Digivara hoidmine: kontrolli, vastutuse ja usalduse arhitektuur

Krüptoraha ostmine on muutunud järjest lihtsamaks, kuid selle turvaline hoidmine aastate või aastakümnete jooksul on endiselt omaette probleem. Hinnakõikumine on risk, mida kõik näevad, ent hoidmise risk jääb sageli tahaplaanile. Krüptomaailmas korratakse õigustatult põhimõtet not your keys, not your coins: kui keegi teine kontrollib võtmeid, sõltub sinu ligipääs varale lõpuks temast. Sellest tehakse aga vahel liiga lihtne järeldus, nagu tähendaks võtmete enda käes hoidmine automaatselt turvalisust. Tegelikult liiguvad koos kontrolliga kasutajale ka võtme kaotamise, varguse, pahavara, õngitsuse, vigase varukoopia ja eksliku tehingu kinnitamise riskid.

Seetõttu pole digivara hoidmisel kõige olulisem küsimus ainult see, kelle käes on võtmed. Olulisem on vaadata kogu süsteemi: kuhu risk koondub, kui palju inimeselt endalt nõutakse ning kui hästi peab lahendus vastu nii välisele ründajale, teenusepakkuja ebaõnnestumisele kui ka inimese enda eksimusele. Täielikult keskne haldus ja täielik omahaldus asetavad vastutuse skaala eri otstesse, kuid kumbki ei muuda riski olematuks. Head lahendused püüavad riski pigem hajutada ning vähendada võimalust, et üksainus viga toob kaasa pöördumatu kaotuse.

Hoidmise risk on päris

Krüpto ajalugu annab selleks piisavalt näiteid. Mt. Goxi vastu toime pandud rünnakutes varastati USA justiitsministeeriumi kohtudokumentide järgi ligikaudu 647 000 bitcoin'i ning rünnakud aitasid kaasa kunagise maailma juhtiva Bitcoini börsi maksejõuetusele [1]. FTX-i puhul polnud keskne probleem häkkimine, vaid organisatsiooni sisemine kontroll: Samuel Bankman-Fried mõisteti süüdi skeemides, mille käigus väärkasutati miljardite dollarite väärtuses FTX-i klientide raha [2]. Celsius esindas omakorda mudelit, kus inimesed andsid oma krüptovara platvormile hoiule ja said selle eest tootlust, kuni väljamaksed 2022. aastal peatati ning ettevõte pankrotti läks. USA föderaalse kaubanduskomisjoni järgi võttis Celsius klientidelt üle nelja miljardi dollari väärtuses krüptovara ning kasutas seda muu hulgas tegevuskuludeks, teiste klientide tasudeks, laenudeks ja kõrge riskiga investeeringuteks [3].

Celsius pole minu jaoks ainult ajalooline näide. Oli aeg, mil suur osa minu enda krüptovarast asus seal ja teenis väikest intressi. Viisin selle enne ettevõtte kokkuvarisemist välja, kuid tagantjärele oleks liialdus kirjutada tulemus ainult hea riskianalüüsi arvele. Selles oli ka õnne. Just niisugused kogemused teevad abstraktse haldusriski väga praktiliseks: süsteem võib näida kasutajale aastaid täiesti toimiv, kuni ühel hetkel selgub, et ta usaldas midagi, mille tegelikku riskimudelit ta lõpuni ei näinud.

Probleem ei kuulu seejuures ainult krüpto algusaega. 2025. aasta veebruaris varastati Bybitist ligikaudu 1,5 miljardi dollari väärtuses krüptovara ning FBI omistas ründe Põhja-Koreale [4]. 2026. aasta esimesel poolel registreeris TRM Labs 207 eraldi krüptohäkki, mis oli nende andmestiku kõrgeim kuue kuu näitaja. Kuigi kogukahju jäi väiksemaks kui 2025. aasta erakordses esimeses pooles, tuli ligikaudu 76% varastatud väärtusest infrastruktuuri ja operatiivsete ligipääsude kompromiteerimisest [5]. Sageli ei murta enam plokiahela krüptograafiat ennast, vaid inimest, privaatvõtit, kasutajakontot või süsteemi seda osa, millel on õigus tehingut kinnitada.

Tehisaru suurendab siin mõlema poole võimekust. Kaitsevahendid muutuvad paremaks, kuid sama tehnoloogia aitab automatiseerida luuret, muuta sotsiaalset manipuleerimist veenvamaks ning kiirendada pahatahtlike tööriistade loomist. ENISA 2025. aasta ohumaastiku ülevaade kirjeldab suurte keelemudelite kasutamist muu hulgas õngitsuse, pettuste, luure ja pahavara arendamise toetamiseks [6]. Küberturvalisuse areng ei kõrvalda seetõttu hoidmise küsimust, vaid sunnib ka hoidmise arhitektuuri edasi arenema.

