Skip to content

Cryptocurrency consulting

In short: Cryptocurrency support deals with understanding the mechanics and securing access, never with the merits of an investment: it is neither investment advice, nor fund management, nor any guarantee of return. What it covers comes down to a handful of concrete objects — keys that authorise transfers, wallets that shelter those keys, platforms that hold on behalf of others, networks that reverse nothing — and to one question of method: how not to lose access, and how not to be defrauded.

Cryptocurrencies are almost always discussed from the wrong end, that of what they might be worth, whereas nearly every difficulty encountered by those who approach them is of another kind: access lost for want of understanding what a backup actually is, irreversible transfers sent to the wrong address or over the wrong network, holdings left indefinitely with an intermediary without knowing what that means, and abundant fraud that never attacks cryptography and always attacks people. This page therefore describes a technical object and a practice of caution, not an opportunity: what support covers for an individual as well as for a business and what it formally excludes, what a key, a wallet, an exchange platform and a network really are, how a setup that can be sustained over time is put in place, the mistakes that destroy access or attract fraud, and the situations — numerous ones — where the reasonable conclusion is to put nothing in place at all. It recommends no asset, states no expectation of value and invites nobody to acquire anything.

What cryptocurrency support covers, and what it excludes

In short: This support deals with understanding the mechanics and securing access. It is neither investment advice, nor fund management, nor any guarantee of return: no asset is recommended, no amount is suggested, no expectation of value is stated, and no decision to acquire or dispose is taken on anyone else’s behalf.

The word cryptocurrency denotes an entry rather than an object. There is no coin, no file, no physical token being moved from one pocket to another: there is a shared ledger, copied by a large number of machines applying the same rules, in which every unit is attached to an address. Holding therefore means being able to write into that ledger a line the other machines will accept, that is, possessing the key that authorises the transfer out of a given address. This key is not a password you ask to have reset: nobody keeps a spare, no service regenerates it, no identity document replaces it. Everything on this page follows from that single sentence. What is protected, what is lost, what is stolen and what is passed on is never a sum of money: it is a means of authorising, and it behaves accordingly.

So it must be said at once what this support is not, because the subject attracts confusion and some of it is expensive. This support is neither investment advice, nor fund management, nor any guarantee of return. No asset is presented as worth holding, acquiring or disposing of; no amount is suggested; no expectation is stated about what anything will be worth; no transaction is carried out on anyone else’s behalf and no key is held in place of its owner. The question of whether one should hold any of this does not belong to the discipline, and anyone answering it confidently should be listened to with suspicion. What does belong to it is of another order: understanding what you are handling, knowing where access lives, knowing what destroys it, and recognising the methods designed to take it away from you.

For an individual, support starts with vocabulary, because mistakes often begin with a misunderstood word: the difference between an account opened with an intermediary and a wallet whose keys you hold, between an address and a key, between a recovery phrase and a password, between a network and the unit circulating on it. It then turns to securing access: where the recovery phrase is kept, in what form, in how many copies, sheltered from what, and by what procedure it would be used if the usual device disappeared. It finally covers two points that people readily postpone: recognising fraud techniques, which target people rather than machines, and organising succession, because access nobody else knows how to find disappears with its owner, and no later step restores it.

For a business the need is rarely the same. It usually arises from an outside request — a customer offering to settle this way, a supplier asking for it, a partner who has already set it up — or from an activity that handles these objects itself. Support then bears on questions of organisation before it bears on tools: who inside the business is authorised to initiate a transfer and who approves it; how authorisation is kept separate from execution; where the company’s means of access are held as opposed to a person’s, and what becomes of those means when that person leaves; what is recorded, and in what form, so that accounting entries and reporting obligations can be met without acrobatic reconstruction. That last point deserves to be raised early: obligations exist, their content depends on the applicable framework and on the exact nature of the activity, and they cannot be improvised at closing time.

