Ask an institution what stops it acting in digital assets and the answer is rarely conviction. It is custody: whether an investment committee, an auditor and an insurer can all be satisfied that someone identifiable holds the asset, and that a court would agree it belongs to the client rather than the firm. The question gets answered with a brand name, the phrase "qualified custodian" and a headline insurance limit. None of the three tells you what you need to know, and one of them is not a status any regulator grants.
Three major custodians on the programme, and no session called custody
Across both days and every stage of the Paris 2026 programme, not one session title contains the word custody, custodian, safekeeping or self-custody. The word appears on the agenda exactly once, inside a company name: Julian Sawyer, billed as chief executive of Zodia Custody.
The nearest thing to a custody panel was How Institutions Actually Access Tokenised Assets, Taostats Stage, Day 2, Wednesday 3 June 2026, 10:00–10:35: Fabian Dori of Sygnum, Sawyer, Matthew Felice Pace of Spectrum Nodes and Moritz Platt of Google, moderated by Xavier Gomez of Vancelian. Titles are as billed. Sawyer took that stage sixteen days after Standard Chartered announced, on 18 May 2026, that shareholders and noteholders had accepted its non-binding offer for Zodia's custody business, subject to regulatory approval. BitGo was represented by chief operating officer Jody Mettler on Privacy and Compliance: Two Sides of the Same Coin. Anchorage Digital's co-founder Diogo Mónica was billed twice, jointly as general partner at Haun Ventures and executive chairman of Anchorage, on a pitch track and a stablecoins panel. And the main-stage session on who controls institutional access seated a bank, an exchange and an asset manager, with no custodian on it.
Custody is treated as plumbing, in vocabulary borrowed from a securities world whose protections do not travel with it. Our piece on who was on stage lists the roster; this one asks what those firms legally are.
"Qualified custodian" is not a licence anyone issues
In the United States the term is a definition inside an adviser rule, 17 CFR 275.206(4)-2, with four limbs unchanged since it was last amended in January 2010: a bank, or an FDIC-insured savings association; a registered broker-dealer holding client assets in customer accounts; a registered futures commission merchant; and a foreign financial institution that customarily holds financial assets and keeps advisory clients' assets segregated from its own.
Notice what is absent. No crypto limb. No trust company limb. No application process. Nobody is designated a qualified custodian by a regulator: an adviser concludes that a counterparty falls inside a limb, and bears the consequence of being wrong. A page asserting "we are a qualified custodian" is publishing an interpretation of a rule, not a permission.
The 2025 development was not a rule either. On 30 September 2025 the SEC's Division of Investment Management issued a no-action letter saying staff would not recommend enforcement where a state trust company is treated as a bank for crypto custody. The relief is conditional, and the conditions do the work: an independent public accountant's internal control report, and a custodial agreement under which the trust company will not "lend, pledge, hypothecate, or rehypothecate" the assets without the client's prior written consent. Staff letters are revocable and confer nothing permanently. The rulemaking behind them is unfinished: the 2023 Safeguarding Rule proposal, File No. S7-04-23, was formally withdrawn as of 17 June 2025, and its successor sits on the Unified Agenda as "Amendments to the Custody Rules", at proposed rule stage with no date and no published text.
Two custodians, one charter, opposite duties
Banking supervision moved faster. OCC Interpretive Letter 1183 of 7 March 2025 rescinded the letter that had imposed a supervisory non-objection process on banks wanting to offer crypto custody, and on 12 December 2025 the OCC conditionally approved five national trust bank charters at once: Circle's First National Digital Currency Bank, Ripple National Trust Bank, BitGo, Fidelity Digital Assets and Paxos.
The BitGo letter converts BitGo Trust Company, a South Dakota trust company in Sioux Falls, into an uninsured national trust bank under charter 25366. It will not take deposits and will not be FDIC insured. Approved activities include custody, settlement, key management, staking, escrow and stablecoin issuance. The load-bearing line: "the Bank will generally provide custody services and escrow services in a fiduciary capacity."
The Fidelity letter, same date, same regulator, same charter type, converts Fidelity Digital Asset Services, a New York trust company, into a national trust bank. Its load-bearing line runs the other way: custody, transfers, trade execution, settlement and reporting "will be provided on a non-fiduciary basis". Staking and stablecoin issuance are non-fiduciary too. The one fiduciary item is asset management for affiliates, which is not a client custody service at all.
Both may accurately call themselves a national trust bank. Neither description tells a client whether anyone owes them a duty of loyalty and care, or merely a contractual promise to keep something safe.
