Skip to content

Security, answered.

Straight answers to the questions investors ask, read before you commit a rupee.

Is Qatobit safe? Are my funds safe?

Qatobit publishes Live Proof of Reserves, available at any time, so you can see that your holdings are accounted for without waiting on a request or a quarterly cycle. User funds are kept separate from operational funds, and user assets are insured. One thing to be clear about: Proof of Reserves and insurance protect the assets in custody. They do not protect against the price of an asset falling, which is market risk and stays with you.

What is Proof of Reserves?

A live, verifiable record of the crypto Qatobit holds on behalf of users. It is the crypto equivalent of an audit, except it is continuously current rather than periodic, and it is available to you at any time.

Should I move my Bitcoin to a hardware wallet?

For long-term holding of a meaningful position, yes. Hardware wallet (self-custody) shifts the position out of platform-level operational risk and gives the user full control of the keys. The trade-off is operational complexity: the user manages the seed phrase, backups, and recovery procedures. For investors who plan to trade actively or to use the position within structured baskets like QSI Core or QSI Growth, platform custody is operationally simpler. Many investors hold both: platform custody for the active position, self-custody for the long-term storage portion.

Is Qatobit's Proof of Reserves a one-time audit or a live record?

It's a continuously current record, checkable at any time, produced on an ongoing basis instead of a periodic cycle.

Do I own the actual coins when I invest through a crypto platform?

No. You hold a claim the platform owes you, backed by crypto sitting in wallets the platform controls. The private key, which authorizes moving those coins on their blockchain, stays with the platform.

What is a private key, and why does it decide who controls crypto?

A private key is the cryptographic code that authorizes moving a specific coin on its blockchain. Whoever holds that key controls the coin, regardless of whose name sits on the account showing a balance.

What happened to WazirX users' crypto after the 2024 hack?

The Lazarus Group stole approximately 234.9 million dollars from WazirX on 18 July 2024. Withdrawals froze for every user. A Singapore court approved a restructuring scheme in October 2025, and the exchange resumed operations more than fifteen months after the breach. Recovery now happens through tokens.

What happened to Vauld users when it froze withdrawals in 2022?

Vauld suspended all withdrawals, buying and selling, and deposits on 4 July 2022, after users tried to pull roughly 198 million dollars in a matter of weeks. The company cited financial difficulty. Users could not access funds that were legally theirs while the platform pursued restructuring.

Does institutional custody or Proof of Reserves guarantee a platform cannot fail?

No. Proof of Reserves can show that specific crypto exists in specific wallets on a given day, and fund segregation can show it is kept apart from company money. Neither one guarantees the platform survives as a business, or that a court process could never freeze access.

Does proof of reserves mean a crypto platform is solvent?

No. It shows that specified assets exist in specified wallets at one point in time. Solvency requires proving liabilities too, and the PCAOB has said these reports likely do not address liabilities at all.

What is the biggest limitation of a proof-of-reserves report?

It is a point-in-time snapshot. A platform can hold the coins it shows on the day of the check and still have borrowed, pledged, or lost them the following week.

Did an accounting firm ever stop doing proof-of-reserves work?

Yes. Mazars produced these reports for Binance, Crypto.com, and KuCoin, then paused all crypto work in December 2022. It said the reports were not audits and only reflected a historical point in time.

Does a rebalancing crypto basket make proof of reserves harder to read?

Yes. A basket that rebalances monthly changes its own composition between checks. A snapshot taken mid-cycle says less about that basket than it would about a holding that never moves.

What can I actually check on Qatobit's Proof of Reserves page?

The live reserves figure, checked at a moment you pick rather than a date announced in advance, and whether the platform documents keeping user funds separate from operational funds. Together those answer more of the PCAOB's core concern than a single snapshot, though neither is a formal proof of solvency.

Was any customer money taken in the CoinDCX hack?

No. CoinDCX said the 44.3 million dollars taken in July 2025 came from an internal operational wallet used for liquidity. Customer funds stayed separately in cold storage and were not affected.

How much was stolen in the CoinDCX hack, and when?

CoinDCX lost 44.3 million dollars, taken across multiple transactions inside about five minutes on July 18, 2025, according to Halborn's post-mortem.

How did the attackers get into CoinDCX's systems?

Police investigators said the attackers used a fake freelance job offer to get a CoinDCX employee to install malware on a work laptop. That gave them access to the systems managing the exchange's liquidity operations.

Did CoinDCX customers pay for the loss?

No. CoinDCX said it absorbed the full 44.3 million dollar loss from its own treasury reserves. Customer funds and fees were untouched.

What did CoinDCX offer for the return of the stolen funds?

On July 21, 2025, CoinDCX said it would pay up to 25 percent of any recovered funds to whoever helps trace and retrieve the stolen crypto.

Is a proof-of-reserves attestation the same as a financial audit?

No. CryptoTimes' coverage of CoinSwitch's own sixth edition made this explicit: an SRS 4400 attestation confirms specific agreed facts, like a reserve ratio, and "does not constitute a full financial audit" of the business.

Which Indian crypto platforms have published a proof-of-reserves attestation?

As of 25 August 2026, CoinSwitch has published six editions since January 2023, most recently reporting a ₹613.08 crore surplus as of 31 March 2026. ZebPay and Giottus have each explained the concept publicly since November 2022 but have not published their own dated attestation.

Does a reserve surplus mean a platform is completely safe?

No. A surplus shown in an attestation is a snapshot of one date and says nothing about liabilities, encumbrances, or whether the same coins were held there the day before or after. It is one useful fact, and on its own it stops well short of a safety guarantee.

Why do some proof-of-reserves reports not name the auditing firm?

CoinSwitch's published editions describe the reviewer only as "a qualified chartered accountancy firm" rather than naming it, across at least two consecutive editions. The standard applied, SRS 4400, is still named and checkable even when the firm is not.

What is the difference between a platform's crypto holdings and its liabilities?

Holdings are what a platform has on hand right now. Liabilities are what it owes customers. A proof-of-reserves attestation compares the two at a point in time; it does not track ongoing obligations the way a liabilities statement would.

What is the fastest way to check where a crypto platform's money sits?

Look for a live or dated Proof of Reserves page, or ask support whether customer money is held separately from the company's own. Only a specific, checkable statement counts as an answer here; general reassurance means the platform has not answered.

Does FIU-IND registration mean my money is protected like it would be with a mutual fund?

No. FIU-IND registration means the platform reports under anti-money-laundering rules: identity checks, transaction records, and filings on suspicious activity. SEBI-style investor protection and a guaranteed recourse fund sit outside that requirement, so treat "registered" and "regulated like a mutual fund" as two separate questions with two separate answers.

