TrendCrypt News
The SEC Is Redrawing Who Can Hold Crypto for Investors
The SEC has proposed a new crypto custody framework that could let advisers hold certain client assets themselves and use state trust companies, reshaping who controls institutional crypto keys.

Institutional crypto custody used to sound simple.
There were two options:
leave the assets with a crypto custodian
or
do not invest.
The SEC is proposing a more complicated answer.
On October 1, the Commission published a new custody framework for registered investment advisers and regulated funds that would, under certain conditions, allow them to:
- maintain crypto with traditional permitted custodians,
- use qualifying state trust companies,
- in limited circumstances, hold certain crypto assets themselves.
That last option is the most important.
The proposal calls it:
self-custody.
But this is not the same self-custody a retail Bitcoin holder means when they move coins to a hardware wallet.
The client would not necessarily hold the key.
The adviser or fund would.
That means institutional crypto custody is starting to create a third model between:
customer holds the key
and
outside custodian holds the key.
The regulated financial firm itself may become the custodian.
The SEC’s proposal is designed partly around a real market problem:
for some crypto assets, a legally permitted third-party custodian may not exist yet.
A new token can become economically relevant before a bank, broker or approved custodian is technologically ready to support it.
Under the proposed framework, that gap would no longer automatically prevent an adviser or fund from holding the asset.
But the SEC is not proposing:
advisers can hold any crypto however they want.
The self-custody option would come with conditions.
Among them are expectations around:
- determining whether a permitted custodian is actually available,
- safeguarding expertise,
- cybersecurity,
- internal oversight,
- client reporting,
- disclosure.
The proposal also expands the possible third-party custody market by allowing qualifying:
state trust companies
to hold client and fund crypto assets under specified conditions.
That creates a much more important question than:
Which exchange holds the Bitcoin?
Institutional investors increasingly need to ask:
Who legally and technically controls the keys, under what rules, and what happens if that control fails?
That is where crypto custody regulation is moving next.
Key Takeaways
- The SEC proposed new crypto custody rules on October 1, 2026.
- The proposal affects:
- registered investment advisers,
- registered investment companies,
- business development companies.
- It is a proposed rule, not final law.
- Public comments remain open for 60 days after Federal Register publication.
- The proposal would create a more explicit custody framework for certain crypto assets.
- It would permit advisers and regulated funds to use traditional permitted custodians where available.
- It would also allow qualifying state trust companies to act as crypto custodians under specified conditions.
- Under limited circumstances, advisers or funds could also use what the proposal calls: self-custody.
- Adviser self-custody does not mean the client personally holds the private keys.
- It means the regulated adviser itself directly safeguards the client crypto.
- A major threshold condition is that the adviser determines no permitted custodian is available for the relevant asset.
- That determination would need to be revisited periodically.
- The proposed framework also contemplates:
- cybersecurity protections,
- safeguarding expertise,
- internal reporting,
- client account statements,
- disclosures.
- State trust companies would not automatically qualify simply because they exist.
- Advisers or funds would need a reasonable basis for believing the trust company:
- is authorized to provide crypto custody,
- maintains appropriate safeguarding policies.
- That due diligence would need to be revisited over time.
- The proposal would also modernize:
- recordkeeping,
- reporting,
- financial-statement audit requirements,
- certain broker-dealer custody rules.
- The proposal does not automatically apply to every token or coin.
- Applicability depends on whether the crypto asset falls within the relevant legal categories under:
- the Advisers Act,
- the Investment Company Act.
- Retail self-custody remains a separate concept.
- Blockchain transparency does not eliminate the need for:
- custody controls,
- ownership records,
- segregation,
- governance.
- Institutional custody risk increasingly includes:
- key compromise,
- insider misuse,
- software failure,
- custodian insolvency,
- operational mistakes.
- The larger trend is: crypto custody is becoming a regulated systems problem, not merely a private-key problem.
What Did the SEC Actually Propose?
The Commission proposed changes to custody rules under two major federal securities-law frameworks:
- the Investment Advisers Act of 1940,
- the Investment Company Act of 1940.
These rules govern how registered advisers and regulated investment funds safeguard assets.
The existing custody frameworks were written around traditional financial assets.
Think:
- securities accounts,
- banks,
- broker-dealers,
- paper certificates.
Crypto creates different mechanics.
Crypto Does Not Sit Neatly Inside Old Custody Rules
Traditional custody often assumes there is:
a recognized institution capable of holding the asset.
Crypto can develop faster than institutional custody infrastructure.
A new asset may:
- launch,
- trade,
- gain substantial value
before a permitted custodian supports it.
That creates a regulatory dead end.
The adviser may believe the asset belongs in a portfolio.
But no approved third party can hold it.
The SEC Is Trying to Close That Gap
The proposed framework gives advisers and funds more than one path.
Crypto Custody Options Under the Proposed Framework
| Model | Who Holds the Assets? | How It Works | Key Distinction |
|---|---|---|---|
| Traditional permitted custodian | Bank, broker-dealer or other permitted custodian under applicable rules | Custodian holds assets for the adviser or fund | Long-established financial custody model |
| State trust company | Qualifying state-chartered trust company | Can hold crypto under the proposed framework if conditions are met | Expands the pool of permitted crypto custodians |
| Adviser self-custody | Registered investment adviser itself | Adviser directly safeguards client crypto under limited circumstances | Only available subject to proposed conditions |
| Fund self-custody | Regulated fund / its controlled custody process | Fund maintains crypto through its own safeguarded infrastructure | Still subject to fund custody obligations |
| Retail self-custody | Individual investor | Investor controls their own private keys directly | Different concept from adviser “self-custody” |
This is more flexible than a system requiring every crypto asset to sit with the same type of outside custodian.
What Does “Self-Custody” Mean Here?
This phrase needs immediate clarification.
When a retail user says:
I self-custody Bitcoin.
They usually mean:
I personally control the private key.
That is not exactly what the SEC proposal means.
Adviser Self-Custody Means the Adviser Holds the Client Asset
Suppose:
- an investment adviser manages a client’s crypto portfolio.
Under adviser self-custody:
the adviser itself would maintain custody of the relevant crypto.
The client is still using an intermediary.
The intermediary simply happens to be the adviser rather than an external custodian.
That Is Why “Self-Custody” Can Be Misleading
From the client’s perspective:
someone else still controls the operational keys.
The client may have:
- beneficial ownership,
- account rights.
But they are not necessarily holding:
- seed phrase,
- signing authority.
This is institutional custody conducted internally.
