Posts

The trader of the future with the amber and violet visor looks at a monumental glowing vault door which, seen from the side, turns out to be a paper thin panel standing on nothing, with emptiness behind it

The exchange: where you buy, and what happens if it goes down

Hi trader,

last lesson we left off on a sentence that now needs explaining properly: on an exchange the keys are theirs.

If you missed the earlier pieces, keys and wallets is what you need to make sense of this one.

Today we look inside the box. What an exchange actually is, what happens when you click buy, and what happens to your money the day it shuts down. Because it is not a theoretical scenario: it has already happened, more than once, and people lost everything.

Ok, vamos.

The thing almost nobody has clear

An exchange is not the blockchain.

It is a company. With servers, employees, a legal department and, above all, a database.

And that is not a pedantic distinction, because it has an enormous consequence: when you buy on an exchange, nothing happens on the blockchain.

Zero. No row gets written on the public ledger. No network fee. No confirmation to wait for.

Two numbers change in their database: the euro one goes down, the bitcoin one goes up. And the bitcoin it shows you are not “yours”: they are a share of a pile the exchange keeps for all its customers together, and it holds the keys.

Comparison between buying on an exchange, where only two rows change in the company database without touching the blockchain, with no fee and no wait but the keys held by the exchange, and withdrawing, where the transaction is actually written on the public ledger, the network fee is paid, confirmation is needed and the keys become yours
The two things that look the same. On the left a purchase on an exchange: two rows change in the company database, the blockchain never notices. On the right a real transfer: the row gets written on the public ledger, with a fee and a confirmation time.

Inside, though, it is a real market

And this is where it gets interesting for somebody who trades, because you already know the mechanism.

Inside the exchange there is an order book, exactly like on futures: a list of who wants to buy and at what price, and who wants to sell and at what price.

And there are the two ways of being in the market we covered in the order flow series: there is the one who places a limit order and waits at their price, and the one who sends a market order and pays to get in now.

If that feels familiar it is because it is: it is the exact same dynamic as bid/ask candles, aggressive against passive.

There is also a practical detail worth money, and it has to be stated precisely because it gets told badly out there.

Many exchanges apply two different fees: a lower one for whoever adds liquidity to the book and a higher one for whoever removes it. The jargon calls them maker and taker.

Careful though, because they do not coincide with limit and market. If you place a limit order inside the spread, it executes immediately against the book and pays the expensive fee, exactly like a market order. You only get the cheap fee if your order sits there waiting and somebody else executes against it.

And it is not a universal rule either: on some exchanges, including the most used one in the world, the two fees at base tier are identical, so that advantage does not exist at all. On others the gap is double. Go and look at your own fee table, it is a boring page that tells you what you are actually paying.

Why sending to another user is free

This also explains something that confuses a lot of people.

If you send crypto to somebody on the same exchange, it is often instant and costs nothing. If you send it out, you pay and you wait.

By now you know why: in the first case you are not using the blockchain at all. Two rows are just changing in their internal database, which costs them nothing.

In the second case the transaction really does have to be written on the ledger, and that is where you pay.

Custodial, and what it means for you

The exchange holds everybody’s keys, and it keeps them in two places: some in vaults connected to the internet, so it can serve withdrawals quickly, and most of it in vaults kept offline, far harder to drain.

As long as everything works, this does not concern you at all.

The day it stops working, this is the only thing that concerns you.

What happens if it goes down

Here we get to the serious part, and I will say it without dancing around it.

You are not a depositor. In practice you are much closer to a creditor.

When a bank fails, in Europe there is a deposit guarantee up to a hundred thousand euros. On an exchange that safety net does not exist: no guarantee fund, no compensation scheme, and it is not me saying it, it is the European authorities themselves in a consumer warning.

The European rules that came into force in recent years did introduce a real protection though, and it would be dishonest to leave it out: anybody authorised in Europe is required to keep client crypto separate from its own, so that its creditors cannot get their hands on it if it fails.

It is serious protection, and it did not exist before. But it depends on two things: that the provider really is authorised in Europe, and that it really did follow the rules. If it did not, you find out on the day of the collapse, and at that point you join the queue and wait for a court to decide who gets what, and over how many years.