Krüptoraha ei asu tegelikult rahakotis

Kogu teema muutub selgemaks, kui alustada ühest lihtsast eristusest. Krüptoraha ei asu rahakotis samal moel nagu sularaha füüsilises rahakotis. Vara seisund on plokiahelal ning rahakott on süsteem, millega tõendatakse õigust selle vara suhtes tehinguid teha. Seetõttu tasub konkreetse rakenduse nime asemel vaadata seda, kes saab tehingu lubada, kuidas allkiri tekib, kuhu koondub ligipääsurisk ning kuidas taastatakse kontroll siis, kui telefon, võti või mõni teine süsteemi osa kaob.

Siit tuleb ka mõiste, mida võiks nimetada reaalseks turvalisuseks. Krüptograafiliselt väga tugev süsteem ei pruugi olla päriselus turvaline, kui selle kasutamine või taastamine on inimese jaoks liiga keeruline. Mõttelise mudelina võib reaalset turvalisust vaadata tehnilise kaitse, kasutatavuse ja taastatavuse koosmõjuna. Perfektselt kaitstud privaatvõti ei aita inimest, kes kaotab ainsa taastefraasi, samamoodi nagu suurepärase kasutuskogemusega keskne teenus ei kaota teenusepakkuja enda riski. Turvaline süsteem peab arvestama korraga nii ründaja kui ka eksiva inimesega.

Siin paiknebki digivara hoidmise maastik. Ühes ääres kannab suure osa tehnilisest vastutusest institutsioon, teises kasutaja ise. Nende vahele on tekkinud ka kolmas võimalus, kus võtmehaldusest saab hajutatud võrgu ülesanne. Järgnev joonis ei ole absoluutne turvalisuse edetabel, vaid lihtsustatud kaart sellest, kuhu eri mudelid kontrolli, vastutuse ja peamised riskid paigutavad.

Digivara hoidmise maastik. Risk ei kao ühegi mudeli puhul, kuid selle asukoht ja iseloom muutuvad.
Digivara hoidmise maastik. Risk ei kao ühegi mudeli puhul, kuid selle asukoht ja iseloom muutuvad.

Üks praktiline eristus aitab seda kaarti veel paremini lugeda: investeerimine, kauplemine, hoidmine ja kasutamine ei ole sama ülesanne. ETF võib olla väga hea investeerimisvahend, börs kauplemisvahend ja riistvararahakott pikaajalise hoidmise vahend, kuid ükski neist ei pea olema parim kõigis neljas rollis. Samal põhjusel ei pea koht, kust vara ostetakse, olema koht, kus seda pikaajaliselt hoitakse. Reguleeritud pank, neopank või börs võib olla hea ühendus euro ja krüptovara vahel, samal ajal kui hoidmiseks kasutatakse teistsuguse riskimudeliga lahendust.

Keskne haldus: vähem tehnilist vastutust, rohkem institutsionaalset usaldust

Kõige lihtsam tee krüptovarasse on jääda suuresti tavapärase finantssüsteemi sisse. Bitcoin ETF või ETP võib olla täiesti ratsionaalne valik inimesele, kes tahab osaleda Bitcoini hinnaliikumises, kuid ei soovi Bitcoiniga plokiahelal midagi teha. Sel juhul pole kasutajal Bitcoini aadressi ega võimalust vara omal soovil teisele aadressile saata; tal on finantsinstrument, mille väärtus on seotud Bitcoiniga. See vähendab tehnilist koormust väga suurel määral, kuid lahendab ka teistsugust ülesannet kui päris plokiahelavara omamine.

Pank võib minna sellest sammu võrra edasi. Näiteks LHV võimaldab Eestis krüptovara osta ja hoida ning sai 18. mail 2026 MiCA tegevusloa. Samas ei saa LHV kaudu ostetud krüptovara praegu välisesse rahakotti saata ega väljast sisse tuua ning kliendile eraldi rahakotiaadressi ei anta [7]. Kasutaja saab seega tugeva institutsionaalse hoidmislahenduse, kuid mitte vabalt liigutatavat plokiahelavara.

Siin on tähtis vältida vana krüptomaailma lihtsustust, mille järgi kõik keskne haldus oleks olemuslikult ebaturvaline. Tänane reguleeritud Euroopa teenusepakkuja pole sama riskimudel mis varase krüptoajastu reguleerimata börs. MiCA nõuab klientide krüptovara õiguslikku ja operatiivset eraldamist teenusepakkuja enda varast, halduspoliitikat, meetmeid pettuse, küberohu ja hooletuse vastu ning protseduure vara kliendile tagastamiseks. Teenusepakkuja vastutab talle omistatavast juhtumist tuleneva vara või sellele ligipääsu vahendite kaotsimineku eest [8].

Reguleerimine ei kaota siiski institutsionaalset riski. Pank, neopank või börs kontrollib endiselt kasutajakontot, tehnilist infrastruktuuri ja vähemalt osa väljamakseprotsessist. Võivad tekkida regulatiivsed piirangud, riskikontrollid, ajutised väljamaksepeatused või ettevõtte enda tehnilised probleemid. Keskse halduse olemuslik kompromiss on seega üsna lihtne: kasutaja loobub suurest osast võtmehalduse koormast ning saab vastutasuks sõltuvuse institutsioonist ja selle protsessidest.

