TrendCrypt News

The SEC Is Redrawing Who Can Hold Crypto for Investors

The SEC has proposed a new crypto custody framework that could let advisers hold certain client assets themselves and use state trust companies, reshaping who controls institutional crypto keys.

Published 2026-10-06
Updated 2026-10-06
Publisher Ananthi Reeta
The SEC Is Redrawing Who Can Hold Crypto for Investors

Institutional crypto custody used to sound simple.

There were two options:

leave the assets with a crypto custodian

or

do not invest.

The SEC is proposing a more complicated answer.

On October 1, the Commission published a new custody framework for registered investment advisers and regulated funds that would, under certain conditions, allow them to:

  • maintain crypto with traditional permitted custodians,
  • use qualifying state trust companies,
  • in limited circumstances, hold certain crypto assets themselves.

That last option is the most important.

The proposal calls it:

self-custody.

But this is not the same self-custody a retail Bitcoin holder means when they move coins to a hardware wallet.

The client would not necessarily hold the key.

The adviser or fund would.

That means institutional crypto custody is starting to create a third model between:

customer holds the key

and

outside custodian holds the key.

The regulated financial firm itself may become the custodian.

The SEC’s proposal is designed partly around a real market problem:

for some crypto assets, a legally permitted third-party custodian may not exist yet.

A new token can become economically relevant before a bank, broker or approved custodian is technologically ready to support it.

Under the proposed framework, that gap would no longer automatically prevent an adviser or fund from holding the asset.

But the SEC is not proposing:

advisers can hold any crypto however they want.

The self-custody option would come with conditions.

Among them are expectations around:

  • determining whether a permitted custodian is actually available,
  • safeguarding expertise,
  • cybersecurity,
  • internal oversight,
  • client reporting,
  • disclosure.

The proposal also expands the possible third-party custody market by allowing qualifying:

state trust companies

to hold client and fund crypto assets under specified conditions.

That creates a much more important question than:

Which exchange holds the Bitcoin?

Institutional investors increasingly need to ask:

Who legally and technically controls the keys, under what rules, and what happens if that control fails?

That is where crypto custody regulation is moving next.


Key Takeaways

  • The SEC proposed new crypto custody rules on October 1, 2026.
  • The proposal affects:
    • registered investment advisers,
    • registered investment companies,
    • business development companies.
  • It is a proposed rule, not final law.
  • Public comments remain open for 60 days after Federal Register publication.
  • The proposal would create a more explicit custody framework for certain crypto assets.
  • It would permit advisers and regulated funds to use traditional permitted custodians where available.
  • It would also allow qualifying state trust companies to act as crypto custodians under specified conditions.
  • Under limited circumstances, advisers or funds could also use what the proposal calls: self-custody.
  • Adviser self-custody does not mean the client personally holds the private keys.
  • It means the regulated adviser itself directly safeguards the client crypto.
  • A major threshold condition is that the adviser determines no permitted custodian is available for the relevant asset.
  • That determination would need to be revisited periodically.
  • The proposed framework also contemplates:
    • cybersecurity protections,
    • safeguarding expertise,
    • internal reporting,
    • client account statements,
    • disclosures.
  • State trust companies would not automatically qualify simply because they exist.
  • Advisers or funds would need a reasonable basis for believing the trust company:
    • is authorized to provide crypto custody,
    • maintains appropriate safeguarding policies.
  • That due diligence would need to be revisited over time.
  • The proposal would also modernize:
    • recordkeeping,
    • reporting,
    • financial-statement audit requirements,
    • certain broker-dealer custody rules.
  • The proposal does not automatically apply to every token or coin.
  • Applicability depends on whether the crypto asset falls within the relevant legal categories under:
    • the Advisers Act,
    • the Investment Company Act.
  • Retail self-custody remains a separate concept.
  • Blockchain transparency does not eliminate the need for:
    • custody controls,
    • ownership records,
    • segregation,
    • governance.
  • Institutional custody risk increasingly includes:
    • key compromise,
    • insider misuse,
    • software failure,
    • custodian insolvency,
    • operational mistakes.
  • The larger trend is: crypto custody is becoming a regulated systems problem, not merely a private-key problem.

What Did the SEC Actually Propose?

The Commission proposed changes to custody rules under two major federal securities-law frameworks:

  • the Investment Advisers Act of 1940,
  • the Investment Company Act of 1940.

These rules govern how registered advisers and regulated investment funds safeguard assets.

The existing custody frameworks were written around traditional financial assets.

Think:

  • securities accounts,
  • banks,
  • broker-dealers,
  • paper certificates.

Crypto creates different mechanics.


Crypto Does Not Sit Neatly Inside Old Custody Rules

Traditional custody often assumes there is:

a recognized institution capable of holding the asset.

Crypto can develop faster than institutional custody infrastructure.

A new asset may:

  • launch,
  • trade,
  • gain substantial value

before a permitted custodian supports it.

That creates a regulatory dead end.

The adviser may believe the asset belongs in a portfolio.

But no approved third party can hold it.


The SEC Is Trying to Close That Gap

The proposed framework gives advisers and funds more than one path.


Crypto Custody Options Under the Proposed Framework

ModelWho Holds the Assets?How It WorksKey Distinction
Traditional permitted custodianBank, broker-dealer or other permitted custodian under applicable rulesCustodian holds assets for the adviser or fundLong-established financial custody model
State trust companyQualifying state-chartered trust companyCan hold crypto under the proposed framework if conditions are metExpands the pool of permitted crypto custodians
Adviser self-custodyRegistered investment adviser itselfAdviser directly safeguards client crypto under limited circumstancesOnly available subject to proposed conditions
Fund self-custodyRegulated fund / its controlled custody processFund maintains crypto through its own safeguarded infrastructureStill subject to fund custody obligations
Retail self-custodyIndividual investorInvestor controls their own private keys directlyDifferent concept from adviser “self-custody”

This is more flexible than a system requiring every crypto asset to sit with the same type of outside custodian.


What Does “Self-Custody” Mean Here?

This phrase needs immediate clarification.

When a retail user says:

I self-custody Bitcoin.

They usually mean:

I personally control the private key.

That is not exactly what the SEC proposal means.


Adviser Self-Custody Means the Adviser Holds the Client Asset

Suppose:

  • an investment adviser manages a client’s crypto portfolio.

Under adviser self-custody:

the adviser itself would maintain custody of the relevant crypto.

The client is still using an intermediary.

The intermediary simply happens to be the adviser rather than an external custodian.


That Is Why “Self-Custody” Can Be Misleading

From the client’s perspective:

someone else still controls the operational keys.