What do you need to set up a multisig wallet for a crypto portfolio?

Setting up a multisig wallet needs three things. It needs a multisig contract, such as a Gnosis Safe, or a chain's native multisig feature. It needs a separate wallet and key for each signer. And it needs an agreed signing threshold decided before deployment, such as 2 of 3 signers. The contract itself is deployed first, either through a service like Gnosis Safe or a blockchain's built in multisig function. This contract, not any single wallet, becomes the address that actually holds the funds. Every signer connects their own personal wallet to that contract afterward. Before deployment, the group decides the threshold: how many of the total signers must approve a transaction before it can move funds. A common setup is 2 of 3, meaning any two of three signers can approve, protecting against one lost or compromised key. Each signer needs a fully separate wallet and private key, never a shared one. Say three co-founders want to protect a 1 crore rupee equivalent crypto treasury. They deploy a Gnosis Safe with a 2 of 3 threshold and each connects their own hardware wallet as a signer. Moving funds now needs any two of the three to approve. Losing one device or one key does not lock the treasury. Changing the signer list or threshold later usually needs its own approved transaction from the existing signers. It should be decided carefully before deployment rather than fixed after funds arrive. A multisig with only two total signers offers little protection, since losing either one can lock the funds entirely. Investors who hold a Qatobit Crypto Index are not required to set up or manage a multisig wallet themselves. Assets sit under institutional custody on the platform's side of the process.

What is the difference between a web3 wallet and a hardware wallet?

A web3 wallet, such as MetaMask, is browser or app based software connected to the internet. It is used to interact with apps and sites. A hardware wallet is a separate offline device that holds the private key and signs transactions. The two are often used together as interface and signer. A web3 wallet on its own stores the private key inside the browser or phone. That device stays connected to the internet whenever the wallet is open. This convenience is also the risk: malware on the same device could theoretically access a key stored this way. A hardware wallet keeps the private key on a separate physical device that never connects directly to the internet. When a transaction needs signing, the web3 wallet sends the request to the hardware device. The device signs it internally, and only the signed result returns to the browser. The key itself never leaves the offline device. Say an investor holds a 5 lakh rupee crypto position and wants to interact with a lending app. They connect MetaMask as the interface and pair a hardware wallet to it. Every transaction the app requests still needs a physical button press on the hardware device. The app itself can never move funds without that confirmation. Using MetaMask alone for a large position leaves the key exposed to browser based attacks. A malicious site could trick the wallet into signing an unintended transaction. Pairing it with a hardware wallet does not remove this risk entirely. A signer can still be tricked into approving a bad transaction on the device screen. An investor holding a Crypto Index through Qatobit does not need a web3 wallet. A hardware device is not needed either to interact with the platform. Assets sit under institutional custody rather than a personal wallet the investor manages directly.

Can you recover a wallet without password and seed phrase?

A self-custody wallet has no recovery path once both the password and the seed phrase are gone. The seed phrase is the only backup for the private key. Losing both it and the password means the funds are permanently inaccessible. Social recovery wallets and custodial exchange accounts are the two exceptions to this rule. A standard self-custody wallet, like MetaMask or a hardware wallet, generates a private key that only the seed phrase can restore. There is no company, support line, or password reset process behind it, because nobody but the holder ever has the key. This is the tradeoff for full control of the funds. A social recovery wallet is the deliberate exception. Instead of a single seed phrase, the wallet owner names a group of trusted guardians in advance. A majority of them can approve a recovery that restores access without the original seed. A custodial exchange account works differently. The exchange holds the keys, so losing a password still leaves a recovery path through identity verification with the platform. Say an investor holds 5 lakh rupees in a self-custody wallet. They lose both the seed phrase and the device with the saved password. There is no support ticket, no identity check, and no backup that restores access. The funds remain on the blockchain but are permanently unreachable by anyone. Writing a seed phrase down in one place only creates a single point of failure. Keeping no backup copy stored separately is exactly the failure this question describes. A second physical copy, stored somewhere separate from the first, is the only real protection for a standard self-custody wallet. A Qatobit account does not rely on a self-managed seed phrase for recovery. Assets sit under institutional custody rather than a personal wallet. Account recovery follows the identity verification process any custodial platform uses.

What is the difference between a hardware wallet and a software wallet?

A hardware wallet stores the private key on a dedicated offline device with a secure element chip, built to resist extraction. A software wallet keeps the key encrypted on a phone or computer that stays connected to the internet. Software wallets suit frequent transactions, while hardware wallets reduce exposure to online attacks. The secure element chip inside a hardware wallet is the same category of chip used in a bank card. It is designed so the key can sign a transaction internally, without ever being exposed outside the chip. Even if the connected computer is infected with malware, the key itself stays inaccessible. A software wallet trades that isolation for convenience. The key sits encrypted on the same device used for browsing. Opening the wallet and signing a transaction takes seconds, with no separate device to plug in. That same connectivity is what exposes it to malware, phishing sites, and browser exploits that a hardware wallet is designed to resist. Say an investor splits a 5 lakh rupee crypto holding between two wallets. They keep 50,000 rupees in a software wallet on their phone for regular trading. The remaining 4.5 lakh rupees sits in a hardware wallet that stays disconnected except when a transfer is needed. The split limits how much is exposed to an online attack at any time. A hardware wallet still needs careful handling of its own. A device bought secondhand, or pre-initialised by someone else, can carry a seed phrase the buyer never generated. Buying only from the manufacturer or an authorised reseller avoids this specific risk. An investor allocating through Qatobit does not need to choose between a hardware or software wallet for that allocation. The index sits under institutional custody on the platform, separate from any personal wallet the investor may also hold.

What is the difference between a hardware wallet and a USB drive?

A hardware wallet has a secure chip that signs transactions internally, so the key never leaves the device. A USB drive is plain storage, and a key file on it is exposed once plugged into a computer. Malware can read a key from a USB drive but not from a secure chip. A hardware wallet is purpose built hardware. It runs signing software inside a chip designed to resist even physical extraction attempts. It never reveals the raw private key to the connected computer, only a signed transaction. A USB drive is a general storage device with no such protection. If a private key is saved onto it as a plain text or image file, that file behaves like any other file. It is exposed the moment the drive is plugged in and opened. Any malware already running on that computer can read it directly. Say an investor stores a printed seed phrase photo for a 5 lakh rupee holding on a USB drive as a backup. If that computer later gets infected with malware while the drive is plugged in, the malware can copy the photo. It can read the seed phrase directly from it. A hardware wallet storing the same key would never expose it this way. Encrypting the file on the USB drive raises the bar but does not remove the risk entirely. A keylogger on the same computer could still capture the password typed to decrypt it. A hardware wallet avoids this whole category of attack by never exposing the key to the connected computer in the first place.

