Are you an investment adviser or fund manager wondering how to keep client crypto assets safe and compliant? This article explains what crypto custody means, why regulators are stepping in, and how the latest SEC proposals could shape your approach to holding digital assets.
What is crypto custody and how does it work?
In traditional finance, custody refers to the safekeeping of assets by a trusted third party, such as a bank or a specialized custodian. For cryptocurrencies, custody involves storing private keys—the secret codes that grant access to blockchain balances—in a way that prevents loss, theft, or unauthorized use.
There are two main models:
- Self‑custody: The investor holds the private keys directly, often using hardware wallets or software wallets. This gives full control but also full responsibility for security.
- Third‑party custody: A licensed custodian stores the keys on behalf of the client. The custodian may use cold storage (offline devices) for maximum security, while providing reporting and insurance services.
Regulators focus on third‑party custody because it introduces a fiduciary relationship: the custodian must act in the best interests of the client and protect assets against fraud, hacking, and operational failures.
Why is the SEC proposing new rules now?
The U.S. Securities and Exchange Commission (SEC) has long viewed many crypto tokens as securities. When an adviser or fund holds such tokens on behalf of clients, the SEC treats that activity as a form of securities custody, which is already regulated for traditional assets. However, the rapid growth of crypto investments exposed gaps in existing rules, especially around:
- Safeguarding private keys and ensuring they are not co‑mixed with the custodian’s own assets.
- Providing transparent reporting and audit trails for clients and regulators.
- Establishing clear standards for insurance and loss recovery.
To address these gaps, the SEC released a proposal that would extend existing custody requirements—originally designed for stocks and bonds—to digital assets held by investment advisers and registered investment companies.
Real‑world illustration
In March 2026, the SEC formally proposed new crypto custody rules that would apply to registered investment advisers and funds. The proposal outlines specific obligations for entities that hold crypto assets on behalf of clients, such as maintaining segregated accounts, implementing robust cybersecurity controls, and undergoing regular independent examinations.
What it means for you
If you manage client portfolios that include cryptocurrencies, the proposed rules could affect several aspects of your operation:
- Choice of custodian: You may need to partner with a custodian that meets the SEC’s security and reporting standards, or upgrade your own infrastructure to satisfy them.
- Compliance costs: Additional audits, insurance policies, and cybersecurity measures could increase operational expenses.
- Client communication: You’ll have to disclose custody arrangements more transparently, explaining how assets are protected and what recourse exists if a loss occurs.
- Regulatory risk: Non‑compliance could result in enforcement actions, fines, or restrictions on your ability to manage crypto assets.
How to evaluate custody options
When selecting a custodian or building your own custody solution, consider these concrete factors:
- Regulatory status: Verify that the custodian is registered with the SEC or a comparable authority and holds a qualified custodian license.
- Segregation practices: Ensure client assets are kept separate from the custodian’s own holdings to prevent co‑mixing.
- Security protocols: Look for multi‑layered defenses such as hardware security modules (HSMs), air‑gapped cold storage, and regular penetration testing.
- Insurance coverage: Confirm that the custodian carries insurance that covers digital asset theft or loss, and understand the policy limits.
- Audit and reporting: The custodian should provide regular, independent audit reports and real‑time reporting dashboards for clients.
- Disaster recovery: Review the custodian’s contingency plans for data breaches, natural disasters, or operational failures.
FAQ
Do I need a third‑party custodian if I already use a hardware wallet?
Self‑custody can satisfy regulatory requirements if you can demonstrate robust controls, segregation, and reporting. However, many advisers prefer third‑party custodians because they simplify compliance and provide audit trails that regulators expect.
What happens if a custodian is hacked?
If the custodian holds insurance that covers crypto losses, you may be able to recover some or all of the assets. The SEC’s proposed rules would require custodians to disclose their insurance policies and the extent of coverage to clients.
Are all crypto tokens subject to these custody rules?
The SEC focuses on tokens it classifies as securities. Tokens that are clearly utilities or commodities may fall outside the scope, but the classification can be nuanced. Conduct a thorough legal analysis of each token in your portfolio.
Will these rules apply to offshore advisers?
The proposal targets U.S. registered advisers and funds. Offshore entities that market to U.S. investors may still need to comply if they fall under SEC jurisdiction, but the exact reach will depend on future rule finalization.
This article references reporting from coindesk.com.