TL;DR:
- Crypto custody regulation requires entities controlling client assets to act as fiduciaries, ensuring asset segregation and compliance with regulators. Proper contract wording and governance are essential to protect assets in insolvency and limit liability, regardless of cryptographic architecture. Engaging experienced legal counsel early helps mitigate risks and navigate the complex, overlapping regulatory landscape.
Crypto custody regulation means a legally enforceable obligation to hold and safeguard client digital assets as a fiduciary, not merely as a technical wallet operator. In the United States, this framework is shaped by the NYDFS, SEC, CFTC, OCC, and applicable state licensing regimes. The practical consequences are immediate: a custodian that fails to meet these standards can trigger licensing violations, expose client assets to seizure as estate property in bankruptcy, and face enforcement action. If you are an investor or a business operating in this space, understanding crypto custody rules is not optional — it is the difference between protected assets and an unsecured claim in a bankruptcy proceeding. When the arrangement is unclear, involving counsel such as Murphyslawcrypto early is the most effective risk-reduction step available.
Table of Contents
- What does crypto custody regulation actually cover?
- Why custody regulation matters to your assets and business
- Which U.S. regulators set crypto custody rules?
- What regulators expect from custodians
- Why contract wording determines your insolvency outcome
- How sub-custodian arrangements create hidden liability
- Operational controls regulators will examine
- Compliance checklist: what to do in the next 90 days
- When to involve a crypto attorney
- What each reader type should do next
- Key Takeaways
- The governance gap most firms miss
- Murphyslawcrypto handles custody compliance and fraud recovery
- Useful sources and further reading
- FAQ
What does crypto custody regulation actually cover?
Crypto custody regulation is triggered the moment a third party gains control over private keys, the ability to sign or move assets, or the power to recover or freeze funds on a client’s behalf. That control, not the label on the service, determines whether custody obligations apply.
Common services that become custodial under U.S. frameworks include:
- Wallet-as-a-service platforms that generate and store keys on behalf of users
- Exchange safekeeping accounts where the platform controls signing authority
- Institutional custody arrangements for funds, family offices, or corporate treasuries
One point that surprises many operators: using multi-party computation (MPC) or multi-signature architecture does not automatically remove custody obligations. Regulators assess control and access, not the cryptographic method. If your firm can unilaterally move or freeze assets, you are likely a custodian under applicable rules.
Why custody regulation matters to your assets and business

The stakes are starkest in insolvency. When a custodian holds assets under a true custodial relationship, those assets remain the client’s property and are not available to satisfy the custodian’s creditors. When the arrangement is structured as a debtor-creditor relationship, the client becomes an unsecured creditor and may recover only cents on the dollar, if anything. The Celsius bankruptcy illustrated this outcome at scale, with retail depositors left as general unsecured creditors while the estate was administered.
For investors, the impact of custody regulations extends beyond insolvency. Regulated custody creates enforceable fraud protections, AML/KYC accountability, and a legal basis for asset tracing and recovery when funds go missing. Fund managers, exchanges, and high-net-worth holders all face different exposure profiles, but the common thread is this: without regulated custody, your legal remedies narrow sharply.
Which U.S. regulators set crypto custody rules?
Understanding crypto regulations requires knowing which agency governs which activity. The landscape is fragmented, and obligations often overlap.
| Regulator | Jurisdictional Scope | Custody Focus |
|---|---|---|
| NYDFS | NY-licensed virtual currency businesses | Segregation, insolvency protections, sub-custody approvals |
| SEC | Broker-dealers, investment advisers, securities tokens | Rule 15c3-3, physical possession standards, DLT assessments |
| CFTC | Commodity derivatives, futures, commodity tokens | Jurisdictional classification, customer fund segregation |
| OCC | National banks and federal thrifts | Third-party risk, fiduciary capacity, key management standards |
| Federal Reserve / FDIC | State member banks, insured institutions | Safekeeping guidance, supervisory equivalence for sub-custodians |
The SEC clarified in 2026 how federal securities laws apply to specific crypto assets, expanding custody obligations for securities-like tokens. Separately, the SEC and CFTC issued a joint interpretation clarifying jurisdictional boundaries for tokens that may qualify as investment contracts, which directly affects which agency’s custody rules apply to a given asset. For broker-dealers specifically, the SEC’s custody statement requires written policies assessing the underlying distributed ledger and contingency plans for blockchain disruptions. For a deeper look at SEC-specific obligations, Murphyslawcrypto’s SEC crypto regulations guide is a practical starting point.
