SEC Crypto Custody Rules: Who Checks Fund Keys?

18 min read
3 views
Oct 2, 2026

A fund can show a wallet full of tokens and still fail the only test that matters. The SEC just opened the door to self-custody, but the harder question is who checks the keys before coins vanish.

Financial market analysis from 02/10/2026. Market conditions may have changed since publication.

I still remember the first time a portfolio manager told me, with a straight face, that a screenshot of a wallet was “basically an audit.” The balance looked tidy. Ten thousand units, right block, right ticker. What the picture could not show was who else could sign, whether a key had been copied weeks earlier, or whether half those coins were already pledged somewhere off the chain. That gap is exactly why the new crypto custody debate feels less like a paperwork tweak and more like a trust test.

On October 1, the securities regulator proposed a framework that would, in limited cases, let registered advisers and regulated funds hold crypto assets themselves. It would also open a clearer path for state-chartered trust companies to act as custodians. A press note is not a green light. The text is a proposal, comments come later, and the interesting part is not the headline. It is the evidence a firm would have to produce when a transfer cannot be undone and the party watching the assets is also the party holding the keys.

What The Proposal Actually Puts On The Table

The draft sits under both the adviser rulebook and the fund rulebook. That matters more than most summaries admit. An adviser who can reach client coins is already inside a custody problem. A registered fund, or a business development company, has a separate duty around safeguarding portfolio holdings. Treating both as “a fund that now keeps its own keys” flattens two regimes the proposal is trying to address at once.

According to the Commission’s own description, crypto could be held in self-custody only in defined circumstances, and state trust companies could be used as custodians for client and fund crypto. The same package also touches adviser audits and broker-dealer custodial services for regulated funds. None of that is a blank permission slip. As of early October, publication in the Federal Register had not even started the comment clock. The agency has said the public gets 60 days after that publication, not after the news release.

I’ve found that people skip the phrase under certain circumstances because it is boring. It is also the whole rule. An adviser cannot treat a headline as its own exception. Who qualifies, what safeguards are mandatory, and how an examiner verifies them will be settled in the proposing release, the comment file, and whatever final text survives. Until then, existing obligations still sit on the desk.

A press release is a map to a proposed rule, not a substitute for its conditions.

There is a useful chronology here, and it is easy to mash together. Staff previously took a conditional no-action position on certain state-chartered trust companies. A staff letter is not a Commission rule. The current draft invites comment on a wider architecture, including direct control by the adviser or fund. An earlier White House review of the package was a procedural stop, not the moment the rule took effect. If you price the market as if keys can already come home, you are trading a rumor.

Two Older Rules Meet A New Asset

The adviser custody rule cares about clients whose assets the adviser can access. The fund regime adds demands on how portfolio securities and similar investments are kept. Calling a state trust company a magic fix for both sets of questions is the sort of shortcut that looks clean in a slide and falls apart in an exam. The charter tells you which regulator is in the picture. It does not, by itself, prove the firm’s books can name which client owns which coin.

Chairman Paul Atkins has framed the package as a compliant path where the old framework had not kept pace. That is a fair complaint. Existing rules were written before this asset class, and the mismatch has pushed some advice toward arrangements that are harder to inspect. A narrower list of qualified custodians can also pile assets into a handful of shops. One outage, one broad freeze, and a lot of funds feel it together. A conditional route for direct custody might spread that operational risk, but only if the standards are clear enough to test.


A Wallet Balance Is Not A Custody Audit

Suppose a fund says it holds 10,000 units of a token. An auditor can open an address and see 10,000 units at a chosen block. Fine. That proves a balance existed at a point in time. It does not prove the fund exclusively controls the address. It does not prove those units belong to that fund rather than several clients with overlapping claims. And it does not prove the address was not briefly topped up for the snapshot.

One control test is a signed challenge. The custodian signs a unique message from the address without moving the coins. That is evidence of signing ability at the moment of the challenge. It is not evidence of exclusive signing ability, of sound key storage, or of an enforceable customer claim. An on-chain test transfer adds evidence of transaction authority, and it also adds transfer risk. Neither replaces a reconciliation between the general ledger, the customer subledger, the wallet inventory, and third-party confirmations.

That is the first calculation I would want an examiner to demand. For every asset, sum customer and fund entitlements. Reconcile that sum to all controlled addresses, plus unsettled receivables, less transfers already committed. Then repeat the exercise on several randomly chosen dates and look at movements around the cutoff. A one-day equality can be staged. A reproducible ledger with authorization records and exception logs is harder to fake.