Retail Self-Custody vs Adviser Self-Custody vs Third-Party Custody
| Question | Retail Self-Custody | Adviser Self-Custody | External Custodian |
|---|---|---|---|
| Who controls keys? | Individual investor | Adviser or fund infrastructure | Third-party custodian |
| Primary responsibility | Investor | Adviser / fund | Custodian with adviser oversight |
| Regulatory framework | Depends on investor and product | Adviser / fund custody rules | Custody agreement + regulatory requirements |
| Single-person risk | Can be high | Should be controlled through institutional procedures | Depends on custodian design |
| Recovery / continuity | Often limited to user`s backup | Institutional continuity processes expected | Custodian recovery procedures |
These arrangements can all be described using the word:
custody.
The risk models are very different.
Self-Custody Would Not Be the Default
The proposal does not simply say:
any adviser that prefers controlling keys internally can do so.
One central condition is whether an eligible outside custodian exists.
The adviser would need to determine that:
no permitted custodian is available to maintain the relevant crypto asset.
That changes the role of self-custody significantly.
It Is Designed as an Availability Solution
Imagine a new crypto security launches.
The adviser wants client exposure.
No permitted custodian supports it.
Under a strict outside-custodian-only regime:
the investment may be impossible.
Under the proposal:
self-custody could provide a compliant path.
Advisers Would Need to Revisit That Determination
A crypto asset may have no institutional custodian today.
Six months later:
several may support it.
The adviser should not be able to rely forever on:
none were available when we first bought it.
The proposal therefore contemplates recurring reassessment.
The Availability Test Matters More Than It First Appears
It prevents self-custody from becoming:
a cheaper way to avoid paying an external custodian.
The adviser cannot simply say:
We prefer holding the keys ourselves.
It needs to fit the proposed conditions.
Self-Custody Creates a Conflict
There is a reason custody functions are often separated from:
- portfolio management.
If the same organization:
- chooses investments,
- controls assets,
- maintains records,
more power sits in one place.
That creates possible conflict.
Separation of Functions Can Reduce Abuse
Traditional finance often splits:
- investment decisions,
- custody,
- accounting.
Why?
Because one organization cannot easily:
- move assets,
- alter records
without another institution seeing the discrepancy.
Crypto self-custody reduces some of that external separation.
The proposal therefore relies more heavily on internal controls.
What Would Advisers Need to Do?
The precise requirements are still proposed rather than final.
The SEC’s materials describe safeguards around several areas.
Key Conditions Around Proposed Adviser Self-Custody
| Condition | What It Means | Why It Matters |
|---|---|---|
| No permitted custodian available | Adviser must determine that no permitted custodian is available for the crypto asset | Prevents self-custody from becoming the automatic default |
| Periodic reassessment | Availability determination must be revisited regularly | Self-custody cannot continue indefinitely without review |
| Safeguarding expertise | Firm must have appropriate capability to protect the assets | Crypto custody requires specialized operational knowledge |
| Cybersecurity controls | Security protections must address theft, loss and misuse | Private-key compromise can cause irreversible loss |
| Internal oversight | Firm must maintain internal reporting and governance | Reduces dependence on one individual or one wallet operator |
| Account statements / client information | Clients must receive appropriate reporting | Custody should remain auditable and understandable |
| Disclosure | Clients must understand the custody arrangement and related risks | Self-custody changes the risk model materially |
This is much closer to institutional custody than:
buy hardware wallet and write seed on paper.
Safeguarding Expertise Matters
Running institutional crypto custody is technically difficult.
A firm needs to understand:
- signing,
- transaction construction,
- blockchain confirmation,
- network-specific behavior.
One bad operational decision can be irreversible.
Crypto Custody Is Not Generic IT
A company can have:
- strong cybersecurity team
and still lack crypto-custody expertise.
Crypto introduces unusual risks.
For example:
- signing the wrong transaction can permanently move assets.
There is no bank chargeback.
Key Management Is the Center of the System
The most basic crypto custody question remains:
Who can sign?
Everything else builds around that.
Different Ways Institutional Crypto Keys Can Be Controlled
| Model | Typical Controller | Signing Structure | Main Risk |
|---|---|---|---|
| Retail hardware wallet | Usually one individual or household | Seed phrase, device, passphrase | Personal loss or compromise |
| Institutional hot wallet | Company operational team | Online signing system | Fast access but high online exposure |
| Institutional cold storage | Custody or treasury team | Offline / isolated signing procedures | Lower online exposure, slower operations |
| Multi-party signing | Several approved operators or systems | Multiple approvals required | Reduces single-person compromise risk |
| MPC custody | Distributed signing participants | Signing authority split across systems | No single complete private key needs to exist in one place |
Institutional systems usually try to avoid one person having unrestricted control.
A Seed Phrase in a Safe Is Not Enough
That may be acceptable for:
personal Bitcoin.
For a billion-dollar fund:
it creates obvious problems.
What if the person who knows the seed:
- dies,
- steals it,
- loses it?
Institutional custody needs:
- continuity,
- role separation.
Multi-Signature Can Reduce Single-Person Risk
A wallet might require:
3 of 5 approvals.
That means one stolen key cannot move assets.
It also creates operational complexity.
Who holds the keys?
How are they replaced?
What happens if several signers are unavailable?
MPC Is Another Institutional Approach
Multi-party computation can distribute signing authority across several systems.
No one machine necessarily holds the complete private key in ordinary operation.
This can reduce:
- single-key compromise risk.
It does not eliminate:
- governance,
- software risk.
Cold Storage Reduces Online Exposure
Long-term assets can be held through:
- offline,
- highly isolated
signing systems.
That makes remote theft harder.
The trade-off:
slower access.
Hot Wallets Still Have a Role
Some assets need to move quickly.
An adviser executing active strategies may not be able to keep everything:
deep offline.
That creates the familiar security trade-off:
accessibility vs exposure.
Institutional Self-Custody Requires Wallet Architecture, Not One Wallet
A serious custody program may separate:
- long-term holdings,
- operational liquidity,
- testing wallets,
- fee wallets.
The word:
wallet
can hide an entire internal treasury architecture.
Withdrawal Governance Becomes Critical
A safe custody system should answer:
- who requests transfer?
- who approves?
- who signs?
- who verifies destination?
The same person should not necessarily perform every step.
Separation of Duties Reduces Insider Risk
Imagine one portfolio manager can:
- add withdrawal address,
- approve it,
- sign transaction.
That creates enormous insider risk.
Institutional custody should make fraudulent transfers difficult even for insiders.
Crypto Custody Is About Insider Threats Too
Hackers get most headlines.
