The U.S. Securities and Exchange Commission is considering a major change to the way investment advisers and regulated funds hold cryptocurrencies.
Under a proposal announced on October 1, certain advisers and funds could be allowed to hold crypto assets directly instead of relying entirely on outside custodians.
But the proposal raises a difficult question.
If the same institution that owns the crypto also controls the private keys, who independently verifies that the assets are really there, properly segregated and protected from misuse?
That question sits at the center of the SEC’s proposed crypto custody framework.
SEC proposes conditional crypto self-custody
The SEC’s proposal covers registered investment advisers and regulated funds, including registered investment companies and business development companies.
Under the proposed framework, crypto assets could be held in self-custody in certain circumstances.
The proposal would also allow state trust companies to serve as custodians for client and fund crypto assets.
However, the SEC has not simply approved unrestricted self-custody.
The proposal still contains conditions that would determine when advisers or funds can use direct custody.
It is also not yet a final rule.
The public will have 60 days to submit comments after the proposal is published in the Federal Register.
That publication date, rather than the SEC’s October 1 announcement, starts the formal comment period.
A crypto wallet balance does not prove ownership
Crypto custody creates challenges that do not exist in exactly the same form with traditional assets.
Suppose a fund says it owns 10,000 tokens.
An auditor could check a blockchain explorer and confirm that a wallet contains 10,000 tokens.
But that does not answer several important questions.
It does not prove that the fund is the only entity capable of controlling the wallet.
It does not prove that the tokens belong exclusively to that fund rather than being associated with multiple customers.
It also does not show whether the crypto has been pledged, borrowed against or otherwise encumbered through an offchain agreement.
A blockchain can show the balance.
It cannot automatically show the legal ownership structure behind that balance.
Auditors need more than a wallet screenshot
One way to demonstrate control over a crypto wallet is through a signed message.
An auditor could ask the custodian to sign a unique message using the private key connected with a particular blockchain address.
This can prove that the institution had signing ability at that moment.
But even that test has limitations.
It does not prove that no one else copied the private key.
It does not show whether key-storage procedures are secure.
And it does not establish which customer legally owns the assets.
A small test transaction can provide further evidence that the wallet can move assets.
But neither test replaces proper accounting reconciliation.
An independent examiner still needs to compare:
- Wallet balances
- General ledger records
- Customer or fund subledgers
- Outstanding transactions
- Third-party confirmations
- Legal ownership records
The strongest evidence comes when all of those records agree consistently over time.
Private keys create a different kind of custody risk
A traditional vault has a physical door.
A crypto private key is simply information.
That makes digital asset custody fundamentally different.
A private key can potentially be copied without removing the original.
An employee or attacker could duplicate signing information without leaving the type of physical evidence normally associated with traditional theft.
The first clear sign of compromise may be an unauthorized blockchain transaction.
That is why institutions often use technologies such as hardware security modules and multiparty computation.
These systems can reduce the risk of a single person controlling a wallet.
But they do not eliminate the need for oversight.
Auditors must understand how signing systems actually work.
Multisignature alone does not guarantee security
A wallet might use a three-of-five signing arrangement, meaning at least three of five authorized signers are required to approve a transaction.
That sounds secure.
But the real level of security depends on how those signing credentials are managed.
If three signing shares are stored in the same cloud account, one security breach could potentially compromise enough credentials to authorize a transaction.
The same risk exists if a single administrator can change wallet policies, reset credentials or alter the signing threshold.
A proper review should therefore examine:
- Who can approve transactions
- Who can modify approval policies
- Who can recover signing credentials
- Where key shares are stored
- How policy changes are logged
- Who receives alerts when sensitive settings change
The number of signers matters, but governance around those signers matters just as much.
Crypto transactions can be difficult to reverse
Another challenge with self-custody is transaction finality.
Traditional financial intermediaries can sometimes reverse an incorrect internal transaction before settlement is completed.
Crypto transfers are different.
Once a valid blockchain transaction reaches finality, an adviser may have no technical way to reverse it.
Recovery may depend on the person receiving the assets voluntarily returning them.
In some cases, a token issuer may have a freeze function.
In other cases, legal action may be necessary.
Those remedies are very different from preventing a transaction from happening in the first place.
That means funds using self-custody need strong approval and recovery procedures before assets are transferred.
Why funds might want direct crypto custody
Despite the risks, self-custody can offer practical advantages.
Some blockchain assets require active interaction with their native networks.
A fund might need to:
- Stake tokens
- Participate in governance
- Redeem blockchain-based assets
- Interact with smart contracts
- Move assets between protocols
- Manage time-sensitive network activity
Routing every action through an outside custodian can introduce delays.
It can also create concentration risk if many investment firms depend on the same small group of service providers.
The SEC proposal appears intended, in part, to address this mismatch between traditional custody rules and blockchain-native assets.
But gaining more operational control also creates additional responsibility.
A fund that controls its own wallets must be able to demonstrate that those controls are secure and independently verifiable.
Self-custody may be a limited exception
The proposed framework appears to place limits on when advisers can use self-custody.
