Skip to content
Wed, Aug 12 CAP $1.96T
27 Fear Live
EN
The Hashrate
Top Exchanges & Wallets· July 25, 2026 ·Updated July 30, 2026 ·6 min read ·1,212 words

How to Evaluate a Crypto Exchange, and Why Custody Is the Question Underneath

There is no universally best exchange, only trade-offs you should be able to name. Here are the criteria worth checking before you deposit anything, and what hot wallets, cold storage and seed phrases actually mean for who controls your coins.

This article is for informational purposes only and is not financial advice.
Abstract technical cover graphic in the Cryptocurrency Miners house style

Key takeaways

  • No legitimate exchange, wallet, support agent or airdrop will ever ask for your seed phrase. Anyone who does is stealing from you.
  • Evaluate exchanges on jurisdiction, disclosure, withdrawal reliability and incident history rather than on fees or promotions alone.
  • An exchange balance is a claim on a company; only coins in a wallet whose keys you hold are directly yours.
  • Hot and cold storage are not a ranking. They are a split between convenience and long-term safety, and most people need both.

Almost every guide to choosing an exchange is really a list dressed as advice, and the ordering usually reflects who pays the publisher rather than who protects the user. This page does not rank anything. It sets out the criteria you can apply yourself, and then addresses the question that sits underneath the whole subject: when you hold crypto somewhere, who actually controls it?

Start with the safety rule that overrides everything else on this page. No legitimate exchange, wallet, support agent, developer, airdrop or migration tool will ever ask for your seed phrase or private keys. Not to verify your account, not to fix a stuck transaction, not to qualify you for anything. Every single request is theft. If you internalise one sentence from this article, make it that one.

Criteria for evaluating an exchange

Find out which company actually holds your assets and where it is incorporated, which is often not the country in the marketing. That determines whose rules apply, what happens if the business fails, and whether you have any practical route to a complaint. A platform that makes this hard to establish has told you something useful.

What it discloses, and how it can be checked

Look for concrete, verifiable statements rather than assurances. Are reserve holdings published in a form an outsider can inspect? Is there any independent examination of them, and does it cover liabilities as well as assets, given that a reserve figure means nothing without knowing what is owed against it? Are terms of service, fee schedules and asset listing standards published and dated? Vague claims about being fully backed, with nothing behind them, are marketing copy.

Security posture

Check what account protections are actually available: app-based or hardware two-factor authentication rather than SMS alone, withdrawal address allow-lists, session and device management, notification on every sensitive action. Then check what the platform does on its own side, such as how much it holds in cold storage and how withdrawals are authorised internally. Look up the incident history too. A past breach is not automatically disqualifying; how openly it was disclosed and what changed afterwards is far more revealing.

Withdrawal reliability

This is the criterion people check last and regret most. An account balance is only meaningful if you can move it out. Look for a consistent record of withdrawals processing without unexplained delay, clear published limits, and no history of pausing withdrawals during volatile periods while the platform insists everything is fine. Before committing anything substantial, send a small test withdrawal and watch how it behaves.

Costs you can actually compare

Headline trading fees are the smallest part of the bill for most people. The real cost is the spread you pay on execution, the network and processing fees on deposits and withdrawals, and any conversion charge applied when moving between currencies. Compare total round-trip cost on a realistic transaction size rather than a fee table.

Asset coverage and listing standards

A very long list of tokens is not a feature by itself. What matters is whether the platform publishes any standard for what it lists and delists, and how much notice it gives before removing something you hold. Concentrate on whether the assets you care about have depth, because thin markets cost you far more in slippage than any fee schedule.

Support that exists before you need it

Test support with a trivial question before you have a serious one. Note whether replies come from a human, whether there is a documented escalation path, and whether the platform’s official contact channels are clearly published, since impersonation of support is one of the most common ways accounts are drained.

Custody: the question underneath

When you hold coins on an exchange, you do not hold coins. You hold an entry in that company’s database representing a claim against it. In normal conditions the distinction is invisible. It becomes the only thing that matters when the company is hacked, becomes insolvent, freezes accounts, or is instructed by an authority to do so. That is the whole meaning of the phrase not your keys, not your coins. It is not tribal sloganeering; it is an accurate description of a legal and technical difference.

