There are three feeding arrangements in this house and they are not interchangeable. There's the bowl on the kitchen floor, refilled daily, entirely exposed — anyone could walk past it. There's the cupboard, which holds the week's supply and stays shut. And there's the box in the garage with the bulk order in it, which gets opened roughly once a month.
Nobody designed this. It emerged because the risks are different at each level, and treating them the same would be either exhausting or careless.
Almost everyone in bitcoin runs one bowl, on the floor, for everything. That's the mistake this article is about.
1. Why One Wallet Is the Wrong Shape
A single wallet has to serve two contradictory jobs: convenient enough to spend from, and secure enough to hold savings in. Optimise for either and you damage the other.
If it's convenient — on your phone, keys on a device that browses the web, used weekly — you've accepted a threat surface appropriate to pocket money and applied it to your savings. If it's secure — hardware device in a drawer, seed in a safe deposit box — you'll find yourself dragging it out to send twenty euros, which either makes you avoid using bitcoin at all, or makes you cut corners with the thing that protects everything.
The fix isn't more security. It's separation by purpose.
2. The Three Tiers
The floor bowl — spending. A Lightning wallet on your phone. Custodial or self-custodial, small balance, used constantly. The amount here should be one you'd be irritated but not harmed to lose entirely: think of it as the cash in your physical wallet. Convenience is the whole point and security is proportionate to a small number.
The cupboard — working funds. A software wallet you control, on a device you trust, holding weeks-to-months of intended spending or funds in transit. Its own seed, backed up on paper or metal, separate from everything below it. This is where donations land, where an exchange withdrawal arrives before it's moved on, where you keep enough to act without touching savings.
The garage — savings. A hardware wallet, seed on metal, geographically separated backup, a written letter for your family, and an annual recovery drill. Opened rarely and deliberately. This tier holds the bulk and is not consulted casually. If you're following the multisig logic, this is the tier that eventually graduates to it.
Three seeds. Three backups. No shared keys between tiers — because the entire point is that compromising one tells an attacker nothing about the others.
3. How Funds Move Between Them
The flow is one-directional and boring, which is how you want it:
Exchange → cupboard → garage. Buy, withdraw promptly, let it sit briefly in the working wallet, then move to savings in deliberate batches.
Garage → cupboard only when you genuinely intend to spend a large amount, and never as a reflex.
Cupboard → floor bowl in small top-ups, the way you'd take cash out for the week.
Two things to keep in mind while doing this. Each move costs a fee, so batching beats trickling. And each move creates a link on a public ledger — moving donations straight into savings connects a public wallet to a private one, permanently. Sweep deliberately, in batches, knowing what it publishes.
4. Naming Things Honestly
Whatever you do, write it down — not the seeds, the structure. One page:
- Which wallet is which, and what each is for.
- Which device holds which, and where each backup lives.
- Which one has a passphrase, if any (and where that's recorded, separately).
- The rough amount tier in each — "small / working / most of it" is enough.
This page is for two readers. Future you, in eighteen months, who will not remember which of three seeds belongs to which wallet. And your family, who will need the map rather than a puzzle.
Keep it with your will, never with the seeds.
5. The Failure This Prevents
The disaster scenario in self-custody is almost never "everything at once". It's a single compromised thing that happens to hold everything: a phone that got malware, a laptop where the seed was typed once during a stressful restore, a backup photographed "temporarily", a device handed to a repair shop.
With three tiers, each of those incidents costs you one tier. Annoying, survivable, recoverable. With one wallet, each of them costs you everything.
That's the entire argument. You are not adding security — you're adding compartments, so that being wrong once is a bad day rather than a final one.
The Point
The kitchen bowl is exposed on purpose, because what's in it doesn't matter much and the convenience does. The garage box is awkward on purpose, because what's in it matters a great deal and the convenience doesn't.
The mistake isn't leaving food on the floor. It's leaving all the food on the floor and then trying to feel secure about it by worrying more.
Three bowls. Three seeds. One mistake should cost one tier. 🐾⚡
Not financial advice — I feed a cat and write about Bitcoin, which qualifies me for neither profession. Test every backup with small amounts before trusting it. Do your own research.
Tags: Bitcoin, Self Custody, Crypto Wallets, Security, Cryptocurrency