Bitcoin Custody for Businesses and Treasuries
Business custody has one question at the centre of it and a lot of paperwork around the edges. The question is who can produce a valid signature, and the follow-up that decides whether your policy is real: what happens when that person resigns, dies, or is standing in an airport with someone else's hand on their shoulder. Everything else, the insurance certificate, the auditor's request list, the board memo, is downstream of those two answers.
Your company needs its own counsel and its own accountants for this, and that is not a formality. The rules below are quoted from primary sources and dated, but how they apply to your entity, your jurisdiction, your regulator and your auditor is a question only your own advisers can answer. Nothing here is legal, accounting, tax or investment advice.
The three models, without the sales pitch
Most businesses arrive at Bitcoin through an exchange account because that is where the coins were bought. That is a reasonable place to buy and a poor place to sit. An exchange balance is a claim against a company, recorded in a ledger you cannot audit, and our guide to custodial and non-custodial wallets covers what a bankruptcy court has already said about who owns those coins when the company fails.
The second model is a third-party custodian under a proper custody agreement. This is what most finance teams end up wanting, and it is often the right answer. The important work is reading the agreement rather than the brochure: whether assets are segregated or pooled, what the custodian may do with them, what the withdrawal process requires, and what happens to your coins if the custodian enters an insolvency of its own.
The third is holding your own keys in a quorum. It removes the counterparty entirely and replaces it with an operational burden that a small finance team has to actually carry, forever, including through staff turnover.
| Exchange account | Third-party custodian | In-house multisig | |
|---|---|---|---|
| Who signs | The platform | The custodian, on instruction | Your officers, to a quorum |
| Withdrawal can be halted | Yes, unilaterally | Per the agreement and applicable law | No |
| Key-person risk | None on your side | Low, mostly authorised-signatory admin | High, and it is the main job |
| Auditor can confirm balances | Platform statement | Custodian confirmation | Chain data plus your descriptor |
| Insurance | Usually the platform's, not yours | Negotiable, read the limits | Specialist, expensive, narrow |
| Ongoing cost | Trading spread | Basis points on assets | Hardware, process, and staff time |
| Fails when | The platform fails | The contract says something you missed | People leave and the process was fiction |
| Suits | Buying, not holding | Most treasuries, most boards | Firms with real operational discipline |
What to read in a custody agreement
If you pick the middle column, the agreement is the product. The website is not. Custody offerings that look identical in a comparison table can differ completely in what happens on the worst day, and the difference is written down in a document most finance teams skim once during onboarding.
Read it with one question in mind: if this company failed tomorrow, what would a court be looking at? The Celsius ruling covered in our custody explainer turned on ordinary contract law rather than anything exotic, and the terms said what they said. Ask your counsel to give you a written answer on each of the following, in the agreement's own words rather than the sales team's.
| Find the clause on | The question it answers |
|---|---|
| Title and ownership | Does the agreement say the assets remain yours, or does anything in it transfer title? This is the clause the Celsius holding turned on. |
| Segregation | Are your coins in dedicated addresses, or pooled with other clients in an omnibus arrangement? |
| Use of assets | May the custodian lend, pledge, stake or rehypothecate anything, under any circumstances, with or without notice? |
| Sub-custodians | Can the custodian delegate to a third party, and does its liability survive that delegation? |
| Regulatory status | Which entity in the group actually holds the assets, chartered where, and supervised by whom? |
| Withdrawal mechanics | Who may instruct, what authenticates them, what the stated turnaround is, and on what grounds it can be suspended |
| Insolvency | What the agreement says happens to your assets, and whether counsel agrees a court would read it that way |
| Termination and exit | How you get everything back, how long it takes, and what it costs to leave |
What "qualified custodian" actually means
This phrase does more work in sales decks than it does in law, so it is worth being exact about it.
