What Are the Risks of Crypto Custody?

By Safeheron Team
|

Crypto custody risk refers to the possibility that an enterprise may be unable to control, transfer, or recover its digital assets because of technical compromise, operational errors, internal misconduct, service disruption, unclear legal relationships, or recovery failures when storing private keys, authorizing transactions, using third-party custodians, or operating self-custody infrastructure.

An enterprise can place its assets with a custodian, control its own private keys or key shares, or combine third-party custody with self-custody wallets. However, no custody model eliminates every risk. Each model simply changes who controls the signing authority, who assumes operational responsibility, which service providers the enterprise depends on, and how assets can be recovered following a system failure.

Assessing crypto custody risk therefore requires more than asking where private keys are stored. Enterprises must also examine asset ownership, signing architecture, approval permissions, asset segregation, transaction execution, audit records, service continuity, and exit arrangements.

How Is Crypto Custody Different From Traditional Asset Custody?

Traditional securities custody generally relies on account records, registrars, banking systems, and legal intermediaries. When an account error or unauthorized transaction occurs, some systems may provide mechanisms for freezing, reversing, or addressing the transaction through legal procedures.

Crypto assets, however, are controlled through blockchain addresses and valid signatures. A blockchain generally does not determine whether a signer is an authorized employee, a hacker, or an insider who has obtained a private key. It only verifies whether the transaction contains a valid signature and complies with network rules.

This gives crypto custody several distinctive characteristics:

  • Private keys, key shares, or smart contract permissions may directly determine control over assets.
  • Confirmed on-chain transactions are generally difficult to reverse.
  • Sending assets to the wrong address may result in permanent loss.
  • Wallets must continuously support different blockchains and signature algorithms.
  • Transactions can occur around the clock without being limited by banking hours.
  • Smart contracts, cross-chain bridges, staking, and DeFi introduce additional risks.
  • An on-chain balance does not necessarily prove that an enterprise has clear legal ownership of the assets.

Technical control of an address, contractual ownership of the assets, and customer balances recorded in accounting systems must therefore remain consistent.

What Are the Main Crypto Custody Risks?

Risk CategoryMain IssuePotential Consequence
Private key and signing riskPrivate key exposure, compromised key shares, or breached signing devicesUnauthorized transfer of assets
Transaction authorization riskBypassed approval processes, incorrect approvals, or employee collusionMalicious transactions executed with valid signatures
Custodian riskCustodian failure, misconduct, or service terminationSuspended withdrawals or restricted asset access
Asset segregation riskCustomer assets mixed with the custodian’s proprietary assetsUnclear ownership and recovery priority during insolvency
Cybersecurity riskAccount takeover, leaked API credentials, or compromised administration systemsLoss of control over wallets and withdrawal systems
Operational riskIncorrect addresses, networks, gas settings, amounts, or transaction parametersPermanent loss or failed transactions
Liquidity and availability riskWithdrawal limits, system maintenance, or delayed manual reviewInability to access funds when required
Compliance riskCustody model does not meet local legal or client asset requirementsRegulatory penalties or business disruption
Blockchain riskCongestion, forks, node failures, or chain reorganizationsTransaction delays and uncertain balance status
Smart contract riskContract vulnerabilities, administrator permissions, or oracle failuresFrozen or stolen assets
Concentration riskMultiple business functions rely on one custodian or technology providerA single failure affects all funds
Recovery riskInvalid backups, unavailable personnel, or insufficient key sharesPermanent loss of asset control

1. Private Key Exposure Is Not the Only Key Management Risk

Enterprises often treat private key exposure as the central wallet security concern, but key management risks also include:

  • Accidental deletion of private keys
  • Damaged recovery phrase backups
  • Insufficient key shares to meet the signing threshold
  • Simultaneous compromise of signing devices
  • Multiple keys being effectively controlled by the same person or system
  • Key generation processes that cannot be independently verified
  • Poorly designed key rotation or personnel replacement procedures
  • Recovery materials being stored in the same location as production keys

Cold storage can reduce the risk of continuous private key exposure in online environments, but it cannot prevent backup loss, insider collusion, failed recovery, or malicious transactions being signed by offline devices.

Multisig and MPC-TSS can reduce the risk of a single complete private key becoming a critical point of failure. However, enterprises must still determine whether the participants are genuinely independent and whether an attacker could compromise enough signing devices or accounts to meet the required threshold.

