“Not your keys, not your coins” is the most repeated security principle in Bitcoin. It’s good advice, and it’s also the source of a dangerous confusion when you move from holding Bitcoin to lending against it.
Holding the keys gives you control. It does not, by itself, give you a legal claim that a court will enforce. Those are two different things, governed by two different systems — one cryptographic, one legal — and the gap between them is precisely where secured lenders discover, usually in a bankruptcy, that the protection they thought they had was only half-built.
This is the distinction the entire legal architecture of Bitcoin-backed lending turns on. Everything in it follows from getting this one thing straight.
Two layers that look like one
When you hold Bitcoin’s private keys, you have control in the technical sense: the practical ability to move the asset, to benefit from it, and to stop anyone else from doing so. The network enforces this. No court order is required for the keys to work, and no counterparty can override them. This is real power, and it’s the thing “not your keys, not your coins” is pointing at.
But control is a fact about the cryptographic layer. A legal claim is a fact about the legal layer — and the legal layer asks a different question. Not “can you move the asset?” but “what kind of interest do you have in it, and will that interest be recognized and ranked when it’s contested?”
Those two questions usually travel together, so it’s easy to assume they’re the same. In normal conditions they are. The problem is that collateral isn’t tested in normal conditions. It’s tested in disputes — a borrower’s bankruptcy, a competing creditor’s claim, an insolvent custodian — and in a dispute, the question that decides the outcome is the legal one. Can you move the asset matters far less than whether your interest in it is the one the law puts first.
Where the gap opens for a lender
Consider a lender doing exactly what sound practice recommends: it holds a key in a multi-signature arrangement, so the borrower can’t move the collateral without it. Operationally, this is excellent. The lender has genuine practical control. The borrower can’t run off with the Bitcoin.
Now the borrower goes bankrupt. Other creditors appear, and they too have claims against the borrower’s assets — including, potentially, this Bitcoin. The question that now determines whether the lender keeps its collateral is not “does the lender hold a key?” It’s “is the lender’s security interest in this Bitcoin perfected, and does it rank ahead of these other creditors?”
That is a pure legal-layer question, and the key doesn’t answer it. Perfection and priority are determined by property law — by whether the legal system recognizes the lender’s interest as a perfected security interest and where it sits in the queue. A lender can have flawless cryptographic control and still find, in the borrower’s bankruptcy, that another creditor’s claim is recognized ahead of its own. The keys protected the lender from the borrower. They did nothing about the other creditors, because that was never a question the keys could reach.
This is the gap. Technical control protects you operationally, in the moment, against the parties who would need the keys to act. Legal claim protects you in a dispute, against everyone whose competing interest is resolved by law rather than by cryptography. A complete position needs both. Control without a perfected legal claim is a position that works right up until it’s contested by someone the keys can’t stop.
Why Bitcoin makes this harder, not easier
There’s an intuition that Bitcoin should make all of this simpler — that because the asset is held directly and enforced by math, you can rely less on the legal system. That intuition is half right and wholly dangerous.
It’s true that direct control and on-chain verifiability reduce your reliance on certain kinds of legal enforcement. You don’t need a court to confirm the collateral exists; anyone can verify that in seconds. You don’t need a custodian’s cooperation to know the asset is there. That’s a genuine reduction in dependency, and it’s real.
But it reduces reliance on the legal system; it doesn’t remove it. The questions that matter most in a dispute — what kind of property interest you hold, whether it’s perfected, how it ranks against competing claims, how it’s treated in an insolvency — are still legal questions, and Bitcoin’s cryptographic properties don’t answer them. Worse, Bitcoin makes them harder to answer, because the legal frameworks were built for assets that don’t behave like Bitcoin. The law has settled categories for securities, for goods, for receivables. Bitcoin fits none of them cleanly, which means the legal characterization of your interest is, in much of the world, still unsettled. The cryptography is certain. The law is not. Relying on the certainty of the first to wave away the uncertainty of the second is the exact mistake.
What this opens onto
Stating the distinction cleanly is the whole purpose of this piece, because every subsequent question in the legal architecture is a version of it:
How do you convert technical control into a legally recognized form of control that perfects a security interest? That’s the question of perfection-by-control. What happens to your claim when the custodian holding the keys goes bankrupt, versus when the borrower does? Those are questions about whether the legal structure isolates your interest or leaves it exposed. Why should the lender never also be the custodian? Because bundling them collapses exactly the separation that keeps your legal claim clean. Each of these is the keys-vs-claim gap, examined from a different angle.
The reason this is the starting point is that the most expensive errors in Bitcoin-backed lending don’t come from losing the keys. They come from believing the keys were enough — from building real cryptographic control and assuming the legal claim came with it. It doesn’t. The keys give you the asset. Only the legal architecture gives you the claim to the asset that survives a fight over it — and the fight is the only time it ever mattered.
Your keys are necessary. They are not sufficient. The rest of the architecture is what makes them count.

