reportsinstitutional crypto custody what large financial institutions should watch for
Institutional Crypto Custody: What Large Financial Institutions Should Watch For
RISK ASSESSMENT
Institutional Crypto Custody: What Large Financial Institutions Should Watch For
A buyer-and-oversight risk assessment for Tier-1 banks selecting or supervising a third-party digital asset custodian. The headline controls — "segregated, insured, audited" — mean less than most diligence teams assume. This report tiers the six risks that actually decide whether client assets survive a custodian failure, anchored in MiCA Article 75, NYDFS custody guidance, the MAS Payment Services Act, the OCC's 2025 letters, and the Celsius and Prime Trust failures, and converts each into a due-diligence and oversight playbook.
CustodyRisk AssessmentBankruptcy RemotenessSegregation

Executive Summary

By mid-2026 the regulated custody options for a Tier-1 bank are real: OCC-supervised national banks[1], MiCA-licensed CASPs[2], NYDFS trust companies[3], and MAS-regulated DPT custodians[4] all now hold digital assets under explicit rules. The infrastructure is no longer the question. The question is whether your client assets survive the custodian failing — and on that, the marketing words “segregated, insured, audited” carry far less weight than diligence teams assume. Three findings drive this assessment.

01
The binding risk is legal, not cryptographic
None of the custody failures that cost clients money — Celsius, Prime Trust, FTX — began with broken cryptography. They began in contracts and ledgers. Celsius depositors learned the difference in court: the Earn terms had quietly moved title to the platform, so “their” coins were estate assets and they were unsecured creditors[5]. Operational segregation — your coins in a separate wallet — is not legal segregation — you holding bankruptcy-remote title. A custodian can show you the first while the contract quietly delivers a debtor-creditor relationship. NYDFS, MiCA, and MAS now all require the second by rule[3][2][4], but the burden is on you to confirm the specific agreement and booking entity clears the test.
02
Key custody can be intact while client assets bleed out
Prime Trust is the case to study: an institutional platform, no breach — yet Nevada’s receivership filing found more crypto owed to clients than the firm held, a hole dug over eighteen months of funding withdrawals from omnibus customer money after it locked itself out of its own legacy wallets[6]. The full mechanics are in the risk analysis; the summary-level lesson is that omnibus custody makes your protection only as strong as the custodian’s internal ledger discipline — a control no cold-storage diagram evidences.
03
The assurances are weaker than they read
“Insured” usually means an aggregate policy, split between hot-wallet crime and cold-wallet specie cover, riddled with exclusions, capped well below total assets under custody, and shared across every client[7]. “Audited” often means a proof-of-reserves attestation that shows assets at a snapshot but never liabilities — solvency’s missing term — and can be staged by borrowing around the date[8]. And jurisdiction is a variable, not a footnote: the identical provider can clear the segregation and capital tests in one booking entity and fail both in another — the US eased its balance-sheet treatment via SAB 122[9], while Basel’s 1250% risk weight still hangs over arrangements whose finality and enforceability are unproven[10].
WHAT THIS MEANS OPERATIONALLY
The diligence file has an order. First, a bankruptcy-remoteness legal opinion naming the specific booking entity; second, a SOC 1 Type II report covering key control and withdrawal funding; third, the actual insurance policy wording; fourth, a full-scope audit of liabilities. The cold-storage brochure and the smart-contract audit come after. What separated the survivors of 2022–2023 was not architecture — it was the habit of treating custody as a counterparty exposure whose failure had already been rehearsed: if this firm files tomorrow, is there evidence on file that the assets are still legally your clients’?

Risk Analysis

Custody looks solved. As of mid-2026 a Tier-1 bank can appoint an OCC-supervised national bank[1], a MiCA-licensed CASP[2], a NYDFS-chartered trust company[3], or a MAS-regulated DPT custodian[4] to hold digital assets, and every marketing deck says the same three words: segregated, insured, audited. All three mean less than your diligence team assumes.

