The Four Layers of Crypto Risk: A UK Investor's Guide

By Simon Bumford, Founder · · 12 min read

Most investors protect against one type of crypto risk and ignore three. Learn the four layers, from lost keys to failed exchanges, and audit your own in minutes.

Four ways to lose the same coin

There are four fundamentally different ways to lose cryptocurrency, and they demand four different defences. You can lose the keys. The business holding your assets can fail or be robbed. The code and systems your asset depends on can break. And you can be deceived, targeted or simply die without a plan. Most holders, including careful ones, concentrate everything on one layer, usually the keys, and never examine the other three. The layers are worth naming precisely, because the defences do not transfer between them. A steel seed plate does nothing when your exchange freezes withdrawals. Choosing a reputable exchange does nothing when a phishing call catches you tired. This guide takes each layer in turn, with recent verified examples, then gives you a short self-audit to run against your own holdings in about ten minutes. It is written for UK holders, so the regulatory reality appears where it belongs, starting with the blunt part: the FCA's position is that anyone investing in crypto should be prepared to lose all their money, and the Financial Services Compensation Scheme is highly unlikely to cover crypto losses. For now, the protection you have is mostly the protection you build.

Layer one: key risk

Key risk is the oldest and simplest: whoever holds the keys holds the coins, and keys that are lost or destroyed take the coins with them, permanently and without appeal. A Chainalysis study estimated as far back as 2017 that between 2.78 and 3.79 million bitcoin, then 17 to 23 per cent of all coins in existence, were already lost forever. The case law is now British as well as Californian: in January 2025 the High Court dismissed James Howells' claim against Newport City Council over the landfill containing his hard drive and its keys to roughly 8,000 bitcoin, holding that waste delivered to the tip became the council's property under the Control of Pollution Act 1974. And programmer Stefan Thomas remains the parable of the category: 7,002 bitcoin on an encrypted drive that allows ten password guesses, eight of them already spent when he went public in 2021. 2026 added a nastier variant: you can do everything right on the wrong firmware. TRM Labs documented the theft of roughly $116 million from over 5,200 Coldcard hardware wallet addresses beginning in July 2026, exploiting a 2021 firmware flaw that generated seeds with far too little randomness. Affected owners had to migrate to fresh seeds; updating the firmware alone fixed nothing. Managing this layer is mostly discipline, and it is fully within your control: a recovery phrase recorded offline on paper or steel, never photographed or typed into anything, stored in two places, and proven by an actual test restore. Our hardware wallet backup guide covers the craft, and multisig removes the single point of failure for larger holdings. Keep the firmware lesson too: buy devices new, direct from the maker, and apply security updates when the maker publishes them.

Layer two: counterparty risk

Counterparty risk is every business standing between you and your coins: exchanges, custodians, payment processors, lending platforms. When one fails, your legal position is usually that of an unsecured creditor, and the FCA has warned that FSCS cover is highly unlikely and that the Financial Ombudsman is generally unavailable for crypto. The case list writes itself. Mt. Gox reported around 850,000 bitcoin missing in 2014, and although roughly 200,000 were later found, creditors waited a decade for repayments. FTX collapsed in November 2022 owing customers roughly $8 billion according to US prosecutors, and its founder is serving 25 years. Celsius froze withdrawals in June 2022 owing users $4.7 billion, and its founder was sentenced to 12 years in May 2025. Theft reaches the biggest names too: the FBI attributed the February 2025 theft of approximately $1.5 billion from Bybit, the largest crypto theft on record, to North Korean state actors. The category stays current: on 9 August 2026 the payment platform Coinsbuy confirmed unauthorised withdrawals from its wallets, estimated by blockchain investigators at roughly $8 million, though the company says client funds were covered in full from its reserves. Two subtleties are routinely missed. First, counterparty risk includes your data as well as your money: Coinbase's May 2025 breach saw bribed support contractors steal names, home addresses and account balance snapshots for 69,461 customers, proof that a solvent, honest counterparty can still leak the file that makes you a target. Second, the standard fix shifts risk to the layer above: moving coins off exchanges into self-custody removes the counterparty and makes you the single point of failure instead. Do it, but do it properly: minimal balances on platforms, withdrawals to a wallet whose backup you have tested, and eyes open that you have just promoted yourself to custodian.

