Custody is the arrangement under which a third party holds the asset backing a token, plus the legal terms deciding whose asset it is when that third party fails. In the US the test is whether the holder is a "qualified custodian" under SEC Rule 206(4)-2 and whether client assets sit in a client-name account or a client-only omnibus. The EU has no qualified custodian label at all, and asks instead whether the firm holds a MiCA authorisation for custody and whether client holdings are segregated from its estate. A structure built for one regime does not answer the other.
Segregation is not an operating practice, it is a claim priority. If the custody arrangement does not place client assets outside the custodian's estate, the holder is an unsecured creditor the day the custodian files, whatever the dashboard said the night before.
Scroll to see the full diagram
What qualified custodian means, and what it does not reach
It is a status list, not a quality rating. Rule 206(4)-2 makes it a fraudulent act for a registered investment adviser with custody of client funds or securities to keep them anywhere other than with a qualified custodian, and the rule names four institution types: a bank or an FDIC-insured savings association, a broker-dealer registered under section 15(b)(1) of the Exchange Act holding the assets in accounts complying with Rule 15c3-3, a futures commission merchant, and a foreign financial institution that customarily holds financial assets for customers and keeps advisory client assets segregated from its proprietary assets.1
Two limits get missed. The rule attaches to the adviser rather than the asset, so it binds registered investment advisers and nobody else. And it reaches funds and securities, so a non-security digital asset held for a client sits outside the text.
The SEC proposed closing both gaps in February 2023. The Safeguarding Advisory Client Assets proposal would extend the regime from funds and securities to any client assets, explicitly including non-security crypto, and would replace the current "maintain" standard with "possession or control."2 As of August 2026 it is still a proposal. Design against the rule in force, and keep a note of what changes if it is adopted.
The EU asks a different question entirely
MiCA has no qualified custodian category. Eligibility runs through authorisation: a firm providing custody and administration of crypto-assets on behalf of clients must be authorised as a crypto-asset service provider for that specific service, and if it passes assets to another firm for the same service, that firm must hold the same authorisation.3 Whether the firm is a bank is beside the point; the authorisation is.
Article 75 is more explicit on segregation than the US rule is. Client crypto-assets must be held separately from the provider's own holdings on the distributed ledger itself, legally segregated from the provider's estate so that its creditors have no recourse in insolvency, and operationally segregated as well. Article 70 adds the general safekeeping duty and requires client funds other than e-money tokens to be placed with a credit institution or central bank by the end of the next business day.3
Then Article 75(8) does something the US rule does not. It makes the provider liable for the loss of crypto-assets or of the means of access to them where the incident is attributable to the provider, capped at the market value of the asset at the time the loss occurred.3 Read the cap. If the asset appreciates between the incident and the payout, the holder absorbs the difference. If it falls, the provider does.
One boundary matters more than any of this for RWA work. MiCA does not apply to crypto-assets qualifying as financial instruments, deposits or funds, so custody of a tokenized bond or fund unit is not a MiCA question at all. It falls to MiFID II and the existing EU securities rules.3 In the structures we have reviewed, founders tokenizing securities in Europe regularly diligence the wrong regime and get clean answers to questions that do not govern them.
Custody of the token is not custody of the asset
An RWA structure has two custody layers and they are usually at different firms under different law. The off-chain asset sits with a securities or commodities custodian, governed by the rules for that asset class. The token and the key material controlling it sit with whoever runs the wallet, governed by the crypto-asset rules. Diligencing one is diligencing half.
The failure modes split the same way. A flawless securities custodian does not help if the minting key is on a laptop, and flawless key management does not help if the bills were never delivered into a segregated account. Ask for both chains of evidence, from both firms, and check that the two registers reconcile to the same number on the same date.
Watch the wording on the crypto leg. Holding a key is not the same as having exclusive control of it. A signature shows that somebody can sign. It does not show that nobody else can, or that a second firm is not counting the same balance in its own reporting.