How does a hardware wallet connect to an app like MetaMask?

A hardware wallet connects to MetaMask as a signer, not a replacement for it. MetaMask builds each transaction, while the hardware device signs it internally over a USB or Bluetooth connection. The private key never leaves the hardware device, even while paired. Pairing starts inside MetaMask, which offers an option to connect a hardware wallet instead of importing a private key directly. Once paired, MetaMask shows the hardware wallet's account like any other. Every outgoing transaction still routes through the physical device for a signature. When a transaction is sent, MetaMask displays the details and sends the unsigned data to the hardware device. The device shows the same details on its own small screen. The user must physically approve it there before anything is signed. Only the signed result returns to MetaMask and gets broadcast to the network. Say an investor pairs a hardware wallet with MetaMask to interact with a lending app for a 5 lakh rupee position. Every time the app requests a transaction, MetaMask forwards it to the hardware device. The investor checks the amount and address on the device screen before pressing approve. Approving a transaction on the hardware device screen without actually reading the details defeats the entire purpose of the pairing. A malicious app can send a transaction that looks routine in MetaMask but drains funds when blindly approved on the device. Reading the device screen every time is the actual protection, not just owning the device.

What is the difference between crypto custody and a depository account?

A depository like NSDL or CDSL holds securities electronically under SEBI regulation, with a defined framework for investor protection. A crypto custodian holds private keys or manages on-chain assets, with no equivalent depository regulation in India yet. Both remove the need to personally manage the asset, but the legal protection differs. A depository in the Indian securities market holds shares and bonds in electronic form on behalf of investors, replacing physical share certificates. It operates under a SEBI license. Clear rules cover investor grievance processes, record keeping, and liability if something goes wrong at the depository's end. A crypto custodian performs a similar practical function. It holds the private keys or manages the on-chain assets, so the investor does not have to run a personal wallet. The difference is regulatory. There is no depository style regulation specific to crypto custody in India yet. The legal protections around a custodian's failure are not codified the way NSDL's are. Say an investor holds 5 lakh rupees in mutual fund units through a depository account. A separate 5 lakh rupees sits in crypto through a custodian. If the depository participant fails, SEBI's framework defines exactly how the investor's holdings are protected and transferred. A crypto custodian dispute, without the same regulatory framework in place, follows a less defined path. This gap does not make crypto custody unsafe by default. The legal backstop an Indian investor is used to from NSDL or CDSL does not yet exist in the same form for crypto. Checking what a specific custodian actually does matters more than assuming depository style protection applies. That means separating client funds from operational funds, and publishing verifiable proof of holdings. Qatobit holds investor assets under institutional custody and publishes live Proof of Reserves, available at any time. The accounting behind the custody arrangement does not sit behind a request form or a quarterly cycle.

What is the difference between a multisig wallet and an MPC wallet?

A multisig wallet requires multiple separate signatures, each visible in the transaction itself. An MPC wallet splits one private key into shares that compute a signature together off-chain, producing one normal looking signature. Changing an MPC setup usually needs no on-chain transaction, while changing multisig signers usually does. In a multisig setup, each signer holds a complete, separate private key. The blockchain records exactly how many signatures approved the transaction and from which addresses. Anyone looking at the transaction on a block explorer can see it was a multisig approval. MPC works differently. One private key is mathematically split into shares held by different parties. Those parties jointly compute a valid signature without ever reconstructing the full key in one place. The resulting signature looks identical to an ordinary single signer transaction, so the multi party structure is invisible on-chain. Say a fund manages a 1 crore rupee crypto treasury and compares the two models. A multisig setup would show every approval publicly on-chain, useful for a transparent audit trail. An MPC setup would show a single clean signature each time. That suits a fund that wants its internal signer structure kept private. MPC key shares can be reshuffled among parties without any on-chain transaction. A departing team member's access can be revoked more quietly and cheaply than with multisig. Removing a multisig signer usually needs its own approved transaction. This flexibility is also why MPC setups need extra scrutiny of the off-chain process. There is no on-chain record to audit afterward.

Can a hardware wallet transaction be traced back to its owner?

A hardware wallet transaction can be traced, since the wallet address and its full history stay public on the blockchain. A hardware wallet only hides the private key, not the on-chain address or its activity. Identity checks at an exchange used to fund the wallet can link that address to a real person. Every transaction a wallet address makes is recorded permanently on the public blockchain, visible to anyone using a block explorer. This is true whether the key controlling that address lives in a hardware wallet, a software wallet, or a paper backup. The device changes nothing about the address's visibility. What a hardware wallet actually protects is the private key, the secret that authorises spending from the address. It offers no privacy feature for the address itself or the pattern of transactions it makes. Anonymity and security are separate properties, and a hardware wallet only provides the second one. Say an investor buys 25,000 rupees of crypto on an exchange that requires identity verification. They withdraw it to a hardware wallet's address. That exchange has an internal record linking the investor's identity to that specific address. Anyone who later obtains that record can connect the wallet's public transaction history to the person. The record could reach them through a legal request or a data breach. Moving funds through several intermediate addresses does not remove the traceability either. Blockchain analysis tools can often follow a chain of transfers and cluster addresses that likely belong to the same holder. True address level privacy needs specific privacy focused techniques, not just a hardware wallet.

What is the difference between a hardware wallet and a paper wallet?

A paper wallet is a printed private key or seed phrase, with no signing hardware behind it. A hardware wallet has a secure chip that signs transactions internally, never exposing the key to a computer. Paper wallets are vulnerable to physical damage, fading ink, and exposure the moment they are used. Creating a paper wallet means generating a key offline, then writing or printing it onto paper. That paper becomes the only record of the key. A paper wallet is pure storage. There is no chip, no software, and no signing process built into the paper itself. A hardware wallet is active hardware. When a transaction needs signing, the device computes the signature inside its own secure chip and only returns the signed result. Using a paper wallet means eventually importing the raw private key into some software. That step is needed to actually spend the funds. At that point the key touches an internet connected device directly. Say an investor printed a paper wallet holding 5 lakh rupees of crypto two years ago. They now want to spend part of it. Importing that key into a software wallet exposes the full key to that device. This is the first exposure since the wallet was printed. A hardware wallet holding the same funds would never expose the key at all during that same spend. Paper degrades. Ink fades, water damages it, and a house fire destroys it completely, with no backup unless a second copy exists somewhere else. A hardware wallet is also a single physical object that can be lost or damaged. It never requires exposing the raw key just to make a transaction, which is the deeper structural weakness of paper.

