Self-custody without the paranoia
Almost every guide to self-custody is written for the wrong threat model. They open with supply-chain attacks on hardware wallets, move to air-gapped signing machines, and end somewhere near a discussion of whether your firmware can be trusted. All of that is real. Almost none of it is what will actually cost you money.
The overwhelming majority of self-custody losses come from three things: losing the backup, mis-recording the backup, and being unable to use the backup under stress. A setup that defends brilliantly against a targeted attacker while failing at any of those three is a worse setup than a simple one that handles them well.
Start by naming your actual threat
Write down, honestly, who you are defending against. For most people holding an ordinary amount, the list is short: yourself in five years, a house fire or flood, an opportunistic thief who finds a piece of paper in a drawer, and generic remote malware. Notice that two of those four are accidents, not adversaries.
If your list genuinely includes a well-resourced targeted attacker — because you are publicly associated with a large holding — then the elaborate guides apply and you should follow them. If it does not, adopting that complexity buys you very little and costs you a great deal in the one dimension that matters most: the chance that the recovery actually works when you need it.
Complexity is the real adversary
Every additional step in a custody scheme is a step that can be forgotten, misremembered, or misexecuted years later by someone tired and stressed. A passphrase you added on top of your seed phrase is genuinely useful protection against someone who finds the seed — and it is also the single most common way people permanently lose access, because the passphrase was never written down anywhere, on the theory that writing it down would defeat the purpose.
The honest framing is that you are trading one failure mode for another. More complexity moves risk away from theft and toward loss. Less complexity does the reverse. There is no configuration with zero risk on both axes, and pretending otherwise is how people end up with schemes they cannot execute.
A setup that handles the realistic cases
A hardware wallet from a mainstream vendor, purchased directly from the manufacturer rather than a marketplace reseller, covers the remote-malware case well. It keeps the key off a general-purpose computer, which is where the vast majority of ordinary compromise happens.
The seed phrase should be recorded on something that survives water and fire. Paper in a drawer fails to both, and it fails silently — you will not discover the problem until the day you need it. Stamped metal plates are inexpensive relative to what they protect and remove an entire category of accident.
Store two copies in genuinely separate locations. Two copies in the same building is one copy with extra steps, because the realistic disaster destroys the building. A second location introduces a small theft risk in exchange for removing a large loss risk, and for most threat models that trade is clearly correct.
Then — and this is the step almost everyone skips — perform a recovery. Wipe the device, restore from the written phrase, and confirm the addresses match. An untested backup is a hypothesis. People discover a transcription error in their seed phrase at exactly the moment they can least afford to, and the only way to find it in advance is to try.
Plan for the case where you are not there
A long holding period makes this more than a morbid formality. If the funds are meant to matter to anyone other than you, someone else must be able to reach them. That does not require handing over the keys today. It requires that a trusted person knows a setup exists, knows roughly where to look, and has a path to instructions — even something as unglamorous as a sealed letter with a solicitor.
The failure here is total and surprisingly common. Funds that are perfectly secured and completely unrecoverable are, from the perspective of everyone who outlives you, identical to funds that were stolen.
Re-check on a schedule
Put a recurring reminder in the calendar, once or twice a year. Confirm both backups are physically where you think they are, confirm the device still powers on, and confirm you can still read your own handwriting. Fifteen minutes annually is not a burden, and it converts custody from an assumption you made once into a fact you keep verifying.
That is the whole discipline. Not sophistication — repetition. The setups that survive a decade are boring, tested, and documented well enough that a stressed person can follow them.