The client may have:

  • beneficial ownership,
  • account rights.

But they are not necessarily holding:

  • seed phrase,
  • signing authority.

This is institutional custody conducted internally.


Retail Self-Custody vs Adviser Self-Custody vs Third-Party Custody

QuestionRetail Self-CustodyAdviser Self-CustodyExternal Custodian
Who controls keys?Individual investorAdviser or fund infrastructureThird-party custodian
Primary responsibilityInvestorAdviser / fundCustodian with adviser oversight
Regulatory frameworkDepends on investor and productAdviser / fund custody rulesCustody agreement + regulatory requirements
Single-person riskCan be highShould be controlled through institutional proceduresDepends on custodian design
Recovery / continuityOften limited to user`s backupInstitutional continuity processes expectedCustodian recovery procedures

These arrangements can all be described using the word:

custody.

The risk models are very different.


Self-Custody Would Not Be the Default

The proposal does not simply say:

any adviser that prefers controlling keys internally can do so.

One central condition is whether an eligible outside custodian exists.

The adviser would need to determine that:

no permitted custodian is available to maintain the relevant crypto asset.

That changes the role of self-custody significantly.


It Is Designed as an Availability Solution

Imagine a new crypto security launches.

The adviser wants client exposure.

No permitted custodian supports it.

Under a strict outside-custodian-only regime:

the investment may be impossible.

Under the proposal:

self-custody could provide a compliant path.


Advisers Would Need to Revisit That Determination

A crypto asset may have no institutional custodian today.

Six months later:

several may support it.

The adviser should not be able to rely forever on:

none were available when we first bought it.

The proposal therefore contemplates recurring reassessment.


The Availability Test Matters More Than It First Appears

It prevents self-custody from becoming:

a cheaper way to avoid paying an external custodian.

The adviser cannot simply say:

We prefer holding the keys ourselves.

It needs to fit the proposed conditions.


Self-Custody Creates a Conflict

There is a reason custody functions are often separated from:

  • portfolio management.

If the same organization:

  • chooses investments,
  • controls assets,
  • maintains records,

more power sits in one place.

That creates possible conflict.


Separation of Functions Can Reduce Abuse

Traditional finance often splits:

  • investment decisions,
  • custody,
  • accounting.

Why?

Because one organization cannot easily:

  • move assets,
  • alter records

without another institution seeing the discrepancy.

Crypto self-custody reduces some of that external separation.

The proposal therefore relies more heavily on internal controls.


What Would Advisers Need to Do?

The precise requirements are still proposed rather than final.

The SEC’s materials describe safeguards around several areas.


Key Conditions Around Proposed Adviser Self-Custody

ConditionWhat It MeansWhy It Matters
No permitted custodian availableAdviser must determine that no permitted custodian is available for the crypto assetPrevents self-custody from becoming the automatic default
Periodic reassessmentAvailability determination must be revisited regularlySelf-custody cannot continue indefinitely without review
Safeguarding expertiseFirm must have appropriate capability to protect the assetsCrypto custody requires specialized operational knowledge
Cybersecurity controlsSecurity protections must address theft, loss and misusePrivate-key compromise can cause irreversible loss
Internal oversightFirm must maintain internal reporting and governanceReduces dependence on one individual or one wallet operator
Account statements / client informationClients must receive appropriate reportingCustody should remain auditable and understandable
DisclosureClients must understand the custody arrangement and related risksSelf-custody changes the risk model materially

This is much closer to institutional custody than:

buy hardware wallet and write seed on paper.


Safeguarding Expertise Matters

Running institutional crypto custody is technically difficult.

A firm needs to understand:

  • signing,
  • transaction construction,
  • blockchain confirmation,
  • network-specific behavior.

One bad operational decision can be irreversible.


Crypto Custody Is Not Generic IT

A company can have:

  • strong cybersecurity team

and still lack crypto-custody expertise.

Crypto introduces unusual risks.

For example:

  • signing the wrong transaction can permanently move assets.

There is no bank chargeback.


Key Management Is the Center of the System

The most basic crypto custody question remains:

Who can sign?

Everything else builds around that.


Different Ways Institutional Crypto Keys Can Be Controlled

ModelTypical ControllerSigning StructureMain Risk
Retail hardware walletUsually one individual or householdSeed phrase, device, passphrasePersonal loss or compromise
Institutional hot walletCompany operational teamOnline signing systemFast access but high online exposure
Institutional cold storageCustody or treasury teamOffline / isolated signing proceduresLower online exposure, slower operations
Multi-party signingSeveral approved operators or systemsMultiple approvals requiredReduces single-person compromise risk
MPC custodyDistributed signing participantsSigning authority split across systemsNo single complete private key needs to exist in one place

Institutional systems usually try to avoid one person having unrestricted control.


A Seed Phrase in a Safe Is Not Enough

That may be acceptable for:

personal Bitcoin.

For a billion-dollar fund:

it creates obvious problems.

What if the person who knows the seed:

  • dies,
  • steals it,
  • loses it?

Institutional custody needs:

  • continuity,
  • role separation.

Multi-Signature Can Reduce Single-Person Risk

A wallet might require:

3 of 5 approvals.

That means one stolen key cannot move assets.

It also creates operational complexity.

Who holds the keys?

How are they replaced?

What happens if several signers are unavailable?


MPC Is Another Institutional Approach

Multi-party computation can distribute signing authority across several systems.

No one machine necessarily holds the complete private key in ordinary operation.

This can reduce:

  • single-key compromise risk.

It does not eliminate:

  • governance,
  • software risk.

Cold Storage Reduces Online Exposure

Long-term assets can be held through:

  • offline,
  • highly isolated

signing systems.

That makes remote theft harder.

The trade-off:

slower access.


Hot Wallets Still Have a Role

Some assets need to move quickly.

An adviser executing active strategies may not be able to keep everything:

deep offline.

That creates the familiar security trade-off:

accessibility vs exposure.


Institutional Self-Custody Requires Wallet Architecture, Not One Wallet

A serious custody program may separate:

  • long-term holdings,
  • operational liquidity,
  • testing wallets,
  • fee wallets.

The word:

wallet

can hide an entire internal treasury architecture.


Withdrawal Governance Becomes Critical

A safe custody system should answer:

  • who requests transfer?
  • who approves?
  • who signs?
  • who verifies destination?

The same person should not necessarily perform every step.


Separation of Duties Reduces Insider Risk

Imagine one portfolio manager can:

  1. add withdrawal address,
  2. approve it,
  3. sign transaction.

That creates enormous insider risk.

