A digital asset fund can name a recognized custodian in its private placement memorandum and still be unable to answer the most important custody question: who can move the assets?
The answer may change by token, wallet, venue, and activity. Long-term holdings may sit in cold storage with a third-party custodian. Assets awaiting execution may remain at an exchange. A manager-controlled wallet may interact with a staking contract or decentralized protocol. Stablecoins may move through a separate treasury workflow. Each location creates a different combination of legal, technical, and counterparty risk.
Institutional diligence therefore tests more than the name of the custodian. A credible digital asset custody architecture must connect three things: the fund’s legal entitlement to each asset, the technical authority required to transfer it, and the operating approvals that control when that authority is used.
“Who has custody?” contains three different questions
In traditional finance, custody arrangements often rely on familiar account structures, intermediaries, and ownership records. Digital assets add a technical control layer that can change the practical answer even when the contract appears clear.
Legal entitlement concerns who owns the asset and what claim the fund has if a custodian, exchange, or other intermediary fails. The relevant record may include a custody agreement, account designation, subcustody terms, books and records, and the treatment of client assets in insolvency.
Technical control concerns which private key, key shares, credentials, devices, or smart-contract permissions can authorize movement. A fund may be the beneficial owner while a custodian has exclusive technical control. In another arrangement, the manager and custodian may each hold part of the signing authority. A protocol position may be controlled through an administrator key or a manager-controlled wallet even though the underlying tokens originated in a custodial account.
Operational authority concerns the people and process permitted to initiate, approve, execute, and verify a transaction. Two employees may be required to approve a withdrawal, but that rule is useful only if the technology enforces it or the custodian will reject an instruction that bypasses it.
Those three answers should be consistent. A side agreement stating that only the custodian can move assets is inaccurate if the manager retains a recovery key. A wallet policy requiring two approvers provides little protection if one person controls both credentials. A blockchain address proves where an asset resides, but not by itself who owns the beneficial interest or how the asset would be treated in an intermediary’s insolvency.
Map every location before choosing the control model
Custody design should begin with an asset-and-wallet inventory rather than a preferred technology. The manager needs to know which assets the fund expects to hold, what the strategy will do with them, and where each activity can occur.
| Asset location | Typical purpose | Core diligence question |
|---|---|---|
| Third-party cold or warm custody | Longer-term holdings and reserves | What legal and technical rights does the custodian have, and how does the fund retrieve assets? |
| Exchange or prime account | Trading and near-term liquidity | How much may remain there, for how long, and who monitors the exposure? |
| Manager-controlled wallet | Protocol access, unsupported assets, or treasury operations | Who holds signing authority, and is the arrangement legally permissible for the manager and asset? |
| Smart contract or staking address | Staking, lending, liquidity, bridging, or other on-chain activity | Which contract risks, withdrawal conditions, and administrative controls replace ordinary custody? |
The inventory should identify the network, token, wallet address or account, legal owner, service provider, signing structure, business purpose, balance limit, reconciliation source, and responsible person. It should also show whether the position can be frozen, bridged, wrapped, staked, lent, or rehypothecated.
This exercise often exposes an offering-document problem. A PPM may state that all digital assets will be maintained with an institutional custodian even though the strategy requires direct interaction with protocols the custodian does not support. The solution is not to hide the exception inside a technical policy. The manager should determine which activities it will actually conduct, whether they are legally and operationally supportable, and how the documents should describe them.
Asset classification belongs in that analysis. A tokenized security, a non-security crypto asset, and cash do not necessarily fall within the same regulatory custody framework. Veritas Global’s discussion of the SEC’s current digital-asset taxonomy explains why token format alone does not resolve the legal treatment. The manager should analyze the assets and its regulatory status rather than applying one custody conclusion to the entire portfolio.
Private-key technology does not replace governance
Cold storage, hardware security modules, multi-signature arrangements, and multi-party computation can reduce particular risks. None establishes a complete control environment on its own.
A multi-signature wallet may require two of three keys, but diligence should identify who controls each key, how the devices are secured, and whether two keys can be accessed from the same place. A multi-party computation arrangement can distribute signing across key shares, but the fund still needs to understand participant authentication, policy configuration, recovery, and whether the provider can change the signing rules. Cold storage limits online exposure but may create delays or concentrated physical and personnel dependencies.
The AIMA Digital Asset Custody Guide treats key generation, key management, governance, cybersecurity, insolvency, operational risk, and service-provider diligence as connected subjects. That is the right frame. The technology should implement a policy that the manager understands and can test.
