What you will learn in this lesson
In the introductory lesson Crypto from Scratch we said that holding crypto safely deserved a lesson of its own. This is that lesson. It answers one simple but decisive question: when you say "I own tether," where exactly is that tether, and who is able to move it? The answer determines which risks fall on you. You will learn what a private key and a recovery phrase do, why a balance on an exchange is not the same kind of thing as a balance in your own wallet, where centralized and decentralized exchanges part ways, and which legal and security risks are specific to Iran's market. Nothing beyond the introductory lesson is assumed.
Definitions
Address: a string of letters and numbers that plays the role of an account number on a blockchain. It is public, and anyone can see its balance.
Private key: the secret that allows assets to be moved out of an address. Whoever holds the private key is the effective owner of those assets. Your name and your national ID appear nowhere on the blockchain.
Recovery phrase (seed phrase): a list of typically twelve or twenty four words from which your private keys are derived. This phrase is the asset itself: anyone who sees it can rebuild your wallet anywhere in the world and empty it.
Wallet: contrary to the common picture, a crypto wallet does not hold coins inside it. The coins are always on the blockchain. The wallet holds your keys and signs transactions.
Hot and cold wallets: a hot wallet is connected to the internet (a phone app or a browser extension) and is built for everyday payments. A cold wallet is offline, and the key never leaves the device.
Hardware wallet: a small standalone device that stores the private key and signs the transaction inside itself. It is the most common form of cold wallet.
Custodial and non-custodial: in custodial holding, the key belongs to an intermediary (usually an exchange) and what you hold is a claim on that company. In non-custodial holding, the key is yours and there is no intermediary.
Centralized exchange (CEX): a company that keeps user assets in its own wallets and records trades in its internal database. It has registration, identity verification, and customer support.
Decentralized exchange (DEX): a software contract on a blockchain that lets two wallets trade with each other directly. There is no account to open and assets never leave your wallet, but there is also no support desk and no way to undo a mistake.
Transfer network: a single token such as tether is issued on several different blockchains. Sending on a network the destination does not support usually means the assets are lost.
The mechanism: what ownership means on a blockchain
Ownership on a blockchain differs fundamentally from ownership in the banking system. It can be seen in four steps:
- The ledger only knows addresses. The blockchain records how much a given address holds. There is no column for the owner's name or identity.
- Moving assets requires a signature. To move a balance out of an address, the transaction must be signed with that address's private key. The network checks the signature only, not who produced it.
- So ownership means access to the key. Hold the key and you are the owner. Lose it and the assets stay on the chain but become permanently unusable. There is nobody to verify your identity and reset a password.
- Transactions are irreversible. Once the network confirms a transaction, no institution can void it. A mistake in the address or in the choice of network is a mistake that cannot be undone.
Three places to hold, three different risks
Those four steps produce three practical options, and the key point is that none of them is risk free. Each simply moves the risk somewhere else.
Option one, a balance on a centralized exchange. Here the key belongs to the exchange, and what you hold is a number in its database, that is, a claim. The convenience is real: forgetting a password is not a catastrophe, support exists, and converting to toman is straightforward. In exchange, you accept the intermediary's own risk: a hack, insolvency, suspended withdrawals, or a frozen account.
Option two, a personal non-custodial wallet. The key is yours, so intermediary risk disappears. But the entire responsibility moves to you as well: a lost recovery phrase, malware on your phone, or entering the phrase on a fake site all end in the total loss of the assets, with no way back.
Option three, a mix. The conventional practice is to keep the bulk of the assets in a cold wallet and leave only the amount needed for current trading on the exchange. This does not remove risk, but it stops a single point of failure from taking everything.
A worked example
Every figure in this section is hypothetical and is included only to show the structure of the calculation.
Suppose you hold the equivalent of $1,000 in tether and trade four times a month. If you keep all of it on the exchange, one event (a hack or suspended withdrawals) puts one hundred percent of the assets at stake. If you move all of it to a personal wallet, a different event (a leaked or lost recovery phrase) again puts one hundred percent at stake. Now suppose you place $800 in a cold wallet and $200 on the exchange: the worst case of each event is $800 or $200 respectively, not $1,000.
Now bring in the cost. Suppose each withdrawal from the exchange to a personal wallet carries a $1.5 network fee. At four withdrawals a month you pay $72 a year, which on $1,000 of capital is 7.2 percent a year, a figure that can easily exceed a year's return. If you batch those four withdrawals into a single monthly one, the cost falls to $18, or 1.8 percent a year. The numerical lesson is that security is not free, and how often you move assets is itself a computable cost.