Tootluse lisamine muudab pilti veel kord. Börsi tootlus, laenamine või DeFi farming pole enam pelgalt hoidmine, sest vara pannakse midagi tegema. Lisanduvad krediidi-, likviidsus-, nutilepingu-, protokolli- ja majanduslikud riskid. Siin muutub küsimus „kus mu vara on?“ kiiresti küsimuseks „mida minu varaga tehakse?“. DeFi ise ei ole seejuures hoidmisviis ega tingimata keskne süsteem; seda saab kasutada ka täiesti omahalduslikust rahakotist ning seetõttu tasub seda käsitleda pigem täiendava kasutus- ja riskikihina.

Omahaldus: kontroll ja vastutus liiguvad inimesele

Krüpto teine klassikaline tee on võtta kontroll võimalikult täielikult enda kätte. Tarkvararahakoti puhul kontrollib kasutaja tavaliselt ise privaatvõtit või sellest tuletatud taastefraasi. Börsi või panga maksejõuetus ei saa siis iseenesest vara liigutada ning kasutaja võib teha tehinguid ilma teenusepakkuja loata. Samas muutuvad tema enda arvuti, telefon, taastefraas ja otsustusvõime turvasüsteemi osaks. Pahavara, võltsleht või ekslikult kinnitatud tehing võib teha kahju, mida ükski klienditugi enam tagasi ei pööra.

Riistvararahakott viib selle mudeli tehniliselt märksa tugevamale tasemele, sest allkirjastamisvõti eraldatakse tavalisest internetiühendusega arvutist. Selle lahenduse oluline tugevus on ka portatiivsus: levinud BIP-39 standardit kasutava taastefraasi abil saab rahakoti vajadusel taastada teises ühilduvas lahenduses ka siis, kui algne seade või tootja pole enam kasutatav [9]. See on tugev sõltumatuse omadus ning põhjus, miks hästi üles ehitatud riistvaraline omahaldus jääb suurte pikaajaliste varade puhul väga arvestatavaks lahenduseks.

Sama omadus loob aga oma riskiklassi. Taastefraasi peab kaitsma varguse, kopeerimise, tulekahju, kadumise ja pärimisel tekkivate probleemide eest. Kui summa muutub suureks, pole enam tegu lihtsalt väikese seadme ostmisega, vaid oma võtmehalduse süsteemi rajamisega. Riistvararahakott ei päästa ka olukorras, kus kasutaja ise kinnitab seadmel pahatahtliku tehingu. Võti võib olla täielikult kaitstud ja täita siiski täpselt selle korralduse, mille kasutaja talle teadmatusest annab.

Mitme allkirjaga ehk multisig-süsteem saab ühe võtme riski veelgi vähendada, nõudes näiteks kolmest eraldi võtmest kahe nõusolekut. Safe'i tüüpi nutikontod võimaldavad määrata nii omanike hulga kui ka minimaalse kinnituste arvu, mis peab enne tehingu täitmist kokku tulema [10]. Organisatsiooni või väga suure varakogumi puhul võib selline ülesehitus olla erakordselt tugev, kuid koos turvalisusega kasvab ka protsessi keerukus. Tuleb otsustada, kes võtmeid hoiab, kuidas käituda inimese lahkumise, surma või kättesaamatuse korral, kuidas hallata varukoopiaid ning kuidas kontrollida, et mitu inimest ei kinnitaks üheskoos valesti koostatud tehingut.

Omahaldus ei ole seega automaatselt keskse haldusega võrreldes turvalisem. Ta eemaldab ühe riskiklassi ja võtab vastu teise. Tehniliselt tugev ülesehitus võib olla pädeva kasutaja käes väga turvaline, kuid muutuda tavakasutaja jaoks hoopis keerukusest tulenevaks riskiks.

Võrgupõhine haldus: kolmas mudel

Oisy erilisus ei alga rahakotist endast, vaid taristust, mille peale see on ehitatud. Tavapärane tarkvararahakott töötab kasutaja telefonis või arvutis ja jätab privaatvõtme kaitsmise kasutaja ülesandeks. Keskne teenus viib sama vastutuse enda infrastruktuuri. Oisy töötab aga Internet Computeri peal — uut tüüpi pilvetaristul, kus nii rakendus ise kui ka krüptograafiline võtmehaldus saavad toimida võrgu tasandil. Seda laiemat taristukihti käsitleme eraldi EFTI Krüptopilve allikas [14].

See võimaldab lahendada privaatvõtme probleemi teisiti. Bitcoini, Ethereumi või Solana vara kontrolliv terviklik privaatvõti ei asu kasutaja telefonis, Oisy serveris ega ühegi võrgusõlme käes. Tegelikult ei moodustata seda kunagi ühe tervikliku võtmena. Kui kasutaja tehingu kinnitab, loob Internet Computeri võrk ühiselt vajaliku allkirja, mida vastav plokiahel saab kontrollida nagu tavalist kehtivat tehingut [11][12]. ICP tehnoloogias nimetatakse selle aluseks olevat võimekust chain-key krüptograafiaks ning eri plokiahelatega suhtlemise tervikut Chain Fusioniks, kuid kasutaja jaoks on põhiloogika lihtne: võtit ei pea hoidma ei inimene ega üks teenusepakkuja, sest selle turvalisus on ehitatud võrku endasse.

