

Crypto custody regulation determines how banks, centralized exchanges, investment advisers and other cryptocurrency custodians may safeguard client crypto assets. Rules vary by asset class and institution, but generally focus on control of cryptographic keys, segregation of customer assets, cybersecurity, anti-money laundering controls and safe custody operations. These requirements matter to institutions and clients because loss or compromise of a private key can make digital assets inaccessible or transferable without authorization.
The U.S. Office of the Comptroller of the Currency confirms that national banks and federal savings associations may conduct crypto asset custody and execution services and may use third-party sub-custodians.
A July 2025 Federal Reserve, FDIC and OCC joint statement says banking organizations must conduct crypto asset safekeeping in a safe and sound manner with appropriate risk management.
Effective digital asset custody depends on controlling cryptographic keys and protecting them against loss, theft and unauthorized transactions.
U.S. custody requirements vary according to whether crypto assets are securities, the type of financial institution involved and the services being performed.
Under the EU's Markets in Crypto-Assets Regulation (MiCA), custody providers must segregate client crypto assets from their own holdings.
U.S. crypto custody regulation is not a single comprehensive regulatory framework. Banking law, securities rules, anti-money laundering requirements and state licensing can apply simultaneously.
For banks, regulatory clarity increased substantially in 2025. OCC Interpretive Letter 1183 reaffirmed that crypto asset custody and certain distributed ledger technology activities are permissible for national banks and federal savings associations. The OCC also eliminated its earlier crypto-specific supervisory non-objection process.
The Federal Reserve followed in April 2025 by withdrawing the requirement that state member banks provide advance notification before engaging in certain crypto activities. Crypto activities instead became part of the normal supervisory process.
This does not remove regulatory oversight. Banks must still manage operational, legal, cybersecurity, liquidity and third-party risks in a sound manner.
Crypto custody requirements can apply differently across financial institutions, investment managers and digital asset businesses.
| Entity | Main custody considerations |
|---|---|
| National banks and federal savings associations | Safety and soundness, private-key controls, third-party risk and custody operations |
| State member banks | Federal Reserve supervision and applicable state requirements |
| Registered investment advisers | Custody Rule requirements when holding client funds or securities |
| Registered investment companies | Investment Company Act custody requirements |
| Centralized exchanges | AML/KYC, licensing, cybersecurity and customer asset controls |
| Crypto-asset service providers in the EU | MiCA authorization, custody policies and client asset segregation |
Dedicated crypto exchanges may also face state money-transmitter licensing and other regulatory requirements depending on their business model and jurisdiction.
Self custody is different because the customer directly controls the keys rather than delegating control to a bank, exchange or another custodian. This distinction is central to broader explanations of crypto custody and private-key management.
The most important requirement is effective control over assets held for clients.
Federal banking regulators describe crypto asset safekeeping as involving control of cryptographic keys or other sensitive information needed to transfer assets. Banks therefore need governance around private key generation, storage, access, recovery and destruction.
Operational security may use cold storage, hardware security modules, multi-signature arrangements or multi-party computation. These custodial solutions reduce reliance on a single private key or single point of failure.
Banks must also identify risks created by smart contracts, blockchain forks and other characteristics of distributed ledger technology. Ongoing monitoring, transaction controls and incident-response procedures form part of broader risk management.
Custody can be outsourced. The OCC's Interpretive Letter 1184 guidance confirms that banks may outsource permissible crypto custody activities and execution services to third parties, including a sub-custodian, subject to appropriate third-party risk management. Banks may also buy or sell assets held in custody when acting on customer instructions.
Safeguarding client assets is particularly important for investment advisers.
Under the SEC's existing Custody Rule, registered investment advisers with custody of covered client funds or securities generally must maintain those assets with qualified custodians such as eligible banks or registered broker-dealers. Covered assets generally must be kept in a separate client account or an account containing only client assets.