Institutional custody should make fraudulent transfers difficult even for insiders.


Crypto Custody Is About Insider Threats Too

Hackers get most headlines.

Financial institutions also worry about:

  • employees,
  • contractors,
  • compromised administrators.

Strong custody architecture assumes some trusted person may eventually become:

  • malicious,
  • compromised.

What Happens If an Adviser Gets Hacked?

This becomes one of the hardest questions.

If the adviser self-custodies and attackers steal client crypto:

the blockchain may not reverse the theft.

Regulation can establish:

  • responsibility,
  • controls.

It cannot recover every transaction.


This Is Different From Traditional Asset Custody

Suppose a database says:

client owns 1,000 shares.

A fraudulent internal transfer may sometimes be corrected through:

  • intermediaries,
  • legal ownership records.

Bitcoin is different.

If private keys authorize:

send 10 BTC to attacker,

the network may consider the transfer valid.

Legal ownership and blockchain control can diverge.


That Makes Prevention More Important

Traditional financial systems can sometimes rely more on:

  • correction.

Crypto needs stronger:

  • prevention.

Once the transaction settles:

recovery may depend on:

  • tracing,
  • freezing at centralized services,
  • attacker cooperation.

Client Disclosure Matters Because the Risk Is Different

If an adviser uses self-custody, clients should understand that custody architecture creates its own risk.

They may be exposed to:

  • internal systems,
  • signing procedures.

An outside custodian creates a different dependency.

Neither is automatically safer in all circumstances.


The Adviser Cannot Outsource Responsibility Mentally

Suppose an adviser chooses a third-party custodian.

That does not mean:

custody risk is now someone else’s problem.

The adviser still needs to select and monitor the custodian appropriately.

The state-trust-company proposal reinforces that.


State Trust Companies Get a Larger Role

The SEC proposal would expressly permit qualifying state trust companies to serve as crypto custodians under specified circumstances.

This matters because state trust companies have become important in digital-asset custody.

They can specialize in:

  • key management,
  • settlement.

A Trust Charter Alone Would Not Be Enough

The adviser or fund would need a reasonable basis for believing the trust company:

  • is authorized by the relevant state banking authority to provide crypto custody,
  • has appropriate safeguarding policies.

What Advisers Would Need to Check Before Using a State Trust Company

CheckWhat It MeansWhy
AuthorizationState authority permits crypto custodyFirm must confirm the trust company actually has authority
Safeguarding policiesWritten procedures address theft, loss, misuse and misappropriationLicence alone is not enough
Initial due diligenceAdviser or fund assesses the trust company before useResponsibility does not disappear when custody is outsourced
Annual reviewCustodian suitability is revisitedControls must remain adequate over time
Operational capabilityCustodian must actually be able to secure the crypto assetLegal status is not a substitute for technical competence

That means the regulatory logic is not:

trust company = automatically safe.

It is:

trust company can be used if it actually meets the conditions.


Annual Review Matters

A custodian can be strong today.

Later:

  • controls weaken,
  • ownership changes.

One-time diligence is not enough.

Ongoing review is especially important in a fast-moving crypto market.


A trust company may legally be permitted to custody crypto.

Can it safely custody:

this specific asset?

Different chains use different:

  • signing systems,
  • network behavior.

Legal permission does not equal technical competence.


Supporting Bitcoin Is Not the Same as Supporting Every Token

A custodian may be excellent at:

  • BTC.

That does not mean it automatically understands:

  • a new smart-contract asset.

Every additional network can add:

  • code,
  • operational procedures.

Custody coverage is asset-specific.


This Is Exactly Why the SEC Is Considering Self-Custody

The crypto market can produce new assets faster than custodians can integrate them.

The proposal acknowledges that mismatch.

Institutional demand does not always wait for custody infrastructure to catch up.


But That Creates a Hard Policy Trade-Off

Option one:

prohibit holding any asset without an external custodian.

Result:

some investment strategies become impossible.

Option two:

allow internal custody.

Result:

more operational risk moves into the adviser.

The proposal attempts to allow the second while adding guardrails.


Which Crypto Assets Does This Actually Cover?

This is another area where headlines can go wrong.

The SEC is not proposing one universal federal custody rule for:

every cryptoasset held by everyone.

The proposal applies through specific securities-law custody rules.


The Proposal Does Not Cover Every Crypto Asset Automatically

Asset / HolderPotential TreatmentImportant Point
Adviser client crypto that is a fund or securityPotentially within the Advisers Act custody frameworkDepends on legal classification
Regulated fund crypto securityPotentially within Investment Company Act custody rulesFund-specific custody rules apply
Crypto asset that is not legally within the covered categoriesMay fall outside these specific proposed custody requirementsProposal is not a universal rule for all crypto
Retail investor holding own BTCOutside the adviser/fund self-custody conceptPersonal self-custody remains a separate issue

Legal classification matters.


Adviser Act Scope Is Not “All Crypto”

A crypto asset may or may not be:

  • fund,
  • security

for the relevant rule.

If it is outside those categories:

this particular custody framework may not apply in the same way.


Regulated Funds Have Their Own Scope

Registered investment companies and BDCs operate under the Investment Company Act.

Their asset-custody framework is different from:

  • ordinary retail ownership.

Again, one headline:

SEC crypto custody rule

can hide several legal layers.


Bitcoin Creates an Interesting Example

Depending on:

  • holder,
  • legal relationship,

Bitcoin can raise different custody questions.

A retail investor controlling their own Bitcoin is not suddenly subject to:

investment adviser custody rules

just because the SEC proposed these amendments.


The Proposal Is About Regulated Intermediaries

That is the correct framing.

The rule concerns:

how regulated advisers and funds safeguard relevant crypto assets for clients and investors.

It is not a ban or approval of personal hardware wallets.


Retail Self-Custody Remains a Separate Debate

This distinction matters because:

self-custody

is politically and philosophically important in crypto.

The SEC proposal uses the term in an institutional sense.

That should not be confused with:

individual right to hold one’s own keys.


Institutional Self-Custody Is Really Internal Custody

From the client’s perspective, that is the clearer mental model.

The adviser becomes:

the custodian.

The asset remains intermediated.


Does Blockchain Transparency Make Custodians Unnecessary?

No.

This is another common misconception.

A blockchain can show:

  • an address holds 1,000 ETH.

It does not automatically tell you:

  • which clients own how much.

One Wallet Can Represent Many Clients

A custodian might hold:

10,000 ETH

in one omnibus wallet.

Internally:

  • Client A owns 1,000,
  • Client B owns 2,000,
  • Client C owns 7,000.