Siit tuleb ka Oisy mõiste network custody ehk võrgupõhine haldus [13]. Keskse halduse puhul kannab võtme eest vastutust institutsioon, omahalduse puhul kasutaja ise, võrgupõhise halduse puhul aga võrk. Kasutajale jääb otsustusõigus selle üle, millal ja kuhu vara liigub. Võrgupilv võimaldab seega võrgupõhist haldust — uut tüüpi rahakott on võimalik tänu uut tüüpi pilvearhitektuurile.

See eristab Oisyt lahendustest, mis püüavad sama probleemi lahendada ainult parema rakenduse, turvalisema seadme või usaldusväärsema teenusepakkujaga. Oisy rakendus ise töötab samuti Internet Computeri võrgus ning võimaldab ühes kasutajaliideses hallata otse mitme plokiahela varasid, sealhulgas Bitcoini, Ethereumi, Solanat ja ICP-d [13]. Näiteks Bitcoin jääb Bitcoini võrku; Oisy ei pea seda muutma enda varaks ega hoidma kasutaja eest keskse haldurina.

Kasutaja jaoks on kõige nähtavam erinevus klassikalise taastefraasi puudumine. Ligipääs seotakse Internet Identityga, mis toetab tänapäevaseid pääsuvõtmeid ning vajadusel ka Google'i, Apple'i ja Microsofti kaudu autentimist [15]. Nii ei pea kasutaja aastakümneid kaitsma ühtainsat saladust, mille kadumine või vargus võiks tähendada kogu vara kaotamist.

Just siin tekib Oisy praktilise kesktee väärtus. Tegemist pole lihtsalt ühe „parema rahakotiga“ olemasoleval turul, vaid teistsugusel tarkvaraalusel töötava lahendusega. Otse plokiahelal oleva vara kasutatavus ja kasutaja kontroll säilivad, kuid võtme turvalisusest saab suuresti võrgu omadus.

Ka see arhitektuur pole siiski riskivaba ega lõplik. Oisy kasutab praegu tavapärast oisy.com domeeni, mis jääb osaks kasutaja ja võrgus töötava rakenduse vahelisest usaldusahelast. ICP enda turvajuhised käsitlevad veebidomeeni kontrolli reaalse usalduspiirina [16] ning Oisy konkreetset oisy.com juhtumit on eraldi analüüsitud ka Internet Computeri arendajate foorumis [17]. Domeeni kompromiss ei annaks ründajale Oisy hajutatud privaatvõtit ega murraks võrgu krüptograafiat, kuid pahatahtlik kasutajaliides võiks muutuda tehingute autoriseerimise ründepinnaks.

See nõrkus ei asu seega võrgupõhise võtmehalduse tuumas, vaid selle ühenduses tänase DNS-i ja veebidomeenide maailmaga. Ka seda kihti saab tulevikus tugevamalt siduda võrgu enda krüptograafilise usaldusmudeliga. Praegu jääb väike, kuid reaalne pärandveebi risk alles, mis näitab pigem seda, et ka selle arhitektuuri areng pole veel lõppenud.

Kuidas Oisyt praktiliselt kasutada?

Inimesele, kes soovib omada päriselt plokiahelal olevat krüptovara, kuid ei taha rajada enda ümber keerukat võtmehalduse süsteemi, võib Oisy olla lihtne tee. Alustada tasub ametlikust oisy.com aadressist ning wallet'i loomisel kohe läbi mõelda ka taastamine. Olulise vara ligipääsu ei tohiks jätta ühe telefoni või ühe konto külge; Oisy soovitab Internet Identityle lisada sõltumatuid taastamisviise ja varuseadmeid [11].

Vara võib seejärel osta sobiva reguleeritud panga, neopanga või börsi kaudu ning saata Oisy vastava plokiahela aadressile. See on koht, kus tasub meeles pidada varasemat põhimõtet: ostukoht ei pea olema hoiukoht. Esmalt võiks saata väga väikese testsumma, kontrollida selle jõudmist ning teha ka väikese väljuva tehingu. Oisy enda juhised rõhutavad samuti õige võrgu ja aadressi kontrollimist varade teisest rahakotist ületoomisel [18].

Alles siis, kui vastuvõtmine, saatmine ja ligipääsu taastamise loogika on endale selged, on mõistlik liikuda suurema summani. See põhimõte kehtib sõltumata valitud rahakotist: suurt summat ei tasu usaldada süsteemile, mille kasutamist ja taastamist pole ise väikese summaga läbi proovitud.

Milline lahendus siis valida?

