Custody
Who can restore access to your crypto?

At a glance
Recovery depends on the custody and wallet design. Resetting a platform login is different from recovering keys to a self-custody wallet. For a conventional recovery-phrase wallet, losing the required recovery material can leave no provider able to restore access.
On this page
“I forgot my password” can describe very different problems. A service may help reset an exchange login, while the same phrase applied to a locally encrypted wallet may require recovery material the provider never held. Identify the system before following a recovery offer.
Name the access layer
Ethereum.org explains wallets as tools for interacting with an account. In a conventional self-custody setup, control comes from keys, not from a website's password-reset email. Other wallet designs can use different recovery arrangements; investigate the exact product instead of assuming every wallet uses the same seed backup.
MetaMask's recovery guidance distinguishes its local password from its Secret Recovery Phrase. This distinction is specific to the relevant wallet setup, not a guarantee about every sign-in method it offers.
Build a private responsibility map
| Access problem | First question | Do not assume |
|---|---|---|
| Exchange login lost | What is the verified account-recovery procedure? | A reset guarantees withdrawals |
| Wallet device lost | What recovery method was configured? | Installing the app restores keys |
| Local password forgotten | Is required recovery material available securely? | Support knows your phrase |
| Keys or phrase exposed | Who else may now authorize transactions? | Changing a login password removes key access |
This is a decision aid, not a recovery service. Do not put actual phrases, private keys or authentication codes into the map.
Two hypothetical failures
In the first case, a phone is lost but the required offline recovery material remains securely available. The task is to follow the wallet's authenticated recovery instructions on a trusted device, with special attention to what kinds of accounts the backup covers.
In the second, both device access and required recovery material are lost. A person claiming they can regenerate the secret from a public address has not established a capability to recover it. A public address is not a substitute for authorization. Do not send money or secrets to test an unsolicited promise.
Plan around the actual failure
List the wallet design, official documentation, backup location policy and who is authorized to act if you cannot. Keep those records private and separate from the secrets themselves. A public screenshot proving that a backup exists is not helpful if it exposes the backup.
Custody choices move responsibilities; they do not remove risk. A provider can have operational or solvency problems, and self-custody can fail through lost keys or unsafe signing. See token permissions for a different kind of access that a password reset may not address.
CoinFom editorial note: research, writing, translation and review used AI assistance. No live transaction was performed for this article. Numerical examples are hypothetical and do not demonstrate returns. Sources checked September 26–27, 2026. Educational content, not personalized advice. See About CoinFom, our editorial and affiliate policy, or send a correction. CoinFom may earn referral commissions on other pages; this article contains no signup link.