Institutional Crypto Custody
Institutional guide to crypto custody architecture, MPC, multisig, hot and cold storage, legal segregation, governance, recovery and reconciliation.
Reading progress — saved on this device
Institutional custody is the control framework for safeguarding signing authority, approving transfers, segregating client assets and recovering from operational failure. “Cold storage” alone is not a complete control description.
Learning objectives
- Separate key-management technology from governance and legal asset segregation.
- Compare hot, warm, cold, MPC and multisignature models without assuming one is universally superior.
- Assess approval, recovery, sub-custody, reconciliation and insolvency dependencies.
Custody architecture
Institutional custody combines cryptography, people, policy and law. Private keys or signing shares determine who can authorise blockchain transactions, but the surrounding governance decides when those credentials may be used, who can change policy and how exceptional events are handled. A hardware security module or MPC network does not compensate for an administrator who can silently remove approval requirements.
Hot wallets remain online and support rapid transfers, exchange settlement and collateral movement. They face the greatest online attack surface, so institutions generally limit balances and apply transaction limits. Warm architectures add stronger policy controls or partial isolation while preserving operational speed. Cold storage isolates signing more deeply and reduces online compromise risk, but increases latency and recovery complexity.
MPC and multisignature systems are often confused. MPC distributes a signing process across independent shares and can produce a normal blockchain signature. Multisig typically expresses a threshold rule at protocol or smart-contract level. A 3-of-5 threshold sounds diversified, but it is not meaningfully independent if three signers sit in the same office, depend on one cloud account, or report to one administrator with override rights.
Legal segregation is separate from address structure. A custodian can hold client assets in individually labelled wallets, omnibus wallets or sub-custody arrangements. Institutions need to understand whether assets remain beneficially owned by clients, whether they can be rehypothecated, and what happens in custodian insolvency. On-chain visibility cannot answer those legal questions by itself.
Network events create additional policy questions. Forks, airdrops, token migrations, staking rewards and smart-contract upgrades may require the custodian to support new software or claim assets. Contracts should state who has economic entitlement and whether the custodian has discretion not to support technically risky events.
Operational controls should include address whitelisting, dual control, velocity limits, transaction simulation, policy engines, secure change management and independent reconciliation. Reconciliation should compare blockchain balances, internal books, sub-custodian records and client entitlements. A small unexplained difference can signal a booking error, unsupported token or unauthorised transfer and should not be dismissed because total assets appear correct.
Recovery deserves the same attention as normal signing. The organisation should rehearse signer loss, device failure, employee departure, regional outage and compromise scenarios. Recovery material that has never been tested is not a reliable control. Conversely, a recovery path that is too easy can become the attack path.
Worked example
A treasury holds £100 million in crypto and chooses £2 million in an online operational wallet, £18 million in a warm policy-controlled wallet and £80 million in deeply isolated storage. Those percentages are not automatically “safe”. If ordinary settlement repeatedly requires staff to bypass cold procedures, the design is operationally wrong even though 80% is technically cold.
The treasury also uses a 3-of-5 multisig. Three keys are held in the same London office, one by the same company’s cloud administrator and one by an external director. The formal threshold is three, but a single physical or organisational failure could compromise the three London keys. Real independence should be mapped by failure domain, not counted by key number.
Institutional due-diligence workflow
- Map every wallet tier and the maximum value permitted in each.
- Identify who holds signing shares, admin rights, recovery rights and policy-change authority.
- Review legal segregation, sub-custody and rehypothecation terms.
- Test whitelists, limits, transaction review, incident response and recovery exercises.
- Reconcile internal books with chain and sub-custodian records and investigate exceptions.
Common mistakes
- Treating the word “cold” as proof of institutional-grade security.
- Ignoring legal segregation and insolvency treatment because assets are visible on-chain.
- Assuming a high multisig threshold means independent control when signers share failure domains.
- Failing to understand who can change wallet policy or upgrade signing software.
- Designing recovery only after a signer or device has already been lost.
Knowledge checkpoint
- Why is MPC not automatically safer than multisig?
- What is the difference between technical and legal segregation?
- Why should recovery controls be tested before an emergency?
- Which records should custody reconciliation compare?
FAQs
❓ Is MPC safer than multisig?
Not universally. Security depends on implementation, participant independence, administration, recovery and operational controls.
❓ Why keep any assets hot?
Operational liquidity can require rapid transfers. The institutional approach is normally to cap hot exposure and control it rather than assume all assets can remain offline.
❓ Does on-chain segregation guarantee client ownership?
No. Legal ownership and insolvency treatment depend on contracts and applicable law.
❓ What is the most overlooked custody control?
Change and recovery governance: who can alter policy or restore access can be as important as who signs ordinary transactions.
Summary
Institutional custody is a system of cryptographic authority, governance, legal segregation and operational control. Strong design limits online exposure, separates genuine failure domains, controls administrators, rehearses recovery and independently reconciles assets and entitlements. No single technology label substitutes for that complete control map.
Want this in a personalised order?
Take the crypto assessment and get a custom path of 10 modules matched to what you already know. Free, no card required.
Build my path →