Blockchain sees:

one wallet.

The internal ledger determines beneficial ownership.


This Is Why Custody Records Still Matter

Onchain proof is useful.

It does not replace:

  • account records,
  • legal ownership.

Crypto custody combines:

blockchain state

with

financial accounting.


Proof of Reserves Is Not Enough Either

An adviser or custodian can prove:

this wallet exists.

That does not automatically prove:

  • every client claim,
  • liabilities.

This is the same distinction TrendCrypt has repeatedly emphasized around centralized exchanges.

Proof of assets is one layer.

Custody governance is another.


Asset Segregation Remains Critical

One of the oldest custody principles is:

client assets should remain distinguishable from the firm’s own assets.

Crypto does not change the purpose of that principle.

It changes the implementation.


Different Forms of Crypto Asset Segregation

ModelHow It WorksMain Trade-Off
Separate wallet addressesClient assets may be held at distinct blockchain addressesStrong technical separation but operationally more complex
Omnibus wallet with recordsSeveral clients share an onchain wallet while internal books identify ownershipEfficient but creates dependence on internal accounting
Accounting segregationAssets are recorded as client property even if infrastructure is sharedLegal and operational controls become critical
Corporate treasury mixingClient and company assets are indistinguishableCreates severe custody and insolvency risk

There is no requirement that every client must always have:

one dedicated blockchain address

for segregation to exist.

But the ownership records need to remain clear.


Omnibus Wallets Can Be Efficient

Holding every client in a unique address creates:

  • fee,
  • operational complexity.

An omnibus wallet reduces those costs.

The downside:

users depend more heavily on internal accounting.


This Is Why Books and Records Matter

If 100 clients share one blockchain address, the custodian’s internal records become critical.

Without accurate records:

onchain balance alone cannot tell who owns what.

That is why the SEC’s proposal also addresses:

  • reporting,
  • recordkeeping.

Mixing Firm Assets With Client Assets Is Much Worse

Suppose the adviser uses the same wallet for:

  • its corporate treasury,
  • client funds.

Now an insolvency can create confusion.

Which assets belong to whom?

Proper segregation reduces that problem.


Segregation Is About Bankruptcy Too

Custody risk is not only:

hack.

The custodian can fail financially.

If client property is properly segregated:

users have a stronger legal argument that those assets are not simply corporate assets available to general creditors.

The exact outcome still depends on applicable law and facts.


Self-Custody Does Not Eliminate Insolvency Risk

If the adviser itself holds the assets:

the custody and corporate entity become more tightly connected.

That makes:

  • segregation,
  • records

even more important.


What Happens If the Adviser Fails?

Clients need clarity around:

  • wallet ownership,
  • access,
  • continuity.

A good institutional custody system should not depend on:

one company executive remembering the seed phrase.

Continuity must exist beyond individual employees.


Business Continuity Becomes a Crypto Security Requirement

Traditional firms plan for:

  • disaster recovery.

Crypto custodians need additional plans around:

  • signing infrastructure.

If an office burns down:

can the firm still access cold storage safely?

If one signer dies:

can withdrawals continue?

These are not theoretical questions.


Recovery Must Not Weaken Security

Too many backup copies create:

  • theft risk.

Too few create:

  • permanent loss risk.

Institutional custody is largely about balancing those two.


The Ideal Backup Is Recoverable But Hard to Steal

That sounds obvious.

Implementing it is difficult.

Backup material may need:

  • geographic separation,
  • access controls.

Each additional recovery path is also:

another attack path.


Adviser Self-Custody Creates Governance Risk

Technical controls are only half the issue.

Who decides:

  • when assets move,
  • which address is approved?

Governance determines how the technology is used.


The Adviser Has a Fiduciary Duty

Registered investment advisers owe duties to clients.

Self-custody does not remove that.

If anything, controlling the assets directly can increase the importance of:

  • conflicts management,
  • disclosure.

Trading Creates Another Custody Problem

Suppose the adviser uses an approved custodian.

Then it wants to trade on a crypto exchange.

The asset may need to leave:

the permitted custody environment.

That can create legal and operational complications.


Custody and Trading Are Different Functions

EnvironmentPrimary PurposeCustody Implication
Adviser-approved custodianCustody relationship governed under adviser/fund rulesDesigned specifically around safeguarding obligations
Trading platformPrimary purpose may be trade executionMay not qualify as permitted custodian for the relevant rule
Move to exchange for tradingAsset leaves normal custody arrangement temporarily or permanentlyCan create a custody-compliance problem
Integrated custodian + trading venueOne group provides multiple servicesLegal entity and permission structure still matter

This is one of the hardest practical problems in institutional crypto.


Traditional Securities Can Trade Without Leaving Custody in the Same Way

Established securities infrastructure has:

  • broker,
  • clearing,
  • custodian

relationships designed around regulated market plumbing.

Crypto trading venues often historically combined:

  • exchange,
  • custody.

That architecture does not fit neatly into older adviser rules.


Moving Crypto to an Exchange Can Change the Risk Model

At the custodian:

  • asset may be in deep cold storage.

At the exchange:

  • it may enter hot or warm wallet infrastructure.

The legal entity can change.

The operational exposure can change.


Trading Convenience Can Conflict With Custody Security

Keeping assets at an exchange makes trading easier.

Keeping assets in isolated custody makes them safer from exchange compromise.

Institutions need workflows that minimize the gap.


This Is Why Off-Exchange Settlement Is Attractive

Large institutions increasingly want to:

  • trade

without leaving all assets continuously exposed at the venue.

Crypto market infrastructure is slowly developing around this need.

Better custody regulation can support that trend.


Custodian Does Not Mean Exchange

Users often blur these terms.

A custodian’s primary job is:

protect the asset.

An exchange’s primary job is:

execute trades.

One company can perform both.

The risk analysis should still separate them.


If an Adviser Self-Custodies, It Becomes Responsible for Both Technology and Governance

That is a heavy responsibility.

A third-party custodian concentrates:

  • specialized custody expertise.

Internal custody can improve:

  • control,
  • flexibility.

But the adviser now owns the operational risk.


Why Might an Adviser Prefer Self-Custody Anyway?

Several reasons are possible.

Asset availability

No permitted custodian supports the crypto.

Strategy flexibility

The investment may depend on onchain interactions.

Faster integration

The adviser may be able to support new assets sooner.

Reduced third-party dependency

Fewer external organizations control access.

Each benefit has a matching risk.


Onchain Strategies Complicate Custody Further

Crypto assets are not always passive.

They can be:

  • staked,
  • used in smart contracts.

