Skip to content

BLOG · LEARN WEB3

Crypto-asset custody: who can custody, how it works and how to choose a custodian

13 AUG 2026 2 MIN READ Unknown Gravity

Crypto-asset custody: who can custody, how it works and how to choose a custodian

Custodying crypto-assets means managing the keys that move them: whoever controls the key controls the asset. That is why custody on behalf of third parties is a regulated service in the EU — under MiCA it requires CASP authorisation — and why the first decision for any company touching crypto-assets is where and how its keys live.

Self-custody or delegated custody

In self-custody, the holder keeps their own keys: total control, total responsibility, no recourse if they are lost. In delegated custody, a professional third party manages them with legal obligations towards the client. Between the two sits a nuance that is often missed: delegating the interface does not remove custody, it relocates it — if your product holds your clients keys, the custodian is you, with everything that implies.

What MiCA requires from a custodian

Custody and administration of crypto-assets on behalf of clients is one of the ten services defined by MiCA, so a professional custodian needs CASP authorisation. The core obligations: segregation of clients crypto-assets from the firms own estate, a register of positions per client, a written custody policy, and liability towards the client for the loss of crypto-assets or of the means of access where the incident is attributable to the custodian. Without authorisation or a regulated-entity notification, there is no service.

Cold, hot, multisig and MPC

Technology distributes the risk. Cold wallets keep keys offline (maximum security, less agility); hot wallets stay connected for daily operations. Serious custodians combine both with multisig (several keys to authorise a movement) or MPC (the key never exists whole in one place), per-operation limits and separation of duties. No technology replaces operations: most losses come from processes, not from cryptography.

Custody in regulated tokenization is a different animal

If the token is a transferable security, we are no longer in MiCA: custody belongs to entities authorised to hold financial instruments — credit institutions and investment firms — and ownership is fixed by the register administered by the ERIR. That is the terrain of our security tokens service: the wallet is just the window; the source of truth is the register.

Choosing a custodian: the short list

Verifiable authorisation (CASP or authorised financial entity, in the supervisors register); real, audited segregation rather than promised; documented technology (cold/hot split, multisig or MPC, key management); insurance or capital that answers for losses; contingency and key-succession plans; and transparency about sub-custodians. If a provider cannot show these six things in writing, the answer is no.

Where we fit

We design and integrate the custody layer of asset tokenization platforms and digital-asset products: key architecture, segregation, limits and recovery, working with regulated custodians where the case demands it. If you are deciding how to custody your products assets, book a call.