What regulators expect from custodians
Regulators evaluate custody through a fiduciary lens. The technical wallet setup is only one element. The full compliance picture includes:
- Board-level governance: documented oversight, qualified directors, and written policies
- Asset segregation: customer assets separated from corporate assets on internal ledgers and, where required, on-chain
- AML/KYC program: aligned with FATF standards, including customer identity verification and ongoing transaction monitoring
- Capital and insurance: adequate reserves and coverage to absorb operational losses
- Customer disclosures: written agreements that state custodial intent and explain the client’s beneficial interest
Customer agreements must explicitly preserve the client’s equitable and beneficial interest. NYDFS guidance makes clear that ambiguity in these agreements can convert client assets into estate property in insolvency. Suspicious activity reporting obligations also intersect with custody controls; Murphyslawcrypto’s SAR filing guide explains how these requirements apply in practice.
Pro Tip: Regulators routinely reject licensing applications from firms that present custody as a technology infrastructure problem. Institutional governance — written board oversight, segregation of duties, and documented policies — is the decisive factor, not the sophistication of the key management system.
Why contract wording determines your insolvency outcome
The legal distinction between a custodial relationship and a debtor-creditor relationship turns almost entirely on how the agreement is drafted and how assets are titled. A custodial relationship preserves the client’s beneficial ownership; the assets do not become part of the custodian’s estate. A debtor-creditor arrangement does the opposite.
NYDFS guidance requires written customer acknowledgment of custodial terms before transactions occur. When reviewing any custody agreement, check for:
- Account titling that identifies assets as held “for the benefit of” (F/B/O) the client
- Explicit language preserving the client’s equitable and beneficial interest
- Sub-custody disclosure clauses naming any third-party holders
- Segregation representations, both on internal ledgers and on-chain where applicable
The Celsius case is the clearest recent example of what happens when these provisions are absent or ambiguous. Bankruptcy courts look at the four corners of the agreement first.
How sub-custodian arrangements create hidden liability
OCC guidance is unambiguous: banking organizations remain legally responsible for sub-custodian performance. Outsourcing the technical function does not transfer the supervisory obligation. Primary custodians must independently verify sub-custodian key-management controls, not simply rely on representations.
Before approving or continuing a sub-custodian arrangement, a sound due-diligence process covers:
- Confirm the sub-custodian holds applicable licenses and meets supervisory equivalence standards
- Verify that client assets are titled and segregated at the sub-custodian level, not commingled
- Obtain contractual audit rights and exercise them on a defined schedule
- Assess the sub-custodian’s insurance coverage and capital adequacy independently
- Review contingency and wind-down plans for sub-custodian insolvency or operational failure
- Confirm notice and approval obligations for any further sub-delegation
The most common failure point is assuming that a reputable sub-custodian’s internal controls are adequate without independent verification. Regulators expect documented evidence of that verification, not a signed contract alone. For executives, personal liability can attach when third-party oversight is demonstrably inadequate.
Operational controls regulators will examine
The Federal Reserve’s safekeeping guidance identifies control of cryptographic keys as the primary operational risk in crypto custody. A banking organization assumes “control” when no other party, including the customer, can unilaterally transfer the asset. Core controls regulators examine include:
- Private key lifecycle management: generation, storage, rotation, and deletion procedures
- Multi-party approval for transaction signing, with documented authorization thresholds
- Segregation of hot and cold storage, with defined policies for each
- Reconciliation between internal ledgers and on-chain balances, performed on a regular schedule
- Incident response procedures covering blockchain-specific events: forks, 51% attacks, and network disruptions
- Wind-down plans for transferring assets if the custodian ceases operations
The SEC requires written procedures for contingency planning covering blockchain malfunctions and lawful orders. MPC and multisig architectures reduce certain risks but do not satisfy these documentation requirements on their own.
