GuideWallets & Custody

Bitcoin Custody for Businesses and Treasuries

~13 min read

Business custody has one question at the centre of it and a lot of paperwork around the edges. The question is who can produce a valid signature, and the follow-up that decides whether your policy is real: what happens when that person resigns, dies, or is standing in an airport with someone else's hand on their shoulder. Everything else, the insurance certificate, the auditor's request list, the board memo, is downstream of those two answers.

Your company needs its own counsel and its own accountants for this, and that is not a formality. The rules below are quoted from primary sources and dated, but how they apply to your entity, your jurisdiction, your regulator and your auditor is a question only your own advisers can answer. Nothing here is legal, accounting, tax or investment advice.

Three columns comparing custody models. Exchange or broker: the platform signs, it can freeze unilaterally, you hold a claim in their ledger, and the main failure is insolvency and the creditor queue. Third party custodian: the custodian signs on instruction, freezing depends on the agreement and the law, you hold a custodial account, and the main failure is the contract read too late. In-house multisig: named officers sign to a quorum, nobody outside can freeze it, you hold coins on the public chain, and the main failure is lost keys or lost people.
Three models, and one row that decides the rest. Note that none of the three columns says "no risk." They relocate the risk to different places, and the job is choosing which failure your business can actually survive.Original diagram by BTCLinks.

The three models, without the sales pitch

Most businesses arrive at Bitcoin through an exchange account because that is where the coins were bought. That is a reasonable place to buy and a poor place to sit. An exchange balance is a claim against a company, recorded in a ledger you cannot audit, and our guide to custodial and non-custodial wallets covers what a bankruptcy court has already said about who owns those coins when the company fails.

The second model is a third-party custodian under a proper custody agreement. This is what most finance teams end up wanting, and it is often the right answer. The important work is reading the agreement rather than the brochure: whether assets are segregated or pooled, what the custodian may do with them, what the withdrawal process requires, and what happens to your coins if the custodian enters an insolvency of its own.

The third is holding your own keys in a quorum. It removes the counterparty entirely and replaces it with an operational burden that a small finance team has to actually carry, forever, including through staff turnover.

Exchange, third-party custodian and in-house multisig compared on control, failure modes, audit and cost
Exchange accountThird-party custodianIn-house multisig
Who signsThe platformThe custodian, on instructionYour officers, to a quorum
Withdrawal can be haltedYes, unilaterallyPer the agreement and applicable lawNo
Key-person riskNone on your sideLow, mostly authorised-signatory adminHigh, and it is the main job
Auditor can confirm balancesPlatform statementCustodian confirmationChain data plus your descriptor
InsuranceUsually the platform's, not yoursNegotiable, read the limitsSpecialist, expensive, narrow
Ongoing costTrading spreadBasis points on assetsHardware, process, and staff time
Fails whenThe platform failsThe contract says something you missedPeople leave and the process was fiction
SuitsBuying, not holdingMost treasuries, most boardsFirms with real operational discipline
The key-person row is the one to argue about internally. Businesses tend to underrate it when the setup is new and everyone who built it still works there.Table by BTCLinks.

What to read in a custody agreement

If you pick the middle column, the agreement is the product. The website is not. Custody offerings that look identical in a comparison table can differ completely in what happens on the worst day, and the difference is written down in a document most finance teams skim once during onboarding.

Read it with one question in mind: if this company failed tomorrow, what would a court be looking at? The Celsius ruling covered in our custody explainer turned on ordinary contract law rather than anything exotic, and the terms said what they said. Ask your counsel to give you a written answer on each of the following, in the agreement's own words rather than the sales team's.

Clauses to locate in a third-party Bitcoin custody agreement and why each matters
Find the clause onThe question it answers
Title and ownershipDoes the agreement say the assets remain yours, or does anything in it transfer title? This is the clause the Celsius holding turned on.
SegregationAre your coins in dedicated addresses, or pooled with other clients in an omnibus arrangement?
Use of assetsMay the custodian lend, pledge, stake or rehypothecate anything, under any circumstances, with or without notice?
Sub-custodiansCan the custodian delegate to a third party, and does its liability survive that delegation?
Regulatory statusWhich entity in the group actually holds the assets, chartered where, and supervised by whom?
Withdrawal mechanicsWho may instruct, what authenticates them, what the stated turnaround is, and on what grounds it can be suspended
InsolvencyWhat the agreement says happens to your assets, and whether counsel agrees a court would read it that way
Termination and exitHow you get everything back, how long it takes, and what it costs to leave
Row three is the one to insist on in writing. "We do not lend client assets" as a statement on a webpage and a clause prohibiting it in the agreement you signed are different things, and only one of them is enforceable.Table by BTCLinks.