What remains is to place the boundary of the service, because it is a sharp one and blurring it serves nobody. Tax, accounting and legal questions call for professionals qualified to answer them, and their answer depends on a framework that is not the same for everyone. Activities consisting in holding other people’s assets, exchanging on behalf of third parties or offering a custody service are, under many frameworks, regulated activities subject to authorisation; carrying them out without that authorisation exposes you to consequences far beyond the technical subject. Useful support therefore stops at what it can establish without standing in for anyone: how things work, what the operational risks are, which gestures protect and which expose. The decision to hold belongs entirely to whoever bears its consequences; it should be taken informed, unhurried, and preferably without the person encouraging it having an interest in it.

Keys, wallets, platforms and networks: what each word covers

In short: A private key authorises transfers, a wallet shelters keys rather than funds, a recovery phrase is access itself. A balance on a platform is a claim against its operator. A network does not undo what it has recorded, and two networks are not interchangeable.

Three objects blur together in everyday use and do not serve the same function. The address is public: it is what you hand out in order to receive, and it allows nothing beyond receiving and looking. The private key is what signs: it proves, without ever being revealed, that whoever requests a transfer is entitled to request it. The recovery phrase, finally, is a sequence of words from which every key in a wallet can be recomputed — which is why it is worth exactly what the holdings it controls are worth, and why it is the one element whose loss is irreparable and whose disclosure is immediately fatal. One practical consequence follows, counter-intuitive at first: backing up a wallet does not mean copying a file or duplicating a device, but putting that sequence of words out of harm’s way, and nothing else.

A wallet therefore holds no funds: it keeps keys and assembles the transactions that use them. The forms differ by what the key is exposed to. A wallet installed on a phone or a computer is convenient and shares the fate of that machine, malicious software included. A dedicated device keeps the key outside the operating system and lets nothing out but signatures, which shifts the risk towards physical handling and towards the screen on which you check what you are signing. A transcription of the phrase on paper or metal only serves to restore, but it is what survives fire, theft of the device and hardware failure. Multi-signature arrangements finally exist, requiring several approvals to transfer and removing the single point of failure, at the cost of a complexity you must be able to operate over the long run. The major distinction, however, is not about form but about custody: either the keys are held by their owner, or they are held by a third party, and almost everything else follows from that.

An exchange platform performs several functions worth telling apart. It converts official currency into units of a network and back; it matches buy and sell orders; and, by default, it holds for its customers whatever they leave there. It is that third function which misleads. A balance displayed in an account is not a holding: it is a claim against the operator, whose value depends on its solvency, its honesty and the soundness of its own computer security. Until the units have been withdrawn to an address whose key you hold, the network ledger does not know the customer, it knows the platform. Add to this a few things worth knowing before starting: opening an account requires identity verification, access can be suspended for reasons that have nothing to do with the user, and the terms of use describe what happens in the event of failure — a document almost nobody reads and which nonetheless answers the only question that truly matters.

A network behaves differently from an ordinary payment system, and three properties are the source of the unpleasant surprises. The first is irreversibility: a transaction recorded and confirmed cannot be undone, there is no chargeback, no service to complain to, no compensation; a mistyped address produces a lost transfer, and nothing more. The second is the cost of processing: every transfer pays a fee to the network, varying with congestion at the time, which makes some operations disproportionate when the amount moved is small. The third is the public nature of the ledger: entries are viewable by everyone, at any time, without permission or justification. This is called pseudonymity rather than anonymity, because an address carries no name but all of its movements are visible, kept indefinitely, and attachable to an identity as soon as one point of contact links that address to a person.

Networks are not interchangeable, and that sentence covers a very common cause of loss. Each has its own rules, its own address format and its own unit: Bitcoin names both a network and the unit circulating on it. Other networks additionally let third parties issue their own tokens, which circulate on that network without being the same thing as its native unit — hence a practical consequence often discovered too late: paying the transfer fee for a token also requires holding the network’s native unit, failing which nothing moves. Sending to an address belonging to another network, or to an address that is valid but corresponds to a different chain, produces in some cases a definitive loss. Two further notions deserve to be understood before touching any of this. Automated contracts first: a program recorded on the network executes what it says, and the authorisation granted to it may cover far more than the operation of the moment, a signature given without being read remaining valid afterwards. Tokens announced as backed by an official currency second: the parity they display is not a property of the network but an undertaking given by an issuer, and it is worth exactly what that issuer is worth.