  • The chain supplies the outer asset count.
  • The institution supplies the allocation.
  • An independent party has to test the bridge between the two.
  • A screenshot of either side is not the bridge.

There is also a distinction between key control and asset availability that gets lost in product demos. A wallet might require a hardware device, several approvals, and a recovery process. A signer can still be unreachable during a market shock. A recovery signer can become a single point of failure. An upgradeable contract can change the transfer rules underneath the position. An auditor needs governance, access logs, backup policy, change controls, and incident drills, not a balance tile from a dashboard.

Why A Copied Key Changes The Evidence

A bank vault has a door. A crypto private key is information. An employee can copy a signing secret without shrinking the original, and the first visible misuse may be the transfer itself. Hardware security modules and multiparty computation can shrink exposure and split signing authority. They also shift the audit from counting keys to inspecting the devices, the software, the quorum policy, and the admin privileges that produce signatures.

Consider a three-of-five arrangement. It sounds safer than one person with a seed phrase. The label tells you almost nothing. If three shares live in the same cloud tenant, or if administrators share a recovery privilege, one broken boundary can still authorize a send. If signers can change the quorum or the whitelist, the change process is as consequential as the signature. An independent review should ask who can approve, who can rewrite the approval rule, who can restore shares, and who sees those events in real time.

A copied key can move assets while leaving no broken door and no missing receipt.

Self-custody also changes the economics of a mistake. A traditional intermediary can sometimes reverse a bad internal book entry before settlement. A signed on-chain transfer that reaches finality usually cannot be recalled by the adviser. Recovery may depend on the recipient, on a token issuer’s freeze power, or on litigation. Those are different remedies with different clocks. A policy that says the manager will “attempt to recover assets” is not the same thing as a segregated account or an insurer’s enforceable promise.

Perhaps the strongest case for direct control is practical, and I do not think critics should wave it away. Some assets are native to a network and depend on timely staking, governance votes, redemptions, or contract calls. Forcing every operation through an unsuitable third party can add delay and a new concentration risk. The proposal is a response to that mismatch. A fund that gains operational freedom also inherits the job of showing a verifier exactly how it constrains that freedom.

The Scarcity Exception, Not A Standing Election

The self-custody condition looks narrower than the shorthand. A commissioner statement on the draft says an adviser would first determine that no permitted custodian is available for a given crypto asset, then repeat that determination quarterly. That is a scarcity exception. It is not a standing choice between equally available ways to hold a popular coin. It also makes the market for qualified services part of the compliance test. If a custodian later supports the asset, the adviser’s premise may expire.

The repeated determination needs a paper trail, or it is theater. Which custodians were approached? Which asset and network version were offered? What services were requested, and why was each provider unavailable? A shop that can store an ERC-20 token but cannot process staking rewards or a bridge withdrawal may or may not meet the portfolio’s actual need under the eventual text. The adviser should not settle the question by quietly redefining availability as convenience or price.

Quarter-to-quarter comparison is tougher than an opening memo. Imagine an adviser self-custodies a newly issued token in January because no permitted custodian supports its chain. A provider adds support in March. At the next assessment, the adviser should record the provider’s actual service, whether it can safeguard the same asset, and any reason migration is infeasible. Depending on the final rule, a documented plan to move the position may be required. Migration cost, tax friction, and operational risk are real. They cannot be assumed to waive the threshold until someone reads the text.

  1. Name the custodians contacted and the dates.
  2. Describe the asset, the network, and the service requested.
  3. Record why each provider was unavailable, in their words where possible.
  4. Keep rejected bids, not only the ones that support the exception.
  5. Revisit the file every quarter, including after a provider adds support.

Another awkward case is a fund holding a token through a contract that a qualified custodian can view but cannot withdraw from on its own. Does availability mean safekeeping the receipt token, operating the contract, or only storing the asset after redemption? The answer decides whether self-custody is an exception for the asset or an exception for the strategy. Commenters can help by bringing concrete workflows instead of a general plea for flexibility. An examiner will need a repeatable standard, not a fresh definition for each profitable trade.

