Home
» News
»
Institutional Crypto Custody: How Banks Are Storing Digital Assets Safely in 2026
Institutional Crypto Custody: How Banks Are Storing Digital Assets Safely in 2026
Institutional crypto custody is no longer just a specialist service offered by crypto-native firms. Large banks are now providing, building, or partnering for digital-asset custody because asset managers, corporations, funds, and other institutions increasingly want the operational controls, governance, reporting, and legal accountability they already expect from traditional securities custody.
The important point is that “safe custody” does not mean a bank puts Bitcoin or Ether into a physical vault. Crypto assets remain recorded on their blockchain. What the custodian protects is the ability to authorize transactions: the cryptographic keys, signing systems, access policies, recovery procedures, and records that determine who can move the assets.
A conceptual institutional custody setting showing a secure vault, server infrastructure, and Bitcoin and Ether symbols. In real custody operations, the critical protections are cryptographic key control, governance, segregation, and recovery procedures rather than physical coins.
What does a bank actually hold when it “holds” crypto?
A bank custodian generally does not take physical possession of a cryptocurrency because there is no physical instrument to possess. The U.S. Office of the Comptroller of the Currency explained this distinction in its 2020 Interpretive Letter 1170: digital assets exist on a blockchain or distributed ledger, while control is exercised through cryptographic keys. In practical terms, custody means safeguarding the keys or other signing authority that can move those assets.
That distinction matters because the primary loss scenarios are different from traditional vault theft. A custodian must defend against stolen credentials, compromised signing devices, malicious insiders, software vulnerabilities, incorrect transaction approvals, lost keys, protocol changes, cyberattacks, and operational mistakes.
Action for an institution: ask a prospective custodian to describe exactly what it controls. Does it hold complete private keys, use distributed signing, rely on a sub-custodian, or combine several methods? “Bank-grade custody” is not a technical architecture by itself.
Does bank custody mean the bank owns the crypto?
Not necessarily. Custody and ownership are separate concepts. A properly structured custody arrangement is designed so that client assets remain attributable to the client rather than becoming the bank’s trading inventory.
This separation is especially explicit in the European Union’s Markets in Crypto-Assets Regulation. Under MiCA, providers that custody crypto assets for clients must maintain position records, establish a custody policy, segregate client holdings from their own holdings, and take steps so that client crypto assets are legally and operationally separated from the provider’s estate. MiCA also requires procedures for returning assets or access means to clients.
The Basel Committee likewise distinguishes segregated custody activity from a bank simply taking a directional crypto position. Its current cryptoasset standard, effective January 1, 2026, notes that custody services involving segregated client assets generally do not create the same credit, market, or liquidity exposure as owning the crypto, although they still create significant operational risk.
Action for an institution: review the legal custody agreement, not just the product page. Confirm whose name the assets are recorded under, whether client assets are segregated from house assets, what happens in insolvency, and whether the custodian can lend, pledge, rehypothecate, or otherwise use the assets.
What makes the private-key layer institutional-grade?
There is no single approved design used by every bank. Exact implementations are often intentionally not public. However, strong institutional systems usually try to remove the possibility that one employee, one laptop, or one compromised credential can move client assets by itself.
Controls may include hardware security modules, distributed key-generation or signing systems, multi-person approvals, separate administrator and transaction roles, tightly controlled signing environments, allowlisted destination addresses, transaction limits, network segmentation, and tamper-resistant cryptographic hardware. Some institutions also divide signing authority across locations or systems so that a single-site failure does not destroy access.
When a bank or its technology provider relies on cryptographic modules, recognized security standards can provide useful evidence. NIST FIPS 140-3, for example, defines requirements for cryptographic modules covering authentication, physical security, sensitive security-parameter management, self-tests, software security, and lifecycle assurance. FIPS validation alone does not prove that an entire custody platform is secure, but it is one relevant control to evaluate.
Action for an institution: ask which parts of the signing stack are independently validated, which components can access key material, and whether a single administrator can change transaction policies or recover keys without an independent approval path.