How support unfolds, from the need to everyday practice

In short: First establish whether the stated need really calls for this tool, even if the answer is no. The choice of arrangements follows the constraints of use rather than sophistication. The setup is verified by a test restore before any transfer. What remains is the training, which is the real deliverable.

The starting point is the use, expressed without the vocabulary of the sector. Receiving payment from a customer who has no other means, holding yourself what you already hold with an intermediary, letting an association receive donations without going through a third party, or simply understanding what a relative is talking about: these are different needs, calling neither for the same arrangements nor for the same level of caution. Assessment therefore consists in establishing what must be possible, how often, for how many people, and above all what must remain impossible. Three questions almost always make the rest obvious: who must be able to initiate a transfer, what happens if that person becomes unavailable, and what the real harm would be if access disappeared tomorrow. The first honest conclusion of this stage is sometimes that no arrangement is needed at all, and stating that conclusion is part of the work.

The choice of arrangements follows from those answers and not from a product’s reputation. Four criteria are usually enough. Frequency of access, which sets what you handle routinely against what you put away for the long term, and which often justifies separating the two. The number of people who must authorise, which by itself decides whether a multi-signature arrangement is worth its trouble. The acceptable harm should a device be stolen or lost, which sets the line between what stays immediately reachable and what is put out of reach. Sustainable complexity last, the criterion most easily neglected: an arrangement its owner cannot operate without help, or whose recovery procedure remains opaque to them, will fail at the exact moment it was meant to serve. At comparable security, a documented, widespread and boring arrangement is preferable to an ingenious construction nobody will remember how to operate.

The setup then follows an order in which no step can be skipped without consequence. The recovery phrase is generated on the device itself, never by means of an online service, and it is transcribed by hand onto a medium that connects to nothing. It is verified by a test restore — wiping the device, restoring it from the transcription alone, checking that exactly the same addresses come back — because a backup that has never been tested is not a backup but an assumption. The copies are stored in places whose destruction is not correlated, which rules out the drawer next to the device, and in conditions where neither a visitor nor a passing tradesman will stumble on them. None of this is of any interest while nothing of value is at stake: that is precisely why the order matters, verification having to precede the first transfer rather than follow it.

Early use serves to turn an installation into a verifiable habit. A test transfer of negligible value precedes any significant movement, towards each new destination and not once and for all. The address is checked on the screen of the signing device rather than on the computer’s, whose display may have been altered by malicious software; failing that, the first and last characters are re-read after pasting. The network is checked before the amount, because that is the costliest and the most discreet mistake. A written note completes the whole: it states what exists, where the elements of access are and what procedure to follow in case of loss, without ever containing the phrase itself. That note is what distinguishes an arrangement from a memory, and it is what makes the whole thing transferable to somebody other than the person who installed it.

What remains is the part that decides everything else and that no hardware buys. Losses observed in this field owe far more to behaviour than to cryptography: nobody breaks a key, they get its owner to hand it over. Training therefore bears on simple, non-negotiable reflexes. The recovery phrase is entered nowhere: on no site, in no form, at no interlocutor’s request, whatever the apparent legitimacy of the request. An approach you did not ask for is suspect by construction, and the urgency invoked is the first sign of the technique rather than a reason to hurry. Software is obtained from an official source you verified yourself, never from a link you received. The recovery procedure is rehearsed at regular intervals, failing which it is discovered to be broken on the day it is needed. And the whole is reviewed as soon as the people change, because an arrangement whose only holder of the instructions has left is no longer an arrangement.

The mistakes that destroy access or attract fraud

In short: Leaving your keys with a third party while believing you hold; photographing or typing your recovery phrase; answering an approach you did not ask for; believing an announced return; and neglecting irreversibility as well as the absence of any succession plan.