Qualified custodian is a defined term in the SEC's custody rule, 17 CFR 275.206(4)-2, which sits under the Investment Advisers Act. That rule governs a specific situation: an investment adviser registered or required to be registered under section 203 having custody of client funds or securities. It makes it a fraudulent, deceptive or manipulative act under section 206(4) to have that custody unless a qualified custodian maintains the assets, in a separate account for each client or in accounts containing only clients' assets, along with notice and account-statement conditions.
Read what that does and does not cover. If your company holds bitcoin on its own balance sheet, you are not an adviser and these are not client assets, so the rule does not apply to you at all. A custodian describing itself as qualified is telling you something about its regulatory category. It is not a certificate that your treasury is safe, and it is not a requirement your operating company is failing to meet.
| Category in paragraph (d)(6) | What the rule requires |
|---|---|
| A bank or savings association | A bank as defined in Advisers Act section 202(a)(2), or an FDIC-insured savings association |
| A registered broker-dealer | Registered under section 15(b)(1) of the Exchange Act, holding the client assets in customer accounts |
| A registered futures commission merchant | Registered under section 4f(a) of the Commodity Exchange Act, and only for client funds, security futures and related securities |
| A foreign financial institution | One that customarily holds financial assets for customers, keeping advisory clients' assets segregated from its proprietary assets |
What actually changed, and what did not
Three developments matter, and none of them is the one people usually cite.
First, the SEC's 2023 Safeguarding Advisory Client Assets proposal, which would have pulled a much wider set of client assets into the qualified-custodian framework, was formally withdrawn. The Commission withdrew a group of proposals issued between March 2022 and November 2023 and stated that it does not intend to issue final rules on them, and that it would issue a new proposed rule if it decides to revisit the area. The expansion people planned around did not happen.
Second, on 30 September 2025 the staff of the Division of Investment Management issued a no-action letter about registered advisers and regulated funds holding crypto assets with certain state-chartered trust companies. Commissioner Hester Peirce's statement the same day is worth reading precisely, because it is more careful than the coverage was: the letter "does not expand the definition of a permissible custodian," and the custody provisions it addresses apply only to "funds and securities" under the Advisers Act and "securities and similar investments" under the 1940 Act.
Third, and this one does touch ordinary companies, the SEC rescinded Staff Accounting Bulletin 121 through SAB 122, issued 23 January 2025 and effective 30 January 2025. SAB 121 had required an entity safeguarding crypto assets for platform users to put a liability and a corresponding asset on its own balance sheet. Its removal changed the economics of offering custody, which is why the set of institutions willing to do it has been widening since.
Designing a quorum that survives your staff
A quorum answers the question a single hardware wallet cannot: how do you stop any one person from moving the money, without creating a situation where one person leaving strands it? A 2-of-3 is the usual starting shape for a small company, with 3-of-5 for larger balances and larger boards. The mechanics of building one are in our multisig setup guide.
Three design rules matter more than the specific numbers. Separate the keys by person and by building, because a quorum where all three devices live in one safe is a single point of failure with extra steps. Give one key to someone outside day-to-day operations, typically a director or outside counsel, so that a dispute among the executives cannot deadlock the treasury. And write the descriptor down. A multisig wallet cannot be reconstructed from the seed phrases alone; you also need the descriptor that says which keys, in what arrangement, at what derivation. Businesses have lost access to coins they still fully controlled because that file existed in one place and that place was a laptop.
Key-person risk is the whole game
Ask a finance team who holds the keys and you will get names. Ask what happens to those keys in each of the situations below and you will find out whether there is a policy or a habit.
| The event | What must already be true |
|---|---|
| A key holder resigns | Device surrendered, key treated as compromised, balance rotated to a fresh quorum within a stated number of days |
| A key holder is dismissed for cause | The same, executed the same day, and a quorum that still functions without them |
| A key holder dies | A named successor, and access to the location, not just to the device |
| A key holder is coerced | A quorum they cannot satisfy alone, and a second approver who can refuse |
| Two key holders are on the same flight | A travel policy that prevents it, or a quorum that tolerates it |
| The office burns down | Backups in a different building, tested, not assumed |
| The person who built the setup leaves | Written procedure a competent stranger can execute, and someone else who has done a dry run |
| The auditor asks for proof of control | A rehearsed signing demonstration, and the descriptor available to show |
Two operational habits are worth adopting on day one. Rehearse a recovery on an empty wallet before funding anything, with the people who will actually do it under pressure rather than the person who designed it. And keep the signing procedure boring and written, because our threat-model guide makes the point that most losses at this scale start with a convincing message and a rushed approval, not with cryptography. Succession, including the version where nobody is available, is covered in our guide to inheritance planning, and the underlying storage methods in the cold storage guide.