At minimum, the design should answer:
- Who may request, approve, and execute a transfer?
- How are identities and devices authenticated?
- Does the platform enforce separation of duties?
- Which destination addresses are permitted, and who can change the allowlist?
- What transaction, asset, time, or value limits apply?
- How are new addresses verified outside the original communication channel?
- Who reviews the completed transaction and reconciles it to the fund’s records?
- What happens if a signer leaves, becomes unavailable, or is suspected of compromise?
The answers should reach contractors and service providers as well as employees. A fractional chief operating officer, outsourced trading team, or affiliated technology company can create access and succession issues that a policy written only around the manager’s payroll will miss.
Transfer controls should make a bad instruction difficult to complete
A strong workflow separates initiation, approval, execution, and reconciliation. The same person should not ordinarily be able to create a new destination, authorize the transfer, and mark it as correctly completed without another control.
Address allowlisting can reduce the chance of sending assets to an unauthorized destination, but changes to the allowlist require their own approval and cooling-off logic. Test transfers can help with a new address, although the team should verify that the test and final transfer use the same network and destination. Out-of-band confirmation is useful when payment or wallet instructions change. Transaction limits and time delays may create an opportunity to stop an abnormal movement before final settlement.
Controls also need to account for blockchain mechanics. A mistaken network selection, malicious approval, compromised front end, unlimited token allowance, or bridge interaction can produce a loss even when the destination address was entered correctly. The operating procedure should distinguish a simple transfer from a smart-contract approval or protocol interaction and require the appropriate level of review.
Reconciliation closes the process. On-chain visibility is not a substitute for mapping addresses to the fund’s books, cost records, and beneficial ownership. The manager or administrator should reconcile balances and movements across custodians, venues, wallets, protocols, and the general ledger, investigate differences, and preserve the evidence used.
Custodian diligence must examine the legal bargain
A license, charter, System and Organization Controls report, or insurance certificate can be relevant. None answers every custody risk.
The manager should review the custodian’s authority in the relevant jurisdiction and the services covered by that authority. It should understand whether assets are held in segregated or omnibus wallets, how the provider identifies the fund’s interest, whether subcustodians or affiliates are used, and whether assets may be pledged, lent, or otherwise used. The agreement should be tested for withdrawal rights, service suspension, forks, airdrops, staking, liability standards, indemnities, loss allocation, termination, data access, and return of assets.
Insolvency analysis deserves its own attention. The fund should understand whether it is expected to retain ownership of the assets or hold a contractual claim against the provider, how the records support that position, and which law governs. Marketing language describing assets as “segregated” may not answer how a court or insolvency official would treat the arrangement.
Insurance also requires precision. Coverage may apply only to specified theft events, particular storage environments, employee misconduct, or losses within a policy limit shared across customers. It may exclude protocol failures, unauthorized instructions made with valid credentials, market loss, or insolvency. The relevant question is not whether the custodian has insurance. It is which loss the policy is expected to cover, for whose benefit, and subject to what limits and exclusions.
Independent control reports and certifications require context. A SOC 2 report may describe security and availability controls, while a SOC 1 report may address controls relevant to financial reporting. The scope, exceptions, subservice organizations, user responsibilities, and remediation matter more than the logo on a diligence slide.
IOSCO’s Policy Recommendations for Crypto and Digital Asset Markets emphasize records that establish the nature, amount, location, and ownership status of client assets, together with protection against loss or misuse. Those are useful diligence tests even when a particular manager or provider is outside the recommendations’ direct regulatory context.
Current U.S. custody law still requires an asset-specific analysis
For an investment adviser registered or required to be registered with the SEC, Rule 206(4)-2 under the Investment Advisers Act applies when the adviser has custody of client funds or securities. The rule defines custody to include certain authority to obtain possession and certain roles, including acting as general partner of a pooled vehicle. It also establishes qualified-custodian and verification requirements, with an audit approach available to qualifying pooled investment vehicles that satisfy the rule’s conditions.
That legal rule should not be confused with the broader operational use of “custody” for every token and wallet. Whether a particular digital asset is a fund, security, or neither for purposes of the rule can matter. So can the adviser’s registration status, the identity of the entity holding the asset, and the actual authority to move it.
The SEC proposed a new safeguarding rule in 2023, but withdrew the proposal effective June 17, 2025. It should not be described as current law.
