Wallets and custody solutions for digital assets in a more regulated crypto market

a[data-rs-seo-link]{text-decoration:underline!important;color:#1a56db!important;cursor:pointer!important;}a[data-rs-seo-link]{text-decoration:underline!important;color:#1a56db!important;cursor:pointer!important;}
The practical answer for custody choice
Wallets and custody solutions are the systems, legal arrangements and operating controls that determine who can move digital assets and how loss, theft, error and insolvency risk are managed. For small personal holdings, a well-secured self-custody wallet may be enough. For trading desks, treasury teams, funds, token projects or client assets, custody needs to be reviewed as a control framework, not just as an app, account or vault.
The practical questions are direct: who controls the private keys or signing rights, how are transactions approved, are client assets segregated, what happens if a provider fails, and which regulatory duties apply? As crypto markets mature, custody has become a central topic in wallets and custody coverage because it connects technology, compliance and operational resilience. The right model depends less on marketing claims than on asset size, transaction frequency, governance needs, jurisdiction and recovery planning.

What a wallet really controls
A crypto wallet does not usually hold coins in the way a physical wallet holds cash. It manages the credentials needed to authorize transactions on a blockchain. The asset record remains on-chain, while the wallet stores or helps use private keys, seed phrases, signing shares or smart contract permissions. That distinction matters because the main risk is not simply whether assets are online or offline. It is whether an attacker, insider, mistaken user or failed process can create a valid transaction.
Most custody designs can be assessed through four layers. The first is key generation: how the secret material is created and whether it is generated in a controlled environment. The second is key storage: whether keys or key shares are held on a phone, hardware device, hardware security module, offline vault, multi-party computation setup or smart contract account. The third is transaction authorization: who can approve transfers, what limits apply, and whether approvals require more than one person or system. The fourth is recovery and continuity: what happens if a device is lost, a signer leaves, a custodian is disrupted, or a governance key is compromised.
Industry guidance from NIST on cryptographic key management, the CryptoCurrency Security Standard and audit-oriented materials from accounting bodies point to the same broad lesson: custody security depends on lifecycle controls. A cold wallet with weak recovery procedures, poor access records or unclear sign-off rules can still fail. A hot wallet can be appropriate for limited working balances if transaction limits, monitoring and rapid incident response are strong.
The main custody models
Self-custody wallets
Self-custody means the user or organization controls the private keys or equivalent signing authority. This can involve a mobile wallet, browser wallet, desktop wallet, hardware wallet, multisignature wallet or smart contract account. The main advantage is direct control: the user does not depend on an exchange or custodian to release funds. The main drawback is that mistakes may be final. Lost seed phrases, malware, phishing approvals and poor inheritance planning can create permanent loss.
Self-custody is often suitable for users who understand wallet security, hold assets for the long term, and do not need institutional reporting or regulated client asset protection. For larger balances, self-custody should normally move beyond a single seed phrase. Hardware wallets, multisignature arrangements, geographically separated backups, test transactions and written recovery procedures can reduce single points of failure.
Exchange custody
Exchange custody is convenient because assets can be traded quickly and balances appear in a familiar account interface. It may be practical for active traders who need immediate access to order books, margin or fiat rails. However, exchange custody combines asset safeguarding with trading venue risk, account takeover risk and, in some cases, legal uncertainty over the customer’s status if the platform becomes insolvent.
For that reason, exchange balances are often better treated as working capital rather than long-term treasury. A practical operating rule is to keep only the amount needed for near-term trading on an exchange and move longer-term holdings to a separate custody setup with stronger segregation and governance.
Third-party custodians
A specialist custodian provides custody as a service, usually with institutional controls such as role-based approvals, policy engines, audit logs, insurance arrangements where available, segregation processes and operational support. Some custodians use cold storage, some use multi-party computation, some use hardware security modules, and many combine methods depending on asset type and transaction needs.
A custodian should not be assessed only by the technology it advertises. Buyers should review legal terms, regulatory status, bankruptcy treatment, asset segregation, service-level commitments, audit reports, incident history, subcontractors and procedures for withdrawals, forks, airdrops and unsupported tokens. A custodian that is strong for bitcoin cold storage may not be the right fit for a team that needs frequent smart contract interactions across several chains.