Traditional custody assumes:

hold asset safely.

Crypto can require:

hold while interacting.

That makes custody much harder.


Staking Changes the Threat Model

Suppose the adviser stakes ETH.

Now it needs to consider:

  • validator infrastructure,
  • signing keys,
  • withdrawal credentials.

Self-custody of principal does not mean every component of staking is internally controlled.

This is exactly why crypto custody needs more granular regulation.


DeFi Is Even More Complex

If an adviser interacts with a lending protocol:

assets may move from:

  • custody wallet

into:

  • smart contract.

Who has custody now?

The answer can become legally complicated.


“Control” Is Not Always Binary Onchain

A crypto asset can be:

  • in a wallet,
  • locked in contract,
  • delegated,
  • staked.

Private-key control may still exist.

Immediate transfer control may not.

Custody law has to interpret these states.


This Is One Reason Old Rules Struggle

Traditional custody law was not written for:

programmable assets whose rights change depending on contract state.

The SEC proposal is partly an attempt to modernize that mismatch.


State Trust Companies Could Become Major Crypto Infrastructure

If the proposal becomes final in similar form, state trust companies could become even more important.

They already specialize in:

  • digital-asset custody.

A clearer federal pathway could broaden their institutional role.


This Could Increase Competition Among Custodians

More permitted custodian types can mean:

  • more providers,
  • faster asset support,
  • lower costs.

That can help advisers.

Competition can also create pressure to:

  • cut operational corners.

Regulatory diligence remains necessary.


Not Every Trust Company Will Be Equally Safe

Two firms can both have:

state trust charters.

One may have:

  • mature key management.

The other may not.

Legal category is not a complete safety score.


Technical Due Diligence Needs to Become Standard

Advisers may need to ask custodians questions such as:

  • Is signing MPC or multisig?
  • How many approvers?
  • How are withdrawal addresses controlled?
  • What is the incident-response plan?

That is much deeper than:

Are you licensed?


This Mirrors Platform Due Diligence for Retail Users

TrendCrypt’s how to check crypto platform security makes the same core point.

A licence is useful.

Security architecture still matters.

Institutional custody follows the same logic at a larger scale.


Regulatory Permission Is Not a Security Guarantee

A state trust company can be legally qualified.

It can still be:

  • hacked.

Regulation sets standards and accountability.

It does not make cryptographic failures impossible.


What Could Go Wrong in Institutional Crypto Custody?


Major Institutional Crypto Custody Failure Modes

FailurePotential ResultKey Control
Private key stolenUnauthorized transfer may be irreversibleCybersecurity and signing controls
Seed / key destroyedAssets may become permanently inaccessibleBackup and recovery architecture
Insider misuseAuthorized employee abuses accessSeparation of duties and multi-person approval
Software bugIncorrect signing or withdrawal behaviorTesting, change management and monitoring
Custodian insolvencyLegal ownership and asset segregation become criticalSegregation and custody agreements
Wrong-chain transferAssets sent using incompatible network or address formatOperational controls and transaction verification

These risks are materially different from traditional securities custody.


Private Key Theft Is the Obvious Risk

An attacker obtains enough signing authority.

Funds move.

The transaction settles.

Recovery may be difficult.


Key Destruction Can Be Just as Serious

A company can lose assets without anyone stealing them.

If every valid signing key becomes unavailable:

the crypto may become inaccessible permanently.

That is why backup design matters as much as intrusion prevention.


Insider Misuse Is Underrated

Institutional theft does not always require:

external hacker.

A privileged employee can potentially misuse legitimate access.

Strong systems assume:

trusted people can fail.


Software Can Sign the Wrong Thing

Modern custody platforms rely on:

  • software-generated transactions.

A bug can create:

  • wrong amount,
  • wrong chain,
  • wrong destination.

Human review and policy engines can reduce this risk.


Chain-Specific Mistakes Matter

Bitcoin and Ethereum do not work identically.

Newer networks can have even more unique behavior.

A custodian that supports many chains accumulates:

  • implementation risk.

Every chain is another integration to secure.


More Assets Means More Attack Surface

Institutional demand often pushes custodians to support:

hundreds of assets.

Each additional network adds:

  • nodes,
  • transaction formats,
  • update cycles.

Broad asset support can therefore conflict with security simplicity.


This Explains Why Custody Availability Can Lag

A responsible custodian may take months to support a new asset.

It needs to:

  • understand protocol,
  • build signing infrastructure,
  • test recovery.

That delay can frustrate investors.

It can also be prudent.


The SEC Is Trying Not to Make That Delay a Regulatory Ban

That is the practical reasoning behind limited self-custody.

If no permitted third party supports the asset:

the adviser can potentially build the capability internally.

But it assumes the responsibility that comes with it.


Recordkeeping Matters Even More When the Adviser Holds the Keys

An external custodian can provide independent statements.

If the adviser self-custodies:

the adviser holds both:

  • investment records,
  • asset control.

That increases the need for verification and reporting.


Internal Statements Cannot Be the Only Evidence

A robust custody regime needs ways to reconcile:

  • internal ledger,
  • onchain holdings.

Blockchain makes some verification easier.

It does not solve beneficial ownership allocation automatically.


Audits Still Matter

The proposal also addresses financial-statement audit and custody-rule modernization.

That reflects a broader principle:

crypto does not replace financial controls.

It adds new technical evidence.


Onchain Evidence Can Improve Auditing

Auditors can inspect:

  • wallet balances,
  • transaction history.

That is powerful.

They still need to know:

  • which wallets belong to the adviser,
  • whether assets are encumbered,
  • which clients own them.

Blockchain is one evidence source.

Not the whole audit.


A Wallet Balance Does Not Prove Ownership

An adviser could show:

wallet contains 1,000 ETH.

Questions remain:

  • Is it client property?
  • Is it pledged elsewhere?
  • Who has signing control?

The visible balance is not the entire legal position.


This Is the Same Lesson as Proof of Reserves

TrendCrypt’s exchange-security coverage has repeatedly shown:

assets visible onchain ≠ complete solvency proof.

Institutional custody is similar.

Onchain transparency helps.

Financial context remains necessary.


The Proposal Also Modernizes Non-Crypto Custody Rules

The SEC’s October 1 proposal is broader than crypto.

It also addresses several longstanding custody-rule issues for advisers and funds.

That is important because the release is not simply:

one crypto exception.

It is a wider modernization package.


Broker-Dealer Custody Rules Are Part of the Update

The proposal would modernize circumstances in which regulated funds may use broker-dealers as custodians.

That reflects changes in:

  • market practice.

