Crypto news and analysis
Intermediate · Wallets & custody

Institutional crypto custody models

Compare full-service, segregated, omnibus, co-managed, and assisted self-custody models by authority, records, recovery, and access.

15 min read3-question quizUp to 165 XP

Institutional crypto custody is a choice about where an organization's signing authority, account records, and recovery power reside. A fund can appoint a third-party custodian, retain keys through an internal or co-managed arrangement, or combine models by asset and use case. Each model changes who can move assets, who can restore access, and what claim the institution holds when another party fails.

This lesson compares custody models rather than auditing a provider's infrastructure or deciding whether an allocator should hire one. The useful starting point is authority: identify which party can produce a blockchain signature, which records establish the client's entitlement, and which path remains available during an outage, dispute, or key loss. Specialized infrastructure and institutional diligence lessons follow from that model choice.

What you will learn

  • Compare third-party, co-managed, and institution-controlled custody authority
  • Distinguish omnibus, address-segregated, and legally segregated client records
  • Match a custody model to access, recovery, governance, and counterparty requirements

Start with who can authorize movement

In full third-party custody, the provider controls the onchain signing system and the client authenticates requests through the provider's workflow. The institution does not normally possess a blockchain key that can bypass the custodian. This can simplify staffing and recovery, but access ultimately depends on the provider honoring the account agreement and remaining operational.

In institution-controlled custody, the organization operates enough signing authority to move assets under its own rules. Co-managed models divide effective authority or workflow responsibilities between the client and a provider. The dividing line is not the product label or dashboard: ask whether the client, provider, or a defined combination can complete a transfer when the other party is unavailable.

Separate asset control from entitlement records

An omnibus model pools assets in addresses controlled for many customers and uses an internal subledger to assign each client's balance. Address segregation gives a client one or more identifiable blockchain addresses, but address visibility alone does not establish the legal treatment of those assets. Legal segregation depends on contracts, account structure, and applicable law rather than on address layout alone.

These forms can be combined. A provider may give each client a deposit address, sweep deposits into omnibus storage, and preserve client entitlements in its ledger. Another may maintain dedicated addresses but still rely on one shared signing system. State three facts separately: where assets appear onchain, who controls signing authority, and how the client's legal and accounting claim is recorded.

Compare full custody, co-management, and assisted self-custody

Full custody transfers day-to-day key operation and recovery to a provider. Co-managed custody can require both organizational and provider participation, or let the provider administer policy while the client retains a decisive signer. Assisted self-custody supplies software, transaction coordination, or recovery support while the institution retains sufficient cryptographic authority to move assets without the vendor.

Multi-party computation, hardware security modules, and multisignature scripts can support several of these models; they do not define the commercial model by themselves. A provider-operated threshold system may still be full third-party custody if the client controls no signing share. Conversely, a co-managed service may give the client an independent recovery path. Authority under failure is more informative than the cryptographic product name.

Service access changes practical value

Custody can be bundled with trading settlement, collateral movement, staking, governance, reporting, or fiat services. Those capabilities may justify third-party control for an operating balance even when reserves use a different model. The same institution can segment custody by purpose: liquid assets with a service provider, strategic reserves under stronger internal authority, and application assets in a restricted wallet.

Recovery also differs. A full custodian can authenticate authorized contacts and restore account access without giving the client a seed phrase. An institution-controlled model must preserve enough key material, people, and procedures to recover itself. A co-managed arrangement should state whether provider failure, client failure, or either one alone can halt access. Convenience during normal use should be compared with independence during exceptional conditions.

Choose the model before auditing the provider

Write the required authority model in plain language before comparing vendors: who must approve, who can sign, what happens if one party disappears, how client ownership is represented, and which services require assets to remain with a provider. This prevents a familiar brand or technical feature from silently deciding the organization's custody structure.

After the model is selected, separate lessons should examine implementation and diligence. How Custody Platforms Work covers key systems and operational infrastructure. Crypto Custody for Institutions covers provider review, legal terms, controls, insurance, withdrawal testing, and allocator governance. Keeping those questions distinct makes this lesson a reusable model comparison instead of a compressed platform audit.

Reality check

Common misconceptions

Institutional custody always means one provider has complete control of every key.

Full-service custody is one model. Co-managed and assisted self-custody arrangements can preserve client authority or require both parties to act.

A separate blockchain address proves that client assets are legally segregated.

Address segregation, signing control, subledger attribution, and legal segregation are distinct properties that must be described independently.

Before you act

Risks and limitations

  • A full-custody model can concentrate access, recovery, and legal claims with one counterparty.
  • An institution-controlled model can fail when internal signers, backups, or procedures are unavailable.
  • A co-managed model can create an unexpected veto or recovery dependency if authority is described imprecisely.
  • Omnibus and address-segregated arrangements can be mistaken for legal protections they do not provide by themselves.

Key takeaways

  1. Classify custody by who can authorize movement and recover access under failure.
  2. Full custody, co-management, and assisted self-custody allocate authority differently.
  3. Onchain address layout, internal entitlement records, and legal segregation are separate dimensions.
  4. One institution can use different custody models for reserves, collateral, and application activity.
  5. Select the required model before performing infrastructure or provider diligence.

Primary and further reading

Knowledge check

Test your understanding

Score at least 2 out of 3 to complete this lesson. Explanations appear after you submit.

1. A provider pools assets in one onchain address but assigns each client a balance in its records. Which model feature is doing the attribution?
2. A vendor calls its service co-managed, but it can move assets alone and the client has no independent signer. What is the best classification?
3. A treasury wants continued access if its software vendor disappears. Which evidence best supports that requirement?