Outside Europe there is often not even that. In the United States, in 2023, a judge ruled that the crypto deposited by customers of a failed platform belonged to the company and not to them: those customers ended up in line like every other creditor.

And it is not theory.

Mt. Gox, which in 2014 handled most of the world’s bitcoin trading, collapsed losing hundreds of thousands of customer bitcoin. Creditors waited more than ten years to see part of their money again.

FTX, in November 2022, was one of the three largest exchanges in the world, with sports sponsorships and famous faces. It collapsed in a week when it came out that customer money had gone where it should not have. The founder was convicted.

Neither of them looked at risk the day before. That is exactly the point.

And now the detail that can actually save you

When these things happen, the site does not shut down. Something sneakier happens: first they freeze withdrawals, and only then comes the bankruptcy. In between there are days or weeks in which your balance is right there on the screen, you can see it, and you cannot touch it.

It is not an impression, it is the documented sequence of every 2022 collapse: withdrawals frozen on 8 November, bankruptcy filing on the 11th. Another platform froze in June and failed in July, a month later.

So if one day you read that an exchange has “temporarily suspended withdrawals for maintenance”, that is not maintenance. It is the last warning, and it usually arrives when it is already late.

Table comparing a personal wallet, an exchange and a bank across four rows: who holds the keys, what you actually own, what happens if whoever holds the money fails, and how you can lose everything
What you actually hold in the three cases: crypto in your own wallet with your own keys, crypto on an exchange, money in a bank. For each one who holds the keys, what you legally own and what happens if whoever holds it fails.

How to choose one, and how to sit on it

I will never tell you which one to use, and be wary of anybody who does it lightly, because they almost always have an affiliate link in their pocket.

Here are the criteria.

Look at where it is regulated. Europe now has a framework of rules for anybody offering crypto services, and we covered it when it came into force, in the piece on MiCA and stablecoins. A provider authorised in Europe is not bulletproof, but it has obligations that one registered on an island does not.

Proof of reserves is not a promise of solvency. Many exchanges publish a check showing how much they hold. Careful though: it shows what they own, not what they owe, and at one precise instant. A company can have the reserves and have debts bigger than the reserves. It is useful, it is not a guarantee.

Turn on two step verification, but with an app, not with SMS. A phone number can be stolen by convincing the mobile operator to move it to another SIM, and it is a scam that has been going on for years.

And above all: keep on the exchange only what you need to operate. The rest you take out, where the keys are yours. This is the practical consequence of all three lessons so far.

Two clarifications though, because people make two opposite mistakes with this advice.

The first: it does not only apply to bitcoin. The balance almost everybody leaves sitting on an exchange is in euros or stablecoins, and the reasoning there is identical, with the added risk of whoever issues the stablecoin. Taking your crypto out and leaving the bulk inside in stablecoins is not securing anything.

The second: taking it out moves the risk, it does not delete it. Outside, the keys are yours, and so are the ways of losing them we saw last week. If you throw away the recovery phrase, there is not even a queue at the courthouse.

What you do from tomorrow morning

Two things, and the first one is a calculation that takes a minute.

Look at how much you have on the exchange and ask yourself: if they shut the site tomorrow morning, would this amount ruin me? If the answer is yes, that amount is too high, no matter how reliable the company seems to you.

Then make a small withdrawal to your own wallet. Not to move the money: to learn the procedure with pocket change, when you are not in a hurry and not scared. The day you actually want to do it will probably be a day when everybody is withdrawing at once, and that is not a good moment to learn.

And since it is the only irreversible thing I am asking you to do, three hard rules while you do it. Copy the address from the wallet, do not type it by hand. Check that the network selected on the exchange is the same one your wallet expects, because sending on the wrong network is the number one way money disappears on a first withdrawal. And after pasting, read the first and last characters again: there is malware that swaps the address in your clipboard while you copy it.

Where we go next time

So far we have talked about infrastructure: the ledger, the keys, the place where you buy. Next time we move on to what is inside, and to the first distinction that matters: bitcoin and ethereum are not two versions of the same thing, they are two different jobs.