Approved is not open, either. BitGo's letter grants "conditional approval of the Application", attaches seven numbered conditions and five conversion requirements, and ends on a procedural step: only once those are met will the OCC issue a "Conversion Completion Acknowledgement officially authorizing the Bank to commence business as a national trust bank." Fidelity's letter goes further, constituting final approval, but still only to commence business "upon completion of all preopening requirements". BitGo's own blog of 13 December 2025 announces "full, unconditional approval". Where a firm and its regulator describe the same document differently, the regulator's wording is the record. On 5 August 2026 Davis Wright Tremaine recorded that Circle had final approval, granted 10 July 2026, and that it "remains pending for BitGo, Fidelity Digital Assets, and Paxos".
Segregation, and whether a creditor can reach it
If the custodian fails, does the client's asset sit outside the estate? The question decides everything and is asked least. Four jurisdictions answer it with four different legal objects.
Switzerland puts it in statute. FINMA Guidance 01/2026 of 12 January 2026 records that with the entry into force of the DLT blanket act, "comprehensive bankruptcy protection was introduced in Switzerland for cryptobased assets held in custody by third parties", under Article 37d of the Banking Act read with Article 242a of the Debt Enforcement and Bankruptcy Act. The consequence is prudential too: a Swiss bank holding client crypto as segregable custody assets "does not generally have to meet capital requirements for these assets". Delegate abroad and that exemption survives only where the foreign custodian is prudentially supervised and foreign law guarantees the same protection.
The EU puts it in a regulation that defers. MiCA Article 75(7) requires client holdings to be segregated from the provider's own, separately on the distributed ledger and operationally, and legally segregated from its estate "in accordance with applicable law" so creditors have no recourse. That qualifier does the heavy lifting: MiCA does not create the carve-out, it defers to national insolvency law. Article 75(8) caps liability for attributable losses at the market value of the asset lost, at the time the loss occurred.
The UK has not put it anywhere yet. FCA cryptoasset registration is anti-money-laundering supervision and nothing more. In the regulator's own words it "is not a recommendation or endorsement of your business", and being registered "does not mean your customers benefit from the protections of the Financial Ombudsman Service or the Financial Services Compensation Scheme". Zodia Custody's UK credential, announced on 29 July 2021, is that registration. A client-asset regime is coming rather than present: the FCA published policy statements PS26/9 to PS26/13 on 30 June 2026, applications open on 30 September 2026, and the regulated activities begin on 25 October 2027. That is a separate track from PS26/7 on fund tokenisation, published 30 April 2026, which our tokenisation piece cited. The incoming CASS 17.3.3R will require a firm safeguarding cryptoassets to act as trustee under a trust the client has agreed to, and the guidance beside it says plainly that the rule "does not create a statutory trust".
The United States puts it nowhere in particular. The nearest analogue is UCC section 8-503(a), under which financial assets held by a securities intermediary are not its property and are not subject to claims of its creditors. That bites only if the thing held is a "financial asset", and crypto qualifies chiefly through the limb covering property the intermediary "has expressly agreed" to treat as one. Remoteness is manufactured by agreement, not conferred by statute. New York's regulator said as much: its industry letter of 23 January 2023 expects a custodian to take possession "only for the limited purpose of carrying out custody and safekeeping services", and not to establish a debtor-creditor relationship.
Celsius is what happens when the agreement says the opposite. On 4 January 2023 Judge Martin Glenn held that under the Terms of Use, whose transfer of title clause was introduced in version 6 and accepted by 99.86% of Earn account holders, those deposits were property of the bankruptcy estate. Same assets, same wallets. The terms decided who owned them.
Abu Dhabi makes custody a named permission
ADGM writes the vocabulary rather than borrowing it. Providing Custody is one of seven regulated activities for which the FSRA grants permission to use virtual assets, under its guidance (VER07.100625). Custodians send retail clients statements at least monthly and reconcile client holdings at least weekly. Capital is the higher of a base requirement of $250,000 or six months of annual audited expenditure, against 18/52nds of that expenditure for traditional financial assets: on the expenditure limb, close to half as much again for the same clients' assets.
The FSRA declines to require insurance, and says so openly. Insurance is "a second line of defence", so it recommends asset protection policies covering "a minimum of hot wallets". Its taxonomy travels well: Type 1 is an in-house custodial wallet, the firm holding keys as agent; Type 2 is outsourced, the firm wholly responsible while a third party operates; Type 3 is non-custodial, where at no point does the firm have partial or full control. Types 1 and 2 need the permission. Type 3 generally does not, but a firm requiring clients to self-custodise must disclose that "fully and clearly upfront".