In September 2025, the SEC Division of Investment Management issued a no-action letter concerning certain state trust companies. Based on specified facts, representations, and conditions, the staff said it would not recommend enforcement action if registered advisers or regulated funds treated a qualifying State Trust Company as a bank for custody of covered crypto assets and related cash. The position is narrower than a rule change. It requires analysis of the entity and conditions; it does not make every state-chartered trust company an acceptable custodian for every purpose.
Regulatory form does not eliminate operational diligence. The SEC’s 2024 Galois Capital order found that a registered adviser failed to maintain certain crypto asset securities with a qualified custodian. The order also records that approximately half of the fund’s assets under management were lost in connection with FTX’s collapse. The facts connect legal custody compliance with the commercial danger of leaving substantial fund assets on a trading platform. The SEC’s 2026 examination priorities continue to identify custody among core adviser examination areas.
Trading access should not quietly become the custody policy
Digital asset strategies may need assets available for rapid execution. The custody architecture should define how much may remain on an exchange or other trading venue, which assets qualify, how exposure is measured, when balances are swept, and who can approve an exception. It should also identify the fund’s legal counterparty, any lending or setoff rights, withdrawal controls, and the consequences of a market disruption, compliance hold, cyber incident, or insolvency.
Not every exchange balance is improper, and not every strategy can keep all assets in cold storage. The problem arises when trading convenience produces an exposure the documents, limits, and monitoring never approved.
Incident response must cover loss of authority as well as theft
Custody incidents include more than an unauthorized transfer. The fund may lose access because a key share is unavailable, a custodian freezes withdrawals, a signer departs, a sanctions control blocks the account, or a smart contract will not release assets. The response plan should distinguish key or credential compromise, erroneous transfer, provider outage, protocol exploit, chain disruption, and insider misconduct. It should identify who can suspend activity, preserve evidence, contact providers and insurers, assess legal obligations, and communicate with investors.
Recovery needs its own test. Backup material and break-glass credentials should be protected from the event affecting the primary system, and a quorum should remain available if one principal is absent. A controlled exercise can reveal that an emergency contact has left the custodian or a recovery device is inaccessible before a real incident does.
A custody representation should be supported by evidence
Consider a hypothetical digital asset manager whose PPM says the fund uses institutional third-party custody. In practice, 70 percent of the portfolio remains in a custodian’s cold-storage environment, 20 percent is distributed across two trading venues, and 10 percent moves through a manager-controlled wallet used for staking and protocol activity. One founder can approve venue withdrawals. Two employees control the wallet’s signing shares, but both use devices stored in the same office. The administrator receives monthly custodian statements but does not reconcile the protocol positions.
The problem is not solved by changing the PPM to say that the fund “may use other wallets.” The manager needs to decide which exceptions are part of the strategy, assess whether they are legally permissible, reduce concentrated authority, separate signing devices, establish venue limits, extend reconciliation to on-chain positions, and explain the resulting structure accurately.
An institutional LP may ask for the custody agreement, wallet inventory, access matrix, transfer policy, control reports, insurance summary, incident plan, reconciliation samples, exception log, and evidence of periodic access review. It may also ask the manager to walk through an actual transfer from request to final ledger entry.
That walkthrough is often more revealing than a long cybersecurity questionnaire. It shows whether the written rules survive contact with the system.
Institutional readiness depends on a custody model the fund can explain
There is no single wallet architecture suitable for every digital asset fund. A liquid strategy, venture token fund, staking vehicle, and tokenized-securities fund may need different providers and controls. The common requirement is coherence.
The manager should be able to locate every material asset, establish the fund’s legal interest, show who can move it, demonstrate the intended approvals, and explain what happens when the normal process fails. Once those answers are documented and tested, custody becomes an operating system rather than a name in the PPM.
Veritas Global advises digital asset managers and private fund sponsors on custody disclosures, wallet-control policies, custodian and exchange arrangements, operational diligence, and incident-response governance. If your fund’s strategy requires assets to move among custodians, venues, and on-chain protocols, contact us to review whether the legal documents and control architecture describe the same system.
Disclaimer: This article is provided for general informational purposes only and does not constitute legal, tax, accounting, cybersecurity, investment, or other professional advice. It does not create an attorney-client relationship. Digital asset classification, custody requirements, regulatory status, contractual rights, and technical risks depend on specific facts and jurisdictions. Laws, regulations, guidance, and market practices may change. Readers should consult qualified legal, compliance, tax, accounting, and cybersecurity advisers before acting.