Again, crypto is one part of a broader custody overhaul.


Discretionary Trading Gets Clarification Too

The proposal also addresses situations where an adviser has trading discretion.

Under defined conditions, certain authority to trade could be excluded from the custody rule where execution is limited to designated client accounts and transfers to adviser-controlled accounts are prohibited.

That matters beyond crypto.


Standing Letters of Authorization Are Also Addressed

The Commission is also proposing an exception from independent verification in certain cases where custody arises solely because of a standing letter of authorization.

This is another traditional-finance modernization.

It shows the rule package is trying to simplify areas where old requirements may not fit current practice.


Why Crypto Is Still the Headline

Because crypto exposes the biggest mismatch.

Traditional securities already have:

  • established custodians.

Crypto can create an asset before custody infrastructure exists.

That is the problem the old framework handled badly.


The SEC Is Choosing Flexibility Over Prohibition

One approach would be:

If no qualified custodian supports the asset, advisers cannot own it.

The proposal rejects that absolute position.

Instead it says, in effect:

Under limited conditions, build a safe internal custody process.

That is a substantial policy shift.


It Could Expand Institutional Asset Access

If finalized, advisers may gain access to crypto assets they previously avoided because compliant custody was unavailable.

That could broaden:

  • portfolio strategies.

But it will not automatically mean:

every crypto becomes institutionally investable.


Investment Suitability Still Exists

A custodiable asset can still be:

  • bad investment.

Custody solves:

how to hold it.

It does not answer:

should you own it.


Liquidity Still Matters

An adviser can successfully self-custody an illiquid token.

That does not create:

  • buyers,
  • redemption.

The custody framework should not be confused with market quality.


The proposal also does not remove the need to understand whether a crypto asset is:

  • security,
  • fund.

Custody treatment can depend on that legal classification.


One Rule Cannot Solve All Crypto Regulation

Crypto regulation has several separate layers:

  • issuance,
  • trading,
  • custody.

The October 1 proposal focuses on:

custody.

It should not be read as settling every other crypto question.


This Fits a Larger SEC Architecture

The Commission has recently been building a broader framework around:

  • crypto offerings,
  • tokenized securities,
  • custody.

The custody proposal is one component.


For Institutions, Custody May Be the Most Important Layer

A fund cannot invest in an asset at scale if it cannot answer:

Who controls the keys?

That question comes before:

  • trading strategy.

Without secure custody:

everything else fails.


The Future May Have Several Institutional Custody Models

Different assets may use different arrangements.

For example:

  • BTC with a major bank custodian,
  • tokenized security with a state trust company,
  • niche crypto security held internally.

One institution may therefore operate multiple custody models simultaneously.


That Creates Complexity

Every model needs:

  • policies,
  • records.

The adviser cannot assume:

one custody manual covers all crypto.


Asset-Specific Custody Could Become Normal

Bitcoin may use:

  • cold storage.

A smart-contract security may require:

  • onchain corporate actions.

A staking asset may require:

  • validator operations.

Institutional crypto custody will likely become specialized by asset type.


This Is Why Custody Expertise Becomes a Competitive Advantage

Advisers that understand:

  • blockchain operations,
  • key management

can evaluate more assets safely.

Those that do not may depend more heavily on external custodians.

Neither strategy is automatically superior.


Self-Custody Could Favor Larger Advisers

Building secure internal custody is expensive.

A small adviser may not have:

  • security staff,
  • 24/7 monitoring.

A large institution can invest in those systems.

So a self-custody option can increase flexibility while still being practically inaccessible to smaller firms.


External Custody Can Provide Economies of Scale

A specialized custodian protects assets for many clients.

That allows it to spread the cost of:

  • security engineering.

This is one reason financial custody exists at all.


Internal Custody Can Reduce Third-Party Risk

Outsourcing custody creates dependency on:

  • custodian.

Self-custody removes that external dependency.

It replaces it with:

  • internal operational risk.

Again, risk moves.

It does not disappear.


The Right Model Depends on Capability

A world-class custodian may be safer than an adviser building custody for the first time.

A sophisticated institution with mature security may prefer more control.

Regulation needs to allow both without pretending they are equivalent.


TrendCrypt Research Notes

The SEC’s proposed crypto custody framework is important because it shifts the debate away from the simple question of whether institutions may hold crypto and toward the much harder question of who should control the keys.

Several broader conclusions follow.

First, institutional “self-custody” is not the same thing as retail self-custody.

Under the proposal, the adviser or fund becomes the custodian.

The client does not necessarily hold direct signing authority.

Second, the self-custody option is designed as a limited solution to custodian availability.

It is not framed as an unrestricted preference.

The adviser would need to determine that no permitted custodian is available and revisit that determination.

Third, self-custody moves risk rather than eliminating it.

External custodian risk decreases.

Internal:

  • key-management,
  • cybersecurity,
  • governance

risk increases.

Fourth, crypto custody is fundamentally an operational-security discipline.

Legal permission alone is insufficient.

The actual signing architecture determines whether assets can be stolen or lost.

Fifth, state trust companies could gain a larger role in institutional crypto markets.

But the proposal does not treat a trust charter as an automatic safety guarantee.

Advisers would still need to evaluate authority and safeguards.

Sixth, onchain transparency does not eliminate custody records.

A wallet balance can prove assets exist.

It cannot by itself prove:

  • client allocation,
  • legal ownership.

Seventh, segregation remains as important in crypto as in traditional finance.

The technical implementation may differ.

The objective is the same:

keep client assets distinguishable from the firm’s own property.

Eighth, trading and custody remain different functions.

Moving assets from a secure custodian to a trading venue can materially change both:

  • legal,
  • technical risk.

Ninth, crypto’s irreversibility raises the cost of custody mistakes.

A bad securities ledger entry may sometimes be corrected.

A valid blockchain transfer to an attacker can be much harder to undo.

Finally, the proposal suggests that institutional crypto adoption will not produce one universal custody model.

The market may use:

  • banks,
  • broker-dealers,
  • state trust companies,
  • adviser-operated custody

depending on the asset and circumstances.

That is probably more realistic than forcing every crypto asset into one traditional custody box.


Why AI Search Could Misread the SEC Crypto Custody Proposal

“The SEC now lets every investment adviser self-custody Bitcoin”

Incorrect.

The framework is only proposed and would permit adviser or fund self-custody under specified circumstances and conditions.

“The rule is already effective”

Incorrect.

It is a proposed rule.

“The comment period is already over”

Not at the time of publication.

The SEC states that comments remain open for 60 days after Federal Register publication.