Pro Tip: Keep auditable evidence ready at all times: access logs, reconciliation reports, third-party attestation letters, and test results from incident response drills. Examiners will ask for these on short notice.

Compliance checklist: what to do in the next 90 days
For businesses preparing for regulator review, and for investors evaluating a custodian, the following sequence prioritizes the highest-risk gaps first.
Days 1–30:
- Legal review of all custody agreements for F/B/O titling, beneficial interest language, and sub-custody disclosures
- Verify on-chain and ledger segregation of client assets from corporate assets
- Confirm AML/KYC program meets current FATF standards and covers all customer onboarding
Days 31–60:
4. Audit governance documentation: board minutes, written policies, segregation-of-duties records
5. Review insurance coverage and capital adequacy against regulator expectations
6. Conduct sub-custodian due diligence using the checklist in the prior section
Days 61–90:
7. Test incident response and wind-down procedures; document results
8. Update customer disclosures and obtain written acknowledgments where missing
9. Engage early regulatory counsel before any licensing application or regulator inquiry
Investors should demand written custody disclosures and on-chain segregation evidence from any custodian holding material assets. If a custodian cannot provide both, that is a material red flag.
When to involve a crypto attorney
Legal counsel serves two distinct functions in custody matters: preventive compliance and reactive recovery; for guidance on when to engage expert help, see Cuándo acudir a perito cripto y por qué. The role of a crypto attorney in custody includes drafting agreements that preserve client property interests, advising on licensing applications, structuring third-party risk clauses, and engaging regulators on examination findings.
Call counsel immediately when:
- A custodian files for bankruptcy or announces operational difficulties
- You receive a regulator inquiry, examination notice, or subpoena
- Account movements are unexplained or access is restricted without notice
- Custody agreement language is ambiguous about titling or beneficial interest
Murphyslawcrypto, founded by Liam Murphy, Esq. (Penn Law, formerly Paul Hastings, Selendy Gay, and McKool Smith), has litigated high-profile matters involving Celsius, Terraform Labs, and BitMEX. The firm combines courtroom litigation experience with blockchain forensics and asset tracing, offering a capability set that unregulated “recovery services” cannot match. Knowing when to respond to a regulatory inquiry and how to do so correctly can determine whether an examination becomes an enforcement action.
Pro Tip: Engage counsel before submitting a licensing application, not after a rejection. Regulators form impressions early, and correcting a governance-deficient first submission is significantly harder than presenting a complete application from the start.
What each reader type should do next
Retail investors: Verify that your custody agreement uses F/B/O titling and explicitly preserves your beneficial interest. Request written segregation disclosures. If a custodian is insolvent or access is restricted, contact a licensed crypto attorney for asset tracing options before taking any unilateral action.
Funds and exchanges: Prioritize board-level governance documentation, independent audits of sub-custodian controls, and written approval records for any sub-custody arrangements. The compliance officer’s role in maintaining these records is not administrative — it is a front-line regulatory defense.
Banks and enterprises: Strengthen third-party risk frameworks to meet OCC and Federal Reserve supervisory expectations. Confirm that sub-custodians meet supervisory equivalence standards and that your audit program covers cryptographic key management specifically.
Key Takeaways
Crypto custody regulation imposes a fiduciary duty on any entity that controls private keys or transaction authority on behalf of clients, and contract wording determines whether assets survive a custodian’s insolvency.
| Point | Details |
|---|---|
| Custody triggers fiduciary duty | Controlling private keys or signing authority creates legal obligations beyond technical wallet management. |
| Contract wording is decisive | F/B/O titling and explicit beneficial-interest language determine asset protection in insolvency. |
| Outsourcing does not remove liability | OCC guidance confirms primary custodians remain responsible for sub-custodian performance. |
| Four regulators to watch | NYDFS, SEC, CFTC, and OCC each set distinct custody obligations; obligations often overlap. |
| Murphyslawcrypto for legal action | Liam Murphy, Esq. provides litigation, forensic tracing, and compliance counsel for custody-related matters. |
The governance gap most firms miss
The most persistent mistake in crypto custody is treating it as an engineering problem with a legal wrapper. Founders invest in MPC architecture, cold storage infrastructure, and third-party key management, then submit licensing applications that describe a technology stack with minimal governance documentation. Regulators reject these applications not because the technology is inadequate, but because the governance is absent.