The first mistake is to confuse a balance with a holding. Leaving with an intermediary, over the long term, what you believe you own amounts to trusting a company with assets that no procedure reimburses in the event of failure: the network ledger records only the platform, and what is promised to the customer belongs to the contract, not to the network. The same mistake appears in a domestic form: entrusting your keys to a relative reputed to be competent, or letting an acquaintance take care of it. You lose twice, since you stop both controlling access and understanding what you hold, and since the relationship itself deteriorates at the first disagreement. The question to ask is always the same, and it is asked before there is a problem: if that intermediary vanished tonight, would anything be left that I could use on my own?

The second mistake concerns the recovery phrase, and it remains the most regular cause of loss. Any digital form exposes it: a photograph stays in a synchronised gallery, a note is saved to a remote service, an email sent to yourself crosses servers you do not control, an entry in a password manager places it behind a single password, and a keystroke can be recorded. What protects is boring: a handwritten transcription, checked word by word, kept off every device, duplicated in places that will not burn together, possibly engraved on a resistant medium. Two symmetrical excesses then lie in wait. Hiding it so well that you can no longer find it, or that nobody else ever will, amounts to arranging a deferred loss. Storing it where a visitor, a tradesman or a relative will come across it amounts to preparing a theft that is only waiting for its opportunity. Finally, splitting the phrase into scattered pieces looks clever and almost never is: an improvised split often reduces real security while multiplying the ways of never reassembling the whole again.

The third mistake is to answer. Most fraud in this field does not attack networks but people, and the techniques resemble one another closely enough to form a recognisable catalogue. Technical support that contacts you first, when no legitimate service has any reason to do so. A verification or emergency migration page asking for the recovery phrase, which no legitimate party ever needs. An application or extension downloaded from a link you received, imitating the original faithfully down to the logo. Malicious software that silently replaces the copied address with another, hence the need to re-read what you have pasted. A conversation patiently established on a messaging service or a dating site, leading much later to a non-existent investment platform and to payments you will not see again. The rule covering all of these fits in one line: nothing legitimate ever requires your recovery phrase, and any urgency invoked serves first of all to prevent verification.

The fourth mistake is to believe an announced return. The promise of a regular gain, guaranteed or merely presented as customary, has no place here: when a payment is offered, it always remunerates a risk, and the useful question is which risk, borne by whom, and what happens if it materialises. A promise that does not name that risk is either hiding it or inventing it. The signs that should end the conversation are identifiable without any technical skill: a quantified return presented as settled, a bonus for recruiting relatives, an interface displaying growing gains but where any withdrawal first requires an additional payment — fee, tax, unlocking, whatever the pretext —, pressure towards silence or speed, and unverifiable testimonials. How polished a site or an application looks proves nothing, because what costs the most to manufacture in such schemes is precisely the appearance of seriousness.

The fifth mistake gathers everything that irreversibility makes final. Sending without a prior test transfer, pasting an address without re-reading it, picking the wrong network when withdrawing from a platform: each of those gestures is paid for with no recourse and no one to talk to. Two structural forms of neglect are added to them. The single point of failure first — one device, one transcription, one location, one person in the know — where a fire, a burglary or an accident is enough to carry everything away. The absence of a succession plan second: holdings nobody knows exist, or whose access has been organised for nobody, become unusable on death or on the first incapacity, and no later step recovers them. Organising that succession takes method, since access must be made possible for those who ought to obtain it without being made possible for anyone else in the meantime, and that organisation is prepared while there is still time.

When cryptocurrency is not the right answer

In short: When the stated need is better served otherwise; when the value has to be known in advance; when the operational burden exceeds the benefit; when the question belonged to a regulatory framework or a qualified professional; and when what is really being sought is a return.

The first limit is also the least comfortable to state: in a great many situations, cryptocurrency adds nothing to the stated need. A need to collect payment from customers is served by the payment means those customers already use. A need to keep a record that is hard to contest is usually served by simpler arrangements that are, above all, enforceable before whoever matters. A need to modernise an image is not served by a financial instrument. The test that settles it fits in one question, asked out loud: what does this allow that the ordinary means does not, and can I state it without using the vocabulary of the sector? If the answer is slow to come, or if it reduces to the idea that one ought to get into it because everyone is talking about it, the reasonable conclusion is to put nothing in place. Inaction here costs nothing, which is rare enough to be worth noting.