Rejected bids deserve a folder of their own. If a custodian offered support and the adviser declined because fees were high, the record should say so. If the custodian lacked essential withdrawal functionality, the adviser should show the limitation. Those distinctions help a reviewer decide whether the exception was triggered by unavailable safekeeping or by a business preference. They also protect a firm that made a defensible call in a market that moves fast.

Adviser Clients And Fund Shareholders Are Not The Same Pool

The statement also makes the scope plain: both adviser client assets and regulated fund assets are in view, under limited conditions. That does not collapse their governance. In a fund, the board and the service providers need to understand why an exception applies and when it ends. A client in a separately managed account needs a disclosure that a normal person can read: who signs, and where the claim sits. One firm can be responsible for both pools. The evidence trail should still say which legal pool owns each wallet.


State Trusts Move The Boundary, They Do Not Erase It

A state trust company may specialize in wallet operations and segregation while bringing a regulator, an exam program, and an external corporate entity into the chain. Earlier staff relief covered part of this category on a conditional basis. The October proposal would address it in rulemaking. Neither a charter nor the words “trust company” prove the controls of a particular provider. The charter identifies the oversight regime and the firm on the hook for its obligations.

An adviser using a trust company should ask dull questions. Who owns the wallet? Who is the customer of record? Does the company commingle addresses? How would an insolvency administrator identify client property? The answers can differ even when two dashboards look identical. A contract can say assets are held for clients while the operational books make it hard to say which tokens belong to which client. That is a legal and evidentiary problem, not a throughput problem.

The same inquiry applies if the trust company subcontracts the signing technology. A platform vendor may supply wallet software, recovery services, or transaction screening. The trust company can remain the named custodian while an outsourced party has enough access to interrupt withdrawals or rewrite transaction policy. Regulators and advisers should map the actual control path through subcontractors. The location of a private key and the location of legal responsibility can be different places.

There is a real benefit on the other side. A separate custodian can send independent statements and confirmations to an auditor. Independence is not automatic if the custodian leans on the adviser’s own position files and never tests the underlying wallets. A robust external confirmation identifies addresses or a verifiable inventory, customer entitlements, encumbrances, and the scope of what the custodian actually knows. A generic balance certificate leaves the hard questions open.

ArrangementWhat it can proveWhat it still leaves open
Public address snapshotBalance at one blockExclusive control, liens, allocation
Signed challengeSigning ability at that momentCopied keys, recovery powers, storage
State trust companySeparate entity and oversight regimeSegregation quality, subcontractors, insolvency map
Self-custody exceptionOperational reach for unsupported assetsQuarterly scarcity test, board oversight, recovery drills
Proof-of-reserves noteObserved pool versus a stated figureLiabilities, period control, customer-level claims

Shareholders Sit Two Steps Away From The Coins

In a registered fund, the shareholder owns shares, not a direct claim on a particular bitcoin output or token address. The fund owns or controls the portfolio under its governing documents. Service providers keep custody, accounting, and transfer-agent records. A shareholder who asks where the assets are has to walk those layers. The chain answers only the last stretch of the route.

That is why a custody breakdown can become a pricing event before anyone confirms a loss. If the fund cannot establish the inventory, or its right to move it, net asset value, redemptions, and disclosure all get shaky. Liquidity on an exchange cannot repair a missing key or a disputed property claim. The proposal’s audit and fund-custody changes should be read next to its wallet provisions, because they decide how errors are spotted and told.

Picture a token that trades around the clock while the fund strikes a daily NAV. Between the pricing cut and the audit confirmation, assets can move, smart contracts can change, and a custodian can halt transfers. The controls need a defensible cutoff and a subsequent-event review. A daily wallet snapshot tied to a daily ledger, with exceptions explained, beats a monthly reserve claim. The evidence bar rises when the strategy itself shuttles coins between venues, validators, or contracts.

Earlier product-specific relief for a tokenized money market fund is a useful reminder of category. A registered fund can meet a blockchain-recorded asset without handing every shareholder a wallet. That does not mean every custody pattern for every token has been blessed. Relief for one product and a proposed general rule do not have the same reach.

Control Can Live Inside The Contract

Private keys do not exhaust control. A token issuer can sometimes freeze or reissue balances. A bridge administrator may be able to change how an asset is represented on another chain. A lending protocol may hold collateral that can be liquidated. A staking arrangement may block immediate withdrawal. For custody purposes, an address holding a token is one line in the asset’s control map, not the whole map.