Financial institutions also worry about:
- employees,
- contractors,
- compromised administrators.
Strong custody architecture assumes some trusted person may eventually become:
- malicious,
- compromised.
What Happens If an Adviser Gets Hacked?
This becomes one of the hardest questions.
If the adviser self-custodies and attackers steal client crypto:
the blockchain may not reverse the theft.
Regulation can establish:
- responsibility,
- controls.
It cannot recover every transaction.
This Is Different From Traditional Asset Custody
Suppose a database says:
client owns 1,000 shares.
A fraudulent internal transfer may sometimes be corrected through:
- intermediaries,
- legal ownership records.
Bitcoin is different.
If private keys authorize:
send 10 BTC to attacker,
the network may consider the transfer valid.
Legal ownership and blockchain control can diverge.
That Makes Prevention More Important
Traditional financial systems can sometimes rely more on:
- correction.
Crypto needs stronger:
- prevention.
Once the transaction settles:
recovery may depend on:
- tracing,
- freezing at centralized services,
- attacker cooperation.
Client Disclosure Matters Because the Risk Is Different
If an adviser uses self-custody, clients should understand that custody architecture creates its own risk.
They may be exposed to:
- internal systems,
- signing procedures.
An outside custodian creates a different dependency.
Neither is automatically safer in all circumstances.
The Adviser Cannot Outsource Responsibility Mentally
Suppose an adviser chooses a third-party custodian.
That does not mean:
custody risk is now someone else’s problem.
The adviser still needs to select and monitor the custodian appropriately.
The state-trust-company proposal reinforces that.
State Trust Companies Get a Larger Role
The SEC proposal would expressly permit qualifying state trust companies to serve as crypto custodians under specified circumstances.
This matters because state trust companies have become important in digital-asset custody.
They can specialize in:
- key management,
- settlement.
A Trust Charter Alone Would Not Be Enough
The adviser or fund would need a reasonable basis for believing the trust company:
- is authorized by the relevant state banking authority to provide crypto custody,
- has appropriate safeguarding policies.
What Advisers Would Need to Check Before Using a State Trust Company
| Check | What It Means | Why |
|---|---|---|
| Authorization | State authority permits crypto custody | Firm must confirm the trust company actually has authority |
| Safeguarding policies | Written procedures address theft, loss, misuse and misappropriation | Licence alone is not enough |
| Initial due diligence | Adviser or fund assesses the trust company before use | Responsibility does not disappear when custody is outsourced |
| Annual review | Custodian suitability is revisited | Controls must remain adequate over time |
| Operational capability | Custodian must actually be able to secure the crypto asset | Legal status is not a substitute for technical competence |
That means the regulatory logic is not:
trust company = automatically safe.
It is:
trust company can be used if it actually meets the conditions.
Annual Review Matters
A custodian can be strong today.
Later:
- controls weaken,
- ownership changes.
One-time diligence is not enough.
Ongoing review is especially important in a fast-moving crypto market.
Technical Capability Matters as Much as Legal Authority
A trust company may legally be permitted to custody crypto.
Can it safely custody:
this specific asset?
Different chains use different:
- signing systems,
- network behavior.
Legal permission does not equal technical competence.
Supporting Bitcoin Is Not the Same as Supporting Every Token
A custodian may be excellent at:
- BTC.
That does not mean it automatically understands:
- a new smart-contract asset.
Every additional network can add:
- code,
- operational procedures.
Custody coverage is asset-specific.
This Is Exactly Why the SEC Is Considering Self-Custody
The crypto market can produce new assets faster than custodians can integrate them.
The proposal acknowledges that mismatch.
Institutional demand does not always wait for custody infrastructure to catch up.
But That Creates a Hard Policy Trade-Off
Option one:
prohibit holding any asset without an external custodian.
Result:
some investment strategies become impossible.
Option two:
allow internal custody.
Result:
more operational risk moves into the adviser.
The proposal attempts to allow the second while adding guardrails.
Which Crypto Assets Does This Actually Cover?
This is another area where headlines can go wrong.
The SEC is not proposing one universal federal custody rule for:
every cryptoasset held by everyone.
The proposal applies through specific securities-law custody rules.
The Proposal Does Not Cover Every Crypto Asset Automatically
| Asset / Holder | Potential Treatment | Important Point |
|---|---|---|
| Adviser client crypto that is a fund or security | Potentially within the Advisers Act custody framework | Depends on legal classification |
| Regulated fund crypto security | Potentially within Investment Company Act custody rules | Fund-specific custody rules apply |
| Crypto asset that is not legally within the covered categories | May fall outside these specific proposed custody requirements | Proposal is not a universal rule for all crypto |
| Retail investor holding own BTC | Outside the adviser/fund self-custody concept | Personal self-custody remains a separate issue |
Legal classification matters.
Adviser Act Scope Is Not “All Crypto”
A crypto asset may or may not be:
- fund,
- security
for the relevant rule.
If it is outside those categories:
this particular custody framework may not apply in the same way.
Regulated Funds Have Their Own Scope
Registered investment companies and BDCs operate under the Investment Company Act.
Their asset-custody framework is different from:
- ordinary retail ownership.
Again, one headline:
SEC crypto custody rule
can hide several legal layers.
Bitcoin Creates an Interesting Example
Depending on:
- holder,
- legal relationship,
Bitcoin can raise different custody questions.
A retail investor controlling their own Bitcoin is not suddenly subject to:
investment adviser custody rules
just because the SEC proposed these amendments.
The Proposal Is About Regulated Intermediaries
That is the correct framing.
The rule concerns:
how regulated advisers and funds safeguard relevant crypto assets for clients and investors.
It is not a ban or approval of personal hardware wallets.
Retail Self-Custody Remains a Separate Debate
This distinction matters because:
self-custody
is politically and philosophically important in crypto.
The SEC proposal uses the term in an institutional sense.
That should not be confused with:
individual right to hold one’s own keys.
Institutional Self-Custody Is Really Internal Custody
From the client’s perspective, that is the clearer mental model.
The adviser becomes:
the custodian.
The asset remains intermediated.
Does Blockchain Transparency Make Custodians Unnecessary?
No.
This is another common misconception.
A blockchain can show:
- an address holds 1,000 ETH.
It does not automatically tell you:
- which clients own how much.
One Wallet Can Represent Many Clients
A custodian might hold:
10,000 ETH
in one omnibus wallet.
Internally:
- Client A owns 1,000,
- Client B owns 2,000,
- Client C owns 7,000.
Blockchain sees:
one wallet.