What "qualified custodian" actually means

This phrase does more work in sales decks than it does in law, so it is worth being exact about it.

Qualified custodian is a defined term in the SEC's custody rule, 17 CFR 275.206(4)-2, which sits under the Investment Advisers Act. That rule governs a specific situation: an investment adviser registered or required to be registered under section 203 having custody of client funds or securities. It makes it a fraudulent, deceptive or manipulative act under section 206(4) to have that custody unless a qualified custodian maintains the assets, in a separate account for each client or in accounts containing only clients' assets, along with notice and account-statement conditions.

Read what that does and does not cover. If your company holds bitcoin on its own balance sheet, you are not an adviser and these are not client assets, so the rule does not apply to you at all. A custodian describing itself as qualified is telling you something about its regulatory category. It is not a certificate that your treasury is safe, and it is not a requirement your operating company is failing to meet.

The four categories of qualified custodian under 17 CFR 275.206(4)-2(d)(6)
Category in paragraph (d)(6)What the rule requires
A bank or savings associationA bank as defined in Advisers Act section 202(a)(2), or an FDIC-insured savings association
A registered broker-dealerRegistered under section 15(b)(1) of the Exchange Act, holding the client assets in customer accounts
A registered futures commission merchantRegistered under section 4f(a) of the Commodity Exchange Act, and only for client funds, security futures and related securities
A foreign financial institutionOne that customarily holds financial assets for customers, keeping advisory clients' assets segregated from its proprietary assets
Four categories, and no fifth. Notice that "crypto custodian" is not one of them, which is precisely why the question of whether a given trust company fits inside category one has taken up so much of the last few years.Table by BTCLinks from 17 CFR 275.206(4)-2(d)(6), read from the eCFR and verified 2026-07-29.

What actually changed, and what did not

Three developments matter, and none of them is the one people usually cite.

First, the SEC's 2023 Safeguarding Advisory Client Assets proposal, which would have pulled a much wider set of client assets into the qualified-custodian framework, was formally withdrawn. The Commission withdrew a group of proposals issued between March 2022 and November 2023 and stated that it does not intend to issue final rules on them, and that it would issue a new proposed rule if it decides to revisit the area. The expansion people planned around did not happen.

Second, on 30 September 2025 the staff of the Division of Investment Management issued a no-action letter about registered advisers and regulated funds holding crypto assets with certain state-chartered trust companies. Commissioner Hester Peirce's statement the same day is worth reading precisely, because it is more careful than the coverage was: the letter "does not expand the definition of a permissible custodian," and the custody provisions it addresses apply only to "funds and securities" under the Advisers Act and "securities and similar investments" under the 1940 Act.

Third, and this one does touch ordinary companies, the SEC rescinded Staff Accounting Bulletin 121 through SAB 122, issued 23 January 2025 and effective 30 January 2025. SAB 121 had required an entity safeguarding crypto assets for platform users to put a liability and a corresponding asset on its own balance sheet. Its removal changed the economics of offering custody, which is why the set of institutions willing to do it has been widening since.

Designing a quorum that survives your staff

A worked 2-of-3 business quorum. Key A is held by a finance officer on a device in the head office safe. Key B is held by a second officer in a deposit box in another city. Key C is held offline by a director or counsel in a third location. Any two of the three can sign. Below, the departure path: the device is surrendered and its key treated as compromised, the remaining two sign to move the balance to a new quorum, and the old descriptor is retired with the new one backed up in three places. A closing band warns that the descriptor must be backed up separately because a quorum cannot be rebuilt from seed phrases alone.
The lower half is the part most policies leave out, and it is the part that gets used. A quorum nobody has ever rotated is a quorum nobody knows how to rotate.Original diagram by BTCLinks. Setup mechanics in our multisig guide.

A quorum answers the question a single hardware wallet cannot: how do you stop any one person from moving the money, without creating a situation where one person leaving strands it? A 2-of-3 is the usual starting shape for a small company, with 3-of-5 for larger balances and larger boards. The mechanics of building one are in our multisig setup guide.