In Iran's market
The regulatory framework is still taking shape. At its session of 13 Azar 1403 (3 December 2024), the Central Bank of Iran's High Council approved the document "the Central Bank's policymaking and regulatory framework for cryptocurrencies," which placed responsibility for licensing crypto brokers and trustee institutions with the Central Bank and stressed compliance with tax law and anti money laundering rules. Then, at the High Council's forty first session on 5 Mehr 1404 (27 September 2025), the "directive on the establishment, operation, dissolution and supervision of crypto brokers" was approved, taking effect three months after approval.
What in that directive reaches the user's pocket directly. According to published reports on the document, leveraged trading is prohibited, brokers must undergo formal audits and provide a proof of reserve attestation, transaction caps are set according to the volume of deposited assets, and users must sign a risk acknowledgment. The last item matters most for this lesson: within that framework, the Central Bank disclaims responsibility for user losses. In other words, your balance on a crypto exchange, unlike a bank deposit, carries no backing and no deposit insurance.
Licensing is not settled yet. As of Khordad 1405 (June 2026), the Central Bank had published no official list titled "authorized digital currency exchanges," and domestic platforms had not yet received a formal licence from it. The practical consequence for a user is that judging an exchange's credibility currently rests with the user alone.
A legal danger that is taken too lightly. The social affairs and crime prevention department of the Alborz province judiciary, in a notice reported on 6 Mordad 1405 (28 July 2026), warned of a wave of fraud operating behind work from home advertisements: the target is asked to complete identity verification at a crypto exchange with their own documents, then hand the management of that account to someone else for a small payment. In law the account holder is responsible for every transaction carried out and, where an offence occurs, is treated as an accomplice. The simple rule is that your verified account is your legal identity, and a legal identity is not rentable.
The risk a personal wallet does not remove. This is the subtle point of the lesson. On 23 Tir 1405 (14 July 2026) the US Treasury's Office of Foreign Assets Control added four crypto addresses linked to the Central Bank of Iran to its sanctions list, and Tether froze roughly $131 million of USDT held at those addresses. According to the blockchain analytics firm Chainalysis, the total frozen balance linked to that institution reached close to $475 million by then. Understand the mechanism: the issuer of a centralized stablecoin can lock an address's balance at the token level, even when the private key for that address is held solely by its owner. So self custody removes exchange risk but not issuer risk. Bitcoin has no such switch, because it has no issuer, and that is one of the structural differences between bitcoin and tether. You can follow the current tether rate on the tether to toman price page.
Common mistakes
"My crypto is inside my wallet." It is not. The assets are always on the blockchain and the wallet only holds the key. Losing a phone is not the same as losing a recovery phrase: with the phrase, you rebuild the wallet on any other device.
Photographing the recovery phrase. Storing the phrase in a photo gallery, cloud storage, email, or a messaging app makes it exactly as vulnerable as that service. A recovery phrase is meant to be written on paper and kept physically.
"An exchange balance is like a bank deposit." It is not. A bank deposit sits inside a protective framework. A crypto exchange balance is a claim on a company, and as we saw, the current regulatory framework disclaims Central Bank responsibility for losses.
"A personal wallet means complete safety." A personal wallet removes intermediary risk but leaves three others: the user's own mistakes, malware and phishing, and, for tokens that have an issuer, the possibility of a freeze at the token level.
Ignoring the transfer network. Before any withdrawal, the destination address and the chosen network must match. Transactions are irreversible, and no exchange's support desk can recover assets sent over the wrong network. The conventional practice is to send a small test amount before the main transfer.
Trusting messages and links. No legitimate exchange and no legitimate wallet ever asks for your recovery phrase. Any request for that phrase is, without exception, a fraud.
Summary
Owning crypto means having access to the private key, and nothing else. If the key belongs to an exchange, you are a creditor and you accept that company's risk. If the key is yours, you have removed intermediary risk and taken on the full burden of safekeeping, including irreversible mistakes. Neither state is risk free, and the sound choice is a deliberate split between them. Iran's market adds two further layers: a regulatory framework still taking shape that places the burden of losses on the user, and the full legal responsibility attached to your verified account.
The previous lesson in this series, Why Cars Became Quasi-Assets in Iran, looked at an asset whose problem is not safekeeping but depreciation. The full list of lessons is available at Sahmino Academy.