Skip to main content
Academy

What is crypto custody?

Crypto custody is the process of securely storing and protecting digital assets. Unlike money held in bank accounts, cryptocurrencies are controlled through cryptographic keys — and custody is how those keys are protected while still enabling secure access and transactions.

Last reviewed: 9 July 20269 min read

Why crypto custody matters

Ownership of a digital asset comes down to a single question: who controls the private key that can move it? A private key is a string of characters that authorises transactions on a blockchain. Whoever holds that key can spend the associated assets, and there is no central authority to reverse a mistaken or unauthorised transfer.

That reality shifts responsibility. In traditional banking, an institution can restore access, freeze fraudulent transfers and reverse errors. In digital assets, protecting the key is the security model. Custody exists so that individuals, businesses and institutions can hold digital assets without personally operating the security infrastructure required to protect them.

How crypto custody works

At a high level, a custody stack takes assets, protects the keys that control them, and applies policy checks before any outbound transaction is signed and settled on-chain.

  1. User assets
  2. Wallet infrastructure
  3. Key management
  4. Transaction authorisation
  5. Blockchain settlement

Each layer adds a control. Wallet infrastructure separates addresses used for receiving assets from those used for storage. Key management determines where keys live and who can access them. Authorisation defines the rules — whitelists, limits, approvals — that a transaction must satisfy before it is signed. Settlement is the final broadcast to the blockchain, which is public and irreversible.

Private keys explained

A private key is the piece of information that grants control over a blockchain address. In practical terms it is often represented as a seed phrase — a sequence of words that can reconstruct the underlying key.

Losing a private key generally means losing access to the assets it controls. Sharing it, even accidentally, exposes those assets to whoever obtains the copy. Serious custody design is largely about eliminating the situations in which a single person, device or copy can compromise a key.

Types of crypto custody

Self custody

The user holds and manages their own keys, typically through a hardware or software wallet.

Advantages
  • Full control over assets
  • No platform dependency
Risks
  • User carries all operational risk
  • Loss of keys means loss of access

Exchange custody

A trading platform stores keys and executes transactions on the user's instructions.

Advantages
  • Convenient for active trading
  • Familiar account-style experience
Risks
  • Platform dependency
  • Assets exposed to platform operational and solvency risk

Institutional custody

Professional infrastructure with hardware-based key storage, multi-party approvals and monitoring.

Advantages
  • Security-focused controls
  • Governance and separation of duties
  • Ongoing monitoring
Risks
  • Provider dependency
  • More formal onboarding and controls

Hot vs cold storage

Most custody stacks split assets between two environments: a small hot layer that stays connected to the internet for day-to-day movement, and a larger cold layer kept offline for reserves.

Hot walletCold storage
OnlineOffline
Faster transactionsHigher security
More exposure to network threatsReduced exposure
Small operating balanceBulk of reserves
Automated policy checksManual, multi-party authorisation

How The Vision Bank approaches custody

The Vision Bank does not directly hold an EMI or VASP licence. Digital-asset custody is delivered through licensed partner institutions, and we act as an agent and distributor of those services. Our operational role focuses on onboarding, access controls, monitoring and reporting.

Custody arrangements are designed to reduce common risks: keys are held with regulated providers using hardware-based storage, sensitive operations require multi-party approval, and reserves are separated from operational funds. These practices reduce risk but do not eliminate it — see the risk disclosure for a full description of residual risks.

Custody risks

No custody model is risk-free. The categories worth understanding are:

  • Key compromise — private keys are stolen, copied or misused.
  • Operational failures — mistakes in authorisation, deployment or process.
  • Counterparty risk — a partner institution suffers insolvency or service disruption.
  • Blockchain risks — protocol bugs, forks, or network-level events on public chains.
  • Regulatory change — new rules alter what services are available in a jurisdiction.
Important
This page is educational and is not investment, legal or tax advice. Digital assets carry significant risk of loss. See /risk and /legal for the full disclosures that apply to The Vision Bank products.

Where custody sits in the wider stack

Custody is one part of trust in a digital-asset platform. It usually appears alongside transparency reporting — such as proof of reserves — and independent controls. To understand how those pieces fit together, continue with What is proof of reserves?

FAQ

Frequently asked questions

Is crypto custody the same as owning crypto?

Not exactly. Ownership of a digital asset is controlled by whoever holds the private key that authorises transactions. Custody is the practice of safeguarding those keys — either yourself, or through a service acting on your behalf. When a third party holds the keys, you rely on their operational controls to move your assets.

Who controls crypto in custody?

That depends on the model. In self custody, the user controls the keys directly. In exchange or institutional custody, the platform holds the keys and moves funds only under agreed policies and authorisations. Documentation and terms of service describe how instructions flow and how access is controlled.

Can crypto custody be hacked?

Any system that touches the internet has some level of risk. Well-designed custody stacks reduce the blast radius by keeping most assets offline, requiring multiple approvals for transactions, monitoring flows for anomalies, and separating duties between people. No custody model can promise zero risk.

What happens if I lose my private keys?

In pure self custody, losing the private key or seed phrase usually means losing access to the assets. Custody providers introduce recovery processes, but each process has trade-offs between security and recoverability that users should understand before choosing a model.

Is institutional custody safer than a personal wallet?

Institutional custody typically uses hardware-based key storage, multi-party approvals, monitoring and independent controls that would be difficult for an individual to reproduce. It also introduces platform dependency: you are trusting the provider's policies and operations. The right choice depends on how much you hold and how you use it.

Open an account

Put what you've learned into practice

Open a The Vision Bank account to access custody, transparency reporting and crypto-backed lending in one regulated interface.