Crypto custody is the safeguarding and administration of the private keys, credentials and processes needed to control digital assets. A blockchain records assets and transactions; custody determines who can authorise transfers and how access can be recovered, monitored or restricted. The choice between self-custody and a third-party custodian changes both control and risk.
What crypto custody protects
Digital assets generally remain recorded on a blockchain. A custodian does not place the coins inside a physical vault. Instead, the custody arrangement protects the cryptographic keys and signing processes that can move the assets. It may also maintain ownership records, reconcile balances, process deposits and withdrawals, support staking or governance, and provide reporting.
Loss or compromise of a private key can make assets inaccessible or allow an attacker to transfer them. Good custody therefore depends on more than encryption. It requires governance, authorised personnel, secure software and hardware, separation of duties, monitoring, incident response and tested recovery.
Crypto custody: self-custody versus third-party custody
Self-custody
In self-custody, the user controls the keys. A hardware wallet or other signing device may keep secrets away from an internet-connected system. The advantage is direct control. The disadvantage is direct responsibility: a lost seed phrase, malicious approval, device compromise or poor backup process may lead to permanent loss.
Custodial services
With third-party crypto custody, an exchange, specialist custodian, bank or other service provider controls keys on behalf of clients. The provider may offer institutional security, transaction policies, reporting and recovery processes. The client then faces counterparty, legal, operational, insolvency and sub-custody risks.
Crypto custody with hot, warm and cold storage
- Hot wallets: connected systems designed for frequent transactions, with greater exposure to online attack.
- Cold storage: keys kept offline or in tightly isolated systems, usually trading convenience for stronger separation.
- Warm arrangements: designs between those extremes, often combining controlled connectivity with layered approvals.
No universal hot-versus-cold percentage proves safety. IOSCO’s crypto-market recommendations note that regulators need not prescribe one storage threshold; protection of client assets should be the priority. The right design depends on transaction needs, governance and the complete control environment.
Institutional crypto custody controls
- Key generation: creating secrets in a controlled, auditable environment.
- Distributed approval: requiring several authorised parties or cryptographic shares to sign.
- Address controls: allowlists, transaction limits and risk screening.
- Segregation: separating client assets and records from the provider’s own property.
- Reconciliation: comparing on-chain balances with internal client records.
- Recovery: tested procedures for hardware failure, staff loss and disasters.
- Independent assurance: audits and control reviews that cover relevant systems and processes.
The IOSCO policy recommendations for crypto and digital asset markets emphasise client-asset protection, segregation, accurate records, reconciliation, disclosure and the ability to return assets during insolvency. These principles address both technology and the customer’s legal rights.
Major crypto custody risks
- Key compromise: attackers obtain the ability to sign transactions.
- Internal fraud: privileged staff misuse authority or bypass controls.
- Operational failure: software, networks or procedures prevent access or cause incorrect transfers.
- Insolvency: clients may face uncertainty about ownership and recovery.
- Commingling: poor segregation obscures which assets belong to each client.
- Smart-contract risk: staking, token wrapping or DeFi integrations add technical exposure.
- Legal risk: property rights and custody rules differ across jurisdictions.
- Concentration: one provider or technology stack can become a critical point of failure.
A crypto custody due-diligence checklist
- Identify the legal entity and applicable regulator.
- Understand whether assets are segregated on-chain, in books, or both.
- Review who controls keys and how signing approval works.
- Check insurance scope, exclusions and claim limits.
- Examine reconciliation, audit and incident-disclosure practices.
- Understand sub-custodians, foreign jurisdictions and insolvency treatment.
- Confirm withdrawal rules, delays and emergency procedures.
- Test personal recovery arrangements before transferring significant value.
Readers can also review our guide to crypto wallets and the broader discussion of blockchain risks.
The bottom line
Crypto custody is a combination of cryptography, operations, governance and law. Self-custody maximises direct control but places recovery and security duties on the user. Third-party custody can add institutional controls, but it introduces counterparty and insolvency exposure. The sound choice depends on the asset, transaction needs, legal protections and the user’s ability to manage keys safely.