What does a smart contract security audit actually check for?

A smart contract security audit checks the code before it goes live. It looks for known vulnerability classes, such as reentrancy bugs and integer overflow. Audit firms like CertiK or Trail of Bits publish a report rating each finding's severity, from informational to critical. An audit reduces risk but does not eliminate it. Auditors run through the contract's code line by line. They test it against a checklist of known bug patterns that have caused past exploits. A reentrancy bug is one of the most common findings. It happens when a malicious contract calls back into the original function before it finishes updating its own state. An integer overflow, where a number wraps past its maximum value, is another. The audit firm then publishes a report listing every finding, rated by severity, along with whether the project fixed it before launch. A clean report does not mean zero findings. It usually means every critical and high severity finding was addressed. Reading the actual report, not just the badge on a website, shows what was found and what was fixed. Say an investor is considering a 5 lakh rupee position in a new protocol and finds it lists an audit badge. Reading the actual report shows three medium severity findings that were fixed and one low severity finding left open by design. That detail tells the investor more than the badge alone, which only confirms an audit happened. An audit only covers the code as it existed on the day it was reviewed. A contract upgraded afterward is running unaudited code until a new audit covers the change. Audits also cannot catch every exploit, since new attack techniques are discovered constantly. That is why even audited protocols have been hacked before.

Are NFTs inherently a scam or does the risk depend on the project?

NFTs are not inherently a scam. An NFT is a token standard, a way of representing unique ownership on a blockchain. The scam risk sits in specific projects, not in the format. Wash trading and fake floor prices are the most common NFT-specific manipulation tactics. A token standard is just a technical format, the same way a PDF is a format. Whether the document inside it is legitimate is a separate question. NFTs can represent art, event tickets, or in-game items, and the format itself carries no scam risk on its own. Wash trading in NFTs works by an entity buying and selling the same NFT between its own wallets. This fakes trading activity and inflates the apparent floor price. A drainer contract works differently. It disguises itself as a normal mint or claim transaction. The signature it requests actually authorises draining the connected wallet's other assets. Say an investor is offered an NFT with a listed floor price suggesting it is worth 25,000 rupees. Checking the trading history shows the same three wallets trading it back and forth repeatedly, with no outside buyers. That pattern is wash trading, and it means the 25,000 rupee figure reflects manipulation, not real demand. A minting site that asks for a wallet signature before the mint has even started is the classic drainer setup. The signature requested is often far broader than what a normal mint needs. Reading exactly what permission a signature request grants, rather than clicking approve automatically, is the actual protection here.

What is the difference between a bank locker and crypto self-custody?

A bank locker in India operates under RBI's 2021 rules. Those rules cap the bank's liability for its own negligence at 100 times the annual locker rent. Crypto self-custody has no equivalent cap and no third party, since the holder alone controls the keys. RBI's locker rules make the bank liable only when the loss results from the bank's own negligence. That can mean a fire or building collapse caused by poor maintenance. Even then, compensation is capped at 100 times the annual rent paid for that locker. If a locker is opened through fraud unrelated to the bank's fault, the cap may not apply the same way. Disputes over this are common. Crypto self-custody removes the third party entirely. There is no bank, no branch, and no liability cap of any kind, because nobody but the holder ever has the key. This gives full control. It also means there is no institutional backstop if the key is lost, stolen, or the holder makes a mistake. Say an investor keeps jewellery worth 5 lakh rupees in a bank locker paying 5,000 rupees a year in rent. They also keep an equivalent 5 lakh rupees in crypto through self-custody. If the locker is damaged through the bank's negligence, compensation is capped near 5 lakh rupees under the 100 times rule. If the self-custody seed phrase is lost, there is no compensation path of any kind. The locker cap only applies to the bank's own negligence, not theft by an outsider the bank could not reasonably prevent. The comparison is not a clean one. What both cases share is that a third party liability structure, however limited, is something self-custody never offers by design. An investor holding a Qatobit Crypto Index sits closer to the locker model than to self-custody. The assets are held under institutional custody rather than the investor's own private keys.

How can you buy a genuine hardware wallet in India safely?

Buying a genuine hardware wallet in India safely means ordering from the manufacturer's own site or an authorised local reseller. That reduces the risk of a pre-tampered device. Import duties and GST apply when ordering from outside India. A device that arrives already initialised should never be used. Resale marketplaces and unofficial sellers are the main source of tampered devices. A bad actor can pre-generate a seed phrase, seal the box to look untouched, and sell it as new. The manufacturer's own site and its listed authorised resellers are checked against this specifically, which a random marketplace listing is not. Ordering from outside India, directly from a manufacturer with no Indian distributor, means the shipment goes through customs. Import duty and IGST apply on arrival. Buying through an authorised local reseller instead usually means that clearance and tax is already handled in the listed price. Say an investor orders a hardware wallet listed at 8,000 rupees from an international site with no Indian reseller. Customs duty and IGST on arrival can add several hundred to over a thousand rupees more. The exact amount depends on the declared value and current rates. Buying the same device from an authorised Indian reseller often costs about the same all in, without the customs step. A device that arrives with the seed phrase already generated and written on an included card is the clearest sign of tampering. A genuine new device should only generate its seed phrase in front of the buyer, during first setup. That single check catches most tampered devices regardless of where they were bought.

Can a cold storage wallet still be hacked or compromised?

A cold storage wallet can still be compromised. Physical theft of the device, combined with a known PIN or seed phrase, defeats it entirely. Supply-chain tampering, where an attacker pre-loads a seed phrase before the device reaches the buyer, is a documented attack vector. Cold storage means the private key never touches an internet connected device, which blocks remote hacking attempts completely. It does nothing to protect against someone who physically obtains the device and also knows or can guess the PIN protecting it. Supply-chain tampering happens before the buyer ever opens the box. An attacker intercepts the device, generates a seed phrase on it themselves, and reseals the packaging. They wait for the buyer to fund the wallet using a seed phrase the attacker already knows. This is why buying only from the manufacturer or an authorised reseller matters. Say an investor keeps a hardware wallet holding 5 lakh rupees of crypto at home. The seed phrase sits written on a sticky note taped to the device box. If the device and the box are stolen together, the thief gets both. The device and the seed phrase together are enough to move the funds. This happens despite the wallet being offline the entire time. Storing the seed phrase in the same physical location as the device defeats the entire purpose of cold storage's offline design. The two together are exactly what an attacker needs. Storing the seed phrase separately, ideally in a different physical location entirely, is what actually makes cold storage resistant to physical theft.

Can a multisig wallet still be hacked if one key is stolen?

