Changpeng Zhao, former Binance CEO, contended that storing bitcoin on exchanges could be safer than self-custody, citing data showing 1.57 million BTC lost to self-custody errors versus 1.51 million BTC lost to exchange hacks.
Zhao's claim rests on a comparison of aggregate loss figures that reverses the conventional wisdom in crypto that users should hold their own private keys. The data came from researcher Willy Woo, who compiled the loss tallies in a December 2025 report. Zhao's framing treats the two loss categories as roughly equivalent in scale, with self-custody errors marginally larger.
The self-custody figure includes losses from forgotten passwords, corrupted seed phrases, faulty backups, and other user errors that render funds permanently inaccessible. Exchange hacks span breaches of centralized platforms' security, including the 2014 Mt. Gox collapse, the 2022 FTX insolvency, and smaller incidents across trading venues. Zhao did not specify which exchange breaches the 1.51 million BTC figure includes or over what time window.
Zhao's post on X framed the comparison as a statistical argument rather than a blanket endorsement of exchange custody. He noted the analysis does not account for counterparty risk, where users face exposure to exchange management decisions, regulatory seizure, or operational collapse. The statement nonetheless inverts a foundational tenet of the self-custody movement, which has long held that users accepting responsibility for key management reduces systemic risk.

Willy Woo's underlying data set treated the two loss mechanisms as discrete categories without distinguishing between permanent loss and recoverable funds. Exchange hacks sometimes result in partial user reimbursement or recovery through civil proceedings, whereas self-custody errors are typically irreversible. The framing does not separate those outcomes.
Zhao departed from Binance's CEO role in 2023 and has maintained a public profile in crypto discourse since. His statement reached a wide audience on X, where custody debates regularly surface amid regulatory pressure on exchanges and growing institutional interest in self-hosted solutions.
The comparison assumes historical loss ratios remain predictive. Self-custody errors scale with user adoption and complexity, while exchange breaches depend on security spending and attacker sophistication. If the 1.57 million and 1.51 million figures represent cumulative losses over different periods or market cycles, the statistical claim may not hold across future conditions. The number to watch is whether custody platforms or industry groups publish comparable loss tallies that either confirm or challenge Woo's baseline figures.