Üht universaalselt parimat hoidmisviisi ei ole, sest eri lahendused täidavad eri ülesandeid. Praktilise orientiirina võib maastikku vaadata nii:

VajadusTõenäoliselt sobiv mudel
Tahan eelkõige hinnaliikumises osaledaETF/ETP või reguleeritud pank
Tahan lihtsalt osta, müüa või aktiivselt kaubeldapank, neopank või reguleeritud börs
Tahan vara päriselt plokiahelal omada ja kasutadavõrgupõhine haldus või omahaldus
Tahan maksimaalset sõltumatust välistest teenustestriistvaraline omahaldus
Haldan väga suurt vara või organisatsiooni varamitme allkirjaga või muu institutsionaalne ülesehitus
Tahan ühendada otsese plokiahelavara lihtsa kasutuskogemusegaOisy ja võrgupõhine haldus

Oisy on kõige huvitavam seal, kus inimene tahab päriselt plokiahelavara omada, seda vabalt saata ja vastu võtta, kuid ei soovi valida keskse halduri ja ühe enda hallatava privaatvõtme vahel. Selle eripära ei seisne ainult kasutajakogemuses, vaid alusarhitektuuris: uut tüüpi krüptograafiline pilvetaristu võimaldab võtmehalduse viia üksikisikult või ettevõttelt võrgu tasandile. Just see teeb võrgupõhisest haldusest kolmanda mudeli keskse halduse ja klassikalise omahalduse kõrval.

Digivara hoidmise areng ei pea lõpuks tähendama valikut panga ja paberile kirjutatud privaatvõtme vahel. Turvalisust saab vaadata terviklikuma süsteemi omadusena: kuidas jaotatakse kontroll, kui palju sõltutakse ühest inimesest või institutsioonist, kuidas vähendatakse ühe vea mõju ning kuidas taastatakse ligipääs ilma, et kasutaja peaks oma vara üle kontrolli täielikult kellelegi teisele loovutama. Võrgupõhine haldus on üks uus vastus sellele küsimusele ning näitab, et senine valik „kas usalda vahendajat või hoia ise võtit“ ei pruugi enam olla tehnoloogia piir.

Parim hoidmisviis pole see, kus risk näiliselt puudub, sest sellist süsteemi pole olemas. Tugevam lahendus on see, kus riskid on nähtavad, nende asukoht on mõistetav ning üks eksimus ei muutu võimalikult lihtsalt pöördumatuks kaotuseks.

Viited

  1. 1. U.S. Department of Justice. Russian Nationals Charged With Hacking One Cryptocurrency Exchange And Illicitly Operating Another.
  2. 2. U.S. Department of Justice. Samuel Bankman-Fried Sentenced To 25 Years In Prison.
  3. 3. U.S. Federal Trade Commission. FTC Reaches Settlement with Crypto Platform Celsius Network.
  4. 4. Federal Bureau of Investigation. North Korea Responsible for $1.5 Billion Bybit Hack.
  5. 5. TRM Labs. H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion.
  6. 6. European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025.
  7. 7. LHV. Krüptovarad ja Information concerning Crypto-asset Services.
  8. 8. European Securities and Markets Authority. MiCA Article 75 — Providing custody and administration of crypto-assets on behalf of clients.
  9. 9. Ledger. What Is a Seed Phrase? ja Understanding BIP-39.
  10. 10. Safe. Smart Account Concepts.
  11. 11. Oisy Wallet. Asset Control, Recovery, and Governance in Oisy Wallet.
  12. 12. Internet Computer Developer Docs. Chain Fusion.
  13. 13. Oisy Wallet. Why Oisy Wallet ja FAQ.
  14. 14. Eesti Finants- ja Tehnoloogia Instituut. Krüptopilv.
  15. 15. Internet Computer Developer Docs. Internet Identity.
  16. 16. Internet Computer Developer Docs. Canister control — Security concerns and custom domains.
  17. 17. Internet Computer Developer Forum. DNS and frontend trust assumptions for OISY and security-critical ICP dapps.
  18. 18. Oisy Wallet. Migrating Wallets.

Arutelu

Arutelu avaneb sisselogimisel. Ostu ei ole vaja.

Digital asset storage: the architecture of control, responsibility, and trust

Buying crypto has become increasingly simple, but storing it securely for years or decades remains a challenge of its own. Price volatility is the risk everyone sees, while storage risk often receives far less attention. The crypto world rightly repeats the principle not your keys, not your coins: if someone else controls the keys, your access to the asset ultimately depends on them. Yet this is sometimes taken too far, as if holding the keys yourself automatically meant being secure. In reality, control also brings the risks of key loss, theft, malware, phishing, failed backups, and mistakenly approving the wrong transaction.

The most important question in digital asset storage is therefore not simply who holds the keys. It is more useful to look at the system as a whole: where risk is concentrated, how much responsibility is placed on the individual, and how well the solution can withstand an external attacker, the failure of a service provider, or an ordinary human mistake. Fully centralized custody and full self-custody place responsibility at opposite ends of the spectrum, but neither makes risk disappear. Strong systems instead aim to distribute risk and reduce the chance that a single failure leads to an irreversible loss.

