a slightly misspelled name. Never enter an existing recovery phrase into a newly downloaded app you have not verified. This is one of the most common ways people are robbed, and it is entirely preventable.