A multisig wallet can still be hacked. A single stolen key cannot move funds alone, since it sits below the signing threshold. Compromising enough keys to meet that threshold, such as 2 of 3, still allows the funds to move. Phishing each signer separately is the realistic attack path. The signing threshold is exactly what protects a multisig wallet from a single compromised key. If the threshold is 2 of 3, one stolen key alone cannot authorise any transaction. The contract requires a second approval before funds move. This is the entire point of the setup. An attacker who wants to break a 2 of 3 multisig needs to compromise two of the three signers. The target is the people, not the smart contract itself. The contract is usually well audited and far harder to break than a person. Phishing each signer individually, sending each one a convincing fake approval request, is the documented path several real multisig hacks have used. Say a fund runs a 2 of 3 multisig on a 1 crore rupee treasury, with three signers in different cities. An attacker sends all three a fake urgent transaction request through a compromised group chat. Two of the three approve it before noticing anything wrong, and the funds move. The multisig contract itself functions exactly as designed. Raising the threshold means moving from 2 of 3 to 3 of 5, for example. That raises the number of signers an attacker needs to compromise. It also raises the coordination cost for every legitimate transaction. Each signer should independently verify transaction details, rather than trusting a request that arrives through a shared channel. That is what actually stops the phishing path.

How much does a hardware wallet cost to import into India?

Popular hardware wallets typically cost between 60 and 150 US dollars before shipping, roughly 5,000 to 12,500 rupees at usual exchange rates. Ordering from outside India adds customs duty and IGST on arrival, on top of that base price. Buying through an authorised local reseller can avoid the separate customs clearance step entirely. The 60 to 150 dollar range covers most mainstream devices. Simpler models sit at the lower end, and ones with a larger screen or Bluetooth support sit at the higher end. That price is set by the manufacturer and does not include shipping or any India specific charges. Ordering directly from a manufacturer's international site means the package clears Indian customs on arrival. Import duty and IGST apply there, based on the declared value. This step can add a meaningful amount to the final cost and can also delay delivery while the shipment clears. Say an investor buys a hardware wallet priced at 80 US dollars, roughly 6,700 rupees, directly from the manufacturer's international site. Customs duty and IGST on arrival can add another 1,500 to 2,000 rupees. The exact amount depends on current rates and how the shipment is valued. Buying the identical device from an authorised Indian reseller at around 8,500 rupees all in often costs about the same. There is no customs wait either. Prices swing with currency exchange rates and reseller markups. The exact rupee figure moves over time even when the dollar price stays fixed. Check the current listed price on the manufacturer's own site instead of relying on a remembered figure. That avoids budgeting around a stale number.

How many separate cold storage wallets should you actually keep?

Most people keeping cold storage should hold at least two devices, one active and one backup. That avoids a single point of failure. A second device is often kept as a geographic backup or a backup signer in a multisig setup. Each extra device adds its own custody burden, so more is not automatically safer. A single cold storage device is vulnerable to one bad event: a house fire, theft, or a hardware failure. That event can destroy it before a transaction is ever made. Holding two devices protects against that single event wiping out access entirely. So does one device with a securely backed up seed phrase stored elsewhere. A second device is commonly used one of two ways. One is an identical backup with the same seed phrase restored onto it, kept in a different physical location. The other is a separate signer inside a multisig setup, where losing one of several devices does not lock the funds. Both approaches solve the single point of failure problem differently. Say an investor holds 5 lakh rupees in cold storage on one device kept at home. They buy a second identical device and restore the same seed phrase onto it. They store it at a family member's house in another city. A fire or theft at either location no longer means total loss of access. Beyond two or three devices, the benefit flattens out while the burden keeps growing. Each device is another seed phrase or key share that needs secure, separate storage and periodic checking that it still works. Most guidance settles on two to three devices as the practical range for an individual holder. An investor who does not want to manage this decision can allocate through Qatobit's Crypto Indices instead. Assets there sit under institutional custody rather than a personal set of cold storage devices.

How many signatures does a multisig wallet transaction need?

A multisig wallet transaction needs whatever threshold was set at creation. That threshold is structured as an M-of-N scheme, such as 2 of 3 or 3 of 5 signers. A transaction only broadcasts once that minimum number of signers has approved it. The threshold is fixed at deployment and needs a contract-level change to alter. M-of-N means M signatures are required out of a total of N possible signers. A 2 of 3 setup has three total signers but only needs any two of them to approve a transaction. This protects against one lost key without needing all three every time. The transaction sits unbroadcast, essentially pending, until enough signers have approved it. Each additional required signature adds a coordination step. The transaction has to physically reach each signer, get reviewed, and get approved before it moves. A higher threshold relative to the total signers means more security but more friction on every transaction. Say a family sets up a 2 of 3 multisig for a 1 crore rupee crypto holding. The signers sit in three different locations. A transaction to rebalance the holding needs any two of the three to review and approve it before the funds move. If one signer is travelling, the other two can still approve it without delay. Changing the threshold after deployment usually needs its own approved transaction under the existing rules. This applies even for a small change. Moving from 2 of 3 to 3 of 5, as more family members are added, still needs it. It is not a simple settings change. Planning the likely future signer list before deployment avoids a disruptive reconfiguration later.

Is cold storage necessary for crypto or is it optional?

Cold storage is optional for crypto, chosen for the portion not needed for daily buying or selling. It means keeping the private key, the code that authorizes a transfer, on a device that never connects to the internet. That keeps remote attackers out. Software wallets and exchanges stay more convenient for active trading. A private key proves ownership and authorizes a transfer. Keeping it on a phone or laptop exposes it to hacking, malware, or a stolen SIM. A cold wallet is a small hardware device that generates and stores that key offline. Signing a transaction still means plugging in the device or scanning a code. The key itself stays on the device the whole time. Custodial platforms remove this decision for the user, since the platform holds the keys and manages storage on the investor's behalf. Software wallets and exchange accounts sit online, ready for quick buying and selling. Cold storage adds a manual step each time. Active traders often keep a working balance online and move the rest offline. Consider an investor holding 5 lakh rupees in crypto for the long term, with no sale planned for a year or more. Moving that balance to a hardware wallet costs a one-time device purchase and a careful seed phrase backup. A working balance of 25,000 rupees, used for weekly buying and selling, usually stays in a software wallet. Cold storage would slow down every transaction on that smaller, active balance. The edge case is a lost or damaged device with no seed phrase backup. Cold storage blocks remote attackers reaching a key over the internet. A lost physical device is a separate risk with its own fix: a written or metal seed phrase backup, kept apart from the device itself. Skip that backup and the loss becomes permanent. Index exposure through Qatobit removes this decision for the investor. Custody sits with the platform under institutional custody. Live Proof of Reserves stays available at any time. The investor never manages a private key or a cold wallet.

