Crypto news and analysis
Beginner · Institutions

Crypto custody for institutions

Learn how institutions evaluate key security, asset segregation, withdrawal governance, reconciliation, insurance, and custody exits.

14 min read3-question quizUp to 115 XP

For an institution, custody is a provider-selection and oversight decision about legal control, asset availability, operating evidence, and recovery. The buyer does not need to redesign the custodian's signing service, but it does need enough architectural evidence to decide whether the service meets its mandate, whether the contract preserves intended rights, and whether assets can move when markets or the provider are under stress.

Diligence should end in explicit approval conditions: permitted entities and assets, balance limits, withdrawal service levels, authorized use of subcontractors, reporting duties, incident notice, insurance interpretation, and a tested exit route. Labels such as cold storage, regulated, qualified, segregated, or insured are inputs to that decision; none answers the institution's legal and operational questions alone.

What you will learn

  • Turn custody requirements into an evidence-based provider selection scorecard
  • Review account title, permitted use, subcontractors, withdrawals, and insolvency terms
  • Set ongoing exposure limits, service tests, escalation triggers, and exit conditions

Selection begins with mandate and evidence

The institution should define the use case before issuing a questionnaire: long-term reserve, daily trading collateral, staking, fund safekeeping, or tokenized-asset administration impose different availability and reporting needs. A selection scorecard can weight legal ownership, financial strength, asset support, withdrawal latency, control assurance, geographic resilience, pricing, and portability instead of allowing one impressive security feature to dominate.

Architecture evidence remains relevant but is reviewed as a customer control dependency. The buyer should ask how offline storage, hardware modules, multisignature, or multiparty computation connect to named requesters, independent approvals, address allowlists, emergency overrides, and recovery tests. The decision record should identify which assurances were independently tested, which came from management statements, and which remain confidential or unresolved.

Contracts determine the institution's claim

Assets may be separated by blockchain address, by the custodian's internal ledger, by legal account, or by an insolvency-protective structure. These are different facts. A pooled wallet can still have detailed client records, while a dedicated address does not by itself establish that assets are beyond claims against the custodian under relevant law.

The custody agreement should state the contracting entity, account title, permitted use, liens, lending, staking, forks, airdrops, subcontractors, liability standard, incident notice, record access, termination, and treatment after default. Legal counsel must test those provisions against the relevant entity and insolvency regime. Side letters and service schedules should not conflict with the master agreement on withdrawal rights or asset use.

Counterparty diligence tests the provider behind the controls

Operational controls do not substitute for counterparty analysis. Review audited financial statements, capital and liquidity, ownership, affiliated activities, client-asset concentrations, banking relationships, litigation, regulatory status where relevant, and dependence on technology or subcustody providers. The institution should know which entity employs the operators, controls the wallets, signs the contract, invoices the fees, and would owe assets after termination.

Control reports, penetration tests, reserve evidence, and insurance answer bounded questions. Inspect scope, period, exceptions, complementary customer controls, insured party, covered event, deductible, and aggregate limit. Reconciliation samples should connect onchain balances, pending transfers, the custodian's subledger, client statements, and the institution's books, with aged breaks routed to named owners before balances exceed approved limits.

Approval includes limits, monitoring, and exit

Approval should name maximum balances by asset and legal entity, prohibited uses, minimum control evidence, ordinary and urgent service levels, reconciliation frequency, incident-notice deadlines, and triggers for enhanced review or suspension. Monitoring combines financial updates, control-report exceptions, withdrawal latency, outages, subcustodian changes, legal developments, and unresolved breaks rather than relying on an annual questionnaire refresh.

An exit plan identifies alternate custody, preapproved destinations, transfer sequencing, data exports, open staking or settlement positions, and communication authority. It should account for fees, congestion, product restrictions, contract notice, and a provider that is uncooperative or unavailable. A small periodic transfer to the alternate custodian is stronger evidence of portability than a clause that has never been exercised.

Reality check

Common misconceptions

Institutional custody is solved once private keys are placed in cold storage.

Offline keys address one threat while governance, records, recovery, withdrawals, legal title, subcontractors, and reconciliation determine whether the overall service is dependable.

A regulated or insured custodian eliminates custody risk.

Regulatory status and insurance can add protections, but their scope varies and does not eliminate cyber, insolvency, protocol, legal, operational, or availability risk.

Before you act

Risks and limitations

  • Compromised authorization systems can defeat strong cryptography by causing an otherwise valid signature on a fraudulent transfer.
  • Unclear title, liens, or insolvency treatment can delay or reduce recovery even when onchain assets remain visible.
  • Concentrated vendors, data centers, signers, or network infrastructure can create correlated service failures.
  • Strict withdrawal controls can protect against theft while preventing timely collateral movement during market stress.

Key takeaways

  1. Custody combines keys, people, policy, records, contracts, and operating evidence.
  2. Address separation, ledger separation, and legal segregation must be evaluated separately.
  3. Withdrawal tests reveal both security quality and access constraints.
  4. Reports and insurance should be interpreted through scope, date, exclusions, and limits.
  5. A funded custody relationship needs continuous monitoring and a rehearsed exit path.

Primary and further reading

Knowledge check

Test your understanding

Score at least 2 out of 3 to complete this lesson. Explanations appear after you submit.

1. Why does a dedicated blockchain address not prove legal segregation by itself?
2. What does a practical withdrawal test evaluate?
3. How should an institution read a custody control report?