Hybrid and multi-custody structures
Many institutions use more than one custody model. A fund may keep long-term holdings with a qualified or regulated custodian, operational balances in a warm wallet, and small gas balances in hot wallets. A crypto company may use self-custody for protocol operations while keeping treasury reserves with an external custodian. A family office may split assets across providers to reduce concentration risk.
Hybrid structures can add resilience, but they also add complexity. The governance plan must define which assets sit where, who can approve transfers, how reconciliations are performed, and how emergency actions are documented. Without that operating discipline, multi-custody can become a collection of wallets rather than a controlled safeguarding framework.
How regulation is reshaping custody expectations
Regulators have moved custody from the background to the center of crypto market oversight. The Financial Stability Board’s July 2023 global framework emphasized safeguarding of client assets, management of conflicts of interest and cross-border cooperation. IOSCO’s November 2023 policy recommendations for crypto and digital asset markets included a dedicated focus on custody and client asset protection, asking regulators to apply client asset protection principles to crypto-asset service providers that hold or safeguard customer assets.
In the European Union, MiCA created a harmonized regime for crypto-asset service providers, including custody and administration of crypto-assets on behalf of clients. The main CASP framework applied from December 30, 2024, with transitional arrangements for certain existing providers permitted only up to July 1, 2026, or until authorization was granted or refused. For EU-facing custody providers, authorization, conduct standards and client protection expectations are now central business issues.
Singapore has also strengthened digital payment token safeguards. MAS measures introduced in 2024 included requirements for customer assets to be segregated and placed in trust arrangements, supported by books, records and systems intended to protect customer assets. Hong Kong’s Securities and Futures Commission has taken a similarly control-focused approach for licensed virtual asset trading platforms, highlighting vulnerabilities across hot wallets, cold wallets, third-party management, internal controls and threat monitoring.
In the United States, the picture remains more fragmented. The SEC’s 2023 proposed safeguarding rule for investment advisers, which would have expanded and revised custody obligations, was withdrawn effective June 17, 2025. That withdrawal did not remove existing custody, securities, banking, money transmission, commodities or state-level obligations that may apply depending on the entity and activity. It does mean U.S. custody analysis still depends heavily on the type of client, asset, adviser status, service model and jurisdiction.
For banks, the Basel cryptoasset standard that took effect on January 1, 2026, also matters because it formalizes how banks think about cryptoasset exposure, risk appetite and disclosure. The Basel materials include attention to the market value of cryptoassets held in custody for clients as part of reporting narratives. This does not turn every bank into a crypto custodian, but it shows that custody is becoming part of mainstream prudential risk management. See also: Blockchain Technology.
A due diligence checklist for wallets and custody solutions
Strong due diligence should compare technology, legal protections and operational evidence. The following table gives a practical framework for evaluating wallets and custody solutions without relying on a single marketing label.
| Area | Questions to ask | Why it matters |
|---|---|---|
| Control model | Who can sign transactions, and can any one person or system move funds alone? | Identifies single points of failure and insider risk. |
| Key architecture | Is the setup single-key, multisig, MPC, HSM-based, smart contract based or a combination? | Different architectures create different recovery, audit and attack surfaces. |
| Segregation | Are assets legally and operationally segregated from company assets and other clients? | Important for insolvency, reconciliation and client ownership records. |
| Transaction policy | Are there address allowlists, approval thresholds, spending limits and time delays? | Reduces the chance of unauthorized or mistaken transfers. |
| Recovery | What happens if a signer, device, key share or vendor is unavailable? | Prevents security controls from becoming business continuity failures. |
| Audit and reporting | Are there independent control reports, reconciliation records and exportable logs? | Supports oversight by boards, auditors, investors and regulators. |
| Incident response | Is there a tested plan for suspected compromise, chain incidents and emergency withdrawals? | Speed and clarity matter because blockchain transfers can be irreversible. |
A buyer should also understand the limits of insurance. Some policies may cover specific theft scenarios but exclude social engineering, insider conduct, certain smart contract failures, sanctions issues or unsupported assets. Insurance can support a custody program, but it is not a substitute for transaction controls and legal review.
