Institutional crypto custody is the safekeeping of digital assets under segregated accounts, audited key-management controls, and a legal structure that survives a provider failure. The right model depends on how much you hold, how often you trade, and which regulator your charter answers to.
That one-sentence answer hides a lot of moving parts. A pension consultant, a bank treasury team, and a crypto-native fund all mean something different when they say "custody." This guide breaks the market into four workable models, compares what each one actually controls, and maps each model to the situations where it holds up.
What institutional custody actually covers
Custody for digital assets is a bundle of five jobs, and providers differ on every one of them.
First is key generation and storage. Private keys are created inside hardware security modules or through multi-party computation, and they never exist in complete form on an internet-connected machine. Second is transaction authorization: the workflow of approvals, velocity limits, and allowlists that stands between a request and a signed transaction. Third is asset segregation, which keeps client assets in accounts that are legally distinct from the provider's own balance sheet. Fourth is proof and reporting: attestations, SOC 2 audits, and statements your own auditor will accept. Fifth is recovery, meaning a documented, tested path to restore access when people leave, hardware dies, or a data center goes offline.

Screenshot: Anchorage Digital
A provider can be excellent at the cryptography and weak on the legal side, or the reverse. A bankruptcy-remote structure matters as much as the hardware, because the failure you are most likely to face is a business failure, not a broken cipher. The collapse of several lending platforms made the difference plain: customers of true segregated custodians recovered assets, while creditors of commingled platforms waited in line at bankruptcy court.
The vocabulary also matters when you talk to boards. "Cold storage" describes network isolation, not a legal promise. "Qualified custodian" describes a regulatory status, not a security architecture. A clear separation of those two axes — technical isolation and legal standing — is the fastest way to cut through vendor marketing.
Reporting deserves its own line of questioning during diligence. Ask whether the provider delivers a SOC 2 Type II report rather than the weaker Type I, how often wallet-level attestations are produced, and whether statements arrive in a format your fund administrator can reconcile without manual work. Proof-of-reserves publications vary widely in rigor: a snapshot signed by an auditor with liabilities included is evidence, while a bare list of addresses is closer to advertising. Institutions that skip this question tend to discover the gap at their first annual audit, when the external auditor asks for confirmations the provider was never contracted to produce.
Staffing is the last piece that separates institutional custody from a retail wallet with a bigger balance. Someone inside your organization owns the relationship, reviews access lists quarterly, and re-approves the signer roster after every departure. Providers can enforce policy, but only the client knows when an employee has changed roles and should lose transaction rights. The strongest technical setup leaks risk if the people layer around it goes stale.
Four custody models compared
Most institutional setups land on one of four models. The table below normalizes them by control, speed, and what a $100 million portfolio pays per year at typical published fee ranges.
| Model | Who holds keys | Typical annual fee | Cost per year on $100M | Withdrawal speed | Legal segregation |
|---|---|---|---|---|---|
| Regulated third-party custodian | Provider (client-directed) | 0.10%–0.35% | $100,000–$350,000 | Hours to 1 day | Strong, account-level |
| MPC wallet provider | Shared (client + provider shards) | 0.05%–0.15% + platform fee | $50,000–$150,000 | Minutes | Contract-dependent |
| Self-custody with HSMs | Institution | Hardware + staff, roughly fixed | $250,000+ all-in | Minutes to hours | Full, but self-administered |
| Exchange custody | Exchange omnibus | Often bundled with trading | Varies with volume | Instant on-venue | Weakest of the four |
The derived column is the one boards care about: on a $100 million book, a 0.25% custodian fee is $250,000 a year, which is roughly the loaded cost of running a two-person in-house key-management function before you buy any hardware. Below that asset level, third-party custody is usually cheaper than doing it yourself. Above roughly $500 million, the percentage fee starts to dominate and self-custody or negotiated flat pricing gets attractive.
Named examples make the rows concrete. Anchorage Digital operates as an OCC-chartered national trust bank in the regulated third-party row. Coinbase Custody Trust and BitGo Trust hold limited-purpose trust charters in New York and South Dakota respectively and sit in the same row. Fireblocks is the most widely deployed MPC wallet platform among trading firms, and Ledger Enterprise sells the hardware signing stack an institution would run in the self-custody row. Listing them is not an endorsement: fee schedules and charter status change, and each claim in the table should be re-verified against the provider's current disclosures during diligence.

