In the wake of the FTX scandal, many crypto investors are taking a deeper look at the security of their assets. To help make an informed choice, we’ve put together this primer on crypto custody and what to look for when choosing a partner.
How the term “custody” gets used in crypto
In traditional finance, a “custodian” refers to an entity that holds the assets on your behalf and protects them against loss, theft, or misuse.
In crypto, however, the term “custody” tends to be used much more loosely. Many “custody” providers simply offer hot wallets and do not actually custody anything. Because they’re connected to the internet, these software solutions do a great job keeping funds liquid, but they also come with greater surface area for hackers to attack. The quality of the security technology backing the wallets can vary widely, too.
Ultimately, many “custody” providers are just giving you a tool to hold the assets yourself; they’re not actually holding them for you.
The concerns don’t end there, however. Even custodians who do hold your assets — including in offline cold storage — may still have the ability to misuse your funds. You hand them the keys and then hope they have your best interests at heart.
So, who do you trust?
Defining “qualified custody”
Unlike the more generic way “custodian” gets used in crypto, a “qualified custodian” means something much more specific, defined by regulators.
A qualified custodian is a regulated entity (like a bank or a trust) that:
-
Has a fiduciary duty to its clients
-
Holds client funds in segregated accounts
-
Meets rigorous regulatory standards and audits that help protect client funds against loss, theft, or misuse
Because whoever holds the keys controls the coins, working with a qualified custodian — rather than a mere “custodian” — becomes critical. You need to be able to trust your custodian, and a qualified custodian has a fiduciary responsibility to look out for your best interests.
Qualified custodians may offer a number of services that provide extra security, including:
-
Cold storage, where the keys are kept offline
-
Remoteness from bankruptcy, so your funds are protected if the company goes under
-
Segregated accounts, so funds are never commingled
-
Backup keys
-
Battle-tested security technology
-
Redundant human processes
-
Insurance against theft, loss, or misuse
Key questions to ask
When evaluating a custodian, here are some key questions to ask:
Wallet security:
-
Do you offer hot and cold wallets both?
-
How many key shares does each wallet consist of, and where are they held?
-
What technology do you use to secure your wallets?
-
Do you have SOC 1 and/or SOC 2 certifications?
Custodial services:
-
Are you a qualified custodian?
-
Where are you regulated?
-
What happens to my funds in case of bankruptcy?
-
What processes do you use to prevent loss, theft, or misuse?
Insurance:
-
Are my funds protected by insurance and under what conditions?
-
How much insurance coverage do you hold?
What BitGo offers
BitGo offers both hot wallets and cold custodial wallets. Many of our clients keep a portion of their funds in hot wallets for greater liquidity and the rest in cold storage for maximum security.
All our wallets divide keys into multiple pieces and require a minimum threshold to sign any transaction, meaning an attacker would need to compromise multiple keys in order to actually gain control.
Moreover, our custodial wallets are provided by our four regulated trust companies, each of which serve as a qualified custodian. We also maintain up to $250M in insurance coverage against loss, theft, and misuse in situations where we hold all keys to a wallet.
To learn more about our services, please contact our team for more information
The latest
All NewsAbout BitGo
BitGo is the digital asset infrastructure company, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage. Since our founding in 2013, we have been focused on accelerating the transition of the financial system to a digital asset economy. With a global presence and multiple regulated entities, BitGo serves thousands of institutions, including many of the industry's top brands, exchanges, and platforms, and millions of retail investors worldwide. For more information, visit www.bitgo.com.
©2026 BitGo, Inc. (collectively with its parent, affiliates, and subsidiaries, “BitGo”). All rights reserved. BitGo Bank & Trust, National Association (“BitGo Bank & Trust”) is a national trust bank chartered and regulated by the Office of the Comptroller of the Currency (OCC). BitGo Bank & Trust is a wholly-owned subsidiary of BitGo Holdings, Inc., a Delaware corporation headquartered in Sioux Falls, South Dakota. Other BitGo entities include BitGo, Inc. and BitGo Prime LLC, each of which is a separately operated affiliate of BitGo Bank & Trust. BitGo does not offer legal, tax, accounting, or investment advisory services. The information contained herein is for informational and marketing purposes only and should not be construed as legal, tax, or investment advice. Digital assets are subject to a high degree of risk, including the possible loss of the entire principal amount invested. Past performance and illustrative examples do not guarantee future results. BitGo Holdings, Inc., BitGo Bank & Trust, BitGo, Inc. and BitGo Prime LLC are not registered broker-dealers and are not members of the Securities Investor Protection Corporation (“SIPC”) or the Financial Industry Regulatory Authority (“FINRA”). Digital assets held in custody are not guaranteed by BitGo and are not subject to the insurance protections of the Federal Deposit Insurance Corporation (“FDIC”) or SIPC. This communication contains forward-looking statements. Forward-looking statements include all statements that are not historical facts. These statements may include words such as “aim,” “anticipate,” “assume,” “believe,” “contemplate,” “continue,” “could,” “estimate,” “expect,” “forecast,” “foreseeable,” “guidance,” “intend,” “likely,” “may,” “objectives,” “outlook,” “plan,” “potentially,” “predict,” “project,” “seek,” “should,” “target,” “will,” “would,” or variations of these terms and similar expressions. Such forward-looking statements are subject to various risks and uncertainties. Accordingly, there are or will be important factors that could cause actual outcomes or results to differ materially from those indicated in these statements. These factors include but are not limited to those described under “Risk Factors” in BitGo Holdings, Inc.’s registration statement on Form S-1, as amended, relating to the initial public offering. These factors should not be construed as exhaustive and should be read in conjunction with the other cautionary statements that are included in the registration statement. Although BitGo believes that the expectations reflected in its forward-looking statements are reasonable, it cannot guarantee future results. BitGo undertakes no obligation to publicly update or review any forward-looking statement, whether as a result of new information, future developments or otherwise, except as required by law.