Is cold storage enough?
Cold storage remains an important defense because keeping signing keys offline reduces exposure to remote attackers. The OCC’s original crypto-custody guidance described cold wallets as offline storage and contrasted them with internet-connected hot wallets. But “cold” does not automatically mean “safe.”
An offline key can still be lost, mishandled, copied, exposed during recovery, or used by an authorized insider. Institutions also need to process withdrawals, staking events, forks, migrations, and other blockchain-specific operations. That creates a tradeoff between deep offline security and operational availability.
Many institutional designs therefore use tiers. A highly restricted cold layer may protect the bulk of long-term holdings, while smaller operational balances use controlled online or semi-online signing environments. The precise mix depends on withdrawal frequency, supported assets, service-level commitments, and risk appetite.
Action for an institution: do not stop at the question “Do you use cold storage?” Ask what percentage of assets can be online, who can move assets between tiers, how emergency withdrawals are handled, and what controls apply when a key moves from backup or recovery status into active use.
How do banks reduce insider theft and mistaken transfers?
Crypto transactions can be difficult or impossible to reverse after final settlement, so prevention is more important than remediation. Institutional custody therefore depends heavily on separation of duties and transaction governance.
A well-designed process can require multiple approvals from different roles, restrict destinations to pre-approved addresses, delay unusually large transfers, enforce transaction limits, require out-of-band verification, and flag activity that falls outside a client’s normal policy. Internal ledgers should also be reconciled against blockchain records so that discrepancies can be detected quickly.
The Basel Committee treats failures of people, systems, and processes as operational risk. Its 2026 cryptoasset framework explicitly gives loss of a private cryptographic key by a bank as an example of an operational loss and requires banks involved in crypto activities to assess technology, cyber, outsourcing, fraud, data, and resilience risks.
Action for an institution: request a walkthrough of the withdrawal lifecycle from client instruction to blockchain broadcast. The critical question is whether an attacker who compromises one account or one employee can turn that compromise into an irreversible transfer.
What happens when a bank uses a sub-custodian?
A bank-branded custody service does not always mean every cryptographic operation is performed on infrastructure owned by the bank. Banks may use specialized technology providers or sub-custodians for key management, transaction execution, blockchain connectivity, or asset-specific support.
In the United States, the OCC clarified this point in May 2025. Interpretive Letter 1184 confirmed that national banks and federal savings associations may outsource permissible crypto-asset activities, including custody and execution services, subject to appropriate third-party risk management. The bank remains responsible for conducting the activity in a safe and sound manner and in compliance with applicable law.
Sub-custody can improve specialist capability, but it also creates concentration, dependency, outage, contractual, and recovery risk. The institution should know which entity actually controls signing infrastructure and which entity would be responsible after a loss.
Action for an institution: obtain a complete dependency map. Identify the bank, technology provider, sub-custodian, exchange or liquidity venue, blockchain node providers, disaster-recovery sites, and any cloud or security services that are critical to withdrawals.
What regulatory changes have made bank custody easier in the United States?
The U.S. policy environment changed materially in 2025. In March 2025, the OCC reaffirmed that crypto custody is a permissible activity for national banks and federal savings associations and removed a prior supervisory non-objection requirement. Also in March, the FDIC rescinded its prior notification requirement and stated that FDIC-supervised institutions may engage in permissible crypto-related activities without receiving prior FDIC approval, provided they adequately manage the associated risks.
Separately, the SEC’s Staff Accounting Bulletin 122, effective January 30, 2025, rescinded the crypto-safeguarding accounting guidance in SAB 121. That accounting change removed a significant balance-sheet treatment that had complicated some custody business models. It did not, by itself, authorize a bank to custody every crypto asset or override banking, securities, commodities, sanctions, or state laws.
Action for an institution: evaluate regulatory permissions at the entity and jurisdiction level. A global bank may be authorized to provide a service through one subsidiary or country but not another.
Which banks are already providing institutional crypto custody?
Several major banks have publicly documented real custody services rather than only announcing research projects.