SEC Commissioner Hester Peirce said an adviser would first need to determine that no permitted custodian is available for a particular crypto asset.
That determination would then need to be repeated quarterly.
If adopted in that form, self-custody would not simply become a permanent alternative that any adviser could choose whenever it preferred.
Instead, it could function as an exception when suitable third-party custody is unavailable.
This means advisers may need to document exactly why an external custodian cannot provide the required service.
Advisers may need to prove custody is unavailable
A quarterly review could require advisers to keep detailed records.
For example, a firm may need to document which custodians it contacted.
It may also need to record:
- Which crypto asset required custody
- Which blockchain network was involved
- What services the adviser required
- Whether staking or redemption support was needed
- Why each potential custodian was unsuitable
- Whether a provider later added support
This could become especially important for newly launched cryptocurrencies.
Imagine an adviser self-custodies a token in January because no permitted custodian supports the network.
If a qualified provider begins supporting that token in March, the adviser may need to reassess whether continuing self-custody remains justified.
The exact requirements will depend on the final wording of any adopted rule.
Cost alone may not justify self-custody
The concept of availability could also become important.
Suppose a custodian supports a token but charges high fees.
Would the service count as unavailable?
Or would the adviser simply prefer not to pay the cost?
Those are different situations.
Likewise, a custodian may technically support an asset but not provide an essential feature such as staking, smart-contract withdrawals or network-specific redemption.
The final rule may need to define what meaningful custody availability actually means.
Without a clear standard, different advisers could interpret the requirement differently.
State trust companies could become another custody option
The SEC proposal also addresses state trust companies.
These institutions may provide specialized digital asset custody services while operating within a regulated corporate structure.
Using a trust company can separate the investment adviser from the institution actually holding or controlling the assets.
That can make external verification easier.
However, simply being a trust company does not guarantee that every custody system is safe.
Advisers may still need to examine:
- Who legally owns wallet accounts
- Whether customer assets are segregated
- Whether crypto is held in shared addresses
- How client ownership is recorded
- What happens if the custodian becomes insolvent
- Whether custody technology is outsourced
The legal custodian and the technology provider may not always be the same organization.
Outsourced wallet technology adds another layer
A trust company may use an outside provider for wallet infrastructure.
That provider could supply:
- Key management
- Transaction signing
- Recovery services
- Transaction screening
- Wallet software
The trust company may remain legally responsible for custody even though another company controls important parts of the technology.
Regulators and auditors therefore need to understand the entire control chain.
The location of the private key and the location of legal responsibility can be different.
Fund shareholders do not directly own wallet addresses
For investors in a registered fund, custody is even more indirect.
A shareholder owns shares in the fund.
The shareholder does not usually own a direct claim to a specific Bitcoin output or token wallet.
The fund owns or controls the portfolio assets under its governing documents.
Custodians, accountants, transfer agents and other service providers then maintain various records connected to those holdings.
A blockchain explorer can show what exists in an address.
It cannot by itself establish the shareholder’s legal entitlement to the fund’s assets.
Custody problems can affect a fund before assets are actually stolen
A custody failure does not always begin with confirmed theft.
Imagine a fund cannot prove that it still controls a wallet.
Even before assets are known to be missing, the uncertainty could create problems.
The fund may have difficulty:
- Calculating net asset value
- Processing redemptions
- Confirming portfolio holdings
- Preparing financial statements
- Meeting disclosure obligations
A highly liquid crypto market does not solve the problem if the fund cannot access its own tokens.
That is why the custody proposal also matters for audits and accounting.
Smart contracts can complicate custody further
Holding a crypto token in a wallet is only one form of control.
Assets can also be deposited into smart contracts.
For example, a fund could deposit tokens into a DeFi protocol and receive a receipt token in return.
The original asset is no longer sitting directly in the fund’s wallet.
The accounting system then needs to explain what the fund actually owns.
An auditor may need to determine:
- Where the original token went
- What the receipt token represents
- Whether the original asset can be redeemed
- Whether withdrawals can be paused
- Who can modify the smart contract
- Whether both assets have accidentally been counted
Blockchain transparency helps trace transactions.
It does not automatically determine their accounting or legal treatment.
Staking creates another form of control risk
Staking presents similar challenges.
A validator operator may run the technical infrastructure without possessing the credentials required to withdraw the assets.
A custodian may control withdrawal credentials while delegating validator operations to another provider.
If staked assets are locked, slashed or otherwise restricted, the fund may suffer an economic loss even though no private key has been stolen.
That means crypto custody oversight must consider more than simple possession of a key.
Funds need to document the different forms of authority connected with each asset.
Regulators could test custody by simulating failure
One useful way to evaluate custody systems is through practical testing.
Instead of simply reviewing written policies, examiners could simulate real-world problems.
For example, a fund could be asked to handle a withdrawal while one signer is unavailable.
Another test could involve a potentially compromised signing device.
A third could simulate the destination wallet address changing immediately before approval.
These exercises could reveal:
- Who can stop a payment
- Who can replace a signer
- Whether suspicious changes trigger alerts
- How quickly backup procedures work
- Whether the fund can still meet redemption obligations
Testing failure conditions can reveal weaknesses that may not appear in a policy document.