Here’s what most custody diligence gets wrong: it audits the cold-storage diagram. But the failures that actually moved client losses — Celsius, Prime Trust, FTX — did not happen because someone cracked a hardware security module. They happened in the legal documents, the omnibus ledger, and the gap between “we hold your assets” and “you own them.” Six risks decide the outcome, and they are nowhere near equal: the first two account for nearly every loss-given-custodian-failure scenario we can construct across the 150+ jurisdictions we track; the last gets a disproportionate share of the diligence budget.

Tier 1 — the risks that take your assets

1. Legal segregation is not operational segregation — and only one of them survives bankruptcy. Operational segregation means your coins sit in a separate wallet on the custodian’s books. Legal segregation means you hold title and the assets are bankruptcy-remote from the custodian’s estate. A custodian can deliver the first and not the second, and your diligence team will see “segregated” on both. The Celsius estate is the lesson that should be laminated to every custody term sheet: the bankruptcy court read the Earn Terms of Use, found that title to deposited crypto had passed to Celsius, and reclassified depositors who believed they owned their tokens as unsecured creditors[5]. The document, not the wallet, decided ownership. NYDFS now writes the test explicitly — equitable and beneficial interest must always remain with the customer, the relationship must be custodial rather than debtor-creditor, and assets must be segregated “both on-chain and on the internal ledger”[3], guidance it tightened again in September 2025[11]. MiCA Art. 75 reaches the same place by statute: legal and operational segregation, an individual position register per client, and custodian liability for losses attributable to it[2]. MAS requires DPT customer assets held on trust[4]. What this means operationally: read the custody agreement the way a bankruptcy trustee will, not the way a salesperson presents it. If the contract creates a debtor-creditor relationship — anywhere in the yield, staking, or “earn” clauses — operational segregation is cosmetic. When we ran custodian onboarding at scale, this was the clause that killed more mandates than any technology finding, and rightly: a custodian whose own terms let it treat your assets as its balance sheet is not a custodian, and no amount of cold storage fixes that.

2. The custodian can hold your keys and still lose your coins. Operational control failure is the Prime Trust pattern, and it is more common than key theft. Prime Trust migrated client assets to an institutional MPC platform, then — after management turnover — routed funds back into pre-2020 “legacy wallets” it could no longer access. From December 2021 it covered withdrawals by buying replacement crypto with money pulled from its omnibus customer accounts, until Nevada regulators put it into receivership in 2023 owing roughly $69.5M in crypto against $68.6M on hand[6]. No hack. The architecture was institutional-grade; the operational controls around who could move assets, and how withdrawals were funded, were not. This is where the omnibus-versus-segregated-wallet question stops being academic: an omnibus structure means your assets are only as protected as the custodian’s internal ledger and its withdrawal-funding discipline — exactly the two things that failed at Prime Trust. The cryptographic architecture underneath (MPC, multisig, HSM) is a real risk surface, but it is the one with a mature control market; we assess it separately in our custody key management report (2026-002). What this means operationally: ask who can actually authorize a movement of your coins, against what quorum, and how customer withdrawals are funded on a bad day. The SOC 1 Type II report and the key-ceremony evidence matter more than the wallet brochure.

Tier 2 — the risks that produce disputes, capital surprises, and coverage gaps

3. The insurance number is the most over-read figure in the deck. “$500M insured” almost never means your assets are covered for $500M. Custody insurance splits along the architecture — specie responds to cold-storage loss, crime to hot-wallet theft — two products with different perils that seldom sum to your exposure[7]. Standard exclusions gut the coverage where it counts — compromised key generation, authorized-but-mistaken transfers, smart-contract failure, and insider collusion are frequently carved out. And the headline limit is one aggregate spread across the custodian’s entire client base: when a loss hits the whole book, your recovery is a pro-rata slice of a number that is a small fraction of assets under custody. We take the policy anatomy, the exclusions market, and the capacity math apart in our insurance coverage report (2026-005). What this means operationally: the only insurance questions that matter are (a) what perils, hot versus cold, (b) what exclusions, and (c) what limit applies to your assets after every other client has claimed. A certificate of insurance is not a coverage opinion — demand the policy wording.

