Custodial or self-custody for mining payouts: who holds the key, what a freeze looks like, and how to choose in 2026

Miners rarely think about wallets when buying bitcoin. They think about wallets the moment a pool asks for a payout address. Two very different things can go in that field: an address whose key belongs to a service, or an address whose key belongs to you. What follows from that choice is not convenience or interface polish. It is the answer to questions like who can freeze this money, who will ask where it came from, and what remains if the service disappears.

A note on who wrote this. POOL BTC is not a pool, a wallet or an exchange. It is an independent comparison site covering pools, wallets, cards and calculators, so there is no house product waiting at the end. Mechanics and selection criteria below, not personal financial advice.

This piece is a companion to our guide on wallets for mining payouts, which covers dust, payout thresholds and how payout schemes interact with wallet choice. This one takes a different cut: key ownership, hardware devices and address hygiene for accounting.

[IMAGE: sunny day, wooden table on a porch, laptop and a small hardware wallet, green garden in the background, light tones]

Dust in brief: background here, not the subject

Frequent small payouts split a balance into many separate coins, and you later pay for transaction size rather than for the amount. A P2WPKH input weighs roughly 68 vB: spending it costs about 68 satoshis at 1 sat/vB and 13,600 satoshis at 200 sat/vB. Any payout smaller than that becomes economically dead. That argument drives payout threshold choice, and the full treatment lives in wallets for mining payouts. Here it matters only as context: with a custodial service the problem sits on their side of the ledger, with self-custody it sits on yours.

Who actually owns the coins when a pool pays an exchange

The owner is whoever holds the private key. An exchange deposit address belongs to the exchange, and your line in its database is a claim on the service rather than coins under your control. While everything works, the difference is invisible. On the day an account is frozen, a withdrawal is paused or the platform has an incident, it is the only thing that matters.

There is a second, more mundane catch. Many services treat deposit addresses as temporary or rotating, so an address pasted into pool settings six months ago can stop crediting. The funds technically arrive and then sit unallocated until support intervenes. That is exactly why several pools warn against using exchange addresses as payout addresses.

Custodial vs non-custodial for receiving payouts

A custodial wallet is a service holding your keys: an exchange, a payment app, a card provider. A non-custodial wallet is one where the seed phrase exists only with you. For receiving payouts the difference reduces to four things: who can halt the money, who asks about source of funds and when, who carries the cost of handling small inputs, and what you keep if the service goes away.

CriterionCustodialNon-custodial
Who holds the keythe serviceyou
Funds can be frozenyes, by the service or on requestnot without your key
KYC and source of funds questionsalmost always, often at withdrawalusually none at wallet level
Handling small inputsservice sideyours
Payout address stabilitymay rotatepermanent
Access if the service stopsyou are a creditornothing changes
Risk of losing the seednoneentirely yours
History for reportingaccount export, while you have accesswallet dependent, always available

The arrangement most miners settle on: payouts land in a self-custodied wallet, and only the portion actually being sold moves to an exchange. That separates two different risks instead of stacking them on one address.

What an account freeze looks like for a miner

A freeze is a temporary hold on withdrawals pending review: compliance checks, document requests, a dispute over source of funds. For a miner it hurts more than for a trader, because the hold does not catch one transfer. It catches the entire accumulated revenue if every payout for years went to the same custodial address. Hashing continues, access does not.

Mining income sits awkwardly inside standard compliance templates. An exchange purchase has a counterparty and a payment record. A pool payout has a transaction from an address the service reads as unknown. The evidence usually has to be assembled from the pool account, worker statistics, hardware invoices and electricity bills. Assembling that package early is far easier than assembling it while a withdrawal is already on hold.

Worth keeping from your first month of mining:

  1. Exports or screenshots of the payout history from your pool account.
  2. Purchase contracts and payment records for the ASICs.
  3. Electricity bills or the hosting agreement.
  4. A record linking each pool payout address to the wallet that owns it.
  5. Wallet transaction history exported per period, not just for the current year.

Which documents do exchanges accept as proof of mining income

Of the four major venues, two publish an explicit document list for mining specifically: Coinbase and Kraken. Both name mining as a source of funds category and spell out what they will accept. Binance and Bybit, as of 01.09.2026, document only a general enhanced due diligence process with no mining specific list.

The package worth assembling in advance if you deal with Coinbase or Kraken:

  1. Mining payout statements from the pool showing your name.
  2. Screenshots of your pool or monitoring dashboard carrying your name, email or wallet address.
  3. Receipts for ASIC or GPU purchases in your name, as proof of investment in equipment.
  4. Tax documents where mining income appears as a separate line.