The internal ledger determines beneficial ownership.
This Is Why Custody Records Still Matter
Onchain proof is useful.
It does not replace:
- account records,
- legal ownership.
Crypto custody combines:
blockchain state
with
financial accounting.
Proof of Reserves Is Not Enough Either
An adviser or custodian can prove:
this wallet exists.
That does not automatically prove:
- every client claim,
- liabilities.
This is the same distinction TrendCrypt has repeatedly emphasized around centralized exchanges.
Proof of assets is one layer.
Custody governance is another.
Asset Segregation Remains Critical
One of the oldest custody principles is:
client assets should remain distinguishable from the firm’s own assets.
Crypto does not change the purpose of that principle.
It changes the implementation.
Different Forms of Crypto Asset Segregation
| Model | How It Works | Main Trade-Off |
|---|---|---|
| Separate wallet addresses | Client assets may be held at distinct blockchain addresses | Strong technical separation but operationally more complex |
| Omnibus wallet with records | Several clients share an onchain wallet while internal books identify ownership | Efficient but creates dependence on internal accounting |
| Accounting segregation | Assets are recorded as client property even if infrastructure is shared | Legal and operational controls become critical |
| Corporate treasury mixing | Client and company assets are indistinguishable | Creates severe custody and insolvency risk |
There is no requirement that every client must always have:
one dedicated blockchain address
for segregation to exist.
But the ownership records need to remain clear.
Omnibus Wallets Can Be Efficient
Holding every client in a unique address creates:
- fee,
- operational complexity.
An omnibus wallet reduces those costs.
The downside:
users depend more heavily on internal accounting.
This Is Why Books and Records Matter
If 100 clients share one blockchain address, the custodian’s internal records become critical.
Without accurate records:
onchain balance alone cannot tell who owns what.
That is why the SEC’s proposal also addresses:
- reporting,
- recordkeeping.
Mixing Firm Assets With Client Assets Is Much Worse
Suppose the adviser uses the same wallet for:
- its corporate treasury,
- client funds.
Now an insolvency can create confusion.
Which assets belong to whom?
Proper segregation reduces that problem.
Segregation Is About Bankruptcy Too
Custody risk is not only:
hack.
The custodian can fail financially.
If client property is properly segregated:
users have a stronger legal argument that those assets are not simply corporate assets available to general creditors.
The exact outcome still depends on applicable law and facts.
Self-Custody Does Not Eliminate Insolvency Risk
If the adviser itself holds the assets:
the custody and corporate entity become more tightly connected.
That makes:
- segregation,
- records
even more important.
What Happens If the Adviser Fails?
Clients need clarity around:
- wallet ownership,
- access,
- continuity.
A good institutional custody system should not depend on:
one company executive remembering the seed phrase.
Continuity must exist beyond individual employees.
Business Continuity Becomes a Crypto Security Requirement
Traditional firms plan for:
- disaster recovery.
Crypto custodians need additional plans around:
- signing infrastructure.
If an office burns down:
can the firm still access cold storage safely?
If one signer dies:
can withdrawals continue?
These are not theoretical questions.
Recovery Must Not Weaken Security
Too many backup copies create:
- theft risk.
Too few create:
- permanent loss risk.
Institutional custody is largely about balancing those two.
The Ideal Backup Is Recoverable But Hard to Steal
That sounds obvious.
Implementing it is difficult.
Backup material may need:
- geographic separation,
- access controls.
Each additional recovery path is also:
another attack path.
Adviser Self-Custody Creates Governance Risk
Technical controls are only half the issue.
Who decides:
- when assets move,
- which address is approved?
Governance determines how the technology is used.
The Adviser Has a Fiduciary Duty
Registered investment advisers owe duties to clients.
Self-custody does not remove that.
If anything, controlling the assets directly can increase the importance of:
- conflicts management,
- disclosure.
Trading Creates Another Custody Problem
Suppose the adviser uses an approved custodian.
Then it wants to trade on a crypto exchange.
The asset may need to leave:
the permitted custody environment.
That can create legal and operational complications.
Custody and Trading Are Different Functions
| Environment | Primary Purpose | Custody Implication |
|---|---|---|
| Adviser-approved custodian | Custody relationship governed under adviser/fund rules | Designed specifically around safeguarding obligations |
| Trading platform | Primary purpose may be trade execution | May not qualify as permitted custodian for the relevant rule |
| Move to exchange for trading | Asset leaves normal custody arrangement temporarily or permanently | Can create a custody-compliance problem |
| Integrated custodian + trading venue | One group provides multiple services | Legal entity and permission structure still matter |
This is one of the hardest practical problems in institutional crypto.
Traditional Securities Can Trade Without Leaving Custody in the Same Way
Established securities infrastructure has:
- broker,
- clearing,
- custodian
relationships designed around regulated market plumbing.
Crypto trading venues often historically combined:
- exchange,
- custody.
That architecture does not fit neatly into older adviser rules.
Moving Crypto to an Exchange Can Change the Risk Model
At the custodian:
- asset may be in deep cold storage.
At the exchange:
- it may enter hot or warm wallet infrastructure.
The legal entity can change.
The operational exposure can change.
Trading Convenience Can Conflict With Custody Security
Keeping assets at an exchange makes trading easier.
Keeping assets in isolated custody makes them safer from exchange compromise.
Institutions need workflows that minimize the gap.
This Is Why Off-Exchange Settlement Is Attractive
Large institutions increasingly want to:
- trade
without leaving all assets continuously exposed at the venue.
Crypto market infrastructure is slowly developing around this need.
Better custody regulation can support that trend.
Custodian Does Not Mean Exchange
Users often blur these terms.
A custodian’s primary job is:
protect the asset.
An exchange’s primary job is:
execute trades.
One company can perform both.
The risk analysis should still separate them.
If an Adviser Self-Custodies, It Becomes Responsible for Both Technology and Governance
That is a heavy responsibility.
A third-party custodian concentrates:
- specialized custody expertise.
Internal custody can improve:
- control,
- flexibility.
But the adviser now owns the operational risk.
Why Might an Adviser Prefer Self-Custody Anyway?
Several reasons are possible.
Asset availability
No permitted custodian supports the crypto.
Strategy flexibility
The investment may depend on onchain interactions.
Faster integration
The adviser may be able to support new assets sooner.
Reduced third-party dependency
Fewer external organizations control access.
Each benefit has a matching risk.
Onchain Strategies Complicate Custody Further
Crypto assets are not always passive.
They can be:
- staked,
- used in smart contracts.
Traditional custody assumes:
hold asset safely.