4. Proof of reserves is an attestation wearing an audit’s clothes. A Merkle-tree proof of reserves shows that the custodian controlled certain assets at a single block height. It does not show liabilities, it does not prove exclusive key control, and it can be staged by borrowing assets around the snapshot date[8]. Solvency is assets minus liabilities; proof of reserves shows only the first term. FTX could have passed a proof-of-reserves check days before it failed. What this means operationally: treat proof of reserves as a liveness signal, not an assurance. What a Tier-1 board needs is a full-scope financial-statement audit by a recognized firm that examines liabilities and controls — and you should know the difference between “audited” and “attested” before it appears in a board paper.

5. The same custody relationship books differently in every jurisdiction. A custodian’s protections are entity-specific. The same provider may be a bankruptcy-remote NYDFS trust in New York, a strictly-liable CASP under MiCA in the EU, an OCC-supervised national bank in the US federal system, and a trust-account DPT custodian under the MAS Payment Services Act in Singapore — with different segregation mechanics, different liability standards, and different capital consequences in each[2][4][1][3]. Two changes since 2025 matter for the capital and accounting picture. First, the SEC’s rescission of SAB 121 via SAB 122 removed the forced one-to-one liability that had made bank custody capital-punitive in the US; safeguarding obligations now follow ordinary loss-contingency recognition[9]. Second, Basel’s framework still imposes a 1250% risk weight on Group 2 exposures where finality and enforceability are not evidenced[10] — so where your custody arrangement sits in the Basel taxonomy is a capital question, not just a legal one. And the taxonomy’s edges are unsettled: as of mid-2026, no Basel-implementing supervisor had published the tests a custody structure must actually meet to escape Group 2 treatment, so the classification is an argument you make to your examiner, not a box you tick. What this means operationally: a custody schedule that is bankruptcy-remote and capital-efficient in your New York entity can fail both tests in your Singapore or Frankfurt booking entity. Map the analysis per booking location, not per provider.

Tier 3 — real, but bounded

6. Tainted assets and travel-rule gaps follow the coins in. A custodian that accepts a deposit with on-chain exposure to a sanctioned address, a mixer, or stolen funds can find your assets frozen by its own analytics screen — or worse, by an enforcement action against the custodian. FATF’s Recommendation 16 travel rule requires originator and beneficiary information to move with transfers above threshold, and sanctions exposure can sit several hops from the designated wallet[12]. This is a genuine operational risk, but it is bounded: the screening and travel-rule tooling market is mature, and a competent custodian already runs deposit screening as standard customer due diligence. Related and equally bounded is concentration risk — the institutional-grade custodian universe is small, so a systemic event hits many banks at once; the mitigation is diversification across providers and chains, which you can actually execute. What this means operationally: these belong on the diligence list, but do not let them crowd out Tier 1. A flawless travel-rule implementation does not save you from a debtor-creditor custody agreement.

The weighting, in one table

# Risk Tier How it takes your assets Typical “control” on offer Adequate?
1 Legal vs operational segregation 1 Title passes to custodian; you become an unsecured creditor in bankruptcy “Segregated” wallets + standard ToS No — needs a true-custodial legal opinion
2 Operational / key-access control 1 Lost keys, omnibus commingling, withdrawals funded from client pool Cold-storage architecture brochure No — needs SOC 1 Type II + funding discipline
3 Insurance coverage gap 2 Loss falls in an exclusion or exceeds per-client share of an aggregate limit Headline “$XXXm insured” Partial — read the wording, not the number
4 Proof-of-reserves theater 2 Insolvency hidden behind an assets-only snapshot Periodic Merkle attestation No — needs full-scope audit of liabilities
5 Cross-jurisdiction divergence 2 Same arrangement non-remote / capital-punitive in another entity Single-jurisdiction legal review Partial — analyze per booking entity
6 AML taint / travel-rule / concentration 3 Assets frozen on a screen; systemic provider failure Deposit screening, travel-rule tooling Largely yes — bounded, mature controls

Weight your diligence the way this table is weighted. A fresh smart-contract audit and a clean proof-of-reserves snapshot do not compensate for a custody agreement that fails the bankruptcy-remoteness test. If the legal opinion on segregation is stale, silent on which booking entity it covers, or — most often — simply absent, that is a Tier-1 open item that should stop the onboarding, regardless of how good the cold-storage story is.

