Custody is usually discussed as a technical question: hardware or software, online or offline, your own device or an outside provider. The decision a company actually makes is a different one — it settles who is left standing when something is lost.
What is kept is the power to dispose, not the balance
A token does not sit inside a wallet. It sits in the network's ledger and stays there. What is kept is the private key that signs a transfer. The distinction sounds academic, but it has a very practical consequence: whoever holds the key can dispose of the assets — and whoever has disposed of them has done so for good.
That removes a safeguard which is taken for granted elsewhere in payments. A misdirected bank transfer can be reported. There is a procedure, a contact and, in the end, a liability question that someone answers. For a signed transfer in an open network, none of that applies. How such a signature comes about, and from when it counts as final, is covered in How Does a Blockchain Work?.
The question is therefore not where the balance is held. It is: who may sign, and who is liable when the wrong thing was signed.
Three models, one question: who carries the loss
Under self-custody the company holds the keys itself. That grants full control and full responsibility: there is no third party to replace a loss and no address for a complaint. For small amounts this is often appropriate. As holdings grow, so does the effort that sound key management requires — and that effort arises whether or not it is spent.
Splitting the signing power is the obvious refinement. With multisig, M of N signatures must come together. With multi-party computation (MPC), a complete key never exists in any single place. Both remove the single point of failure, often combined with a hardware security module (HSM). The liability, however, does not move outward — it moves inward, into roles, approvals and an emergency plan that someone has to maintain.
Only regulated custody actually shifts the liability. An authorised custodian holds the keys on your behalf. What it owes while doing so is not left to the parties to agree; it is set by supervisory law.
What MiCAR made of custody
Since 30 December 2024 the European crypto-asset regulation MiCAR has applied to crypto-asset services. Providing them commercially requires authorisation. Custody is one of those services; the regulation describes it as the safekeeping or control of crypto-assets — or of the means of accessing them. The qualifier that matters is “on behalf of clients”. A company holding only its own positions is not providing a service to third parties: it needs no authorisation, but it also has no one who is liable to it.
For a company that is a client of such a custodian, four duties are worth knowing. The custodian concludes an agreement setting out its duties and responsibilities. It keeps a register of positions in the name of each client. It maintains a documented custody policy. And it must have procedures in place to return the holdings as soon as possible. Article 70 additionally requires adequate arrangements to safeguard clients' ownership rights — expressly including the event of the custodian's own insolvency.
The sentence that carries the most weight in a selection decision sits at the end of Article 75. The custodian is liable for the loss of crypto-assets or of the means of access where the incident is attributable to it. That liability is capped: at the market value of the lost crypto-asset at the time the loss occurred. Where holdings fluctuate, that clause is worth knowing. What is replaced is the value at the time of the loss, not the value the holding might have reached later.
Four questions that decide the choice
The models are hard to weigh against each other in the abstract. It is more useful to run your own plan past four questions. They apply to every model; only the answers differ:
- Who may act alone? Above which amount does dual control apply, and is it technically enforced or merely described in a policy?
- What happens if a person drops out? Who can still sign then, and has that ever been rehearsed?
- Who owns the holdings if the custodian fails? Segregated holdings and a register of positions are the answer you have put in writing.
- Where does liability end? At market value at the time of the loss — and which further cases does the contract exclude?
It is striking how few of these questions are technical. Three of the four are answered by the organisation, not by the technology.
What one machinery manufacturer made of it
A special machinery manufacturer with around 120 million euros in revenue has been settling part of its supplier invoices in euro stablecoins for a year. That is roughly forty payments a month, and the running balance rarely exceeds a mid six-figure amount. For dedicated key management with on-call staff and a rehearsed emergency procedure, that balance is too small. For a device in a safe whose recovery no one has ever tested, it is too large.
The company therefore settled on a tiered model. An operating balance of about two weeks' payment volume sits in a wallet requiring two of three signatures: treasury, the head of finance, and a third share deposited outside the company. The remainder sits with an authorised custodian. Recipient addresses are bound by a whitelist, and every approval lands in the ERP system's audit trail.
What tipped the decision was not security but the ability to give an account. At the reporting date the auditor asks for evidence of both the holding and the authority to dispose of it. A custodian supplies a confirmation and a register of positions for that purpose. Self-custodied holdings can be evidenced just as well. The company only has to design that procedure itself, document it and defend it before the auditor. That is not an argument against self-custody; it is a cost item that is routinely missing from the calculation.
From the CFO's perspective, three quantities then sit side by side: a running custody fee, a liability capped in amount, and a concentration risk towards a single provider. None of them decides on its own. Together they produce a choice that can be justified — and one that is revisited as soon as the amounts change materially.
Where things actually go wrong
The well-known incidents suggest an attack from outside. In mid-sized companies the more common cause is more mundane: a single person knows the recovery procedure, and that person changes employer. An emergency plan that has never been played through is not a safeguard but an assumption. Anyone setting up a custody model should therefore rehearse the recovery case once in full. The same people who would be responsible in earnest should run it, and the outcome should be recorded.
On the custodian's side the risk lies elsewhere. An attestation of reserves held — proof of reserves — is a statement about one point in time and says nothing about the liabilities standing beside them. Nor does an insurance policy answer by itself which events it covers. And onboarding as a client involves know your customer (KYC) checks that take time and therefore belong in the project plan, not in its final week.
What remains
Custody is not a question of secure or insecure. It is the question of whose mistake costs whom — and it gets answered whether or not it is asked. Asking it produces a decision that can be written down, reviewed and later adjusted.
What helps is therefore less the search for the safest model than a sober allocation: which holdings must be available how quickly, who in the company actually signs, and what a third party promises in writing. If one of those three changes, the appropriate model usually changes with it.
Sources & Date
- •BaFin – Guidance notice: crypto-asset services under MiCAR – (3 January 2025, German — authorisation required where services are provided commercially; custody as defined in Art. 3(1)(17) MiCAR, applicable since 30 December 2024)
- •ESMA, Interactive Single Rulebook – MiCA, Article 75 – Providing custody and administration of crypto-assets on behalf of clients – (client agreement, register of positions, custody policy, return of assets — and the liability capped at market value at the time of the loss in paragraph 8)
- •ESMA, Interactive Single Rulebook – MiCA, Article 70 – Safekeeping of clients' crypto-assets and funds – (adequate arrangements to safeguard clients' ownership rights, expressly including the provider's insolvency)
As of: 13.08.2026