Two cautions on UAE announcements. In-principle approval is not a permission: ADGM's notice of 9 June 2026 on Copper ME describes an IPA as a step towards a Financial Services Permission, not the thing itself. And the geography is routinely blurred. Standard Chartered's own UAE digital asset custody service, launched 10 September 2024, is licensed by the DFSA in the Dubai International Financial Centre, not by the FSRA in Abu Dhabi. Our Gulf piece records the ADGM permissions granted since.
Keys, and what key management does not decide
Two designs dominate. A hardware security module holds a whole private key in tamper-resistant hardware and signs inside its own boundary. Multi-party computation never assembles the key at all: shares sit with separate parties and sign jointly, so no whole key exists. Both answer whether one person or one breach can move the assets. Neither answers who owns them if the firm fails.
Underwriters name internal collusion as the chief worry. Aon's specie team, writing in 2021: "the greatest potential for loss is a group of bad apples within an organisation taking off with the keys". Self-custody deserves an honest account. It removes the custodian's insolvency from the risk register and puts operational failure on the holder, with no reconciliation duty, no client-asset rules and often no cover: Relm Insurance notes that "some policies exclude self-custody unless the insured meets rigorous controls". For a regulated fund with an auditor, that ends the conversation. For an operating company with one concentrated position, it does not.
What the insurance figure covers
Custody insurance is not a guarantee of the assets. Aon's description is the clearest available: specie insurers cover "physical loss or physical damage caused by natural named perils, deliberate and dishonest acts, and third-party physical theft". "It's like cash in a vault; the risk is being unable to retrieve its contents. Insurers cover the keys to the vault."
Online assets are more exposed to attack and to employee collusion, so hot wallet cover costs more and usually starts in a crime policy, while cold storage goes to the specie market, where larger limits come at a better rate. Cold storage cover is written on an aggregated basis, so "any one insured is capped at the market capacity, and once the limit is eroded for one client, it is gone". A headline limit is a pool shared with everyone else in the facility, not a per-client entitlement.
Exclusions matter as much. Relm Insurance, a carrier regulated by the Bermuda Monetary Authority, describes cover for external theft and internal collusion, with exclusions that can include the custodian's own negligence, its failure to follow mandated security procedures, and blockchain-wide failures. The most plausible cause of a large loss, a custodian doing its job badly, is among the likeliest carve-outs. And figures need dates: Aon put available market capacity at roughly $700 million, in 2021.
Then the asset starts working
Safekeeping is static. Almost nothing institutions actually do with digital assets is. Both December letters cover staking. Fidelity's says staking is non-fiduciary; BitGo's reserves its fiduciary description for custody and escrow, and says nothing of the kind about staking. Staking moves an asset into a bonded position, with an unbonding period during which it cannot be sold and exposure to slashing. Who bears a slashing loss, who selects validators and whether rewards accrue gross or net are contract terms, not regulatory defaults.
Lending and settlement do something sharper: they suspend the protection itself. The UK's incoming CASS 17.3.4R exempts a firm from the duty to hold as trustee where it provides qualifying cryptoasset lending, and 17.3.5R does the same for settlement of trades executed on a qualifying platform. Firms must calculate what each trust owes each client at least once every business day, and "promptly identify and resolve any discrepancies", but the trust is not a fixed attribute of the account. It is a state the asset moves in and out of, and the client agreed to the switch when it bought the second service.
Corporate actions have no equivalent infrastructure. There is no registrar, record date or proxy agent for a chain split or an airdrop. ADGM at least sets an expectation, that a firm reconcile client balances across a hard fork and keep clients informed. Elsewhere, whether the custodian supports a fork, which side it treats as the asset, and who takes an airdrop are contractual questions. MiCA's liability cap already excludes "a problem inherent in the operation of the distributed ledger that the crypto-asset service provider does not control", a fair description of a contentious fork. Where custody is outsourced, ADGM's Type 2 rule is the default to demand anywhere: the firm you contracted with remains wholly responsible.
What is still unsettled
One word describes four legal objects. Switzerland has bankruptcy remoteness in statute; the EU in a regulation that defers to national insolvency law; the UK, from 25 October 2027, in a private trust the client must agree to; the United States in a contract, and Celsius showed what follows when the contract says otherwise. A custodian operating across all four is not selling one product.
None of this resolves on a stage, which may be why no programme gives it a title. It resolves in an approval letter, a custodial agreement and an insurance schedule. Ask for the letter rather than the press release, ask whether the duty is fiduciary, and ask which services switch the answer off. The Paris 2026 sessions cited here are archived, bound to that edition, and readable at sessions and agenda. The next edition, at the Louvre Abu Dhabi in the Saadiyat Cultural District on 3–4 December 2026, is capped and by application, in a jurisdiction that already names custody as a permission.