Due Diligence and Oversight Controls

Selecting a custodian is a counterparty decision dressed up as a technology decision. The controls that matter are mostly legal and operational, and most of them are verifiable before you sign — if you ask for the right evidence and refuse to onboard without it. This is the playbook we apply when we evaluate custody arrangements at scale.

1. The seven documents to demand — and not onboard without

Diligence is only as good as the evidence you require. Verbal assurances and certificates of coverage are not evidence. Before onboarding, demand:

  1. A bankruptcy-remoteness legal opinion from independent counsel, naming the specific booking entity and confirming a true custodial (bailment) relationship in which equitable and beneficial interest remains with you. This is the single most important document, and the one most often missing.
  2. The custody agreement itself, read for debtor-creditor language anywhere in the safekeeping, staking, yield, or rehypothecation clauses. One clause that lets the custodian use your assets defeats the legal opinion.
  3. A SOC 1 Type II report (operating-effectiveness, not just design) covering key management, transaction authorization, and withdrawal funding — the Prime Trust failure surface.
  4. A full-scope financial-statement audit by a recognized firm — not a proof-of-reserves attestation. Confirm the auditor examined liabilities, not just wallet balances.
  5. The actual insurance policy wording, not the certificate: perils covered hot versus cold, the exclusion schedule, and the aggregate limit with your realistic per-client share.
  6. A named list of sub-custodians and infrastructure providers, with the consent and due-diligence terms governing them — and confirmation that sub-custody changes require your approval, the NYDFS standard[3].
  7. The regulatory authorization for each jurisdiction you will book in — MiCA CASP, MAS DPT, NYDFS trust charter, OCC national bank — because the protections are entity-specific[2][4][1].

2. Red flags that should stop the onboarding

Some findings are not negotiation points — they are exits. Treat these as disqualifying until cured:

  • Debtor-creditor or title-transfer language anywhere in the agreement. This is the Celsius failure mode in contract form[5].
  • Omnibus-only custody with no segregated-wallet option and no clear withdrawal-funding policy.
  • “Audited” that turns out to mean “attested.” A proof-of-reserves snapshot presented as an audit is a signal about the whole control culture, not just the assurance.
  • An insurance headline with no per-client sublimit and no policy wording on offer.
  • Unnamed or freely-substitutable sub-custodians.
  • A single-jurisdiction legal opinion offered as cover for a multi-entity booking model.

3. Contract terms worth negotiating

Where the relationship clears diligence, the contract is your last control. Negotiate for:

  • An explicit strict-liability standard for loss of assets or means of access attributable to the custodian — MiCA Art. 75 sets this floor in the EU[2], and you should hold non-EU custodians to it by contract.
  • A no-rehypothecation, no-pledge representation, with a breach defined as an immediate event of default.
  • A segregation representation and warranty, restated at each reporting period, covering both on-chain and internal-ledger segregation.
  • Prior-consent rights over sub-custody and material infrastructure changes.
  • Audit and information rights — the right to receive the full-scope audit and SOC reports on a defined cadence, and to inspect on cause.

4. The questions a board should be asking

The board test — could a non-executive director run the oversight from the board paper alone? Five questions force the answer:

  1. If this custodian filed for bankruptcy tomorrow, are our clients’ assets legally theirs, evidenced by whose opinion, and for which booking entity?
  2. Who inside the custodian can move our assets, against what quorum — and how do they fund a stressed day of withdrawals?
  3. What is actually insured, after exclusions, and what is our realistic recovery if the custodian suffers a $1bn loss across all clients?
  4. Is the assurance we rely on a full audit of liabilities, or a snapshot of assets?
  5. Where are we concentrated — which providers, which chains — and what is the plan if the largest one fails?