Is crypto phishing a punishable cybercrime under Indian law?

Yes. Crypto phishing is a punishable cybercrime in India under Sections 66C and 66D of the Information Technology Act, 2000. Section 66C covers identity theft and Section 66D covers cheating by personation using a computer resource. A victim can file a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in. Phishing works by tricking someone into handing over a private key, a seed phrase or exchange login details. A fake wallet-support message, a cloned exchange login page and a fraudulent airdrop link are the three most common methods. Once the attacker has the credentials, funds move out in a single transaction and there is no bank to call and reverse it. The law treats crypto phishing the same way it treats any other cyber fraud. There is no separate crypto statute for it. Investigators use the same IT Act sections, the same portal, and often the same cybercrime cell that handles UPI fraud and card fraud. A complaint should include wallet addresses, transaction hashes and any screenshots of the phishing message. These are the evidence a cybercrime cell works from. Consider someone who lost 25,000 rupees in crypto to a fake exchange login page. Filing a complaint on cybercrime.gov.in within 24 hours gives investigators the best chance of tracing the wallet before funds move again. The portal also has a dedicated financial fraud reporting number, 1930, for faster action on transfers still in progress. Recovery is the harder part. A criminal case under the IT Act can lead to prosecution. It rarely returns the stolen crypto itself. Once funds reach a wallet outside India or pass through a mixer, tracing becomes a cross-border problem that most local cybercrime cells cannot resolve alone.

What happens to your crypto if you lose your hardware wallet device?

Losing a hardware wallet device does not destroy the crypto inside it. The funds stay tied to the seed phrase, a set of 12 or 24 words generated when the wallet was set up. A safely backed up seed phrase restores full access on a new device. A hardware wallet is a signing tool. It never stores the crypto itself, since crypto only ever exists as a balance recorded on its blockchain. What the device holds is the private key. The seed phrase is a human-readable backup of that same key. Buy a replacement device, enter the seed phrase during setup, and the wallet rebuilds the same keys and shows the same balances. The seed phrase is therefore the asset worth protecting. Anyone who finds a lost device without the PIN generally cannot reach the funds. Most hardware wallets wipe themselves after a handful of wrong PIN attempts. The greater risk is a lost device paired with an unprotected seed phrase written down somewhere findable. Consider an investor with 5 lakh rupees in crypto on a hardware wallet who leaves the device in a taxi. A paper backup stored in a home safe means buying a new device of the same brand restores full access within minutes. The blockchain ties ownership to the key alone, so the balance stays exactly where it was before the device went missing. Losing the device and the seed phrase together is unrecoverable. No manufacturer, exchange or support desk can reissue a lost seed phrase, since no one but the owner ever held it. This is the one failure mode that makes hardware wallets unforgiving, unlike an account with a password reset option.

What happens if you lose one key in a multisig wallet setup?

Losing one key in a multisig wallet does not lock the funds, as long as enough of the remaining keys still meet the signing threshold. A common setup is 2-of-3, where any two of three keys can authorize a transaction. Losing one key still leaves two, so funds stay fully accessible. A multisig wallet requires more than one private key to approve a transaction. A normal wallet needs just one. The threshold is set when the wallet is created, commonly 2-of-3 or 3-of-5. Each key is usually held on a separate device or by a separate person, so one lost key does not by itself compromise anything. The response to a lost key is to rotate in a replacement key. The remaining signers approve a transaction that removes the lost key's authority. That same transaction adds a new one, restoring the wallet to its original threshold. Contract-based multisigs, such as a Gnosis Safe, record this change on-chain as a normal transaction. Consider a family holding 1 crore rupees in a 2-of-3 multisig, with keys split between two family members and a lawyer. If one member loses their key, the other two signers approve a transaction swapping in a new key. The wallet keeps working, and the 1 crore rupee balance is never touched during the swap. The whole process typically takes one on-chain transaction. The danger is losing enough keys to fall below the threshold. In a 2-of-3 setup, losing two of the three keys makes the funds permanently inaccessible. No combination of the remaining single key can meet the signing requirement. The threshold set when the wallet was created is what decides how much loss it can survive.

How do you move crypto from an exchange into cold storage?

Moving crypto from an exchange to cold storage means sending it to a receiving address generated by the hardware wallet. The cold wallet address must be created first, before funds are sent. A small test transaction ahead of the full transfer catches address or network mistakes while the amount at risk stays small. The exchange initiates a standard withdrawal, the same as sending crypto to any other wallet. The cold wallet's app or device generates a receiving address for the asset being moved. That address gets pasted into the exchange's withdrawal field. Network fees are paid in the asset itself. A token transfer instead pays the fee in the chain's native token. The most common mistake is a mismatched address format between the asset and the destination chain. That happens when a token built for one network gets sent to an address meant for another. Funds sent to the wrong network format are often unrecoverable. A small test transaction, confirmed as received before the rest follows, is standard practice for anyone moving a meaningful amount. Consider moving 5 lakh rupees worth of crypto off an exchange into a hardware wallet. A test transaction of a few hundred rupees goes first. It confirms the address and network are correct. Waiting for it to arrive keeps the bulk of the transfer safe before the remaining amount is sent. The network fee on the full transfer is usually small, a small fraction of the amount moved. The edge case is a chain that requires a memo or destination tag alongside the address, common on assets like XRP. Leaving that tag off can send funds into the exchange's shared wallet with no way to identify whose deposit it was. Always check whether the destination asset needs a tag as well as an address before sending.

Is a multisig wallet safer than a single hardware wallet?

A multisig wallet is generally safer than a single hardware wallet, since it removes the single point of failure one device represents. A multisig setup needs two or more keys to approve a transaction, so a single compromised device cannot move funds alone. The cost is added coordination, since every transaction needs multiple approvals. A single hardware wallet protects the private key from online attacks. The key still lives in one place, though. If that device and its seed phrase backup are both lost, stolen or compromised, funds move with no second check. A multisig setup spreads the keys across separate devices or people, so no single point of compromise is enough on its own. The added safety comes with added friction. Every transaction needs the required number of signers to review and approve it. That can mean coordinating across devices, locations or people. A single hardware wallet lets one person move funds in seconds. A 2-of-3 multisig means waiting on a second signer, even for a routine transfer. Consider a 25,000 rupee monthly crypto allocation managed by one person. A single hardware wallet is usually proportionate at that scale, since the coordination cost of multisig outweighs the benefit for smaller, frequent transactions. A 1 crore rupee holding, managed by a family or a small team, sits at a different scale. There, a 2-of-3 or 3-of-5 multisig setup starts to make practical sense. The edge case is losing more keys than the threshold allows. A multisig wallet is only as safe as its threshold design. A 2-of-2 setup with no backup signer can be just as brittle as a single hardware wallet, if one of its two keys is lost. Safety comes from the threshold and the backup plan behind it, whatever the wallet is called.