On an exchange you do not have the keys. You have a company’s promise to give you your crypto when you ask for it.

tradingblog.itPosta su X

Let me close with the thing that convinced me to take out the money I do not use.

It was not fear of a collapse, and it is not distrust of any company in particular.

It was a question I asked myself looking at the screen: if this site does not open tomorrow, what do I have in my hands?

The answer was: a screenshot. And the screenshot is not yours.

Suerte Amigo!

Tiziano Brunno

Tradingblog

Want to put your market reading to the test?

Compete and challenge other traders inside an Arena in a demo environment, with no real capital at risk. Discover the Performance Arena Events by The Thunder Trader.

Discover The Thunder Trader →


Disclaimer: purely informational and educational content. It does not constitute financial advice or an invitation to trade. Trading involves the risk of capital loss.

Large ornate key made of amber light dissolving at one end into twelve small carved luminous tiles, floating above an open iron chest that is completely empty, on dark stone

Keys and wallets: what you actually own

Hi trader,

for more than a year I kept my crypto on an exchange and I was convinced I owned it.

I did not.

I had a number on a screen, which is a different thing, and I only realised it when I tried to work out what happens to that number if the company showing it to me shuts down.

This is the lesson that explained it to me. It is the second in the series, and if you missed the first one, what a blockchain is, read that first: here I take for granted that the ledger is made of rows and not of coins.

Ok, vamos.

The question nobody asks

If there are no coins on the ledger, only rows, and the rows are written by the network, then what exactly do you own?

Not an object. Not a file. Not a token inside an app.

You own the ability to sign. Meaning the ability to prove to the network that those rows can be moved by you and by nobody else.

That ability is a secret number, and it is called a private key.

What is inside a wallet

Here is the first misunderstanding to clear out, and the name itself does not help: wallet means wallet, but there is no money inside it.

There are keys.

The mechanism runs one way, and this is the beautiful part. From the private key you derive the public key. From the public key you derive the address, the one you give to other people so they can send you things.

Every arrow works in one direction only. From the address you do not get back to the key, and it is not a question of how clever you are: with today’s computers the age of the universe would not be enough.

Four step chain starting from the twelve seed words and leading to the private key, then the public key and finally the address, with arrows running one way only and a warning that there is no going back, plus the note that the coins are not in the wallet but on the ledger
From the twelve word phrase you derive the private keys, from each of those the public key, and from that the address. The arrows run one way only: there is no going back. The coins are not inside the wallet, they are on the ledger.

So when you say “I moved my bitcoin into the wallet” you are saying something imprecise. The bitcoin did not move anywhere: they are still rows on the ledger. What changed is which key can move them.

The twelve words

Now the part that really counts.

When you open a new wallet, the first thing it makes you do is write down twelve words (sometimes twenty four). It is called the seed, or recovery phrase.

Those words are not a reminder of your password. They are the wallet.

From those twelve words the software derives, with a calculation that is always the same, all of your private keys. All of them. The ones you have now and the ones you will generate in two years.

Which means something very practical: the phone is irrelevant. If it gets stolen, you get another one, you type in the twelve words and you find everything exactly as it was. But if you lose the words and the phone breaks, there is no “I forgot my password” button. There is nobody to call. It is over, full stop.

One detail that shows how well designed this is: the words come from a fixed list of 2,048, and the last one is not free, it carries a check code calculated from the previous ones. Twelve words are worth 128 bits of real randomness, a number with thirty nine digits of possible combinations.

Guessing it is not hard. It is out of the question.

Get one thing into your head though: the words have to be generated by the device, not by your brain. The check on the last word rejects almost every invented phrase, but not all of them, and that is not the point anyway. A phrase thought up by a human being is guessable, because our imagination is far poorer than randomness, and over the years the people who tried it found their wallets emptied.

Two clarifications that are worth real money.

The first. Some wallets let you add a passphrase to the twelve words, an extra word of your own, what some people call the twenty fifth word. If you use it, the twelve words on their own no longer open anything, so it has to be kept as carefully as the rest. And be careful, because if you get it wrong it does not say “error”: it opens an empty wallet, which is the best possible way to give yourself a heart attack.