Storage risk is real

Crypto history provides no shortage of examples. According to U.S. Department of Justice court documents, approximately 647,000 bitcoin were stolen in attacks against Mt. Gox, contributing to the insolvency of what had once been one of the world’s leading Bitcoin exchanges [1]. In the case of FTX, the central problem was not a hack but internal control: Samuel Bankman-Fried was convicted in schemes involving the misuse of billions of dollars in FTX customer funds [2]. Celsius represented another model, in which users deposited crypto assets on a platform in return for yield, until withdrawals were halted in 2022 and the company entered bankruptcy. According to the U.S. Federal Trade Commission, Celsius took in more than four billion dollars’ worth of customer crypto assets and used them for purposes including operating expenses, payments to other customers, loans, and high-risk investments [3].

For me, Celsius is not merely a historical example. There was a period when a large share of my own crypto assets was held there, earning a modest return. I moved them out before the company collapsed, but in hindsight it would be an exaggeration to credit that outcome entirely to good risk analysis. There was also luck involved. Experiences like this make an abstract custody risk very concrete: a system may appear to work perfectly well for years, until one day it becomes clear that the user was trusting something whose actual risk model they never fully understood.

Nor is this a problem confined to crypto’s early years. In February 2025, approximately $1.5 billion in crypto assets was stolen from Bybit, and the FBI attributed the attack to North Korea [4]. In the first half of 2026, TRM Labs recorded 207 separate crypto hacks, the highest six-month total in its dataset. Although total losses were lower than during the exceptional first half of 2025, roughly 76% of the value stolen came from compromises of infrastructure and operational access [5]. Increasingly, attackers do not need to break blockchain cryptography itself. They target the person, the private key, the user account, or another part of the system with authority to approve a transaction.

Artificial intelligence is increasing the capabilities of both sides. Defensive tools are becoming better, but the same technology can automate reconnaissance, make social engineering more convincing, and accelerate the creation of malicious tools. ENISA’s 2025 threat landscape describes the use of large language models to support phishing, fraud, reconnaissance, and malware development, among other activities [6]. Advances in cybersecurity therefore do not make the storage problem disappear; they also force storage architectures to continue evolving.

Crypto does not actually live in a wallet

The subject becomes easier to understand once we make one simple distinction. Crypto does not sit inside a wallet in the same way cash sits inside a physical wallet. The state of the asset exists on the blockchain, while the wallet is the system through which the right to authorize transactions involving that asset is proven. It is therefore more useful to look beyond the name of a particular app and ask who can authorize a transaction, how the signature is produced, where access risk is concentrated, and how control can be recovered if a phone, key, or another part of the system is lost.

This leads to what we might call real-world security. A system can be cryptographically very strong and still be insecure in practice if it is too difficult for a person to use or recover. As a conceptual model, real-world security can be seen as the interaction of technical security, usability, and recoverability. A perfectly protected private key is of little use to someone who loses their only recovery phrase, just as an excellent user experience does not eliminate the risks associated with a centralized service provider. A secure system has to account for both the attacker and the fallible human being.

This is the landscape of digital asset storage. At one end, much of the technical responsibility sits with an institution; at the other, it sits with the individual. Between them, a third model has emerged in which key management becomes the task of a distributed network. The following diagram is not an absolute security ranking, but a simplified map of where different models place control, responsibility, and their main risks.

The digital asset storage landscape. Risk does not disappear under any model, but its location and character change.
The digital asset storage landscape. Risk does not disappear under any model, but its location and character change.

One practical distinction makes the map even easier to read: investing, trading, storing, and using an asset are not the same task. An ETF may be an excellent investment vehicle, an exchange a good trading venue, and a hardware wallet a strong long-term storage solution, but no single option needs to be best at all four. For the same reason, the place where an asset is bought does not have to be the place where it is stored long term. A regulated bank, neobank, or exchange may be a good bridge between euros and crypto assets, while long-term storage can use a solution with a different risk model.

Centralized custody: less technical responsibility, more institutional trust

The simplest route into crypto assets is to remain largely within the traditional financial system. A Bitcoin ETF or ETP can be a perfectly rational choice for someone who wants exposure to Bitcoin’s price but has no need to use Bitcoin on-chain. In that case, the user does not have a Bitcoin address or the ability to transfer the asset freely to another address; they hold a financial instrument whose value is linked to Bitcoin. This reduces the technical burden considerably, but it also solves a different problem from directly owning an on-chain asset.

A bank can move one step closer. In Estonia, for example, LHV allows customers to buy and hold crypto assets and received its MiCA authorization on 18 May 2026. At the same time, crypto purchased through LHV currently cannot be transferred to an external wallet, nor can crypto be deposited into LHV from outside, and customers are not given an individual wallet address [7]. The result is a strong institutional storage model, but not freely transferable on-chain ownership.

It is important here to avoid an older crypto-world simplification in which all centralized custody is treated as inherently unsafe. A regulated European service provider today does not have the same risk model as an unregulated exchange from crypto’s early years. MiCA requires customer crypto assets to be legally and operationally segregated from the service provider’s own assets, along with custody policies, safeguards against fraud, cyber threats and negligence, and procedures for returning assets to clients. The provider is also liable for losses of assets or means of access that are attributable to it [8].