If management cannot answer these from evidence on file, the gap is the finding.

5. Oversight does not end at onboarding

Custody risk is not a point-in-time selection decision; it is an ongoing counterparty exposure. The Prime Trust collapse unfolded over roughly eighteen months after the custodian looked institutional-grade[6]. Build the oversight to match: refresh the bankruptcy-remoteness opinion and SOC report annually, re-test the insurance limit against your growing balances, monitor the custodian’s own financial health and regulatory standing, and re-run the concentration analysis as exposures shift. What the regulation requires and what happens in practice are two different things — and the gap is widest in the quarters when everyone has stopped looking. The institutions that came through the 2022–2023 custody failures with client assets intact were not the ones with the best cold-storage diagrams. They were the ones that treated their custodian as a live counterparty and never stopped asking the five questions above.

REFERENCES
[1]Office of the Comptroller of the Currency. "OCC Clarifies Bank Authority to Engage in Certain Cryptocurrency Activities" (News Release 2025-16; Interpretive Letters 1183 and 1184). May 2025. https://www.occ.treas.gov/news-issuances/news-releases/2025/nr-occ-2025-16.html
[2]European Union. "Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA)," Article 75. June 2023. https://eur-lex.europa.eu/eli/reg/2023/1114/oj
[3]New York State Department of Financial Services. "Guidance on Custodial Structures for Customer Protection in the Event of Insolvency." 23 January 2023. https://www.dfs.ny.gov/industry_guidance/industry_letters/il20230123_guidance_custodial_structures
[4]Monetary Authority of Singapore. "MAS Expands Scope of Regulated Payment Services; Introduces User Protection Requirements for Digital Payment Token Service Providers." 2024. https://www.mas.gov.sg/news/media-releases/2024/mas-expands-scope-of-regulated-payment-services
[5]Cleary Gottlieb. "Novel Issues in the Crypto Bankruptcy Cluster" (analysis of In re Celsius Network LLC, Bankr. S.D.N.Y.). 2023. https://content.clearygottlieb.com/corporate/global-restructuring-insights/novel-issues-in-the-crypto-bankruptcy-cluster/index.html
[6]CoinDesk. "Nevada Files to Place Crypto Custodian Prime Trust Into Receivership." June 2023. https://www.coindesk.com/policy/2023/06/27/nevada-places-crypto-custodian-prime-trust-into-receivership
[7]Lockton. "Cryptocurrency insurance — best practices for custodians." 2024. https://global.lockton.com/news-insights/cryptocurrency-insurance-best-practices-for-custodians
[8]Cobo. "Flaws of Merkle Tree Proof-of-Reserves and Thoughts on Improvement." 2023. https://www.cobo.com/post/flaws-of-merkle-tree-proof-of-reserves-and-thoughts-on-improvement
[9]U.S. Securities and Exchange Commission. "Staff Accounting Bulletin No. 122" (rescinding SAB 121). 23 January 2025. https://www.sec.gov/rules-regulations/staff-guidance/staff-accounting-bulletins/staff-accounting-bulletin-122
[10]Basel Committee on Banking Supervision. "Prudential treatment of cryptoasset exposures" (SCO60). December 2022. https://www.bis.org/bcbs/publ/d545.htm
[11]New York State Department of Financial Services. "Updated Guidance on Custodial Structures for Customer Protection in the Event of Insolvency." 30 September 2025. https://www.dfs.ny.gov/industry-guidance/industry-letters/il20250930-updated-guidance-custodial-structures
[12]Financial Action Task Force. "Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs" (Recommendation 16 / travel rule). June 2024. https://www.fatf-gafi.org/en/topics/virtual-assets.html
Report Overview

Published Date

10 Jun 2026

Reading Time

17 mins

Downloads

0

About Author

Yirifi Admin
Yirifi Admin

Published reports

6
Related Reports

No related reports found.