How segregation gets proven, and on what calendar
A claim of segregation is worth what the evidence behind it is worth, and Rule 206(4)-2 builds three artifacts. First, reporting: the qualified custodian sends an account statement to each client at least quarterly, identifying holdings and every transaction in the period, and the adviser must tell clients to compare it against its own.1
The second is the surprise examination. Client funds and securities are verified by actual examination at least once each calendar year by an independent public accountant, at a time the accountant chooses without notice and irregular from year to year. The accountant files a certificate on Form ADV-E within 120 days, and on finding a material discrepancy notifies the Commission within one business day.1
The third applies when the adviser or a related person is itself the qualified custodian, which is the structure many crypto platforms run. Then the accountant must be PCAOB-registered and inspected, and the adviser must obtain a written internal control report each calendar year, carrying an opinion on whether custodial controls are suitably designed and operating effectively, with holdings reconciled to a custodian other than the adviser or its related person.1
Now do the arithmetic, because the design consequence lives in the intervals rather than in the list of requirements. "At least once during each calendar year" at a date the accountant picks means an examination in January 2026 and the next in December 2027 is fully compliant and leaves close to twenty three months between two verifications. Quarterly statements narrow the gap, but a custodian statement is the custodian reporting on itself. The EU runs a similar interval from the other direction: a statement of position at least once every three months, so up to ninety two days between reads.3 Set your redemption promises against those gaps, not against the marketing page.
Scroll to see the full diagram
Three documented ways custody has failed
FTX is the commingling case. The CFTC's December 2022 complaint alleges that from at least May 2019 through November 2022, FTX customer assets were commingled with Alameda Research's assets and used by Alameda for its own trading, investment and expenses.4 Nothing cryptographic broke. The assets were in the operator's control and the operator spent them.
Prime Trust is the operational case. Nevada's Financial Institutions Division moved a licensed Nevada trust company into receivership in June 2023 after it lost access to legacy wallets and then purchased crypto with customer funds to satisfy withdrawal requests, instead of delivering the segregated assets it was supposed to be holding.5 A charter is a licence to be examined. It is not evidence that the assets are there.
Celsius is the contract case. The FTC's complaint alleges the company took title to customer crypto-assets and transferred deposits into its own proprietary accounts, treating the assets as its property to deploy at its discretion, including to pay operating expenses.6 That one turned on the terms of service. The assets were never segregated, because the contract said they did not have to be.
Three mechanisms: commingling with an affiliate, an operational hole covered with customer money, and a contract that moved ownership on deposit. Only the third shows up in a document review, which is why the artifacts above are the diligence and the representations are not.
What to diligence in a custodian, in order
Start with the entity and the licence. A Nevada trust charter, a New York limited purpose trust charter, a national bank charter and a MiCA authorisation are four different things with four different examination regimes behind them. Ask which legal entity is contracting, which authorisation it holds, and when it was last examined. Then read the licence, not the logo.
Next, the account structure and the related-party map. Are your assets in an account in your own name or in an omnibus holding only client assets, and what does that agreement say happens in insolvency? Is the custodian a related person of the issuer, the adviser or the trading venue? If so, ask for the internal control report and the Form ADV-E rather than the trust page. Ask which sub-custodians are used, and whether each holds the authorisation the primary holds, which the EU requires expressly.3
Finally, control and liability. How many parties are needed to move assets, and can the custodian demonstrate exclusive control of the key material rather than assert it? What do the liability terms cover, and what do they exclude? Under MiCA the cap is statutory. Everywhere else it is whatever the agreement says, and the carve-outs are usually where the value went.
Where custody sits in the rest of the structure
Custody is one of three roles founders collapse into one counterparty. The custodian holds the asset. The transfer agent maintains the register and mints and burns. The issuer is the entity whose promise the holder owns. Keeping them apart is what makes reporting mean anything, because the party holding the asset is then not the party reporting on it. Proof of reserves sits on top of this layer and inherits every weakness in it: an attestation over assets held by a custodian that is a related person of the issuer is an attestation of the group's own numbers.
Bankruptcy remoteness is the other half. Segregation decides whose asset it is. Entity structure decides whose creditors can reach it. Both are jurisdiction-specific and both are tested at the worst possible moment. Neither is a setting inside a contract.
Whether a specific custody arrangement achieves segregation or bankruptcy remoteness in a specific jurisdiction is a fact-specific legal question and belongs with your counsel. This page is reference material for design work. It is not legal advice, and nothing here is a recommendation to buy, sell or hold any asset.