The rule should not be described as requiring every digital asset to be held by a qualified custodian. Whether the requirement applies depends partly on the legal status of the crypto asset and the relevant regulatory framework.
The Securities and Exchange Commission proposed expanding its safeguarding framework in 2023, but the SEC withdrew that proposal in June 2025.
The SEC also issued new crypto-asset securities guidance effective March 23, 2026, further clarifying how federal securities laws apply to different crypto assets and transactions rather than treating every token identically.
Custody can trigger anti money laundering obligations in addition to safekeeping rules. Covered financial intermediaries may need to verify customer identity, monitor crypto transactions and report suspicious activity.
Travel Rule requirements can also require identifying information concerning originators and beneficiaries to accompany qualifying transfers. The precise threshold and obligations depend on the jurisdiction, so there is no single worldwide “Crypto Travel Rule” threshold.
The security rationale is significant. Historical exchange attacks included Mt. Gox, which reported losses involving approximately 850,000 bitcoins in 2014. U.S. congressional testimony later cited more than $1.6 billion stolen from crypto platforms across dozens of hacks since 2011 as of the testimony date. Those figures are historical snapshots, not current cumulative totals.
Modern cryptocurrency custodians consequently use layered cybersecurity, crisis-management procedures, access controls and independent security reviews according to the regulatory regime and risk profile.
Crypto custody has shifted toward greater institutional integration.
The OCC removed crypto-specific pre-approval requirements in 2025 and confirmed that banks can provide custody and execution services using either internal infrastructure or appropriately managed third parties. The Federal Reserve similarly removed its advance-notification expectation for state member banks.
The SEC's Staff Accounting Bulletin 122 also rescinded SAB 121 effective January 30, 2025. Instead of imposing SAB 121's crypto-specific safeguarding accounting treatment, entities now apply established accounting standards when assessing liabilities associated with safeguarding crypto assets.
The GENIUS Act adds another part of the digital-asset regulatory structure through payment stablecoin regulation, but it is not a comprehensive crypto custody law.
In Europe, MiCA provides a more unified system: crypto-asset service providers performing custody must maintain records, protect access methods and legally and operationally segregate customer crypto assets from their own assets.
Custody regulation highlights the difference between assets controlled through a centralized platform and assets managed through self custody. Users considering the latter can compare different key-management structures, including the MPC-based approach used by Gate Vault, where signing authority is distributed rather than placing a complete private key in one location.
Whatever custody model is used, users should assess who controls transaction authorization, how recovery works, what security mechanisms protect the keys and which regulatory protections apply.
Crypto custody regulation governs much more than where crypto assets are stored. Banks, exchanges and other custodians must consider private-key control, asset segregation, AML/KYC, cybersecurity, third-party risk and applicable securities or banking rules. U.S. regulators have moved toward integrating crypto custody into established financial-services supervision, while frameworks such as MiCA impose more explicit crypto-specific custody requirements. The applicable rules still depend heavily on the institution, jurisdiction and legal classification of the assets held.
Yes. The OCC confirms that national banks and federal savings associations may provide crypto custody services in fiduciary or non-fiduciary capacities, subject to applicable law and safe-and-sound banking practices.
Yes. Banks may use third parties or a sub-custodian for permissible crypto asset custody and execution services, but appropriate third-party risk management remains necessary.
Segregation requirements depend on the regulatory framework. SEC custody requirements mandate separate treatment for covered client funds and securities, while MiCA explicitly requires custody providers to segregate clients' crypto assets from their own holdings.
No. The existing Investment Advisers Act Custody Rule applies to client funds and securities. The SEC withdrew its proposed broader Safeguarding Rule in June 2025, so it should not be presented as a current requirement covering every crypto asset.
Effective crypto asset safekeeping requires secure control over the cryptographic keys or other information capable of authorizing transfers. Custodians commonly combine access controls, cold storage, hardware security modules, multi-signature systems or MPC with monitoring and recovery procedures.