BNY announced in October 2022 that its Digital Asset Custody platform was live in the United States, initially allowing select clients to hold and transfer bitcoin and ether. The historical significance is that a globally systemically important bank moved from planning into live digital-asset custody operations.
These examples show that institutional custody is becoming part of mainstream financial infrastructure, but they should not be read as evidence that every bank supports the same assets, jurisdictions, settlement speeds, staking functions, or wallet technologies.
Action for an institution: confirm the current supported-asset list and legal entity directly with the bank before onboarding. Product scope can change faster than a bank’s general marketing materials.
Is insurance a substitute for security controls?
No. Insurance can be useful, but it is not a guarantee that every crypto loss will be reimbursed. Coverage may apply only to specified wallets, causes of loss, internal theft scenarios, or custody locations. Policies can include deductibles, exclusions, sub-limits, and aggregate limits shared across customers.
Institutional clients should also distinguish between the custodian’s own balance-sheet resources, third-party insurance, contractual indemnities, and any statutory customer protection. Traditional deposit insurance should not be assumed to cover crypto assets simply because a bank is the service provider.
Action for an institution: request the insurance summary and relevant contractual language. Compare the maximum covered amount with the value you expect to place in custody, and identify which loss events are explicitly excluded.
What should an institution verify before selecting a bank custodian?
Question
Why it matters
Which legal entity is the custodian?
Licensing, insolvency treatment, and client rights depend on the contracting entity and jurisdiction.
Are client assets legally and operationally segregated?
Segregation reduces the risk that client assets become mixed with the custodian’s own estate.
Who actually controls signing keys?
The bank may operate the signing stack directly or rely on a sub-custodian or technology provider.
Can one person authorize a transfer?
Strong custody should reduce single-person and single-credential failure modes.
How are cold, warm, and online balances governed?
The security-versus-liquidity tradeoff depends on how assets move between storage tiers.
What is the recovery process after key loss or system failure?
Backups are only useful if they are secure, tested, and operationally recoverable.
How are sub-custodians monitored?
Outsourcing transfers work, not accountability or operational dependency.
What independent assurance exists?
Audit reports, control testing, penetration testing, and cryptographic-module validation can provide evidence beyond marketing claims.
What losses are insured or indemnified?
Coverage may be narrower than the headline insurance amount.
How are forks, airdrops, staking, and protocol upgrades handled?
Asset rights and operational procedures vary by blockchain and can affect recoverability and service continuity.
What is still uncertain?
The legal and supervisory direction is clearer than it was several years ago, but institutional crypto custody is not fully standardized. Banks do not disclose all security architecture, jurisdictions apply different insolvency and property-law rules, and blockchain protocols keep changing. New services such as staking, tokenized deposits, stablecoin settlement, and tokenized securities can also introduce risks that do not fit neatly into a simple “cold wallet” model.
There is also no basis for claiming that a bank custodian is automatically safer than every specialist crypto custodian. Banks bring mature governance, compliance, audit, and operational-risk frameworks, while crypto-native custodians may have deeper experience with specific blockchain technologies. The stronger choice depends on the institution’s assets, transaction frequency, legal requirements, recovery needs, and tolerance for third-party concentration.
Action for an institution: treat custody selection as a due-diligence exercise rather than a brand decision. Security should be demonstrated through architecture, governance, contractual protections, operational testing, regulatory status, and evidence of controls.
Bottom line
Banks are making crypto custody safer by applying traditional custody disciplines to a different technical asset: segregating client property, hardening cryptographic signing systems, limiting who can authorize transfers, using offline or tightly controlled key environments, monitoring third parties, reconciling blockchain records, and planning for recovery. Regulators increasingly permit these services, but they continue to expect banks to manage crypto-specific technology and operational risks with the same seriousness applied to other critical financial infrastructure.
For an institutional client, the most useful question is not “Does this bank offer crypto custody?” It is “Exactly how are my assets controlled, segregated, recovered, and protected when something goes wrong?” The quality of the answer is a better indicator of custody safety than the bank’s name alone.