Loading data...

Custody

General

Safekeeping and control of assets on behalf of users.

Custody is the responsibility for safeguarding and controlling assets, including the authority to move them. In cryptocurrency, custody primarily concerns control of private keys or signing systems. The party capable of authorizing a valid transaction has practical technical control, while legal ownership depends on contracts and applicable law.

Self-custody means an individual or organization controls its own keys. Third-party custody delegates control to an exchange, bank, broker, or specialist custodian. Shared-control designs use multisig or multi-party computation so several approvals or key shares are needed. Sub-custody occurs when the customer-facing provider relies on another company to hold assets, adding a dependency users may not see.

Custody matters because blockchain transfers are normally irreversible. Theft, key loss, insider abuse, a bad backup, or an incorrect transaction can permanently remove assets. Institutions also need accurate books, authorization policies, legal segregation, audit evidence, and continuity when staff leave. Good custody therefore combines technology, operations, governance, and legal structure.

Professional controls include cold storage, hardware security modules, independent approvers, transaction simulation, address allowlists, time delays, value limits, and continuous monitoring. Duties should be separated so one employee cannot create, approve, and reconcile a withdrawal. Recovery and disaster procedures must be tested. A backup that has never been restored or a multisig whose signers cannot coordinate is not reliable.

Customers should determine whether assets are held one-to-one, pooled, lent, or pledged. Proof of reserves can demonstrate control of selected on-chain assets at a point in time, but does not alone reveal all customer liabilities or off-chain obligations. Audits, financial disclosures, legal terms, and withdrawal performance provide additional context. Insurance coverage needs close reading for limits and exclusions.

No custody model removes every risk. Self-custody avoids provider insolvency but makes the owner responsible for security and succession. A qualified custodian can offer strong controls yet remains a counterparty. Businesses should match the model to asset value, transaction frequency, regulatory duties, and operational ability. Individuals should keep seed phrases offline, use hardware signing for valuable funds, and ensure trusted successors can recover assets without giving one person unrestricted access today.

Regular reconciliation between on-chain holdings and customer records helps detect operational errors, missing assets, or unauthorized movement before losses grow.

Frequently asked questions

  • Custody models include direct self-custody, full third-party custody, sub-custody through another institution, and shared-control arrangements using multisig or multi-party computation. Omnibus custody pools customer assets, while segregated custody tracks or stores them separately. The technical key arrangement and legal ownership can differ, so both must be reviewed rather than inferred from a product label.
  • Institutions separate duties, keep most keys offline, use hardware security modules or distributed signing, require multiple approvals, and enforce transaction allowlists and value limits. Mature programs include background checks, access logs, reconciliation, monitoring, incident response, disaster recovery, independent audits, and tested succession. Insurance can supplement these controls but does not replace them or cover every loss scenario.
  • Identify the legal custodian, jurisdiction, licenses, security history, asset segregation, withdrawal rules, and treatment during insolvency. Review whether assets may be lent or pledged and whether insurance applies to crypto. Test withdrawals and use strong account security. Proof of reserves is useful only with reliable liability information and does not guarantee solvency or future access.