Suppose a fund deposits tokens into a smart contract and receives a receipt token. The wallet no longer holds the original asset. The ledger has to explain the exchange and the fund’s enforceable claim against the contract. The auditor needs to know whether redemption is permissionless, whether an administrator can halt it, and whether the fund has counted the original token and the receipt as two assets. Double counting is easy if reports splice incompatible units.

An examiner can test this with a transaction trace. Start at the fund’s acquisition, follow the token into the contract, inspect the contract’s current state, and reconcile the receipt to the portfolio entry. A chain explorer makes the trace possible. It does not decide whether the accounting classification or the legal characterization is right. Adviser status, tokenization, and custody can sit in the same building without becoming interchangeable jobs.

Staking carries the same lesson. A validator operator may run infrastructure without holding withdrawal credentials. A custodian may hold withdrawal credentials and delegate operational signing. If assets are slashed or locked, the economic loss can arrive without a key theft. A custody rule that recognizes crypto should push firms to document each kind of authority on its own line.

Control map, not a single key:
  Signing authority
  Recovery authority
  Quorum-change authority
  Issuer freeze or reissue
  Contract admin or bridge admin
  Withdrawal credentials versus validator ops

The First Exam Should Follow A Failed Transfer

A dry run exposes more than a polished controls memo. Pick an ordinary withdrawal and simulate a failed signer, a suspected compromised device, and a destination address changed at the last minute. Which approval stops the payment? Which person can switch signers? How long does the fund stay unable to meet its own redemption or settlement obligation? The answer is measurable in minutes, access rights, and signed records. That makes it a useful exam question whether the custodian is outside the firm or the adviser itself.

Now flip it. An unauthorized transfer has already hit the chain. The incident log should show the detection time, the transactions affected, the remaining wallets at risk, and the person authorized to tell the board, the clients, and the regulator. A fund that holds the same asset on three networks has to identify all three, not only the address where the alert fired. If the token contract has an issuer freeze, who calls the issuer, and on what authority? If it does not, the recovery plan cannot promise a freeze.

Key recovery deserves the same skepticism. A recovery path can restore control after a lost device. The party able to invoke it may also be able to seize control from the legitimate holder. A meaningful test covers authorization of the recovery itself, independent notification, and a window in which a disputed change can be stopped. Record the actual outcome of the exercise, including the steps that failed. Saying a wallet is multisignature is not a substitute.

These procedures cost money, and they can make the limited exception unattractive for smaller advisers. That is a legitimate comment. The comparison, though, is with the cost of safeguarding a financial client’s assets, not the price of a consumer hardware wallet. A lighter regime could be proportionate for some assets or structures. Its boundary still needs a reason a client and an examiner can both see.

The Case Against Extra Friction

The agency has said existing rules inhibited advisers from offering crypto-related advice. I think that point deserves a straight reading. An investor may want an adviser with fiduciary duties, documented controls, and public fund disclosures, while ambiguity pushes exposure toward less transparent setups. Broader choice has a real benefit even if no single design fits every portfolio.

The answer is not to assume that extra entities always reduce risk. Compare the full loss path. A specialized custodian can fail by cyberattack, insolvency, bad records, or an outsourced technology break. An adviser can fail by weak segregation, conflicted staff, or a thin recovery plan. A rule can demand evidence from both and let clients see which arrangement they are buying. Comments should focus on the testing burden and the disclosure that turn a custody claim into something an outsider can check.

A firm may point to an insurance policy as proof that assets are safe. The policy is a contract with limits, exclusions, and conditions. It is not a copy of the missing coins. An investor needs the insured party, the covered wallets, the covered events, and the aggregate limit. A policy that protects a service provider’s own losses may give a fund only an indirect claim. A limit shared across many customers can be exhausted before one fund is paid in full. Insurance can soften an incident. It cannot verify routine custody or cure a failed property claim.

Proof Of Reserves Is A Snapshot, Not A Seal

The same caution applies to a proof-of-reserves attestation. It may verify that an observed pool met a stated balance at a particular instant. It may not test liabilities, control across the period, off-chain encumbrances, or customer-level allocation. The scope paragraph matters as much as the large number. If an attestor tests a sample of addresses supplied by management, the report should say so. If it tests the full population against an independent ledger, that is stronger. Neither format quietly becomes a financial-statement audit.