How do you remove a signer from a multisig wallet safely?

Removing a signer from a multisig wallet safely means submitting a transaction that changes the signer list. The wallet's existing threshold must approve it first. It runs through the same approval process used for a transfer. The remaining signer count must still meet the wallet's threshold after removal. A multisig wallet's rules, including who the signers are, live in the wallet's own logic on-chain. To remove a signer, the current signers propose and approve a transaction that updates the signer list. Contract-based multisigs like a Gnosis Safe execute this as an on-chain transaction. The change is logged permanently on the blockchain. The threshold has to be checked before a removal goes through. A 2-of-3 wallet dropping to two signers still needs two approvals, which works fine. That same wallet cannot drop to one signer while keeping a threshold of two. Most multisig interfaces refuse a removal that would make the threshold mathematically impossible to meet. Consider a 1 crore rupee company treasury held in a 3-of-5 multisig, where one signer is leaving the company. The remaining four signers approve a transaction removing that person. In the same step, or a follow-up one, they add a replacement, restoring the wallet to five signers. The 1 crore rupee balance is never moved or exposed during this change. The edge case is losing access to enough current signers to approve the removal itself. If a wallet needs three approvals to remove a signer, and only two active signers remain, the wallet is stuck. A workaround, such as a wallet migration, is the only way out. Planning signer changes early, before a threshold is nearly lost, matters more than reacting after the fact.

How does self-custody differ across crypto, stocks and gold ETFs?

Crypto is the one common asset class in India where true self-custody, holding the asset directly through a private key, is possible. Stocks sit in a depository account with NSDL or CDSL, never held directly by the investor. Gold ETF units exist only as demat entries, a paper claim on gold held in a vault. A depository is a regulated intermediary that holds securities electronically on an investor's behalf. NSDL and CDSL are the two depositories in India. Every demat stock holding sits in an account at one of them, accessed through a broker. The investor holds a right to the shares, recorded in that account, rather than a certificate they control directly. A gold ETF works the same way. The fund buys and stores physical gold in a vault. The investor holds units representing a share of that gold, recorded in their demat account. Crypto breaks this pattern, because a private key gives direct, unmediated control over the asset. No depository, broker or vault stands between the holder and the holding. An investor with a 1 crore rupee portfolio split across stocks, gold ETFs and crypto experiences custody differently for each piece. The stock and gold ETF portions sit in one demat account, visible on a single statement with no separate action required. The crypto portion is the only piece where the investor must actively decide whether to self-custody or leave it with a platform. The edge case is that self-custody is optional for crypto. Most Indian crypto holders keep their assets on an exchange or platform instead of managing a private key themselves. That behaves like the depository model investors already know from stocks and gold. True self-custody is available for crypto, and it takes an active decision to opt into. Qatobit's Crypto Indices work on this same custody pattern. The platform holds the underlying crypto under institutional custody and publishes live Proof of Reserves. The investor holds index exposure the same way they already hold stocks and gold ETFs, without managing a private key.

How does self-custody differ from holding crypto through an index basket?

Self-custody means holding a private key directly and being solely responsible for its safety. An index basket gives price exposure to the same underlying assets without the holder ever managing a wallet, a seed phrase or a private key. Custody and rebalancing responsibility sit with the platform instead of the individual. With self-custody, the investor generates or receives a private key, secures it, and is the only party who can move the funds. There is no support desk, no password reset and no recovery if the key is lost, since no third party ever held it. Every decision, from which wallet to use to how to back up the seed phrase, falls to the individual. An index basket removes all of that operational weight from the investor. The platform selects the assets, makes the purchases, rebalances the basket on a schedule and holds the underlying crypto under institutional custody. The investor's decision shrinks to choosing the basket and the amount, instead of managing keys, wallets or on-chain transfers. Consider an investor putting 25,000 rupees a month into self-custodied crypto directly. That needs a wallet, a backup plan for the seed phrase and a separate purchase process for each asset. The same 25,000 rupees a month into an index basket needs none of that. The basket handles selection, purchasing and rebalancing as one product. The choice is between control and operational simplicity. Self-custody gives the holder direct, unmediated ownership of the underlying asset. An index basket exchanges that direct ownership for the platform's custody and management. What the investor gains from an index basket is time and reduced operational risk. Qatobit's Crypto Indices are built exactly on this model. Custody sits with the platform under institutional custody, with live Proof of Reserves available at any time. The investor holds the basket rather than the individual coins inside it.

Can you self-custody crypto without ever using a hardware wallet?

Yes, self-custody only requires holding your own private key. The device it lives on is a separate question. A hardware wallet adds offline protection as an option, never a requirement. Software wallets, such as MetaMask, are fully self-custodial without any hardware at all. What makes a wallet self-custodial is who controls the private key. The hardware it runs on plays no part in that definition. A software wallet generates and stores the key on a phone or computer, encrypted locally, with the user holding the seed phrase as backup. Only the user can authorize a transaction, since no exchange or company holds the key. The difference between a software wallet and a hardware wallet is where the key lives while signing a transaction. A software wallet's key touches an internet-connected device at the moment of signing, which carries some exposure to malware. A hardware wallet keeps the key on a separate offline chip, reducing that specific risk without changing who has custody. An investor moving 25,000 rupees a month into crypto for active use might keep it in a software wallet like MetaMask, for convenience. Signing transactions directly from a phone suits that pace. A larger holding, say 5 lakh rupees meant to sit untouched for a year, sits at a different point. There, the offline protection of a hardware wallet starts to outweigh the extra step it adds. The edge case is exposure. A software wallet carries more exposure to phishing and malware than a hardware wallet does, even though both are equally self-custodial in principle. The word self-custody describes who holds the key. How well that key is protected from every kind of attack is a separate question entirely.

How do you sell crypto that is held in cold storage?