Regulation does not remove institutional risk altogether. A bank, neobank, or exchange still controls the user account, the technical infrastructure, and at least part of the withdrawal process. Regulatory restrictions, risk controls, temporary withdrawal suspensions, or technical failures at the provider can still occur. The basic trade-off of centralized custody is therefore straightforward: the user gives up much of the burden of key management and, in return, becomes dependent on an institution and its processes.

Adding yield changes the picture again. Exchange yield products, lending, or DeFi farming are no longer merely forms of storage, because the asset is being put to work. Credit, liquidity, smart-contract, protocol, and economic risks are added. At that point, the question “where is my asset?” quickly becomes “what is being done with my asset?” DeFi itself is not a custody model and is not necessarily centralized; it can also be used from a fully self-custodial wallet. It is therefore better understood as an additional layer of use and risk.

Self-custody: control and responsibility move to the individual

Crypto’s other classical path is to take as much control as possible into your own hands. With a software wallet, the user typically controls the private key directly, or a recovery phrase from which the key is derived. A bank or exchange becoming insolvent cannot in itself move the asset, and the user can transact without asking a service provider for permission. At the same time, the user’s own computer, phone, recovery phrase, and judgment all become part of the security system. Malware, a fraudulent website, or a mistakenly approved transaction can cause damage that no customer support department can reverse.

A hardware wallet takes this model to a significantly stronger technical level by separating the signing key from an ordinary internet-connected computer. One important strength is portability: with a recovery phrase based on the widely used BIP-39 standard, a wallet can be restored in another compatible solution even if the original device or manufacturer is no longer available [9]. This is a powerful form of independence and one reason why well-designed hardware self-custody remains a very strong option for large, long-term holdings.

The same feature, however, creates its own category of risk. The recovery phrase must be protected from theft, copying, fire, loss, and complications around inheritance. Once the value involved becomes large, this is no longer simply a matter of buying a small device; it becomes a key-management system of its own. A hardware wallet also does not protect the user from every kind of error. A private key can remain perfectly secure while still executing exactly the malicious transaction that the user unknowingly approved.

Multisignature, or multisig, systems can reduce the risk of a single key compromise even further by requiring, for example, two approvals out of three independent keys. Smart accounts such as Safe allow both the set of owners and the minimum number of required confirmations to be configured [10]. For an organization or a very large pool of assets, such an arrangement can be exceptionally strong. But as security increases, so does operational complexity. Someone must decide who holds the keys, what happens if a person leaves, dies, or becomes unavailable, how backups are managed, and how to prevent several people from collectively approving the wrong transaction.

Self-custody is therefore not automatically safer than centralized custody. It removes one category of risk and accepts another. A technically strong setup can be extremely secure in the hands of a capable user, but for an ordinary user the complexity itself can become a source of risk.

Network custody: a third model

What makes Oisy different begins not with the wallet itself, but with the infrastructure beneath it. A conventional software wallet runs on a user’s phone or computer and leaves the protection of the private key to that user. A centralized service moves the same responsibility into its own infrastructure. Oisy, by contrast, runs on the Internet Computer — a new kind of cloud infrastructure in which both the application itself and cryptographic key management can operate at the network level. We explore this broader infrastructure in EFTI’s separate Crypto Cloud source [14].

This makes it possible to solve the private-key problem differently. The complete private key controlling Bitcoin, Ethereum, or Solana assets does not sit on the user’s phone, on an Oisy server, or with any individual network node. In fact, it is never assembled as one complete key at all. When the user approves a transaction, the Internet Computer network jointly produces the required signature, which the destination blockchain can verify just like an ordinary valid transaction [11][12]. The underlying ICP capability is known as chain-key cryptography, while the broader ability to interact with other blockchains is called Chain Fusion. For the user, however, the core idea is simple: neither the individual nor a single service provider has to hold the key, because its security is built into the network itself.

This is where Oisy’s term network custody comes from [13]. With centralized custody, the institution carries responsibility for the key. With self-custody, the user carries it personally. With network custody, the network takes on the key-management function while the user retains the authority to decide when and where assets move. In this sense, a network-level cloud enables network-level custody: a new kind of wallet becomes possible because the underlying cloud architecture is different.

This distinguishes Oisy from solutions that try to solve the same problem only through a better app, a safer device, or a more trustworthy service provider. The Oisy application itself also runs on the Internet Computer network and allows users to manage native assets across several blockchains, including Bitcoin, Ethereum, Solana, and ICP, through a single interface [13]. Bitcoin, for example, remains on the Bitcoin network; Oisy does not need to transform it into its own asset or hold it on the user’s behalf as a centralized custodian.

For the user, the most visible difference is the absence of the traditional recovery phrase. Access is tied to Internet Identity, which supports modern passkeys and, when desired, authentication through Google, Apple, and Microsoft accounts [15]. This means the user no longer has to protect a single secret for decades where loss or theft could mean losing access to the entire asset balance.

This is where Oisy’s value as a practical middle ground becomes clear. It is not simply a “better wallet” competing within the same existing architecture, but a solution built on a different software foundation. The user retains direct access to native on-chain assets and control over transactions, while key security becomes largely a property of the network itself.