Three design rules matter more than the specific numbers. Separate the keys by person and by building, because a quorum where all three devices live in one safe is a single point of failure with extra steps. Give one key to someone outside day-to-day operations, typically a director or outside counsel, so that a dispute among the executives cannot deadlock the treasury. And write the descriptor down. A multisig wallet cannot be reconstructed from the seed phrases alone; you also need the descriptor that says which keys, in what arrangement, at what derivation. Businesses have lost access to coins they still fully controlled because that file existed in one place and that place was a laptop.

Key-person risk is the whole game

Ask a finance team who holds the keys and you will get names. Ask what happens to those keys in each of the situations below and you will find out whether there is a policy or a habit.

Key-person scenarios and the control that should already exist for each
The eventWhat must already be true
A key holder resignsDevice surrendered, key treated as compromised, balance rotated to a fresh quorum within a stated number of days
A key holder is dismissed for causeThe same, executed the same day, and a quorum that still functions without them
A key holder diesA named successor, and access to the location, not just to the device
A key holder is coercedA quorum they cannot satisfy alone, and a second approver who can refuse
Two key holders are on the same flightA travel policy that prevents it, or a quorum that tolerates it
The office burns downBackups in a different building, tested, not assumed
The person who built the setup leavesWritten procedure a competent stranger can execute, and someone else who has done a dry run
The auditor asks for proof of controlA rehearsed signing demonstration, and the descriptor available to show
Row seven is the one that quietly kills treasury programmes. If the only person who understands the setup is the person who built it, the company does not have custody, that individual does.Table by BTCLinks.

Two operational habits are worth adopting on day one. Rehearse a recovery on an empty wallet before funding anything, with the people who will actually do it under pressure rather than the person who designed it. And keep the signing procedure boring and written, because our threat-model guide makes the point that most losses at this scale start with a convincing message and a rushed approval, not with cryptography. Succession, including the version where nobody is available, is covered in our guide to inheritance planning, and the underlying storage methods in the cold storage guide.

The accounting changed, and it changed in your favour

If your reference point for corporate Bitcoin accounting is the old impairment model, update it. That model treated holdings as indefinite-lived intangible assets: you tested for impairment, wrote the carrying amount down to fair value when it fell, and were prohibited from writing it back up when it recovered. A company could hold coins worth far more than the balance sheet said and have no way to report it.

A stylised chart, not real market data. A fair value line rises and falls across eight reporting periods and ends above where it started. Under the old impairment-only model the carrying amount ratchets downward at each new low and never recovers, so the holding is still carried near its lowest point at the end. Under ASU 2023-08 the carrying amount is remeasured to fair value each period and tracks the line exactly.
Stylised shapes, not market data. The red line is the part that made finance teams reluctant: an asset that recovered fully still sat on the balance sheet at its worst moment, permanently.Original diagram by BTCLinks, from FASB ASU 2023-08 and the impairment model it replaced.

FASB Accounting Standards Update 2023-08 added Subtopic 350-60 and replaced that. Crypto assets in scope are measured at fair value in the statement of financial position each reporting period, with changes from remeasurement recognised in net income. Presentation is specified too: crypto assets measured at fair value appear separately from other intangible assets on the balance sheet, and remeasurement changes appear separately from changes in other intangibles in the income statement.

Scope is narrower than "crypto" and worth checking against your actual holdings. Subtopic 350-60 applies to assets that meet all six criteria: they meet the definition of intangible assets; do not provide the holder with enforceable rights to or claims on underlying goods, services or other assets; are created or reside on a distributed ledger based on blockchain or similar technology; are secured through cryptography; are fungible; and are not created or issued by the reporting entity or its related parties. Bitcoin sits comfortably inside all six. Plenty of other tokens do not.

The update is effective for all entities for fiscal years beginning after 15 December 2024, including interim periods within those fiscal years. Early adoption was permitted for statements not yet issued, and adoption requires a cumulative-effect adjustment to the opening balance of retained earnings for the annual period of adoption.