Crypto can require:
hold while interacting.
That makes custody much harder.
Staking Changes the Threat Model
Suppose the adviser stakes ETH.
Now it needs to consider:
- validator infrastructure,
- signing keys,
- withdrawal credentials.
Self-custody of principal does not mean every component of staking is internally controlled.
This is exactly why crypto custody needs more granular regulation.
DeFi Is Even More Complex
If an adviser interacts with a lending protocol:
assets may move from:
- custody wallet
into:
- smart contract.
Who has custody now?
The answer can become legally complicated.
“Control” Is Not Always Binary Onchain
A crypto asset can be:
- in a wallet,
- locked in contract,
- delegated,
- staked.
Private-key control may still exist.
Immediate transfer control may not.
Custody law has to interpret these states.
This Is One Reason Old Rules Struggle
Traditional custody law was not written for:
programmable assets whose rights change depending on contract state.
The SEC proposal is partly an attempt to modernize that mismatch.
State Trust Companies Could Become Major Crypto Infrastructure
If the proposal becomes final in similar form, state trust companies could become even more important.
They already specialize in:
- digital-asset custody.
A clearer federal pathway could broaden their institutional role.
This Could Increase Competition Among Custodians
More permitted custodian types can mean:
- more providers,
- faster asset support,
- lower costs.
That can help advisers.
Competition can also create pressure to:
- cut operational corners.
Regulatory diligence remains necessary.
Not Every Trust Company Will Be Equally Safe
Two firms can both have:
state trust charters.
One may have:
- mature key management.
The other may not.
Legal category is not a complete safety score.
Technical Due Diligence Needs to Become Standard
Advisers may need to ask custodians questions such as:
- Is signing MPC or multisig?
- How many approvers?
- How are withdrawal addresses controlled?
- What is the incident-response plan?
That is much deeper than:
Are you licensed?
This Mirrors Platform Due Diligence for Retail Users
TrendCrypt’s how to check crypto platform security makes the same core point.
A licence is useful.
Security architecture still matters.
Institutional custody follows the same logic at a larger scale.
Regulatory Permission Is Not a Security Guarantee
A state trust company can be legally qualified.
It can still be:
- hacked.
Regulation sets standards and accountability.
It does not make cryptographic failures impossible.
What Could Go Wrong in Institutional Crypto Custody?
Major Institutional Crypto Custody Failure Modes
| Failure | Potential Result | Key Control |
|---|---|---|
| Private key stolen | Unauthorized transfer may be irreversible | Cybersecurity and signing controls |
| Seed / key destroyed | Assets may become permanently inaccessible | Backup and recovery architecture |
| Insider misuse | Authorized employee abuses access | Separation of duties and multi-person approval |
| Software bug | Incorrect signing or withdrawal behavior | Testing, change management and monitoring |
| Custodian insolvency | Legal ownership and asset segregation become critical | Segregation and custody agreements |
| Wrong-chain transfer | Assets sent using incompatible network or address format | Operational controls and transaction verification |
These risks are materially different from traditional securities custody.
Private Key Theft Is the Obvious Risk
An attacker obtains enough signing authority.
Funds move.
The transaction settles.
Recovery may be difficult.
Key Destruction Can Be Just as Serious
A company can lose assets without anyone stealing them.
If every valid signing key becomes unavailable:
the crypto may become inaccessible permanently.
That is why backup design matters as much as intrusion prevention.
Insider Misuse Is Underrated
Institutional theft does not always require:
external hacker.
A privileged employee can potentially misuse legitimate access.
Strong systems assume:
trusted people can fail.
Software Can Sign the Wrong Thing
Modern custody platforms rely on:
- software-generated transactions.
A bug can create:
- wrong amount,
- wrong chain,
- wrong destination.
Human review and policy engines can reduce this risk.
Chain-Specific Mistakes Matter
Bitcoin and Ethereum do not work identically.
Newer networks can have even more unique behavior.
A custodian that supports many chains accumulates:
- implementation risk.
Every chain is another integration to secure.
More Assets Means More Attack Surface
Institutional demand often pushes custodians to support:
hundreds of assets.
Each additional network adds:
- nodes,
- transaction formats,
- update cycles.
Broad asset support can therefore conflict with security simplicity.
This Explains Why Custody Availability Can Lag
A responsible custodian may take months to support a new asset.
It needs to:
- understand protocol,
- build signing infrastructure,
- test recovery.
That delay can frustrate investors.
It can also be prudent.
The SEC Is Trying Not to Make That Delay a Regulatory Ban
That is the practical reasoning behind limited self-custody.
If no permitted third party supports the asset:
the adviser can potentially build the capability internally.
But it assumes the responsibility that comes with it.
Recordkeeping Matters Even More When the Adviser Holds the Keys
An external custodian can provide independent statements.
If the adviser self-custodies:
the adviser holds both:
- investment records,
- asset control.
That increases the need for verification and reporting.
Internal Statements Cannot Be the Only Evidence
A robust custody regime needs ways to reconcile:
- internal ledger,
- onchain holdings.
Blockchain makes some verification easier.
It does not solve beneficial ownership allocation automatically.
Audits Still Matter
The proposal also addresses financial-statement audit and custody-rule modernization.
That reflects a broader principle:
crypto does not replace financial controls.
It adds new technical evidence.
Onchain Evidence Can Improve Auditing
Auditors can inspect:
- wallet balances,
- transaction history.
That is powerful.
They still need to know:
- which wallets belong to the adviser,
- whether assets are encumbered,
- which clients own them.
Blockchain is one evidence source.
Not the whole audit.
A Wallet Balance Does Not Prove Ownership
An adviser could show:
wallet contains 1,000 ETH.
Questions remain:
- Is it client property?
- Is it pledged elsewhere?
- Who has signing control?
The visible balance is not the entire legal position.
This Is the Same Lesson as Proof of Reserves
TrendCrypt’s exchange-security coverage has repeatedly shown:
assets visible onchain ≠ complete solvency proof.
Institutional custody is similar.
Onchain transparency helps.
Financial context remains necessary.
The Proposal Also Modernizes Non-Crypto Custody Rules
The SEC’s October 1 proposal is broader than crypto.
It also addresses several longstanding custody-rule issues for advisers and funds.
That is important because the release is not simply:
one crypto exception.
It is a wider modernization package.
Broker-Dealer Custody Rules Are Part of the Update
The proposal would modernize circumstances in which regulated funds may use broker-dealers as custodians.
That reflects changes in:
- market practice.
Again, crypto is one part of a broader custody overhaul.