Hot wallets and cold storage

A hot wallet is any wallet whose keys live on an internet-connected device: a phone app, a browser extension, a desktop client. It is convenient and appropriate for amounts you actively use, and it is exposed to everything that can compromise that device. Cold storage keeps the keys on something that is not online, typically a dedicated hardware wallet that signs transactions internally and never exposes the keys to your computer.

These are not a ranking with a winner. They are a split. The common approach is to treat a hot wallet like the cash in your pocket and cold storage like a safe, sizing each accordingly. Whichever you use, verify the receiving address on the signing device’s own screen rather than trusting what your computer displays, because address-swapping malware is a well-established technique.

The seed phrase

Your seed phrase, sometimes called a recovery phrase, is a list of words from which every private key in your wallet is mathematically derived. It is not a login. It is the wallet. Anyone who reads it controls the funds; anyone who loses it and has no backup loses the funds permanently, with no recovery process, because there is no institution able to reset it.

Practical handling follows from that. Record it offline, on paper or metal, never as a photo, a cloud note, a password manager entry or a message to yourself. Keep more than one copy in physically separate places, because a single backup turns a house fire into a total loss. Never type it into a website, and treat any prompt to do so as an attack in progress. If you ever suspect it has been seen, generate a new wallet and move everything, rather than hoping.

A note for miners

Mining changes the shape of this problem. Payouts arrive continuously in small amounts, and because electricity and hosting are billed in fiat currency, miners are structural sellers who move funds to an exchange far more often than a typical holder does. That regular flow makes two things more important than usual: that your pool payout address belongs to a wallet whose keys you hold, and that your chosen exchange has a dependable withdrawal record and fee structure you have actually measured. The economics behind that selling pressure are covered on our mining dashboard, and you can model your own cost side with the mining profitability calculator, remembering that any such output is an estimate based on the inputs you provide.

Before you deposit anything

  • Confirm the company, its jurisdiction and its published terms.
  • Enable the strongest available two-factor method and an address allow-list.
  • Make a small test deposit and a small test withdrawal, and time both.
  • Decide in advance what stays on the platform and what moves to self-custody.
  • Set up and verify your recovery backup before you hold an amount that would hurt to lose.

Terminology used above is defined in our glossary, and the wider groundwork sits in the learn section and our beginner trading guides. This article is educational and is not financial advice, nor a recommendation of any particular platform or product.

Answers

Frequently asked questions

Why should nobody ever ask me for my seed phrase?

Because the seed phrase is not a password, it is the keys themselves. Anyone holding those words can regenerate your wallet on their own device and move everything in it, immediately and irreversibly, without needing your phone, your email or your permission. There is no legitimate reason for support staff, a wallet developer, an exchange, a giveaway or a migration tool to see it. Every request for a seed phrase is an attempted theft, without exception, no matter how official the website or urgent the message looks.

Is it safer to keep coins on a large exchange or in my own wallet?

They fail in different ways, so the honest answer depends on which failure you are better equipped to avoid. An exchange concentrates the risk of insolvency, freezes, hacks and policy changes in one counterparty, but it also handles the technical work and can sometimes reverse mistakes. Self-custody removes the counterparty entirely and replaces it with operational risk: lost devices, forgotten backups, mistyped addresses and phishing, all of which are permanent. Many people split the difference, keeping trading balances on an exchange and long-term holdings under their own keys.

What actually makes a hardware wallet different?

A hardware wallet keeps the private keys inside a dedicated device and signs transactions there, so the keys never appear on your internet-connected computer or phone. Malware on that computer can still show you a fraudulent transaction, which is why the device has its own screen: you are meant to verify the destination address and amount on the hardware itself, not in the software. It does not make you immune to mistakes. It narrows the attack surface from anything that can infect your machine down to what you personally approve.

Does this apply to coins I mine as well?

Yes, and arguably more so, because mining produces a steady stream of small incoming payments and it is easy to leave them wherever the pool sends them by default. Check what the payout address actually is, whether it belongs to a wallet you control, and whether that address has been verified rather than pasted from an old note. Miners also sell regularly to cover electricity costs, which means repeated exchange deposits and withdrawals, so withdrawal reliability and fee structure matter more to a miner than to an occasional buyer.

Verified
Luc José Adjinacou
About the author
Luc José Adjinacou
Crypto Writer · Tel Aviv

Crypto writer at Cryptocurrency Miners.

Business and FinanceCrypto
View full profile & all articles →

Keep exploring