Screenshot: Coinbase Prime
Speed cuts the other way. Exchange custody settles instantly on-venue but concentrates counterparty risk at the exact place you trade. A cold-storage custodian gives the strongest isolation and the slowest exit. MPC providers sit in the middle, which is why trading firms cluster there. There is no model that wins every column, and any provider claiming otherwise is describing marketing, not architecture. For a deeper look at the signing technology behind the middle row, see the guide to multi-party computation custody.
More in Guides
Security architecture: cold storage, HSMs, and MPC
Three technical patterns dominate, and they answer different threats.
Deep cold storage keeps keys on devices that never touch a network. Signing happens in an air-gapped ceremony, often with material split across geographically separate vaults. The threat it answers is remote compromise: an attacker who owns your entire network still cannot reach the keys. The price is operational drag. A withdrawal can require multiple people, physical travel, and scheduled windows.
Hardware security modules move the keys into tamper-resistant appliances that can sign on demand but are physically and logically hardened. HSMs answer the insider threat and the malware threat while keeping latency low. Their weakness is that the appliance is a single signing location, so policy enforcement and physical security around it carry the whole load.
Multi-party computation splits a key into shards held by different parties or devices. No complete key ever exists anywhere, and a quorum of shards signs cooperatively. MPC answers the single-point-of-failure problem and enables policy rules like "two officers plus one automated risk check." Its weakness is protocol complexity: the cryptography is newer, and implementation quality varies across vendors.

Screenshot: Fireblocks
Mature providers layer the three. Operating balances sit behind MPC or HSMs for daily settlement, while reserve balances sit in deep cold storage. The split between the layers is a policy decision: a common starting point keeps more than 90% of assets in the coldest tier and rebalances on a schedule rather than on demand.
Governance around the technology matters more than the acronym. Ask who can change the approval policy, how a quorum member is replaced after a departure, and how a recovery drill is evidenced. A vendor with weaker cryptography and tested procedures beats a vendor with elegant cryptography and untested ones.
Two failure patterns are worth naming because they recur in incident reports across the industry. The first is policy drift: an approval workflow configured tightly at launch, then loosened one exception at a time until a single employee can move nine figures. The second is recovery-path concentration, where backup key material for "geographically distributed" shards turns out to sit with one law firm or one cloud account. Both are checkable in an afternoon, and both are invisible in a product demo. Institutional crypto custody diligence that stops at the demo has not started.
Regulation and the qualified custodian question
Legal standing is where institutional custody diverges hardest from retail practice, and three regimes shape the U.S. market.
National banks may provide crypto custody services under the Office of the Comptroller of the Currency's Interpretive Letter 1170, issued in July 2020, which treats safekeeping of cryptographic keys as a modern form of a traditional bank activity. That letter is why several large trust banks now offer digital asset custody through the same fiduciary structures used for securities.
Registered investment advisers face the custody rule under the Investment Advisers Act, and the SEC's proposed safeguarding amendments of February 2023 pushed to cover all client assets, digital ones included, with explicit segregation and written-agreement requirements. Advisers holding client crypto generally need a qualified custodian, and which providers count is a live compliance question rather than a settled one. The tests that separate a marketing claim from actual qualified status are covered in the companion guide to qualified custodian digital assets.

Image: BitGo
State trust charters fill much of the gap. New York's Department of Financial Services supervises virtual currency businesses through the BitLicense and limited-purpose trust charters, with published guidance on custody structures, and Wyoming and South Dakota charters serve a similar role for other providers. Coinbase Custody Trust operates under one such New York limited-purpose trust charter, while Anchorage Digital converted a state charter into a national trust bank charter under the OCC's framework.
Outside the United States, the European Union's Markets in Crypto-Assets framework brings custody of client crypto under a licensing regime with capital, segregation, and liability requirements, and several Asian financial centers run comparable trust or license structures. Institutions with entities in more than one jurisdiction often end up with more than one custodian for that reason alone: the entity that satisfies a U.S. examiner rarely maps one-to-one onto the entity a European supervisor expects to see on the account.
The practical takeaway: match the charter to your own regulator. A bank answers to banking supervisors and wants a custodian that speaks that language. An RIA needs the qualified custodian box checked in a way its examiner accepts. An offshore fund may care more about the governing-law clause and the segregation opinion than about any U.S. charter. Custody selection is a legal decision with a technical component, not the reverse.
Matching a model to your situation
Selection gets easier when you start from the institution rather than the vendor list.
Situation 1 — a registered adviser adding a 3% digital allocation. The controlling constraint is the custody rule, not technology. Choose a regulated third-party custodian with clear qualified-custodian standing, account-level segregation, and reporting your fund administrator can ingest. Pay the basis points; the examiner conversation is the product you are buying. Skip self-custody entirely at this size, because the fixed cost swamps the allocation.
Situation 2 — a trading firm moving size daily across venues. Deep cold storage will strangle the desk. Pick an MPC provider with policy-based approvals, venue allowlists, and sub-hour settlement, and keep only working capital on exchanges. The residual exchange balance is a risk line item to monitor, so set a hard cap on it and sweep above the cap automatically.