Coinbase additionally asks for a Mining Operations Document during onboarding of business accounts classified under mining. Kraken lists mining payout statements that include your name among acceptable proof of source of funds, alongside salary and investment records. Sources: Coinbase help on proof of source of funds, Kraken support, accessed 01.09.2026.

ExchangeMining named as a source of funds categoryExplicit mining document list
Coinbaseyesyes, including pool statements, dashboard screenshots, hardware receipts, tax documents
Krakenyesyes, mining payout statements showing your name
Binanceno, only a general source of funds declaration above base withdrawal tiers plus an EDD questionnairenot found
Bybitmentioned as a possible income category in the Kazakhstan versionnot found, only a general EDD process

Now the scare stories. No publicly confirmed case of an account being frozen specifically because the funds came from mining could be found on Coinbase, Kraken, Binance or Bybit. Adjacent cases exist: a widely discussed account restriction on Binance where crypto was the user's only income source, and a court dispute between a mining company and a bank in Bosnia. Neither is a documented exchange policy against miners. Forum complaints are plentiful but were not verified as primary sources. The practical conclusion holds either way: paperwork is cheaper to collect early than to reconstruct after a withdrawal is on hold.

[IMAGE: bright diagram with two paths, one leading to a building with a lock, the other to a key in a hand, daylight, green and blue palette]

Should you put an exchange address in the pool settings

It works technically and saves one transfer, but it stacks three risks on a single point: an account freeze, a rotated deposit address and failure of the service itself. It also hands the exchange a direct link between your mining flow and your account, so any review covers the entire payout volume at once rather than a single transfer.

There is a case where custodial receiving is reasonable: a very small hashrate where individual payouts are comparable to network fees, combined with selling immediately on receipt. There the service genuinely absorbs the cost of handling tiny amounts. That is a convenience trade with control knowingly given up, not a security decision.

Hot wallet to receive, hardware wallet to hold

The address you hand to a pool is public and tied to your mining activity, so there is no reason to keep everything on it. The working pattern: a hot wallet on a phone or desktop receives payouts, and accumulated funds move periodically to a hardware wallet whose keys have never touched an internet connected machine.

The sequence:

  1. The pool pays to a hot wallet address, one per pool.
  2. Every so often the accumulated balance moves in a single transaction during a quiet fee period.
  3. The long term portion goes to the hardware wallet.
  4. Selling happens as a separate transaction from the portion actually being sold.
  5. The hardware wallet seed stays offline and is never typed into a computer or phone.

Putting the hardware wallet address straight into pool settings is tempting because it removes a step. The cost is that you publish your long term storage address, make it known to the pool, and every later spend from the device has to sweep up a hundred small inputs at once.

What to look for in a hardware wallet

Judge a hardware wallet on four things rather than on brand: whether the firmware is open source, whether the seed restores into another wallet via BIP-39, which address types the device supports, and how usable manual coin selection is in its interface. For a miner that last point matters more than for an ordinary holder, simply because there are more inputs to manage.

Everything below is what vendor pages confirmed on 01.09.2026. Prices in US dollars from the manufacturers' own stores.

ModelPriceTaprootOpen source firmwareWorth noting
Trezor Safe 5$129yesyesflagship of the line, a Bitcoin-only version sits at the same price
Trezor Safe 3$59yes, via Trezor Core firmwareyescheapest entry into the line with Taproot support
Trezor Model Oneprice not confirmed in this passno confirmation of Taproot support found, the device runs the 1.x firmware branchyesolder model, check the vendor site for current status
Coldcard Q$289only in the Edge firmware, not the main branchyesBitcoin only, advanced UTXO handling
Coldcard Mk5$189only in the Edge firmware, not the main branchyesair-gapped signing, steeper learning curve
Ledgernot officially confirmed in this passnot officially confirmed in this passnot officially confirmed in this passbroad software compatibility, but price, firmware openness and Taproot need data straight from the vendor

Trezor and Coldcard prices come from trezor.io and store.coinkite.com. For Ledger, the official pages in this pass returned neither prices as numbers nor explicit wording on Taproot and firmware openness, so the row is deliberately left empty. Absence of confirmation is not the same thing as absence of the feature.

The Coldcard caveat is practical rather than pedantic. Taproot there lives in a separate Edge release channel, which the manufacturer itself describes as the branch for features not yet ready for prime time. If you need Taproot as a working tool rather than a checkbox, that changes the calculus.

A second Coldcard point: the official firmware repository carries a warning about a seed phrase entropy bug affecting seeds generated between 2021 and July 2026. The manufacturer disclosed it themselves and recommends updating the firmware and, where needed, regenerating the seed and moving funds. That is not a reason to strike the brand off a list. It is a reason to check the firmware version on any device and to stop treating a once generated seed as valid forever by default.