The accounting changed, and it changed in your favour
If your reference point for corporate Bitcoin accounting is the old impairment model, update it. That model treated holdings as indefinite-lived intangible assets: you tested for impairment, wrote the carrying amount down to fair value when it fell, and were prohibited from writing it back up when it recovered. A company could hold coins worth far more than the balance sheet said and have no way to report it.
FASB Accounting Standards Update 2023-08 added Subtopic 350-60 and replaced that. Crypto assets in scope are measured at fair value in the statement of financial position each reporting period, with changes from remeasurement recognised in net income. Presentation is specified too: crypto assets measured at fair value appear separately from other intangible assets on the balance sheet, and remeasurement changes appear separately from changes in other intangibles in the income statement.
Scope is narrower than "crypto" and worth checking against your actual holdings. Subtopic 350-60 applies to assets that meet all six criteria: they meet the definition of intangible assets; do not provide the holder with enforceable rights to or claims on underlying goods, services or other assets; are created or reside on a distributed ledger based on blockchain or similar technology; are secured through cryptography; are fungible; and are not created or issued by the reporting entity or its related parties. Bitcoin sits comfortably inside all six. Plenty of other tokens do not.
The update is effective for all entities for fiscal years beginning after 15 December 2024, including interim periods within those fiscal years. Early adoption was permitted for statements not yet issued, and adoption requires a cumulative-effect adjustment to the opening balance of retained earnings for the annual period of adoption.
What you now have to disclose
| When | What you disclose |
|---|---|
| Interim and annual | For each significant holding, judged by fair value: the name of the asset, its cost basis, its fair value, and the number of units held |
| Interim and annual | Aggregated cost bases and fair values for the holdings that are not individually significant |
| Annual | The method used to determine cost basis for computing gains and losses, such as first-in first-out, specific identification or average cost |
| Annual | The income statement line item where gains and losses sit, if they are not presented separately |
| Annual | A reconciliation, in the aggregate, of activity from opening to closing balances, with the changes broken out |
Tax follows a separate track from the accounting, and the two answer different questions. Our Bitcoin tax guide covers the US federal treatment of disposals and the wallet-by-wallet basis rule that took effect in 2025, which interacts directly with the cost-basis method you choose above.
Insurance, and the five questions that decide whether it helps
Custody insurance is real, and it is narrower than most summaries of it. Rather than repeat figures that change per policy and per client, here are the questions that determine whether a certificate is worth anything to your company.
| Ask | Why it decides the outcome |
|---|---|
| Whose policy is it? | A custodian's cover protects the custodian. Your recovery may run through a contractual claim against them, not a direct claim on the insurer. |
| Is your entity a named insured? | If not, you are relying on somebody else's relationship with their carrier, and on their willingness to claim. |
| Is the limit per client or shared? | A large aggregate spread across every client of a large custodian can be a small number in your particular incident. |
| What is actually covered? | Cold storage, hot wallets and assets in transit are usually treated differently, and the difference is where the balance sits. |
| What is excluded? | Insider theft, key loss, coerced but valid signatures, and protocol failure. Between them those cover most of how businesses really lose coins. |
Ask for the certificate and the exclusions, not the marketing page, and have your broker read both. A policy that pays only when an outsider breaks in does not respond to the scenarios in the key-person table above.