What happens after an unauthorized transfer?
Regulators may also want funds to demonstrate how they would respond after assets have already moved.
An incident record should identify:
- When the unauthorized transfer was detected
- Which wallets were affected
- Which other wallets may be at risk
- Who must notify management
- When fund directors are informed
- Whether regulators must be contacted
- Whether the token issuer can freeze assets
The recovery plan must also reflect what is technically possible.
A fund should not promise that stolen crypto can be frozen if the relevant blockchain or token has no such capability.
Recovery mechanisms can create their own risks
A recovery feature can help an institution regain access if a signing device is lost.
But the person or organization capable of triggering recovery may also have significant power over the wallet.
That means recovery procedures need strong controls.
A proper system might include independent approvals, notification requirements and safeguards against unauthorized recovery attempts.
The recovery process itself should also be tested periodically.
Simply saying that a wallet uses multisignature or MPC technology is not enough.
Institutions need evidence that the recovery system actually works as intended.
Self-custody could reduce dependence on a small group of providers
There is also an argument in favor of greater custody flexibility.
Existing financial rules were largely created before blockchain assets became widely used.
If advisers can use only a small number of qualified custodians, large amounts of crypto could become concentrated among a few companies.
An outage, security breach or withdrawal freeze at one provider could then affect many funds at the same time.
Conditional self-custody could spread some of that operational risk.
But that only works if advisers themselves can meet strong and independently testable security standards.
External custodians are not risk-free either
Using an outside custodian does not eliminate risk.
A specialist provider can still fail because of:
- Cyberattacks
- Insolvency
- Poor accounting records
- Weak internal controls
- Technology-provider failures
- Incorrect transaction processing
The relevant question is not simply whether self-custody or third-party custody is safer.
It is whether the complete custody arrangement can be independently checked.
Different models may have different risks.
Insurance cannot replace custody controls
Some custodians or investment firms may point to insurance as protection against crypto losses.
Insurance can be valuable, but it does not prove that custody controls are effective.
Policies can contain exclusions and coverage limits.
The fund also needs to know:
- Who is insured
- Which wallets are covered
- Which incidents qualify
- What the total coverage limit is
- Whether multiple customers share the same limit
Insurance may reduce losses after an incident.
It does not verify that customer assets are properly segregated or protected in everyday operations.
Proof of reserves is also limited
Proof-of-reserves reports can provide useful information about crypto holdings.
But they are not necessarily equivalent to a full financial statement audit.
A reserve report may confirm that certain wallets held a particular amount of cryptocurrency at a specific time.
It may not verify:
- Customer liabilities
- Offchain obligations
- Asset ownership throughout the period
- Whether assets were temporarily moved for the snapshot
- Customer-level allocation
- Encumbrances
The scope of the report therefore matters just as much as the headline reserve number.
Investors need several layers of evidence
Reliable crypto custody requires multiple layers of verification.
Onchain records can establish that assets exist at particular addresses.
Signed challenges or custodian confirmations can provide evidence of wallet control.
Accounting records determine how those assets are allocated to particular portfolios or customers.
Legal agreements establish who ultimately owns the assets and what rights they have if a service provider fails.
No single layer is enough on its own.
A wallet screenshot cannot replace proper legal segregation.
Likewise, a legal agreement cannot replace proof that the crypto actually exists.
The SEC proposal is not yet final
The most important point for investors is that the SEC has proposed a framework.
It has not adopted a final rule.
The official comment period begins after publication in the Federal Register and will run for 60 days.
Public feedback could lead to changes in:
- Self-custody eligibility
- Audit requirements
- Custodian definitions
- Transition periods
- Segregation standards
- Recovery requirements
- Compliance deadlines
Even after a final rule is adopted, other legal issues may still matter.
State property law, bankruptcy law, fund governance requirements and insurance contracts could all affect how crypto custody works in practice.
What should investors watch next?
The next major milestone will be publication of the proposal in the Federal Register.
That will establish the official comment deadline.
Investors and industry participants should also watch the final conditions attached to self-custody.
Important questions include whether advisers need independent examinations, how frequently custody arrangements must be tested and what segregation requirements will apply.
The treatment of state trust companies will also be significant.
Regulators may need to clarify how outsourced wallet technology and subcontracted services fit into the custody framework.
For fund investors, disclosures could become especially important.
Clear reporting should explain who controls wallet credentials, whether assets are pledged or locked, how withdrawals work and what happens after a custody incident.
Ultimately, the most important question is not simply who holds the private key.
It is whether an independent party can consistently connect the blockchain balance to the fund’s accounting records, customer entitlements and legal ownership.
If the final framework makes that process transparent and testable, self-custody could give investment firms more flexibility without forcing investors to rely on trust alone.
If that reconciliation remains unclear, the custody problem will simply move from an external provider to the fund itself.
Disclaimer: This article is for informational and educational purposes only and does not constitute legal, financial or investment advice.


































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