The pitfalls are much the same across every manufacturer:

  1. Buying from a marketplace reseller rather than the vendor invites a tampered device.
  2. A pre-printed seed phrase in the box. The device must generate it during your own setup.
  3. A non-standard seed format that locks you to one manufacturer.
  4. A seed photographed on a phone or saved in cloud notes, which cancels the point of buying hardware.
  5. No on-device confirmation of the destination address before signing.

[IMAGE: bright morning, desk by a window overlooking a forest, hardware wallet and a notebook with a metal seed plate, no dark tones]

Does Taproot change the cost of handling payouts

It does, but not at the receiving end. The address type sets the weight of an input when it is spent: a P2TR input is lighter than P2WPKH, and legacy addresses starting with 1 are the heaviest of all. A wallet filled with taproot outputs sends funds more cheaply than the same wallet on older address types, and the saving compounds precisely when you hold many small inputs.

Two things to verify. Whether your pool accepts a bc1p address as a payout address. And whether your hardware wallet signs taproot inputs with the software you actually use.

Which pools accept bc1p as a payout address

Three pools explicitly confirm support for bech32m (bc1p) payout addresses in their official documentation as of 01.09.2026: Braiins Pool, Ocean and Kryptex. ViaBTC is officially limited to bech32 and legacy formats, with Taproot not listed. For the other eight pools in this sample, the official documentation gives no direct answer either way.

Poolbc1p status as of 01.09.2026
Braiins Poolofficially confirmed, bech32m listed in the FAQ
Oceanofficially confirmed, Bech32m named among four formats
Kryptexofficially confirmed, Taproot listed as a separate format
ViaBTCnot offered, official list covers legacy, P2SH and bech32 only
F2Poolnot officially confirmed or denied
AntPoolnot officially confirmed or denied
Luxornot officially confirmed or denied
Foundry USAnot officially confirmed, the knowledge base mentions legacy and segwit
Binance Poolnot confirmed by a pool primary source
EMCDnot officially confirmed or denied
NiceHashnot officially confirmed or denied
Trustpoolnot officially confirmed or denied

Read that table carefully. "Not confirmed" means exactly what it says: the pool's help pages do not detail the address format. It is not a refusal to support Taproot. Which leads to the practical takeaway: most pools simply do not document the payout address format, so check bc1p validation inside your own pool settings before switching wallets, ideally with one small test payout. If a pool still insists on an address starting with 1, that alone is a reason to compare alternatives, which is easiest to do in the mining calculator.

Why use a separate address for each pool

One payout address per pool solves accounting and privacy with a single setting. A block explorer then shows exactly what each pool delivered without cross checking dashboards. If one pool closes or starts delaying payouts, its history stays isolated, and during a compliance review you can present one clean stream instead of a mixed pile of deposits.

It also helps at tax time. Most jurisdictions want the date, amount and rate at the moment of receipt for every incoming payment, and an export from one clearly sourced address assembles faster. The specific rules depend on your country and we are not giving them here: that is a question for a local tax adviser.

Worth keeping alongside the addresses themselves:

  1. A mapping table: address, pool, worker, date first used.
  2. A backup of the wallet xpub, so the address list can be rebuilt without the seed.
  3. A regular history export instead of one scramble in December.

How to compare real income across pools and what a move costs is covered in the cost of switching pools; timing of the first deposits is in time to first payout; wallet types and how various wallets behaved under pressure are in crypto wallets and wallets that survived hacks.

Short checklist

  1. The payout address belongs to a wallet whose key you hold.
  2. The address is permanent, not a rotating service deposit address.
  3. The address format is verified inside your own pool settings, not taken from a general review.
  4. Each pool has its own address.
  5. Source of funds documentation is collected from month one, not when asked.
  6. Long term savings do not sit on the address the pool knows.
  7. The hardware wallet came from the vendor and generated its own seed.
  8. Device firmware is current, and the seed is not older than the vendor's published warnings.
  9. The seed is BIP-39 and restores into third party wallets.

Bottom line

Choosing a payout wallet is mostly choosing who holds the key, not comparing interfaces. A custodial service takes the hassle of small amounts off your hands and takes, in exchange, the right to freeze your entire revenue and ask where it came from. Self-custody removes that risk and hands you responsibility for the seed and for managing inputs. The compromise most miners land on: receive to your own hot wallet, hold on hardware, one address per pool, and a document pack assembled before anyone asks for it.

[IMAGE: bright closing illustration, sunny meadow, a symbolic key and safe side by side, clear sky]