Discretionary Trading Gets Clarification Too
The proposal also addresses situations where an adviser has trading discretion.
Under defined conditions, certain authority to trade could be excluded from the custody rule where execution is limited to designated client accounts and transfers to adviser-controlled accounts are prohibited.
That matters beyond crypto.
Standing Letters of Authorization Are Also Addressed
The Commission is also proposing an exception from independent verification in certain cases where custody arises solely because of a standing letter of authorization.
This is another traditional-finance modernization.
It shows the rule package is trying to simplify areas where old requirements may not fit current practice.
Why Crypto Is Still the Headline
Because crypto exposes the biggest mismatch.
Traditional securities already have:
- established custodians.
Crypto can create an asset before custody infrastructure exists.
That is the problem the old framework handled badly.
The SEC Is Choosing Flexibility Over Prohibition
One approach would be:
If no qualified custodian supports the asset, advisers cannot own it.
The proposal rejects that absolute position.
Instead it says, in effect:
Under limited conditions, build a safe internal custody process.
That is a substantial policy shift.
It Could Expand Institutional Asset Access
If finalized, advisers may gain access to crypto assets they previously avoided because compliant custody was unavailable.
That could broaden:
- portfolio strategies.
But it will not automatically mean:
every crypto becomes institutionally investable.
Investment Suitability Still Exists
A custodiable asset can still be:
- bad investment.
Custody solves:
how to hold it.
It does not answer:
should you own it.
Liquidity Still Matters
An adviser can successfully self-custody an illiquid token.
That does not create:
- buyers,
- redemption.
The custody framework should not be confused with market quality.
Legal Classification Still Matters
The proposal also does not remove the need to understand whether a crypto asset is:
- security,
- fund.
Custody treatment can depend on that legal classification.
One Rule Cannot Solve All Crypto Regulation
Crypto regulation has several separate layers:
- issuance,
- trading,
- custody.
The October 1 proposal focuses on:
custody.
It should not be read as settling every other crypto question.
This Fits a Larger SEC Architecture
The Commission has recently been building a broader framework around:
- crypto offerings,
- tokenized securities,
- custody.
The custody proposal is one component.
For Institutions, Custody May Be the Most Important Layer
A fund cannot invest in an asset at scale if it cannot answer:
Who controls the keys?
That question comes before:
- trading strategy.
Without secure custody:
everything else fails.
The Future May Have Several Institutional Custody Models
Different assets may use different arrangements.
For example:
- BTC with a major bank custodian,
- tokenized security with a state trust company,
- niche crypto security held internally.
One institution may therefore operate multiple custody models simultaneously.
That Creates Complexity
Every model needs:
- policies,
- records.
The adviser cannot assume:
one custody manual covers all crypto.
Asset-Specific Custody Could Become Normal
Bitcoin may use:
- cold storage.
A smart-contract security may require:
- onchain corporate actions.
A staking asset may require:
- validator operations.
Institutional crypto custody will likely become specialized by asset type.
This Is Why Custody Expertise Becomes a Competitive Advantage
Advisers that understand:
- blockchain operations,
- key management
can evaluate more assets safely.
Those that do not may depend more heavily on external custodians.
Neither strategy is automatically superior.
Self-Custody Could Favor Larger Advisers
Building secure internal custody is expensive.
A small adviser may not have:
- security staff,
- 24/7 monitoring.
A large institution can invest in those systems.
So a self-custody option can increase flexibility while still being practically inaccessible to smaller firms.
External Custody Can Provide Economies of Scale
A specialized custodian protects assets for many clients.
That allows it to spread the cost of:
- security engineering.
This is one reason financial custody exists at all.
Internal Custody Can Reduce Third-Party Risk
Outsourcing custody creates dependency on:
- custodian.
Self-custody removes that external dependency.
It replaces it with:
- internal operational risk.
Again, risk moves.
It does not disappear.
The Right Model Depends on Capability
A world-class custodian may be safer than an adviser building custody for the first time.
A sophisticated institution with mature security may prefer more control.
Regulation needs to allow both without pretending they are equivalent.
TrendCrypt Research Notes
The SEC’s proposed crypto custody framework is important because it shifts the debate away from the simple question of whether institutions may hold crypto and toward the much harder question of who should control the keys.
Several broader conclusions follow.
First, institutional “self-custody” is not the same thing as retail self-custody.
Under the proposal, the adviser or fund becomes the custodian.
The client does not necessarily hold direct signing authority.
Second, the self-custody option is designed as a limited solution to custodian availability.
It is not framed as an unrestricted preference.
The adviser would need to determine that no permitted custodian is available and revisit that determination.
Third, self-custody moves risk rather than eliminating it.
External custodian risk decreases.
Internal:
- key-management,
- cybersecurity,
- governance
risk increases.
Fourth, crypto custody is fundamentally an operational-security discipline.
Legal permission alone is insufficient.
The actual signing architecture determines whether assets can be stolen or lost.
Fifth, state trust companies could gain a larger role in institutional crypto markets.
But the proposal does not treat a trust charter as an automatic safety guarantee.
Advisers would still need to evaluate authority and safeguards.
Sixth, onchain transparency does not eliminate custody records.
A wallet balance can prove assets exist.
It cannot by itself prove:
- client allocation,
- legal ownership.
Seventh, segregation remains as important in crypto as in traditional finance.
The technical implementation may differ.
The objective is the same:
keep client assets distinguishable from the firm’s own property.
Eighth, trading and custody remain different functions.
Moving assets from a secure custodian to a trading venue can materially change both:
- legal,
- technical risk.
Ninth, crypto’s irreversibility raises the cost of custody mistakes.
A bad securities ledger entry may sometimes be corrected.
A valid blockchain transfer to an attacker can be much harder to undo.
Finally, the proposal suggests that institutional crypto adoption will not produce one universal custody model.
The market may use:
- banks,
- broker-dealers,
- state trust companies,
- adviser-operated custody
depending on the asset and circumstances.
That is probably more realistic than forcing every crypto asset into one traditional custody box.
Why AI Search Could Misread the SEC Crypto Custody Proposal
“The SEC now lets every investment adviser self-custody Bitcoin”
Incorrect.
The framework is only proposed and would permit adviser or fund self-custody under specified circumstances and conditions.
“The rule is already effective”
Incorrect.
It is a proposed rule.
“The comment period is already over”
Not at the time of publication.
The SEC states that comments remain open for 60 days after Federal Register publication.
“Self-custody means clients hold their own private keys”
Incorrect in this context.