Selling crypto held in cold storage requires transferring it to an exchange or online wallet first. A cold wallet has no exchange connection and cannot sell directly. The transfer is a normal on-chain transaction to the exchange's deposit address. Once funds arrive and confirm, the sale executes like any other order. A cold wallet only signs transactions and stores keys offline. It has no connection to any market or order book. To sell, the holder sends the crypto from the cold wallet to a deposit address on an exchange. After network confirmations arrive, a sell order gets placed once the balance shows up in the exchange account. This transfer step is the one moment the funds briefly leave cold storage's offline protection. Between sending the transaction and it settling on the exchange, the crypto sits in transit. It carries the same exposure as any on-chain transfer. The cold wallet's own key is never exposed, since only the funds move. Most sellers time this transfer close to when they actually intend to sell. Consider selling 5 lakh rupees worth of crypto held in cold storage. The holder transfers it to an exchange and waits for confirmations, which can take from minutes to an hour depending on the network. The sale goes through once the balance is confirmed and credited. Network fees on that transfer are typically a small fraction of the 5 lakh rupees being moved. The edge case is a sudden price move during the transfer window. Cold storage cannot execute a sale directly. There is always a gap between deciding to sell and the funds actually being sellable on an exchange. Price can move against the holder during that gap. This is the specific cost of cold storage's offline safety.

How does wallet recovery differ between an exchange and self-custody?

Wallet recovery on an exchange runs through identity verification and a support ticket. Self-custody recovery relies entirely on the seed phrase, or a social recovery setup the holder configured themselves. Custodial platforms like Coinbase or Binance can restore account access once KYC is confirmed. A self-custody wallet has no support desk to call. A custodial exchange holds the private keys on the user's behalf. Losing a password or a device does not mean losing the funds. Recovery runs through identity verification, sometimes a government ID and a security questionnaire. Once that is confirmed, the exchange restores access to the same account and balance, the same recovery model used by any bank or brokerage account. Self-custody removes that safety net entirely. If the seed phrase is lost with no backup, there is no company, support line or verification process that can restore access. No third party ever held the key in the first place. Some wallets offer social recovery, where a set of trusted contacts can jointly approve restoring access, but this has to be set up in advance. An investor with 5 lakh rupees on a custodial exchange who forgets their password recovers access within days, through standard KYC verification. The same 5 lakh rupees held in a self-custody wallet, with a lost and unbacked seed phrase, is unrecoverable through any process. No verification step exists that can substitute for the key itself. The trade-off is convenience against control. Custodial recovery is forgiving of a forgotten password but depends on trusting the platform with the keys in the first place. Self-custody removes that trust requirement but shifts all recovery responsibility, and all recovery risk, onto the individual holder. Qatobit's Crypto Indices follow the custodial pattern rather than the self-custody one. Funds sit under institutional custody, and the investor never has to generate, secure or back up a private key.

What is a custody certificate and does it apply to crypto holdings?

A custody certificate is a document a securities custodian issues as formal proof that it holds an asset on an investor's behalf. Traditional custodians, banks and depositories issue these for stocks, bonds and similar instruments. Crypto custodians in India have no equivalent regulated certificate yet, so the concept does not directly carry over. In traditional finance, a custody certificate names the asset, the quantity and the custodian holding it. It gives the investor a paper trail. They can present it to an auditor, a lender or a regulator. It exists because securities are dematerialized, and the investor cannot physically inspect a stock certificate anymore. The custodian's word, backed by regulation, replaces physical possession as the proof. Crypto has no equivalent regulated document in India. No licensing regime for crypto custodians mandates one. Proof of Reserves has emerged as the practical substitute: a cryptographically verifiable record of what a platform actually holds. An investor or an auditor can check the on-chain reserves directly, without relying on a custodian's signed statement. Consider a family office holding a 1 crore rupee position who wants to verify a platform's crypto holdings. A custody certificate, the kind a demat depository would issue, does not exist for this. The available substitute is the platform's Proof of Reserves data, checked against its stated liabilities to confirm the reserves cover what investors are owed. The edge case is that Proof of Reserves and a custody certificate are not the same guarantee. A certificate is a legal attestation backed by regulation and liability. Proof of Reserves is a technical snapshot showing reserves exist at a point in time, without the same legal weight. Until India regulates crypto custody directly, this gap stays unresolved. No regulated custody certificate exists for crypto in India yet, so Qatobit does not issue one. The platform publishes live Proof of Reserves, available at any time, and an investor can check holdings directly through that.

Which popular crypto wallets are self-custodial and which are not?

MetaMask, Trust Wallet, Exodus and Phantom are self-custodial by default, meaning the user alone holds the private key. The main Coinbase app is custodial. The separate Coinbase Wallet app is self-custodial despite sharing the Coinbase name. Kraken and similar exchange accounts stay custodial regardless of any security settings enabled. The distinction is about who ends up holding the private key. A self-custodial wallet generates the key on the user's own device and never sends it to a company's server. A custodial wallet is an account on a company's platform, where the company holds the keys behind it. This is why the same brand name can mean two different custody models, as with Coinbase. The main Coinbase app functions like a bank account. Coinbase holds the keys, and the user logs in with a password. Coinbase Wallet is a separate, standalone app that generates keys on the user's own device, making it self-custodial despite the shared branding. Consider an investor moving 5 lakh rupees between these categories. Checking the specific app matters more than checking the company name alone. Sending funds into the main Coinbase app or a Kraken account means trusting that company's custody and security. Sending the same 5 lakh rupees into MetaMask or Coinbase Wallet means the investor alone is responsible for backing up the key. The edge case is a wallet that looks self-custodial but adds custodial recovery features. An email-based account recovery option, layered on top of a self-custodial key, is one example. Reading a wallet's own documentation on how keys are generated and stored is the only reliable way to confirm which category it falls into. Never assume from the brand name alone.

How do you withdraw funds from a multisig wallet once signed?

Withdrawing funds from a multisig wallet happens only once the required number of signers approve the same proposed transaction. The funds then move in a single on-chain transaction. Each signer reviews and signs the identical transaction, typically through a shared interface. Once the threshold is met, the transaction broadcasts to the network. One signer typically proposes a withdrawal, specifying the amount and the destination address. Each remaining signer reviews that exact proposal through a shared interface, such as a Gnosis Safe dashboard. They add their own signature if they approve it. Nothing moves until the number of signatures collected meets the wallet's threshold, say 2 of 3. Until the threshold is met, the proposed transaction just sits pending, visible to every signer but with no effect on the wallet's balance. Once the last required signature arrives, the transaction broadcasts as one single event, moving the full amount in one step. This differs from a normal wallet, where the transaction executes the moment its one owner signs. Consider a 1 crore rupee treasury withdrawal from a 3-of-5 multisig. The first signer proposes sending the funds to a specific bank-linked exchange account. The remaining signers review the same proposal over the following hours or days. Once the third signature arrives, the full 1 crore rupees moves in one single on-chain transaction. The edge case is a signer approving a different transaction than the one actually proposed. A wrong amount or address, entered separately instead of reviewing the shared proposal, causes this. Multisig safety depends on every signer verifying the exact same transaction details before signing.