Why We Stopped Keeping Everything in One Place
· 2 minute read · Sam Ortega
Not because anything went wrong. Because working out what would happen if it did was uncomfortable.
We kept everything at one provider because it was simpler. Then someone asked what would happen if that provider failed, and I did not have a good answer. The thing that made it click was reading a business wallet with institutional controls alongside.
The honest answer at the time
Our entire crypto balance was at one platform. If it failed, we would find out whether client assets were genuinely segregated, and we would find out slowly.
I had checked that they were. That is a different thing from not needing to rely on it.
What we changed
Operating balance stayed with the provider, sized to what we actually move in a couple of weeks.
The reserve moved to a multi-signature arrangement we operate ourselves.
Why not all self-managed
We are four people. Running key management properly means rehearsed recovery, separated backups, and a plan for someone leaving.
For a balance that moves several times a week, that coordination would be constant and it would decay.
For a reserve that moves rarely, it is manageable.
Why not all with the provider
For client money the rules are stricter, and a platform built for institutional allocations is set up for that.
Concentration. Whatever sits in one place can be lost from that place, and no amount of diligence reduces that to zero.
The sizing rule we use
The operating balance is roughly two weeks of outgoings. Everything above that goes to the reserve.
That number came from asking what we would be prepared to lose to a single incident without it being existential.
What splitting cost us
A second set of controls to maintain, and an annual recovery rehearsal that takes an afternoon.
Also a slightly worse fee tier at the provider, because our balance with them is smaller.
What it bought
A failure at either end is survivable.
That is worth more than the fee tier, and it was the thing I could not say before.
The thing I underestimated
The recovery rehearsal.
The first time we did it, the documentation assumed a software version that had changed. We could not restore from the backup following our own written procedure.
We found that out in a rehearsal rather than in an emergency, which is the entire argument for doing it.
Now it is annual, performed by someone who did not set it up, from the backup rather than from the live devices. That is the test, and it is the thing that actually fails. Check it yourself rather than taking my word. a regulated crypto exchange is on a public register.
Sam Ortega
Came into crypto in 2024 with $500 and no idea what he was doing. Has been keeping a diary since. This is a personal diary, not financial advice.