This architecture is not risk-free or final either. Oisy currently uses the conventional oisy.com domain, which remains part of the trust chain between the user and the application running on the network. The Internet Computer’s own security guidance treats control of a web domain as a genuine trust boundary [16], and the specific role of oisy.com has also been examined in the Internet Computer developer forum [17]. A domain compromise would not reveal Oisy’s distributed private key or break the network’s cryptography, but a malicious user interface could become an attack surface for transaction authorization.

The weakness therefore does not lie in the core of network-based key management, but in its connection to today’s DNS and web-domain infrastructure. Over time, this layer can also be tied more closely to the network’s own cryptographic trust model. For now, a small but real legacy-web risk remains, which is better understood as a sign that the architecture is still evolving rather than as a failure of the network-custody model itself.

How to use Oisy in practice

For someone who wants to own actual on-chain crypto assets but does not want to build a complex key-management system around themselves, Oisy can provide a straightforward path. The starting point should be the official oisy.com address, and recovery should be considered as soon as the wallet is created. Access to meaningful assets should not depend on a single phone or a single account; Oisy recommends adding independent recovery methods and backup devices to Internet Identity [11].

The asset can then be purchased through an appropriate regulated bank, neobank, or exchange and sent to the corresponding blockchain address in Oisy. This is where the earlier principle becomes useful: the place where you buy does not have to be the place where you store. It is sensible to begin with a very small test transfer, confirm that it arrives, and then make a small outgoing transaction as well. Oisy’s own documentation likewise emphasizes verifying the correct network and address when moving assets from another wallet [18].

Only once receiving, sending, and the recovery logic are clear should a larger amount be transferred. This principle applies regardless of which wallet is chosen: a significant amount should not be entrusted to a system whose use and recovery have never been tested with a small amount first.

Which model should you choose?

There is no single universally best storage model because different solutions serve different purposes. As a practical orientation, the landscape can be summarized as follows:

NeedLikely suitable model
I mainly want exposure to price movementsETF/ETP or a regulated bank
I want to buy, sell, or actively tradeBank, neobank, or regulated exchange
I want to own and use assets directly on-chainNetwork custody or self-custody
I want maximum independence from external servicesHardware-based self-custody
I manage very large holdings or organizational assetsMultisig or another institutional setup
I want to combine direct on-chain assets with a simple user experienceOisy and network custody

Oisy is most interesting where someone wants to own native on-chain assets, send and receive them freely, but does not want to choose between a centralized custodian and a single private key that they must secure alone. Its distinguishing feature is not merely the user experience but the architecture underneath it: a new kind of cryptographic cloud infrastructure allows key management to move from the individual or company to the network level. That is what makes network custody a third model alongside centralized custody and classical self-custody.

The development of digital asset storage does not have to end in a choice between a bank and a private key written on paper. Security can increasingly be treated as a property of the system as a whole: how control is distributed, how much depends on a single person or institution, how the impact of one failure is reduced, and how access can be recovered without requiring the user to surrender full control of the asset to someone else. Network custody is one new answer to this question and shows that the old choice — trust an intermediary or hold the key yourself — may no longer represent the technological limit.

The best storage model is not the one in which risk appears to disappear, because no such system exists. A stronger system is one in which the risks are visible, their location is understood, and a single mistake is less likely to become an irreversible loss.

References

  1. 1. U.S. Department of Justice. Russian Nationals Charged With Hacking One Cryptocurrency Exchange And Illicitly Operating Another.
  2. 2. U.S. Department of Justice. Samuel Bankman-Fried Sentenced To 25 Years In Prison.
  3. 3. U.S. Federal Trade Commission. FTC Reaches Settlement with Crypto Platform Celsius Network.
  4. 4. Federal Bureau of Investigation. North Korea Responsible for $1.5 Billion Bybit Hack.
  5. 5. TRM Labs. H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion.
  6. 6. European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025.
  7. 7. LHV. Crypto Assets and Information Concerning Crypto-asset Services.
  8. 8. European Securities and Markets Authority. MiCA Article 75 — Providing custody and administration of crypto-assets on behalf of clients.
  9. 9. Ledger. What Is a Seed Phrase? and Understanding BIP-39.
  10. 10. Safe. Smart Account Concepts.
  11. 11. Oisy Wallet. Asset Control, Recovery, and Governance in Oisy Wallet.
  12. 12. Internet Computer Developer Docs. Chain Fusion.
  13. 13. Oisy Wallet. Why Oisy Wallet and FAQ.
  14. 14. Estonian Finance and Technology Institute. Crypto Cloud.
  15. 15. Internet Computer Developer Docs. Internet Identity.
  16. 16. Internet Computer Developer Docs. Canister Control — Security Concerns and Custom Domains.
  17. 17. Internet Computer Developer Forum. DNS and frontend trust assumptions for OISY and security-critical ICP dapps.
  18. 18. Oisy Wallet. Migrating Wallets.

Discussion

Discussion opens when you sign in. No purchase required.