What you now have to disclose

Disclosure requirements for crypto assets under Subtopic 350-60
WhenWhat you disclose
Interim and annualFor each significant holding, judged by fair value: the name of the asset, its cost basis, its fair value, and the number of units held
Interim and annualAggregated cost bases and fair values for the holdings that are not individually significant
AnnualThe method used to determine cost basis for computing gains and losses, such as first-in first-out, specific identification or average cost
AnnualThe income statement line item where gains and losses sit, if they are not presented separately
AnnualA reconciliation, in the aggregate, of activity from opening to closing balances, with the changes broken out
Row three has an operational consequence people miss: you must pick a cost basis method and be able to defend it, which means your custody records have to support it from the first purchase rather than from the first audit.Table by BTCLinks from FASB ASU 2023-08, paragraphs 350-60-50-1 through 50-3, verified 2026-07-29.

Tax follows a separate track from the accounting, and the two answer different questions. Our Bitcoin tax guide covers the US federal treatment of disposals and the wallet-by-wallet basis rule that took effect in 2025, which interacts directly with the cost-basis method you choose above.

Insurance, and the five questions that decide whether it helps

Custody insurance is real, and it is narrower than most summaries of it. Rather than repeat figures that change per policy and per client, here are the questions that determine whether a certificate is worth anything to your company.

Five questions that determine whether a custody insurance certificate protects your company
AskWhy it decides the outcome
Whose policy is it?A custodian's cover protects the custodian. Your recovery may run through a contractual claim against them, not a direct claim on the insurer.
Is your entity a named insured?If not, you are relying on somebody else's relationship with their carrier, and on their willingness to claim.
Is the limit per client or shared?A large aggregate spread across every client of a large custodian can be a small number in your particular incident.
What is actually covered?Cold storage, hot wallets and assets in transit are usually treated differently, and the difference is where the balance sits.
What is excluded?Insider theft, key loss, coerced but valid signatures, and protocol failure. Between them those cover most of how businesses really lose coins.
Read the last row against the key-person table above. A policy that responds only when an outsider breaks in does not cover the scenarios most likely to happen to you.Table by BTCLinks.

Ask for the certificate and the exclusions, not the marketing page, and have your broker read both. A policy that pays only when an outsider breaks in does not respond to the scenarios in the key-person table above.

Proof of reserves, for your own board

If you use a custodian, a reserves attestation is worth having and proves less than the phrase suggests. It shows that assets existed in addresses the custodian controlled at a moment in time. It does not show whether those assets were pledged elsewhere, borrowed for the snapshot, or matched by liabilities, unless the liability side is included and independently verified. Judge an attestation on three properties: does it cover both sides, is it repeated often enough that a single snapshot cannot be staged, and is the party performing it independent.

If you self-custody, you can do something a custodian cannot offer: demonstrate control directly. Signing a message from the treasury addresses, or making a small test spend in front of the auditor, proves the company holds the keys in a way no statement does. Pair that with the descriptor and a block explorer and the balance becomes independently checkable by anyone your board chooses to appoint. That is a genuine advantage of the in-house model and it is worth putting in the audit plan rather than discovering under time pressure.

A minimum viable custody policy

If you write nothing else, write this. It is one page, and a competent stranger should be able to run the treasury from it.

Minimum contents of a business Bitcoin custody policy
The clauseWhat it has to say
Signers and quorumNamed roles, the threshold, and who may never be a second approver for the same instruction
Key locationsWhich building each key sits in, and who has physical access to that room
Approval pathWho verifies the destination address, on which device screen, and the rule that urgency is grounds to stop
Departure triggerThe event, the rotation deadline in days, and who executes it
Descriptor backupsThree locations, named, at least one outside the primary building
RehearsalAn annual recovery drill on an empty wallet, with a written outcome and a named owner
Cost basis methodThe method chosen for 350-60-50-2, and where the supporting records live
AccountabilityThe role, not the person, answerable when any line above is not done
Eight lines. If drafting them exposes a question nobody can answer, that question is the actual state of your custody programme, and finding it now is cheaper than finding it during an audit.Table by BTCLinks. Cost basis clause per FASB ASU 2023-08, paragraph 350-60-50-2.

That document is short, and a competent stranger should be able to execute the whole treasury operation from it. If yours reads as reassurance rather than instructions, it is not a policy yet. If you are still deciding whether to hold coins directly at all, the property comparison in our piece on Bitcoin versus gold covers what direct custody buys you, and our guide to spot Bitcoin ETFs covers the version where a fund holds the coins and you hold a security instead.

Sources

General information only, not legal, accounting, tax or investment advice, and not a substitute for your own professional advisers. Rules cited are US federal and current as at the verification dates shown. Some links on this site are affiliate links.