What is crypto custody?
Crypto custody is the process of securely storing and protecting digital assets. Unlike money held in bank accounts, cryptocurrencies are controlled through cryptographic keys — and custody is how those keys are protected while still enabling secure access and transactions.
Why crypto custody matters
Ownership of a digital asset comes down to a single question: who controls the private key that can move it? A private key is a string of characters that authorises transactions on a blockchain. Whoever holds that key can spend the associated assets, and there is no central authority to reverse a mistaken or unauthorised transfer.
That reality shifts responsibility. In traditional banking, an institution can restore access, freeze fraudulent transfers and reverse errors. In digital assets, protecting the key is the security model. Custody exists so that individuals, businesses and institutions can hold digital assets without personally operating the security infrastructure required to protect them.
How crypto custody works
At a high level, a custody stack takes assets, protects the keys that control them, and applies policy checks before any outbound transaction is signed and settled on-chain.
- User assets
- Wallet infrastructure
- Key management
- Transaction authorisation
- Blockchain settlement
Each layer adds a control. Wallet infrastructure separates addresses used for receiving assets from those used for storage. Key management determines where keys live and who can access them. Authorisation defines the rules — whitelists, limits, approvals — that a transaction must satisfy before it is signed. Settlement is the final broadcast to the blockchain, which is public and irreversible.
Private keys explained
A private key is the piece of information that grants control over a blockchain address. In practical terms it is often represented as a seed phrase — a sequence of words that can reconstruct the underlying key.
Losing a private key generally means losing access to the assets it controls. Sharing it, even accidentally, exposes those assets to whoever obtains the copy. Serious custody design is largely about eliminating the situations in which a single person, device or copy can compromise a key.
Types of crypto custody
Self custody
The user holds and manages their own keys, typically through a hardware or software wallet.
- Full control over assets
- No platform dependency
- User carries all operational risk
- Loss of keys means loss of access
Exchange custody
A trading platform stores keys and executes transactions on the user's instructions.
- Convenient for active trading
- Familiar account-style experience
- Platform dependency
- Assets exposed to platform operational and solvency risk
Institutional custody
Professional infrastructure with hardware-based key storage, multi-party approvals and monitoring.
- Security-focused controls
- Governance and separation of duties
- Ongoing monitoring
- Provider dependency
- More formal onboarding and controls
Hot vs cold storage
Most custody stacks split assets between two environments: a small hot layer that stays connected to the internet for day-to-day movement, and a larger cold layer kept offline for reserves.
| Hot wallet | Cold storage |
|---|---|
| Online | Offline |
| Faster transactions | Higher security |
| More exposure to network threats | Reduced exposure |
| Small operating balance | Bulk of reserves |
| Automated policy checks | Manual, multi-party authorisation |
How The Vision Bank approaches custody
The Vision Bank does not directly hold an EMI or VASP licence. Digital-asset custody is delivered through licensed partner institutions, and we act as an agent and distributor of those services. Our operational role focuses on onboarding, access controls, monitoring and reporting.
Custody arrangements are designed to reduce common risks: keys are held with regulated providers using hardware-based storage, sensitive operations require multi-party approval, and reserves are separated from operational funds. These practices reduce risk but do not eliminate it — see the risk disclosure for a full description of residual risks.
Custody risks
No custody model is risk-free. The categories worth understanding are:
- Key compromise — private keys are stolen, copied or misused.
- Operational failures — mistakes in authorisation, deployment or process.
- Counterparty risk — a partner institution suffers insolvency or service disruption.
- Blockchain risks — protocol bugs, forks, or network-level events on public chains.
- Regulatory change — new rules alter what services are available in a jurisdiction.
Where custody sits in the wider stack
Custody is one part of trust in a digital-asset platform. It usually appears alongside transparency reporting — such as proof of reserves — and independent controls. To understand how those pieces fit together, continue with What is proof of reserves?
Frequently asked questions
Is crypto custody the same as owning crypto?
Not exactly. Ownership of a digital asset is controlled by whoever holds the private key that authorises transactions. Custody is the practice of safeguarding those keys — either yourself, or through a service acting on your behalf. When a third party holds the keys, you rely on their operational controls to move your assets.
Who controls crypto in custody?
That depends on the model. In self custody, the user controls the keys directly. In exchange or institutional custody, the platform holds the keys and moves funds only under agreed policies and authorisations. Documentation and terms of service describe how instructions flow and how access is controlled.
Can crypto custody be hacked?
Any system that touches the internet has some level of risk. Well-designed custody stacks reduce the blast radius by keeping most assets offline, requiring multiple approvals for transactions, monitoring flows for anomalies, and separating duties between people. No custody model can promise zero risk.
What happens if I lose my private keys?
In pure self custody, losing the private key or seed phrase usually means losing access to the assets. Custody providers introduce recovery processes, but each process has trade-offs between security and recoverability that users should understand before choosing a model.
Is institutional custody safer than a personal wallet?
Institutional custody typically uses hardware-based key storage, multi-party approvals, monitoring and independent controls that would be difficult for an individual to reproduce. It also introduces platform dependency: you are trusting the provider's policies and operations. The right choice depends on how much you hold and how you use it.
Continue in the Academy
From concept to product
Put what you've learned into practice
Open a The Vision Bank account to access custody, transparency reporting and crypto-backed lending in one regulated interface.