Layer three: protocol risk

Protocol risk lives in the code and economic design of the systems themselves: blockchains, smart contracts, the bridges between chains, and the mechanisms that keep stablecoins stable. It is the least visible layer because nothing looks wrong until the moment everything is. Bridges have been the expensive lesson. The Ronin bridge lost around $540 million in March 2022, and Harmony's Horizon bridge lost roughly $100 million in June 2022, both attributed by US authorities to North Korea's Lazarus Group. Wormhole lost over $320 million to a smart contract flaw the same year. Stablecoins supplied the biggest single catastrophe: TerraUSD's algorithmic peg failed in May 2022, erasing an estimated $40 billion, and its creator was sentenced to 15 years in December 2025. Audits help but do not absolve: Balancer, one of the most audited protocols in DeFi, lost over $100 million in November 2025 to a rounding error that had sat in its code for years, as Trail of Bits' analysis shows. Nor does the category stay historical: on 12 August 2026, days before this article was published, Harmony confirmed a fresh exploit in which an attacker minted ONE tokens without authorisation, and by 17 August it had announced plans to roll the chain back, with the full scale still being established. Across 2025, Chainalysis counted more than $3.4 billion stolen in crypto hacks by early December alone. For a UK retail holder the practical control is exposure selection. Bitcoin held in your own wallet touches no bridge, no smart contract and no peg. Every additional protocol you opt into is an additional way to lose funds that has nothing to do with your own care, so know, asset by asset, which code you are trusting, and treat yield that depends on a bridge or an algorithmic mechanism as payment for a risk you are carrying. If apps you have long forgotten still hold permissions over your wallets, our guide to token approvals and wallet drains is the place to start.

Layer four: personal and privacy risk

The last layer is you: the person criminals deceive, the identity that leaks, the phone number that gets hijacked, the estate that never gets planned. It is the layer where the numbers are now largest. Chainalysis estimates around $17 billion was lost to crypto scams and fraud worldwide in 2025. In the UK, Action Fraud logged 25,843 investment fraud reports in 2024 with £649 million lost, and cryptocurrency was the claimed investment in 66 per cent of them; its successor service, Report Fraud, recorded £879.8 million lost to investment fraud in 2025. Behind the scams sit the enablers: unauthorised SIM swap cases in the UK rose over 1,000 per cent in 2024 to nearly 3,000 according to Cifas, and a string of 2025 and 2026 data breaches, from Coinbase's insider theft to the Trezor fulfilment leak, handed criminals exactly the names, home addresses and phone numbers that make deception personal. At the violent extreme, Chainalysis documented a record $58 million stolen through physical attacks on crypto holders in 2025. And then there is the quietest failure in crypto: nothing is stolen, nobody is deceived, the keys are perfect, and the owner is gone. Death or incapacity without a recovery plan converts flawless layer-one security into permanent loss, and it is the only risk on this page whose long-run probability is one. The defences for this layer are unglamorous: phishing scepticism as a reflex, passkeys and authenticator apps, a privacy posture that stops your name and holdings circulating, mapped in our guide to the crypto privacy trail, and a continuity plan your family could actually execute. Most holders have none of the four.

The ten-minute audit

Run your holdings through these twelve questions honestly. The answers never leave your head, and no legitimate assessment, ours included, will ever ask for a seed phrase, a private key or a balance. Keys. If your main device burned tonight, could you recover from a backup you have actually tested? Is every copy of every seed strictly offline, on paper or metal? Was your device bought new from the maker, and is its firmware current? Counterparties. What share of your holdings sits on exchanges or platforms right now, and is each balance there for a reason? If your main platform froze withdrawals tomorrow, how much would be trapped? Do you know what its terms actually promise you in an insolvency? Protocols. For each asset beyond simple coins in your own wallet, can you name the bridge, contract or peg it depends on? Is any position paying you a yield you cannot explain? Do apps you no longer use still hold spending approvals over your wallets? Personal. Would your email account survive a criminal who controls your phone number? Do the people close to you know what a crypto scam call sounds like? And the question that eventually decides everything: if you died this week, would your family recover your coins, or would the coins join the millions already lost in layer one? Score yourself harshly, then get a real number for the final question: the free Bitcoin inheritance scorecard measures your continuity readiness in five minutes and asks for nothing sensitive.