The second. If you restore your words into a different app from the one you started with and you see zero, almost always you have lost nothing: it is the app looking at a different branch of the same tree of keys. Before you panic, try again in the app you started from.

“Not your keys, not your coins”

You will hear this repeated like a prayer. Now you have what you need to understand it, and it takes two lines.

When you buy on an exchange, the keys are theirs. The number you see in your account area is not a row on the ledger: it is a row in the exchange’s database, saying how much they owe you.

You do not own bitcoin. You own a claim against a company.

As long as that company works, the two things look identical, which is why nobody thinks about it. The day it stops working, it turns out they were not identical at all.

I am not telling you exchanges are evil: you go through them to buy, it is normal, I use them too. The problem is not buying there. It is leaving there what you cannot afford to lose.

The three ways people lose everything

There are not a hundred of them. There are three, and they all look like a custody mistake, not a market one.

The three cards of the ways people lose everything: losing the seed, giving it away to whoever asks, and trusting a third party that goes down. For each one how it really happens, how to avoid it, and the blunt consequence
The three ways people lose everything, side by side: you lose the seed, you give the seed away, you trust a third party that goes down. For each one, what actually happens and the rule that avoids it.

One. You lose it. You never wrote it down, or you wrote it on a scrap of paper that got wet, or it lived in a phone note that died with the phone. No recovery possible. It is the stupidest way and also the most common.

Two. You give it away. And here you carve one rule into your head, and it holds forever: nobody legitimate will ever ask you for your seed. Not support, not a site that needs to “validate” your wallet, not a helpful person messaging you, not an app you have to unlock. Nobody. If somebody asks you for it, that person is robbing you, with no exceptions and no special cases.

Three. You trust a third party. The crypto sits on an exchange, or on a platform promising yield, and that one goes down. You did not lose your keys: you never had them.

There is a fourth way, subtler, which is signing without reading and authorising a contract to drain your wallet. We will cover it in the lesson on scams, because it deserves its own space.

What you do from tomorrow morning

Four things, in order, and the third one is the one almost nobody does.

Write the seed on paper. Not a photo, not the cloud, not your phone notes, not a message to yourself. Paper, somewhere that survives a distracted version of you.

And get clear on what you have just created: that piece of paper works like cash. Whoever finds it does not have to guess a password and does not have to break anything, they type in the words and take everything in two minutes, from anywhere in the world. So “somewhere safe” means actually safe, not the top drawer of your desk.

Do not tell it to anybody and do not type it anywhere, other than into the wallet itself when you are restoring.

Test the restore before you put anything serious in there. Put in pocket change, delete the app, install it again, restore with the words and see whether you find everything. It is the only way to know you wrote them down correctly, and finding out afterwards is too late.

If the amount starts to matter, get a dedicated device. The kind where the key never leaves the object and you confirm operations with a physical button. The right question is not “how much does it cost” but “how much am I keeping on it”.

On this one a hard rule though: buy it only from the manufacturer’s site. Never used, never from a marketplace, never from some guy online because it was cheaper. A tampered device arrives with the seed already written down by somebody else, and you pour your money onto it convinced you are safe. It is a scam that exists and that works.

Where we go next time

If the exchange’s keys are its own, then it is time to understand properly what an exchange is, how it really works and what happens if it fails. That is next week’s lesson, and anybody who lived through certain stories already knows why it matters.

A wallet does not hold coins. It holds the ability to sign, and either you have it or somebody else has it in your place.

tradingblog.itPosta su X

Let me close with the thing that sorted my head out on this subject.

In trading we spend our days worrying about market risk: the stop, the size, the drawdown. Then somebody keeps everything on an exchange and never thinks about it, because that risk does not flash on the screen.

But it is a risk like any other, and it has one nasty feature: it does not make you lose a percentage.

It makes you lose everything, all at once.

Suerte Amigo!

Tiziano Brunno

Tradingblog

Want to put your market reading to the test?

Compete and challenge other traders inside an Arena in a demo environment, with no real capital at risk. Discover the Performance Arena Events by The Thunder Trader.

Discover The Thunder Trader →


Disclaimer: purely informational and educational content. It does not constitute financial advice or an invitation to trade. Trading involves the risk of capital loss.