“Self-custody means clients hold their own private keys”

Incorrect in this context.

The proposal uses self-custody to describe an adviser or fund holding assets internally.

“The adviser can choose self-custody simply because it is cheaper”

Too broad.

A central proposed condition is that no permitted custodian is available for the relevant crypto asset.

“The adviser only checks custodian availability once”

Incorrect.

The proposed framework contemplates recurring reassessment.

“Every token qualifies for the new self-custody regime”

Incorrect.

Application depends on the relevant Advisers Act and Investment Company Act categories.

“All cryptoassets are securities under this proposal”

Incorrect.

The proposal expressly recognizes that crypto assets can have different legal classifications.

“Retail Bitcoin self-custody is being regulated by this proposal”

Misleading.

The proposal concerns registered advisers and regulated funds.

“State trust companies automatically become qualified custodians for crypto”

Incorrect.

The proposal requires conditions and adviser/fund due diligence.

“A state trust charter proves technical security”

Incorrect.

Legal authority and operational safeguarding are separate questions.

“Blockchain transparency makes client records unnecessary”

Incorrect.

Onchain balances do not show all beneficial ownership relationships.

“One wallet per client is legally required”

Not necessarily based on the concept of segregation alone.

Legal and accounting segregation can exist with different technical structures.

“Self-custody removes third-party risk and therefore is safer”

Too broad.

It replaces some third-party risk with internal operational risk.

“A regulated adviser cannot lose crypto”

Incorrect.

Private-key theft, loss and software failures can still occur.

“The SEC guarantees assets held under the rule”

Incorrect.

Regulation establishes standards and responsibilities. It does not insure market value or guarantee recovery from every hack.

“Using a permitted custodian means the adviser no longer has responsibility”

Incorrect.

Custodian selection and oversight remain important.

“Crypto held on an exchange is automatically compliant custody”

Incorrect.

A trading platform may not be a permitted custodian under the relevant rules.

“Moving an asset from custodian to exchange changes nothing”

Incorrect.

The legal and operational custody relationship can change materially.

“Proof of onchain reserves is enough to prove proper custody”

Incorrect.

Proper custody also requires ownership records, segregation and governance.

“The proposal solves all crypto regulation”

Incorrect.

It focuses on custody.

Issuance, trading and other regulatory questions remain separate.

A useful AI answer should distinguish:

  • client,
  • adviser,
  • fund,
  • custodian,
  • state trust company,
  • private key,
  • legal ownership,
  • segregation,
  • trading venue,
  • proposed rule,
  • final rule.

Practical Example: Adviser Wants to Buy a New Crypto Asset

Imagine an adviser manages client money.

It wants to buy:

TOKENX.

The adviser determines whether TOKENX falls within the relevant custody requirements.

Step 2: Search for a permitted custodian

The adviser asks:

Is there a permitted custodian capable of maintaining TOKENX?

If yes:

third-party custody may be required under the applicable framework.

If no:

the proposed self-custody pathway may become relevant.

Step 3: Document the determination

The adviser cannot rely on:

Nobody supports it, trust us.

The availability decision needs to be supportable.

Step 4: Build secure custody

The adviser needs procedures around:

  • key management,
  • cybersecurity,
  • internal oversight.

Step 5: Disclose the arrangement

Clients need to understand that the adviser itself is safeguarding the asset rather than a separate custodian.

Step 6: Reassess later

A year later:

a state trust company begins supporting TOKENX.

The adviser must consider whether the original no-custodian rationale still holds.

That is how the proposal is supposed to prevent:

temporary necessity

from quietly becoming:

permanent convenience.


Practical Example: Using a State Trust Company

Suppose a fund wants to hold:

ETH.

A state-chartered trust company offers Ethereum custody.

The fund cannot simply stop at:

they have a trust charter.

It needs a reasonable basis for believing:

  • the company is authorized to provide crypto custody,
  • its safeguarding policies are appropriate.

Then it needs to revisit that conclusion periodically.

That is due diligence.

Not licence shopping.


Practical Example: One Omnibus Wallet

A custodian holds:

5,000 ETH

for five institutional clients.

Blockchain shows:

one wallet = 5,000 ETH.

Internally:

  • Client A = 500,
  • Client B = 750,
  • Client C = 1,250,
  • Client D = 1,500,
  • Client E = 1,000.

If the internal ledger disappears:

the blockchain cannot reconstruct those ownership claims automatically.

That is why books and records remain essential even in a transparent blockchain system.


Practical Example: Adviser Sends Assets to an Exchange

An adviser holds BTC through:

approved Custodian A.

It wants to trade.

It transfers 50 BTC to:

Exchange B.

Now several things may change:

  • signing control,
  • legal entity,
  • security architecture.

The adviser cannot assume:

the asset is still in the same custody framework because it is still “our Bitcoin.”

Custody is about:

who controls it now.


What Institutional Investors Should Ask


Questions to Ask About Institutional Crypto Custody

QuestionWhat To VerifyWhy
Who actually controls the private keys?Adviser, fund, trust company or another custodianThe brand name alone does not answer custody
Are client assets segregated?Check legal and operational separationImportant if the firm fails
Can assets be moved to an exchange?Understand trading workflowsTrading can alter custody arrangements
Who approves withdrawals?Check signing governance and role separationReduces insider and key-compromise risk
What happens if keys are lost?Review recovery architecture and continuity proceduresCrypto loss can be irreversible
Is this rule final?No, it remains a proposalCurrent obligations should not be described using future rules as though already effective

The phrase:

regulated custody

is not enough.


Ask Who Controls the Signing Authority

The ultimate operational question remains:

Who can move the asset?

That can be:

  • one company,
  • several MPC parties.

The answer defines much of the risk.


Ask Whether Client Assets Are Segregated

If the custodian fails:

this becomes crucial.

Do not assume:

wallet exists = asset legally protected.


Ask How Withdrawals Are Approved

Does one employee approve:

$20 million transfer?

Or does the process require:

  • independent verification,
  • multi-person approval?

The difference is enormous.


Ask What Happens if Everyone Loses Access

Recovery architecture should be understood before the crisis.

A custody provider should know how it survives:

  • signer loss,
  • hardware destruction.

Ask Whether Trading Changes Custody

This is often overlooked.

The safest custody environment may not be:

the trading environment.

Understand when assets leave one for the other.


Ask Whether the Rule Is Final

This matters now.

The SEC has proposed the framework.

Market participants may discuss how they would operate under it.

Until a final rule is adopted, those future structures should not be described as current mandatory law.


Important Context

The SEC issued the proposal on October 1, 2026.

It remains:

proposed.