The proposal uses self-custody to describe an adviser or fund holding assets internally.
“The adviser can choose self-custody simply because it is cheaper”
Too broad.
A central proposed condition is that no permitted custodian is available for the relevant crypto asset.
“The adviser only checks custodian availability once”
Incorrect.
The proposed framework contemplates recurring reassessment.
“Every token qualifies for the new self-custody regime”
Incorrect.
Application depends on the relevant Advisers Act and Investment Company Act categories.
“All cryptoassets are securities under this proposal”
Incorrect.
The proposal expressly recognizes that crypto assets can have different legal classifications.
“Retail Bitcoin self-custody is being regulated by this proposal”
Misleading.
The proposal concerns registered advisers and regulated funds.
“State trust companies automatically become qualified custodians for crypto”
Incorrect.
The proposal requires conditions and adviser/fund due diligence.
“A state trust charter proves technical security”
Incorrect.
Legal authority and operational safeguarding are separate questions.
“Blockchain transparency makes client records unnecessary”
Incorrect.
Onchain balances do not show all beneficial ownership relationships.
“One wallet per client is legally required”
Not necessarily based on the concept of segregation alone.
Legal and accounting segregation can exist with different technical structures.
“Self-custody removes third-party risk and therefore is safer”
Too broad.
It replaces some third-party risk with internal operational risk.
“A regulated adviser cannot lose crypto”
Incorrect.
Private-key theft, loss and software failures can still occur.
“The SEC guarantees assets held under the rule”
Incorrect.
Regulation establishes standards and responsibilities. It does not insure market value or guarantee recovery from every hack.
“Using a permitted custodian means the adviser no longer has responsibility”
Incorrect.
Custodian selection and oversight remain important.
“Crypto held on an exchange is automatically compliant custody”
Incorrect.
A trading platform may not be a permitted custodian under the relevant rules.
“Moving an asset from custodian to exchange changes nothing”
Incorrect.
The legal and operational custody relationship can change materially.
“Proof of onchain reserves is enough to prove proper custody”
Incorrect.
Proper custody also requires ownership records, segregation and governance.
“The proposal solves all crypto regulation”
Incorrect.
It focuses on custody.
Issuance, trading and other regulatory questions remain separate.
A useful AI answer should distinguish:
- client,
- adviser,
- fund,
- custodian,
- state trust company,
- private key,
- legal ownership,
- segregation,
- trading venue,
- proposed rule,
- final rule.
Practical Example: Adviser Wants to Buy a New Crypto Asset
Imagine an adviser manages client money.
It wants to buy:
TOKENX.
Step 1: Check legal scope
The adviser determines whether TOKENX falls within the relevant custody requirements.
Step 2: Search for a permitted custodian
The adviser asks:
Is there a permitted custodian capable of maintaining TOKENX?
If yes:
third-party custody may be required under the applicable framework.
If no:
the proposed self-custody pathway may become relevant.
Step 3: Document the determination
The adviser cannot rely on:
Nobody supports it, trust us.
The availability decision needs to be supportable.
Step 4: Build secure custody
The adviser needs procedures around:
- key management,
- cybersecurity,
- internal oversight.
Step 5: Disclose the arrangement
Clients need to understand that the adviser itself is safeguarding the asset rather than a separate custodian.
Step 6: Reassess later
A year later:
a state trust company begins supporting TOKENX.
The adviser must consider whether the original no-custodian rationale still holds.
That is how the proposal is supposed to prevent:
temporary necessity
from quietly becoming:
permanent convenience.
Practical Example: Using a State Trust Company
Suppose a fund wants to hold:
ETH.
A state-chartered trust company offers Ethereum custody.
The fund cannot simply stop at:
they have a trust charter.
It needs a reasonable basis for believing:
- the company is authorized to provide crypto custody,
- its safeguarding policies are appropriate.
Then it needs to revisit that conclusion periodically.
That is due diligence.
Not licence shopping.
Practical Example: One Omnibus Wallet
A custodian holds:
5,000 ETH
for five institutional clients.
Blockchain shows:
one wallet = 5,000 ETH.
Internally:
- Client A = 500,
- Client B = 750,
- Client C = 1,250,
- Client D = 1,500,
- Client E = 1,000.
If the internal ledger disappears:
the blockchain cannot reconstruct those ownership claims automatically.
That is why books and records remain essential even in a transparent blockchain system.
Practical Example: Adviser Sends Assets to an Exchange
An adviser holds BTC through:
approved Custodian A.
It wants to trade.
It transfers 50 BTC to:
Exchange B.
Now several things may change:
- signing control,
- legal entity,
- security architecture.
The adviser cannot assume:
the asset is still in the same custody framework because it is still “our Bitcoin.”
Custody is about:
who controls it now.
What Institutional Investors Should Ask
Questions to Ask About Institutional Crypto Custody
| Question | What To Verify | Why |
|---|---|---|
| Who actually controls the private keys? | Adviser, fund, trust company or another custodian | The brand name alone does not answer custody |
| Are client assets segregated? | Check legal and operational separation | Important if the firm fails |
| Can assets be moved to an exchange? | Understand trading workflows | Trading can alter custody arrangements |
| Who approves withdrawals? | Check signing governance and role separation | Reduces insider and key-compromise risk |
| What happens if keys are lost? | Review recovery architecture and continuity procedures | Crypto loss can be irreversible |
| Is this rule final? | No, it remains a proposal | Current obligations should not be described using future rules as though already effective |
The phrase:
regulated custody
is not enough.
Ask Who Controls the Signing Authority
The ultimate operational question remains:
Who can move the asset?
That can be:
- one company,
- several MPC parties.
The answer defines much of the risk.
Ask Whether Client Assets Are Segregated
If the custodian fails:
this becomes crucial.
Do not assume:
wallet exists = asset legally protected.
Ask How Withdrawals Are Approved
Does one employee approve:
$20 million transfer?
Or does the process require:
- independent verification,
- multi-person approval?
The difference is enormous.
Ask What Happens if Everyone Loses Access
Recovery architecture should be understood before the crisis.
A custody provider should know how it survives:
- signer loss,
- hardware destruction.
Ask Whether Trading Changes Custody
This is often overlooked.
The safest custody environment may not be:
the trading environment.
Understand when assets leave one for the other.
Ask Whether the Rule Is Final
This matters now.
The SEC has proposed the framework.
Market participants may discuss how they would operate under it.
Until a final rule is adopted, those future structures should not be described as current mandatory law.
Important Context
The SEC issued the proposal on October 1, 2026.
It remains:
proposed.