Image: BitGo
Situation 3 — a bank treasury holding a long-term reserve. Trading tempo is near zero and scrutiny is maximal. A layered setup fits: the bulk in deep cold storage under a trust structure your regulator recognizes, a small operating sleeve behind HSMs for scheduled movements, and quarterly recovery drills with documented evidence. Self-custody is viable here if the balance justifies permanent staff, and a chartered sub-custodian is the simpler path if it does not.

Screenshot: Ledger Enterprise
A useful forcing exercise for any of the three: write down the single worst day the setup must survive — a custodian bankruptcy, a signing-quorum member arrested abroad, a venue freeze during a volatile week — and walk the documented procedures against it. If the walkthrough requires a step that exists only in someone's head, the model is not finished, whatever the contract says. Committees approve architectures; incidents test procedures.
Two cross-cutting rules apply in every case. Concentration is a risk of its own, so institutions above a few hundred million in digital assets increasingly split across two custodians to keep an exit path open. And insurance limits are per-provider and often per-vault, so read the policy schedule rather than the press release number.
The same failures repeat across due-diligence files, and most of them are avoidable at the contract stage.
Buying the brand instead of the account structure. Two clients of the same custodian can have materially different protection depending on whether assets sit in an omnibus pool or a segregated account. The account agreement, not the vendor's homepage, is the document that decides your recovery in a failure.
Testing security and skipping recovery. Penetration tests are standard; restoration drills are rare. An untested recovery path is a liability with a delay on it. Insist on evidence of a completed drill, and schedule one within the first year of the relationship.
Ignoring the exit. Migrating custody means re-deriving addresses, re-papering counterparties, and moving assets under time pressure if the relationship ends badly. Negotiate exit assistance and data portability before signing, when leverage is highest.
Treating insurance as a substitute for architecture. Crime policies cover specific named events, carry per-event limits, and exclude most smart-contract and market losses. Insurance narrows the tail; segregation and key governance remove the body of the risk.
Skipping the annual re-review. Custody decisions age. Providers change owners, insurance towers shrink at renewal, and charters get upgraded or surrendered. A selection memo from two years ago describes a company that may no longer exist in that form. Put the custodian on the same annual review calendar as any other material counterparty, with the original selection criteria as the checklist.
Letting the desk choose the custodian. Trading convenience is real, but it is one column in the table, and the people who feel the friction daily are not the people who answer to the board when segregation fails. Keep selection with risk and operations, with the desk as an input.
FAQ
Is an exchange account ever acceptable custody for an institution?
As working capital, yes, with a hard cap and automatic sweeps to segregated custody. As the primary store of a reserve, no, because omnibus exchange structures put you closest to the unsecured-creditor line in a failure.
What does institutional custody typically cost?
Third-party custodians commonly quote between 0.10% and 0.35% of assets per year, with minimums, and MPC platforms less on a percentage basis plus platform fees. Self-custody trades the percentage for a fixed cost in staff, hardware, and audits, which is why it only makes sense at scale.
Do custodians insure the assets they hold?
Most carry crime insurance on custodied assets, but limits are shared across clients and specific to named events like theft of keys. The policy schedule and the segregation structure together determine what you would actually recover.
How long does onboarding with a regulated custodian take?
Plan on several weeks to a few months, driven by compliance review, account documentation, and technical integration of approval workflows. Trading firms should sequence onboarding before capital deployment rather than in parallel.
Can an institution use more than one custody model at once?
Yes, and mature programs usually do: deep cold storage for reserves, MPC or HSM-backed wallets for operations, and capped exchange balances for settlement. The split is a policy decision reviewed on a schedule.
Sources
- Office of the Comptroller of the Currency, Interpretive Letter 1170 on cryptocurrency custody services for national banks (July 2020): occ.gov announcement
- U.S. Securities and Exchange Commission, proposed safeguarding rule enhancements for investment advisers (February 2023): sec.gov press release
- New York State Department of Financial Services, virtual currency business supervision and custody guidance (updated 2023): dfs.ny.gov virtual currency page