Proof of reserves, for your own board
If you use a custodian, a reserves attestation is worth having and proves less than the phrase suggests. It shows that assets existed in addresses the custodian controlled at a moment in time. It does not show whether those assets were pledged elsewhere, borrowed for the snapshot, or matched by liabilities, unless the liability side is included and independently verified. Judge an attestation on three properties: does it cover both sides, is it repeated often enough that a single snapshot cannot be staged, and is the party performing it independent.
If you self-custody, you can do something a custodian cannot offer: demonstrate control directly. Signing a message from the treasury addresses, or making a small test spend in front of the auditor, proves the company holds the keys in a way no statement does. Pair that with the descriptor and a block explorer and the balance becomes independently checkable by anyone your board chooses to appoint. That is a genuine advantage of the in-house model and it is worth putting in the audit plan rather than discovering under time pressure.
A minimum viable custody policy
If you write nothing else, write this. It is one page, and a competent stranger should be able to run the treasury from it.
| The clause | What it has to say |
|---|---|
| Signers and quorum | Named roles, the threshold, and who may never be a second approver for the same instruction |
| Key locations | Which building each key sits in, and who has physical access to that room |
| Approval path | Who verifies the destination address, on which device screen, and the rule that urgency is grounds to stop |
| Departure trigger | The event, the rotation deadline in days, and who executes it |
| Descriptor backups | Three locations, named, at least one outside the primary building |
| Rehearsal | An annual recovery drill on an empty wallet, with a written outcome and a named owner |
| Cost basis method | The method chosen for 350-60-50-2, and where the supporting records live |
| Accountability | The role, not the person, answerable when any line above is not done |
That document is short, and a competent stranger should be able to execute the whole treasury operation from it. If yours reads as reassurance rather than instructions, it is not a policy yet. If you are still deciding whether to hold coins directly at all, the property comparison in our piece on Bitcoin versus gold covers what direct custody buys you, and our guide to spot Bitcoin ETFs covers the version where a fund holds the coins and you hold a security instead.
Related on BTCLinks
Sources
- 17 CFR 275.206(4)-2, Custody of funds or securities of clients by investment advisers. Source of the safekeeping requirement in paragraph (a) applying to advisers registered or required to be registered under section 203, and of the four qualified-custodian categories quoted from paragraph (d)(6). Read from the eCFR and verified 2026-07-29.
- SEC: Safeguarding Advisory Client Assets, withdrawal. Source of the formal withdrawal of proposals issued between March 2022 and November 2023, including the Safeguarding proposal at release IA-6384, and of the statement that the Commission does not intend to issue final rules on them. Verified 2026-07-29.
- Commissioner Hester M. Peirce, statement on the Division of Investment Management no-action letter, 30 September 2025. Source of the date and subject of the no-action letter on state trust companies, the statement that it "does not expand the definition of a permissible custodian," and the scope limitation to "funds and securities" and "securities and similar investments." Verified 2026-07-29.
- SEC Staff Accounting Bulletin No. 122. Dated 23 January 2025, effective 30 January 2025, rescinding the interpretive guidance in Topic 5.FF on obligations to safeguard crypto assets held for platform users. Read from the SEC's own release and verified 2026-07-29.
- FASB Accounting Standards Update 2023-08, Crypto Assets (Subtopic 350-60). Source of the six scope criteria at 350-60-15-1, the fair value measurement with changes in net income, the separate balance-sheet and income-statement presentation, the disclosure requirements at 350-60-50-1 through 50-3, the effective date for fiscal years beginning after 15 December 2024, early adoption, and the cumulative-effect adjustment on transition. Read from the FASB document and verified 2026-07-29.
- BIP-174: Partially Signed Bitcoin Transactions. The standard that lets separate signers in a quorum contribute signatures to one transaction without any device holding more than its own key. Verified 2026-07-29.
- BIP-380: Output Script Descriptors. The specification behind the wallet descriptor that must be backed up alongside the keys for a multisig quorum to be reconstructible. Verified 2026-07-29.
General information only, not legal, accounting, tax or investment advice, and not a substitute for your own professional advisers. Rules cited are US federal and current as at the verification dates shown. Some links on this site are affiliate links.