For a fund investor, the assurance stack has at least four layers. On-chain holdings show assets at addresses. Signed challenges or independent custodian records connect an entity to control. Fund books allocate those assets to a portfolio and reflect payables. Legal documents identify the beneficial owner and the rights if a service provider fails. A hole in one layer cannot be patched by doubling the evidence in another. Two extra explorer screenshots do not repair a missing segregation agreement.

  • On-chain balance: what sat at an address.
  • Control evidence: who could sign, and who else might still be able to.
  • Books: which portfolio, which client, which payable.
  • Legal claim: what survives if the service provider fails.

This is where the proposal’s reference to adviser audits matters. Changing the custody perimeter while also changing audit obligations could strengthen the evidence chain, or it could leave gaps between the people testing it. Commenters should ask which independent professional confirms each assertion, and which assertion sits outside the engagement. An investor deserves a plain answer about the coverage of a report before treating its seal as a guarantee.

What October 2 Cannot Settle

The agency has proposed rules. It has not adopted them. Federal Register publication starts the 60-day comment period. A final rule could change conditions, effective dates, and transition provisions. Litigation or later agency action could alter the framework. The market should not price a press release as immediate permission for a particular fund to pull assets out of an existing custodian.

A federal custody rule also does not erase state property law, bankruptcy claims, contract terms, fund governance, or insurance exclusions. A firm’s technical proof of control is useful only beside those legal facts. Nothing in the announcement is public evidence that any particular trust company or adviser fails to safeguard assets. This is a design question for a proposed system.

The most revealing disclosure may be mundane: a schedule that ties client entitlements to verifiable wallets and names who can change the signers. If the final framework makes that record independently testable, it can widen access without asking investors to trust an uninspected box. If reconciliation stays opaque, moving the private key inside the fund mostly moves the room where the same question gets asked.

The decisive test is whether an independent party can reconcile on-chain control, the books, and client entitlements over time.

Custody examination logic

What Investors And Boards Should Watch

Federal Register publication is the date that starts the comment clock. Check the docket deadline, not the day the press note landed. On self-custody, read which advisers or funds qualify, and whether third-party exams, segregation, and recovery tests are mandatory. On state trusts, check the final definition, the exam standards, and the treatment of subcontracted wallet operations.

Fund disclosures are where this becomes readable for a shareholder. Look for specific descriptions of signers, encumbrances, withdrawal gates, and material custody incidents. Then ask the blunter question: can an auditor match customer entitlements to controlled addresses over time, including assets sitting inside contracts? If the answer is a slogan, you do not have a custody program. You have a brochure.

Has the agency already authorized funds to self-custody crypto? No. On October 1 it proposed conditional changes. The eventual requirements depend on the rulemaking, and current obligations remain relevant until a final rule and any transition take effect. A qualified custodian is an entity that meets specified custody-rule criteria for holding assets for advisory clients. Whether a given state trust company qualifies under a future rule depends on the text and on that firm’s facts.

Can a public wallet address prove a fund owns the crypto? It proves the observed balance at a block. Legal ownership, exclusive signing power, customer allocation, and liens need more. Why does a copied key matter if the coins have not moved? A copy may enable a later unauthorized signature without a visible mark when it was made. Firms need controls that limit, detect, and recover from that possibility. A three-of-five wallet can divide authority, but storage locations, recovery powers, and the ability to change the signing rule decide how independent those five signers really are.

Are state trust companies automatically safer than advisers? They add a separate legal entity and an oversight regime. Each provider’s segregation, audit trail, outsourcing, and recovery process still needs testing. When does the comment period close? Sixty days after Federal Register publication. The October 1 release date is not itself the start. What should an investor ask? Who holds signing authority, how holdings reconcile to shareholder records, which assets are locked or pledged, and who independently tests those claims.

In my experience, the firms that handle this well sound almost dull. They can show you a signer schedule, a rejected-bid file, and a drill that failed once and was fixed. The firms that worry me talk about innovation and then hand you a balance certificate. Crypto custody is not a vibe. It is a claim that someone can still move the assets, that no one else quietly can, and that an outsider can check both statements after the market has closed.

This is educational analysis, not investment advice. Figures and rule text reflect filings and reporting available at the time of writing and will move with each disclosure. Nothing here is a recommendation to buy, sell, or hold any security or asset.

❝
The sooner you start properly allocating your money, the sooner you can stop living paycheck to paycheck.
— Dave Ramsey
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>