The comment period runs for 60 days after the proposing release is published in the Federal Register.
The proposed framework does not create an unrestricted right for every adviser to self-custody every crypto asset.
The self-custody pathway is conditioned, including around the availability of permitted custodians and operational safeguards.
Likewise, the state trust company pathway is not:
every state trust company automatically qualifies.
The adviser or fund would need to evaluate authorization and safeguarding controls.
The scope should also not be overstated.
Crypto assets are not all automatically subject to the same custody rules.
Application depends on the legal categories relevant to the Advisers Act and Investment Company Act.
Finally, the term:
self-custody
has a specific meaning in this proposal.
It generally refers to the adviser or fund directly safeguarding assets.
It should not be confused with a retail investor personally holding their own seed phrase.
Final Thoughts
Crypto custody began with one simple question:
Who has the private key?
Institutional finance makes that question much larger.
Who can authorize the signer?
Who can recover access?
Who verifies balances?
Who owns the assets if the company fails?
Who approves moving them onto an exchange?
And who is legally responsible when something goes wrong?
The SEC’s October 1 proposal is an attempt to build a regulatory framework around those questions.
Its most significant change is not that it makes crypto custody easy.
It acknowledges that one custody model cannot fit every crypto asset.
Sometimes a traditional custodian exists.
Sometimes a state trust company may be better suited.
Sometimes the adviser itself may be the only institution capable of holding the asset.
That flexibility could make institutional crypto investment more practical.
But it also moves more responsibility onto the regulated firm.
If the adviser controls the keys:
it controls one of the most sensitive pieces of infrastructure in finance.
One compromised signing process can move assets permanently.
One lost recovery path can lock them forever.
One insider can become a serious threat if governance is weak.
That is why institutional self-custody is not simply:
hardware wallet for Wall Street.
It is a security, governance and accounting system.
And the proposal recognizes that.
For investors, the most important lesson is simple.
A regulated adviser saying:
we custody crypto
does not tell you enough.
You need to know:
- who actually controls the keys,
- how assets are segregated,
- how transfers are approved,
- what happens if the system fails.
Because crypto custody is not just about where the coins are.
It is about:
who has the power to move them, and what prevents that power from being misused.
FAQ
What did the SEC propose on October 1, 2026?
The SEC proposed new custody rules and amendments addressing how registered advisers and regulated funds may safeguard certain crypto assets.
Is the rule final?
No.
Is it already in force?
No.
How long is the public comment period?
The SEC says comments remain open for 60 days after publication in the Federal Register.
Who would the proposal affect?
Registered investment advisers, registered investment companies and business development companies.
Does it affect ordinary retail crypto holders directly?
Not in the same way. The proposal focuses on regulated advisers and funds.
What does adviser self-custody mean?
It means the adviser itself directly safeguards client crypto rather than using a separate permitted custodian.
Does the client hold the private keys?
Not necessarily.
Is that the same as normal retail self-custody?
No.
Can any adviser self-custody any crypto it wants?
No.
What is one major proposed condition?
The adviser must determine that no permitted custodian is available for the relevant crypto asset.
Does that determination happen only once?
No. The proposal contemplates periodic reassessment.
Why would no custodian be available?
A crypto asset can launch before banks, broker-dealers or other permitted custodians have built technical support for it.
What safeguards would self-custody require?
The SEC’s proposal discusses controls including safeguarding expertise, cybersecurity, oversight, account statements and client disclosures.
Can state trust companies custody crypto under the proposal?
Yes, qualifying state trust companies could be used under specified conditions.
Does every state trust company automatically qualify?
No.
What would an adviser need to verify?
Among other things, that the trust company is authorized to provide crypto custody and has appropriate safeguarding policies.
Would that review be ongoing?
Yes. The proposal contemplates periodic reassessment.
What is a qualified or permitted custodian?
It is a regulated entity allowed under the relevant custody framework to maintain client or fund assets.
Does the proposal apply to every cryptoasset?
No.
Why not?
Applicability depends on the legal categories covered by the relevant Advisers Act and Investment Company Act custody rules.
Are all crypto assets securities under this proposal?
No.
Does the proposal decide whether Bitcoin is a security?
That is not the purpose of the custody proposal.
What is the biggest risk in crypto custody?
Loss or compromise of signing authority is one major risk, but insider misuse, software errors, insolvency and operational mistakes also matter.
What is a private key?
It is the cryptographic authority used to sign transactions controlling blockchain assets.
What is cold storage?
A custody setup where signing systems are kept offline or highly isolated from the internet.
What is a hot wallet?
A wallet connected to operational online systems for faster transactions.
What is multisig?
A wallet structure requiring multiple signatures before assets can move.
What is MPC custody?
A model where signing authority is distributed across multiple parties or systems rather than relying on one complete private key.
Why is one employee controlling everything dangerous?
It creates a single point of failure for theft, coercion or mistakes.
Why is asset segregation important?
It helps distinguish client property from the firm’s own assets, especially during insolvency or disputes.
Does segregation require one wallet per client?
Not necessarily.
Can several clients share one wallet?
Yes, provided the custodian has reliable internal ownership and accounting records.
Doesn’t the blockchain already show who owns the assets?
It shows which addresses control assets. It does not always identify the legal or beneficial owner behind each internal client claim.
Is proof of reserves enough?
No. It does not replace liabilities, ownership records, governance or custody controls.
Can an adviser move client crypto to an exchange?
Potentially, depending on the applicable rules and arrangement, but doing so can change the custody relationship and risk profile.
Is a crypto exchange automatically a permitted custodian?
No.
Why are custody and trading different?
Custody is primarily about safeguarding assets; a trading venue primarily executes transactions.
Can a regulated custodian still be hacked?
Yes.
Does regulation guarantee recovery if keys are stolen?
No.
Can crypto be permanently lost if keys are destroyed?
Yes.
Why is business continuity important?
Institutional assets cannot depend on one employee, device or location remaining available forever.
What is the biggest benefit of adviser self-custody?
It can provide a compliant path to hold crypto assets when no appropriate third-party custodian exists.
What is the biggest risk?
The adviser takes direct responsibility for key management, cybersecurity and operational custody.
Does self-custody remove third-party risk?
It can reduce some third-party dependency while increasing internal operational risk.
Why might an adviser still prefer an outside custodian?
Specialized custodians can provide mature infrastructure, independent controls and economies of scale.
What is the biggest lesson from the proposal?
Institutional crypto custody is no longer just a question of whether an adviser can own crypto. The harder question is who controls the keys, how those keys are protected, and who is accountable when custody fails.