The second limit lies in the variation of value, and it disqualifies whole categories of use. An amount that must be available at a known date and for a known sum — wages, rent, a tax charge, an operating reserve, savings that will be needed — has no place in an instrument whose value expressed in official currency is set by nobody. This is not a forecast, it is a property: nothing in the working of these networks guarantees an exchange value, and the absence of that guarantee is enough to rule out any use where the amount must be certain. The consequence holds equally for a business considering collecting this way: the price announced, the invoice issued and the payment received do not sit at the same instant, the gap has to be assigned to someone, and it must be decided in advance who bears it and what becomes of what has been collected. A business with tight cash cannot afford to carry that gap, and that is reason enough to decline.

The third limit is operational. Self-custody transfers to its owner responsibilities that elsewhere are carried by third parties: there is no longer a service that resets access, no adviser to call, no transaction to dispute, and mistakes are caught by nobody. That burden is permanent rather than concentrated at installation; it presupposes somebody able to carry it over time: keeping transcriptions, rehearsing a recovery procedure, maintaining the list of what exists and of who can reach it, reviewing the arrangement when people change. An organisation whose security rests on one person’s memory does not have an arrangement, it has a reprieve. Where those conditions are not met, the honest conclusion is not to install anyway and hope nothing happens: it is to give up holding the keys yourself, or to give up the use. The dominant risk here is not market risk; it is the total and silent loss of access.

The fourth limit is that of the applicable framework. Obligations exist — reporting, accounting, sometimes prior authorisation — and their content depends both on the framework you fall under and on the exact nature of what you do. Holding for yourself is not the same as holding for others; collecting occasionally is not the same as carrying on an exchange business, and the latter presupposes, under many frameworks, an authorisation you cannot grant yourself. These questions do not belong to technical support but to professionals qualified to answer them, and their answer sometimes determines whether the project can exist at all. Where the viability of what is contemplated depends on that answer, having it established is not a closing formality but the first step: the technical setup only makes sense afterwards. Committing spending in the reverse order exposes you to discovering late that none of it was possible, and to having paid for it.

The fifth limit concerns the request itself, and it is the hardest to hear. When what is really being sought is a return, an investment or a way of making up a deteriorated financial situation, this page has nothing to offer and nobody should pretend otherwise: those questions belong to financial advice professionals, within a framework that provides for disclosure obligations and remedies you will not find elsewhere. Two neighbouring situations call for the same answer. The one where the approach is undertaken under influence — an insistent third party, an opportunity presented as about to close, a person met online who obligingly assists with the first operations — in which case the problem to be dealt with is not technical and the urgent thing is to do nothing. And the one where the prospective holder cannot explain in their own words what they would hold, where access would live and what they would do if it were lost: for as long as that explanation is out of reach, the only defensible decision is to go no further. Doing nothing is a legitimate outcome, and it is better heard from someone with nothing to sell.

Frequently asked questions

What does a cryptocurrency wallet actually contain?

Keys, and nothing else. The units are not inside the device: they are recorded in the network ledger, at addresses whose matching keys the wallet holds. A wallet therefore serves to keep those keys out of reach and to assemble the transactions that use them. Two consequences follow. Destroying or breaking the device destroys nothing as long as the recovery phrase exists elsewhere, since another wallet will recompute the same keys from it. Conversely, a perfectly preserved device protects nothing at all once that phrase has been seen, photographed or typed somewhere by somebody else.

Does this service say what to acquire, when to dispose of it or how much to hold?

No, under no circumstances. It is neither investment advice, nor fund management, nor any guarantee of return: no asset is recommended, no amount is suggested, no expectation of value is stated, and no transaction is carried out on anyone else’s behalf. Those questions belong to professionals qualified to handle them, within a framework that organises their liability and provides remedies. What is dealt with here is of another nature: understanding the mechanics, securing access, avoiding the mistakes that lose everything for good, recognising fraud techniques. The decision to hold or not belongs entirely to the person who bears its consequences.

What is the difference between leaving holdings on a platform and keeping them yourself?