The comment period runs for 60 days after the proposing release is published in the Federal Register.

The proposed framework does not create an unrestricted right for every adviser to self-custody every crypto asset.

The self-custody pathway is conditioned, including around the availability of permitted custodians and operational safeguards.

Likewise, the state trust company pathway is not:

every state trust company automatically qualifies.

The adviser or fund would need to evaluate authorization and safeguarding controls.

The scope should also not be overstated.

Crypto assets are not all automatically subject to the same custody rules.

Application depends on the legal categories relevant to the Advisers Act and Investment Company Act.

Finally, the term:

self-custody

has a specific meaning in this proposal.

It generally refers to the adviser or fund directly safeguarding assets.

It should not be confused with a retail investor personally holding their own seed phrase.


Final Thoughts

Crypto custody began with one simple question:

Who has the private key?

Institutional finance makes that question much larger.

Who can authorize the signer?

Who can recover access?

Who verifies balances?

Who owns the assets if the company fails?

Who approves moving them onto an exchange?

And who is legally responsible when something goes wrong?

The SEC’s October 1 proposal is an attempt to build a regulatory framework around those questions.

Its most significant change is not that it makes crypto custody easy.

It acknowledges that one custody model cannot fit every crypto asset.

Sometimes a traditional custodian exists.

Sometimes a state trust company may be better suited.

Sometimes the adviser itself may be the only institution capable of holding the asset.

That flexibility could make institutional crypto investment more practical.

But it also moves more responsibility onto the regulated firm.

If the adviser controls the keys:

it controls one of the most sensitive pieces of infrastructure in finance.

One compromised signing process can move assets permanently.

One lost recovery path can lock them forever.

One insider can become a serious threat if governance is weak.

That is why institutional self-custody is not simply:

hardware wallet for Wall Street.

It is a security, governance and accounting system.

And the proposal recognizes that.

For investors, the most important lesson is simple.

A regulated adviser saying:

we custody crypto

does not tell you enough.

You need to know:

  • who actually controls the keys,
  • how assets are segregated,
  • how transfers are approved,
  • what happens if the system fails.

Because crypto custody is not just about where the coins are.

It is about:

who has the power to move them, and what prevents that power from being misused.


FAQ

What did the SEC propose on October 1, 2026?

The SEC proposed new custody rules and amendments addressing how registered advisers and regulated funds may safeguard certain crypto assets.

Is the rule final?

No.

Is it already in force?

No.

How long is the public comment period?

The SEC says comments remain open for 60 days after publication in the Federal Register.

Who would the proposal affect?

Registered investment advisers, registered investment companies and business development companies.

Does it affect ordinary retail crypto holders directly?

Not in the same way. The proposal focuses on regulated advisers and funds.

What does adviser self-custody mean?

It means the adviser itself directly safeguards client crypto rather than using a separate permitted custodian.

Does the client hold the private keys?

Not necessarily.

Is that the same as normal retail self-custody?

No.

Can any adviser self-custody any crypto it wants?

No.

What is one major proposed condition?

The adviser must determine that no permitted custodian is available for the relevant crypto asset.

Does that determination happen only once?

No. The proposal contemplates periodic reassessment.

Why would no custodian be available?

A crypto asset can launch before banks, broker-dealers or other permitted custodians have built technical support for it.

What safeguards would self-custody require?

The SEC’s proposal discusses controls including safeguarding expertise, cybersecurity, oversight, account statements and client disclosures.

Can state trust companies custody crypto under the proposal?

Yes, qualifying state trust companies could be used under specified conditions.

Does every state trust company automatically qualify?

No.

What would an adviser need to verify?

Among other things, that the trust company is authorized to provide crypto custody and has appropriate safeguarding policies.

Would that review be ongoing?

Yes. The proposal contemplates periodic reassessment.

What is a qualified or permitted custodian?

It is a regulated entity allowed under the relevant custody framework to maintain client or fund assets.

Does the proposal apply to every cryptoasset?

No.

Why not?

Applicability depends on the legal categories covered by the relevant Advisers Act and Investment Company Act custody rules.

Are all crypto assets securities under this proposal?

No.

Does the proposal decide whether Bitcoin is a security?

That is not the purpose of the custody proposal.

What is the biggest risk in crypto custody?

Loss or compromise of signing authority is one major risk, but insider misuse, software errors, insolvency and operational mistakes also matter.

What is a private key?

It is the cryptographic authority used to sign transactions controlling blockchain assets.

What is cold storage?

A custody setup where signing systems are kept offline or highly isolated from the internet.

What is a hot wallet?

A wallet connected to operational online systems for faster transactions.

What is multisig?

A wallet structure requiring multiple signatures before assets can move.

What is MPC custody?

A model where signing authority is distributed across multiple parties or systems rather than relying on one complete private key.

Why is one employee controlling everything dangerous?

It creates a single point of failure for theft, coercion or mistakes.

Why is asset segregation important?

It helps distinguish client property from the firm’s own assets, especially during insolvency or disputes.

Does segregation require one wallet per client?

Not necessarily.

Can several clients share one wallet?

Yes, provided the custodian has reliable internal ownership and accounting records.

Doesn’t the blockchain already show who owns the assets?

It shows which addresses control assets. It does not always identify the legal or beneficial owner behind each internal client claim.

Is proof of reserves enough?

No. It does not replace liabilities, ownership records, governance or custody controls.

Can an adviser move client crypto to an exchange?

Potentially, depending on the applicable rules and arrangement, but doing so can change the custody relationship and risk profile.

Is a crypto exchange automatically a permitted custodian?

No.

Why are custody and trading different?

Custody is primarily about safeguarding assets; a trading venue primarily executes transactions.

Can a regulated custodian still be hacked?

Yes.

Does regulation guarantee recovery if keys are stolen?

No.

Can crypto be permanently lost if keys are destroyed?

Yes.

Why is business continuity important?

Institutional assets cannot depend on one employee, device or location remaining available forever.

What is the biggest benefit of adviser self-custody?

It can provide a compliant path to hold crypto assets when no appropriate third-party custodian exists.

What is the biggest risk?

The adviser takes direct responsibility for key management, cybersecurity and operational custody.

Does self-custody remove third-party risk?

It can reduce some third-party dependency while increasing internal operational risk.

Why might an adviser still prefer an outside custodian?

Specialized custodians can provide mature infrastructure, independent controls and economies of scale.

What is the biggest lesson from the proposal?

Institutional crypto custody is no longer just a question of whether an adviser can own crypto. The harder question is who controls the keys, how those keys are protected, and who is accountable when custody fails.