---
title: "Crypto-asset custody: who can custody, how it works and how to choose a custodian"
url: "https://www.unknowngravity.com/en/articulos/crypto-asset-custody"
site: Unknown Gravity
published: "2026-08-13T06:40:02+00:00"
modified: "2026-08-13T06:40:02+00:00"
language: en-US
description: "Custodying crypto-assets means managing the keys that move them: whoever controls the key controls the asset. That is why custody on behalf of third parties is a regulated service in the EU — under…"
section: "Home > Cryptocurrencies and tokens > Crypto-asset custody: who can custody, how it works and how to choose a custodian"
---

# Crypto-asset custody: who can custody, how it works and how to choose a custodian

**Custodying crypto-assets means managing the keys that move them: whoever controls the key controls the asset.** That is why custody on behalf of third parties is a regulated service in the EU — under MiCA it requires CASP authorisation — and why the first decision for any company touching crypto-assets is where and how its keys live.

## Self-custody or delegated custody

In [self-custody](/en/glosario/auto-custodia-self-custody), the holder keeps their own keys: total control, total responsibility, no recourse if they are lost. In delegated custody, a professional third party manages them with legal obligations towards the client. Between the two sits a nuance that is often missed: **delegating the interface does not remove custody, it relocates it** — if your product holds your clients keys, the custodian is you, with everything that implies.

## What MiCA requires from a custodian

Custody and administration of crypto-assets on behalf of clients is one of the ten services defined by MiCA, so a professional custodian needs [CASP authorisation](/en/articulos/casp-license-spain-mica). The core obligations: **segregation** of clients crypto-assets from the firms own estate, a **register of positions** per client, a written custody policy, and **liability towards the client for the loss of crypto-assets or of the means of access** where the incident is attributable to the custodian. Without authorisation or a regulated-entity notification, there is no service.

## Cold, hot, multisig and MPC

Technology distributes the risk. [Cold wallets](/en/glosario/cold-wallet-cartera-fria) keep keys offline (maximum security, less agility); [hot wallets](/en/glosario/hot-wallet-cartera-caliente) stay connected for daily operations. Serious custodians combine both with **multisig** (several keys to authorise a movement) or **MPC** (the key never exists whole in one place), per-operation limits and separation of duties. No technology replaces operations: most losses come from processes, not from cryptography.

## Custody in regulated tokenization is a different animal

If the token is a **transferable security**, we are no longer in MiCA: custody belongs to **entities authorised to hold financial instruments** — credit institutions and investment firms — and ownership is fixed by the register administered by the ERIR. That is the terrain of our [security tokens](/en/servicios/security-tokens) service: the wallet is just the window; the source of truth is the register.

## Choosing a custodian: the short list

Verifiable authorisation (CASP or authorised financial entity, in the supervisors register); real, audited segregation rather than promised; documented technology (cold/hot split, multisig or MPC, key management); insurance or capital that answers for losses; contingency and key-succession plans; and transparency about sub-custodians. If a provider cannot show these six things in writing, the answer is no.

## Where we fit

We design and integrate the custody layer of [asset tokenization](/en/servicios/tokenizacion-activos) platforms and [digital-asset](/en/servicios/activos-digitales) products: key architecture, segregation, limits and recovery, working with regulated custodians where the case demands it. If you are deciding how to custody your products assets, [book a call](/en/meeting).