Common questions
What is a qualified custodian?
A qualified custodian is one of four institution types named in SEC Rule 206(4)-2: a bank or FDIC-insured savings association, a registered broker-dealer holding assets in Rule 15c3-3 compliant accounts, a futures commission merchant, or a foreign financial institution that keeps advisory client assets segregated from its proprietary assets.1 It is a status test rather than a quality rating, and it binds registered investment advisers holding client funds and securities.
Does MiCA require a qualified custodian?
No. MiCA has no qualified custodian category. A firm holding crypto-assets for clients in the EU needs authorisation as a crypto-asset service provider for custody and administration specifically, and any firm it delegates to needs the same authorisation. It must also hold client crypto-assets separately on the ledger and legally segregate them from its own estate, so creditors cannot reach them in insolvency.3
How do I know client assets are actually segregated?
Ask for evidence rather than representations. Under Rule 206(4)-2 that means quarterly statements sent by the custodian directly to clients, an annual examination by an independent public accountant at a date the accountant picks without notice, a Form ADV-E filed within 120 days, and, where the adviser or a related person self-custodies, an internal control report reconciling holdings to an outside custodian.1
Can a crypto exchange be its own custodian?
Sometimes, and that is the structure deserving the most scrutiny. Where an adviser or a related person acts as the qualified custodian, Rule 206(4)-2 adds a PCAOB-registered accountant, an annual internal control report, and a requirement that holdings reconcile to a custodian other than the adviser.1 The CFTC's FTX complaint describes what happens when a platform holds customer assets without controls of that kind.4
Is a state trust company a qualified custodian?
A state chartered trust company may meet the bank definition under the Advisers Act, but the charter alone tells you nothing about whether your assets are there. Nevada regulators placed a licensed trust company, Prime Trust, into receivership in June 2023 after it lost access to legacy wallets and used customer funds to buy crypto to cover withdrawals.5 Read the licence, then ask for the control evidence.
See RWA Tokenomics Design for how this applies in practice.
Sources
- 17 C.F.R. § 275.206(4)-2, Custody of funds or securities of clients by investment advisers
Cornell Law School Legal Information Institute, current
Defines qualified custodian, the client-name and client-only account standard, quarterly statements, the annual surprise examination and Form ADV-E, and the internal control report required where an adviser or related person self-custodies. - Safeguarding Advisory Client Assets, Release No. IA-6240 (proposed rule)
U.S. Securities and Exchange Commission, 2023
Proposed February 2023, not adopted as of August 2026. Would extend the custody regime from funds and securities to any client assets, including non-security crypto, and tighten the standard to possession or control. - Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA), Articles 2, 59, 70 and 75
EUR-Lex, Official Journal of the European Union, 2023
Article 75 sets the EU segregation, quarterly statement of position, sub-custodian authorisation and capped-liability rules. Article 70 covers safekeeping and client funds. Article 2(4) removes financial instruments, deposits and funds from MiCA's scope. - CFTC v. Samuel Bankman-Fried, FTX Trading Ltd., Alameda Research LLC, complaint
U.S. Commodity Futures Trading Commission, 2022
Alleges FTX customer assets were commingled with Alameda's from at least May 2019 through November 2022 and used by Alameda for its own trading, investment and expenses. - Prime Trust LLC, Order Appointing Receiver
State of Nevada, Department of Business and Industry, Financial Institutions Division, 2023
State regulator's stated basis for receivership at a licensed Nevada trust company: loss of access to legacy wallets, then use of customer funds to purchase crypto to meet withdrawals. - FTC v. Celsius Network Inc. et al., complaint (S.D.N.Y.)
U.S. Federal Trade Commission, 2023
Alleges Celsius took title to customer crypto-assets and transferred deposits into its proprietary accounts, treating them as its own property to deploy, including to pay operating expenses.
Last reviewed 2026-08
Know the terms but not sure how they apply to your project? That is what an engagement is for. We design, document, and stress-test the whole token economy inside the Tokenomics Data Room.
100+ projects advised. Complete tokenomics in 4 to 6 weeks.