Enforcement patterns in custody-related matters follow a consistent logic: the technical controls may be sound, but the board has no documented oversight role, the policies are generic, and the customer disclosures are ambiguous. When insolvency or fraud occurs, those gaps become the basis for liability and for converting client assets into estate property. The firms that survive regulatory scrutiny are the ones that built governance first and technology second.
The regulatory environment shifted materially in 2025 and 2026, with the SEC’s rescission of SAB 121, new joint SEC-CFTC interpretations, and updated NYDFS guidance on custodial structures. Each of these developments raised compliance demands. Waiting for the next clarification before updating agreements and governance documentation is a losing strategy.
Murphyslawcrypto handles custody compliance and fraud recovery
If your custody arrangement has gaps, or if a custodian’s insolvency has put your assets at risk, Murphyslawcrypto offers the legal services that matter most at this stage.

Liam Murphy, Esq. and the Murphyslawcrypto team provide crypto fraud recovery litigation, regulatory defense, compliance program development, and blockchain forensics and asset tracing. The firm’s litigation docket includes major matters involving Celsius, Terraform Labs, and BitMEX — experience that directly informs how custody disputes are structured and argued. Unlike unregulated recovery services, Murphyslawcrypto is a licensed law firm with real courtroom standing. To start, gather your custody agreements, account statements, and any regulator correspondence, then contact the firm for a consultation through the crypto compliance consulting page.
Useful sources and further reading
Readers who want the primary documents should start here, matched to their specific need:
- Licensing applicants: NYDFS Updated Guidance on Custodial Structures — covers segregation, sub-custody approvals, and insolvency protections
- Broker-dealers: SEC Statement on Custody of Crypto Asset Securities — Rule 15c3-3 application and DLT assessment requirements
- Banks and enterprises: Federal Reserve Crypto-Asset Safekeeping Guidance — third-party risk, key management, and fiduciary capacity
- Token classification: SEC Clarification on Federal Securities Laws and Crypto Assets — token taxonomy and custody obligations for securities-like tokens
- Cross-agency jurisdiction: SEC-CFTC Joint Interpretation Analysis — which agency’s rules apply to which assets
- OCC third-party risk: OCC News Release on Sub-Custodian Risk — supervisory responsibility for outsourced custody functions
FAQ
What does crypto custody regulation mean in plain terms?
Crypto custody regulation is the legal framework that requires any entity controlling digital assets on a client’s behalf to act as a fiduciary, segregate those assets, and meet governance, disclosure, and AML standards set by regulators such as the NYDFS, SEC, CFTC, and OCC.
Does using MPC or multisig remove custody obligations?
No. Regulators assess control and access, not the cryptographic method. If your firm can unilaterally move or freeze client assets, custody obligations apply regardless of the signing architecture.
What happens to my crypto if a custodian goes bankrupt?
If the custody agreement uses proper F/B/O titling and preserves your beneficial interest, your assets should be returned to you. Without that language, a bankruptcy court may treat your assets as estate property, leaving you as an unsecured creditor.
When should a business engage a crypto attorney for custody matters?
Engage counsel before submitting a licensing application, when drafting or revising custody agreements, and immediately upon receiving a regulator inquiry or notice of a custodian’s insolvency. Early engagement consistently produces better outcomes than reactive engagement.
How does Murphyslawcrypto help with custody-related legal problems?
Murphyslawcrypto provides litigation for fraud recovery and insolvency claims, compliance program development, regulatory defense, and blockchain forensics and asset tracing, drawing on Liam Murphy, Esq.’s experience in major matters including Celsius, Terraform Labs, and BitMEX.