It is about who holds the keys, and therefore who really controls. On a platform, the network ledger records only the operator; the displayed balance is a claim against that company, exposed to its failure, to its computer security and to access suspensions decided without the customer. In self-custody, nobody can freeze access, but nobody can restore it either: losing the recovery phrase is final, and so is a handling mistake. There is thus no universally superior choice, but a trade-off between counterparty risk and operational risk, which depends on the real capacity to sustain a procedure over time.

What happens if the recovery phrase is lost?

If no copy survives and no device still works, access is lost for good. There is no recourse: no service keeps a spare, no identity check replaces it, no authority can reassign the units concerned. They remain recorded in the ledger, visible to all, and nobody can move them any more. This is why verifying the backup matters more than choosing the device: a test restore, carried out before any significant transfer, is the only proof that the transcription is accurate and legible. A backup that has never been tested should be treated as non-existent.

Where and how should a recovery phrase be kept?

Off every connected device, transcribed by hand, checked word by word, and duplicated in places whose destruction is not correlated. What is to be banned follows from that rule: photograph, synchronised note, email to yourself, online storage, typing it into any site whatsoever. Two opposite mistakes remain to be avoided. A hiding place so effective that the phrase becomes impossible to find amounts to a loss, merely deferred. Storage reachable by a visitor or a relative amounts to a theft waiting for its opportunity. A fire- and water-resistant medium adds a useful margin, but it does not replace duplication across distinct locations.

Can a transaction sent by mistake be cancelled?

No. An entry confirmed by the network is final: there is no chargeback, no complaints service, no authority able to undo it. A wrong but valid address corresponds either to nobody, or to somebody under no obligation to return anything and whom you will not be able to identify. A transfer made over a network other than the one the recipient expected is most often lost. Three precautions cover the main risk: check the network before the amount, check the address on the screen of the signing device rather than on the computer’s, and precede any significant movement with a test transfer of negligible value.

How can a fraud attempt be recognised?

Three signals are enough to dispel the doubt. The first is the unrequested approach: support that contacts you first, a message announcing an urgent problem with your holdings, an opportunity spontaneously passed on by a stranger. The second is a request for the recovery phrase, on whatever pretext — verification, migration, repair: nothing legitimate ever needs it. The third is an announced return, especially alongside a referral scheme, testimonials or fees to be paid before any withdrawal. One rule of behaviour completes them: urgency exists to prevent verification, so anything pressing should be stopped, checked against a source you obtained yourself, and resumed afterwards if warranted.

Are cryptocurrencies anonymous?

No, and the confusion is dangerous in both directions. The ledgers of most of these networks are public: every transfer, its amount and the addresses concerned are viewable by anyone, indefinitely. An address carries no name, which is why this is called pseudonymity; but as soon as one point of contact links an address to a person — a platform having verified their identity, a payment to a merchant, an address published somewhere — the associated history becomes attachable, including retroactively. The practical consequence is twofold: publishing an address amounts to publishing the movements tied to it, and professional use must take that visibility into account rather than suffer it.

Can a business accept cryptocurrency payments?

Technically, receiving requires only an address. The difficulties are elsewhere and are dealt with beforehand, not after. The value received is not fixed: between the price announced and actual settlement a gap appears which must be assigned to someone, and whether what is collected is converted or kept is settled by a written rule rather than case by case. Accounting treatment and reporting obligations depend on the applicable framework and must be established by a qualified professional. Finally, internal organisation matters as much as the tool: who holds access, who authorises an outgoing transfer, and what happens when that person leaves the company.

What becomes of access to holdings on death or incapacity?

Nothing passes on automatically. Unlike an account held by an institution, there is no third party to whom heirs could make themselves known: without the means of access, the units stay recorded in the ledger and become unusable for everyone. Organising succession therefore means satisfying two contrary requirements — making access possible for those who ought to obtain it, and impossible for anyone else in the meantime. That takes, at a minimum, that the existence of the holdings be known to a trusted person, that the location of the elements of access be documented without the document containing the phrase, and that the chosen arrangement be compatible with inheritance rules, which is a matter for a legal professional.

Let's talk about your project

Discuss your project