Fixing one layer moves the load to another

The four layers behave like connected vessels, which is why single-fix security keeps failing. Moving coins off an exchange converts counterparty risk into key risk: you are the custodian now. Aggressive secrecy reduces personal targeting and silently maximises inheritance risk. Chasing yield converts idle counterparty risk into live protocol risk. Even 2026's Coldcard incident sat on a boundary: it looked like layer one, keys held on hardware, but the cause sat outside the owner's discipline entirely, a flaw in the code that generated the keys. The aim is not perfection in one layer; it is the absence of a gaping hole in any. A holder with a tested backup, minimal platform balances, deliberately chosen protocol exposure, a hardened phone and email, a discreet profile and a documented recovery plan is not invulnerable. They are something more useful: hard to rob, hard to fool, and impossible to bankrupt with any single failure, including their own death.

Where Bitzo fits, and where it does not

Honesty first: no service removes crypto risk, and anyone claiming otherwise is selling something broken. Bitzo does not touch market prices, cannot repair an exchange's balance sheet, and never holds your keys, so layers two and three remain yours to manage with the habits above. Where we work is the pair of gaps most holders leave open. For the inheritance problem inside layer four, a Bitzo continuity plan documents what exists and how verified recovery happens, without keys or seed phrases ever entering a document or our systems; how it works explains the mechanics step by step. For the monitoring gap that spans theft in any layer, the Bitcoin Watchtower watches the addresses you choose from our own UK node and alerts you the moment coins move, usually before the transaction has even confirmed. Start wherever the audit hurt most, and if you would rather talk it through first, book a call. This article is general information, not legal, tax or financial advice; take advice on your own circumstances. Last reviewed 18 August 2026.

Frequently Asked Questions

What are the main types of crypto risk?

Four layers cover almost everything: key risk (losing seed phrases, backups or devices), counterparty risk (exchanges, custodians or payment firms failing, being hacked or leaking data), protocol risk (flaws in blockchains, bridges, smart contracts and stablecoin mechanisms), and personal risk (phishing, SIM swapping, identity exposure, physical coercion, and death or incapacity without a recovery plan). Each layer needs its own defence.

Is crypto covered by the FSCS in the UK?

It is highly unlikely. The FCA says crypto remains largely unregulated in the UK and that buyers should be prepared to lose all their money, and it has warned that neither FSCS compensation nor the Financial Ombudsman Service is generally available for crypto losses. The wider FCA regime is expected to come into force on 25 October 2027, but you should not assume it will bring compensation cover; check the FCA's current guidance.

What happens to my crypto if an exchange goes bust?

Typically you become an unsecured creditor in an insolvency process that can run for years and return a fraction of what you held, as customers of Mt. Gox, Celsius and FTX discovered. Your balance on an exchange is a claim against a company, not coins in your hand. Keep only working balances on platforms and withdraw long-term holdings to a wallet you control and have backed up properly.

Is it safer to keep crypto on an exchange or in a hardware wallet?

They fail differently. An exchange carries counterparty risk: hacks, insolvency and frozen withdrawals. A hardware wallet eliminates the counterparty and concentrates everything on you: the seed backup, phishing resistance and a plan for your death or incapacity. Self-custody done properly is the stronger position; self-custody done badly simply swaps one loss mode for another.

What is protocol risk in crypto?

The risk that the underlying code or economic design fails: a bridge is exploited, a smart contract contains a flaw, a stablecoin loses its peg, or a chain itself is attacked. Bridge hacks such as Ronin and Harmony, the TerraUSD collapse and the 2025 Balancer exploit are all protocol failures. It is reduced by holding simple assets in your own wallet and knowing exactly which code each asset depends on.

What happens to my crypto when I die without a plan?

In most cases it is permanently lost. Exchanges have bereavement processes if your executor knows the accounts exist, but self-custodied coins are unrecoverable without the keys, and no court can conjure them. Your estate may still owe inheritance tax on the value of the holdings even if nobody can access them. A documented recovery plan, which never requires putting keys in your will, prevents both outcomes.

How do I assess my own crypto risk?

Work through the four layers: could you recover from a tested backup; how exposed are you to any single platform; which bridges, contracts or pegs does each asset rely on; and would your security survive a phishing call, a SIM swap or your own death? Ten minutes of honest answers usually reveals one layer with no defence at all, and that is where to start.

Sources

Ready to plan your crypto inheritance?

Speak to our UK-based team about your situation. No obligation, no pressure.

Speak to us