Matching the custody model to the use case
For an individual investor, the priority is usually simplicity without a single catastrophic failure point. A hardware wallet with carefully protected backups may be more appropriate than a complex multisignature setup the user cannot operate. For a high-net-worth individual or family office, a combination of external custody, hardware wallet backups, written inheritance planning and periodic reconciliation may be safer than relying on memory, one device or one exchange account.
For an active trader, liquidity access matters. Keeping every asset in deep cold storage can create delays and missed execution opportunities. A tiered model is often more workable: exchange balances for active strategies, warm custody for near-term liquidity, and cold or third-party custody for reserves. The policy should define maximum exchange exposure and require regular transfers back to safer storage.
For a company treasury, governance is usually the core issue. The board or finance leadership should know who can initiate, approve and verify transfers; which wallets are official; how valuations are recorded; and how custody records connect to accounting systems. Treasury custody should avoid informal arrangements where one founder, employee or contractor controls a seed phrase.
For funds, advisers and service providers, custody is both a security and compliance matter. Investors will expect clear separation of duties, documented controls, independent reporting and an explanation of how assets are protected if a custodian, exchange or technology provider fails. The custody design should be reviewed before launching a product, not after assets have already been collected.
Common mistakes that still cause losses
The first mistake is treating cold storage as automatically safe. Cold storage reduces internet exposure, but it does not solve poor backup handling, coercion risk, unclear authorization, untested recovery, or malicious firmware and supply-chain problems. The second mistake is using a wallet designed for personal convenience as if it were an institutional control system. Browser wallets and mobile wallets are useful tools, but they can be exposed to phishing, malicious approvals and device compromise.
The third mistake is ignoring operational roles. A multisignature wallet with three signers may look strong on paper, but not if all signers use the same cloud storage, sit in the same office, lack replacement procedures or approve transactions without independent verification. The fourth mistake is failing to separate long-term assets from transaction balances. Hot wallets should normally carry limits because they are exposed to more frequent use and more attack paths.
The fifth mistake is relying on proof-of-reserves style information as a complete custody answer. Reserve attestations can provide useful transparency about assets, but they do not always prove customer liabilities, legal ownership, segregation, governance or the absence of encumbrances. Custody due diligence should combine on-chain visibility with legal terms, internal controls and independent assurance.
Frequently asked questions
Are MPC wallets safer than multisignature wallets?
Not automatically. MPC can reduce some on-chain complexity and avoid a single full private key existing in one place, while multisignature can provide transparent on-chain approval rules on supported networks. The safer option depends on implementation, recovery design, vendor controls, governance and the chains being used.
Is self-custody better than using a custodian?
Self-custody gives direct control and removes dependence on a provider, but it also places security, backup and recovery responsibility on the user. A custodian can add governance, reporting and operational support, but it introduces counterparty and legal risk. The better choice depends on asset size, user skill, compliance needs and tolerance for provider risk.
How much crypto should stay on an exchange?
There is no universal percentage. A practical approach is to keep only the amount needed for active trading, settlement or near-term liquidity on an exchange. Longer-term holdings are usually better placed in a dedicated custody setup with stronger controls and clearer recovery procedures.
What should institutions review before choosing a custodian?
Institutions should review regulatory status, legal segregation, key architecture, transaction controls, audit reports, insurance scope, supported assets, withdrawal procedures, business continuity plans, subcontractors and incident response. The review should include legal, finance, security and operations teams.
Do regulations make crypto custody risk-free?
No. Regulation can improve standards for segregation, governance, disclosure and supervision, but it cannot remove market risk, smart contract risk, operational mistakes or all forms of cyberattack. Custody remains a risk management discipline rather than a guarantee.
The bottom line
The market is moving away from simple wallet labels and toward custody systems that can be tested, audited and explained. Good wallets and custody solutions answer three questions clearly: who can move assets, what prevents unauthorized movement, and what happens when something goes wrong. For retail users, that may mean disciplined self-custody and realistic backup planning. For institutions, it means combining technical architecture with legal segregation, governance, reporting and regulatory awareness. In both cases, the strongest custody decision is the one that matches the user’s actual risk, not the one with the most fashionable security terminology.