2. Business Approval and Cryptographic Signing May Be Confused

Enterprise transactions often require review by operations, finance, compliance, and management personnel. These business approvals do not necessarily correspond to an on-chain signing threshold.

If every approver also holds a complete private key, adding more approval steps may increase the number of exposed keys. Conversely, if the signing system only counts approvals without verifying the approver’s role, transaction amount, destination address, or business justification, an attacker may use compromised accounts to authorize a transaction that is cryptographically valid.

A more appropriate design separates the following responsibilities:

  • Who can create transactions
  • Who can review transaction details
  • Who can provide business approval
  • Which devices participate in cryptographic signing
  • Who can modify address allowlists
  • Who can adjust transaction limits
  • Who can add or replace signing participants
  • Who can view and export audit records

Any single account that can modify policies, approve transactions, and control signing may become the system’s effective control point.

3. Custodian Insolvency May Create Asset Ownership Risk

A third-party custodian may provide professional security teams, compliance frameworks, and technical infrastructure, but using one also exposes the enterprise to the custodian’s credit, operational, and insolvency risks.

Enterprises need to determine whether customer assets are separately recorded from the custodian’s and its affiliates’ proprietary assets, whether the contract clearly defines the customer’s property rights, whether the custodian can lend, pledge, or otherwise use customer assets, and whether any sub-custodians are involved.

Updated virtual currency custody guidance issued by the New York State Department of Financial Services in 2025 requires custodians within its regulatory scope to maintain separate accounting and segregation of customer virtual currencies, preserve clear internal audit trails, reconcile on-chain activity with internal books and records, and disclose sub-custody arrangements and their material risks. The guidance also emphasizes that customer assets should not be pledged to secure the custodian’s own obligations.

However, asset segregation does not automatically guarantee immediate return of assets in every jurisdiction. Enterprises should still ask legal counsel to review customer agreements, property rights, governing law, insolvency treatment, and cross-border enforcement issues.

4. Sub-Custody Can Create a Risk Chain That Enterprises Cannot Directly See

The custodian with which an enterprise signs a contract may not directly control all the assets. Some custodians use external wallet infrastructure providers, cloud service providers, banks, liquidity providers, or sub-custodians.

This can create a dependency chain such as:

Enterprise → Primary Custodian → Sub-Custodian → Wallet Technology Provider → Cloud or Data Center Provider

If an enterprise evaluates only its direct contractual counterparty, it may overlook the entity that actually controls the keys or executes transactions. Custody agreements should therefore disclose:

  • Whether sub-custodians are used
  • Which assets and networks are handled by third parties
  • The jurisdictions in which sub-custodians operate
  • Who is responsible for asset reconciliation
  • Who bears responsibility if assets are lost
  • Whether the primary custodian can replace a sub-custodian unilaterally
  • Whether the enterprise will receive advance notice of material changes

Outsourcing does not eliminate risk. It moves some of that risk into a longer supply chain.

5. Account Takeover Can Bypass Secure Key Storage

Even if private keys are stored in hardware security modules, cold wallets, or MPC systems, attackers may still initiate and approve transactions through compromised business accounts. Common attack paths include:

  • Stolen administrator accounts
  • Compromised email or single sign-on systems
  • Exposed API credentials
  • SIM swap attacks
  • Malicious browser extensions
  • Remotely controlled mobile devices
  • Fake login pages
  • Stolen session tokens
  • Social engineering attacks against customer support personnel

Enterprises must therefore examine more than the underlying cryptography. Identity verification, device binding, login risk monitoring, API permissions, session management, and abnormal transaction detection are also essential.

6. Operational Errors Can Cause Permanent Losses

Many crypto asset losses result from routine operational mistakes rather than sophisticated attacks. Examples include:

  • Sending assets to the wrong address
  • Selecting the wrong blockchain network
  • Confusing native tokens with wrapped tokens
  • Failing to maintain enough gas
  • Setting transaction fees incorrectly
  • Interacting with the wrong smart contract
  • Sending funds to a platform that does not support the asset
  • Using an expired or manipulated destination address
  • Misunderstanding memo, tag, or other destination requirements

Address allowlists, small test transfers, transaction decoding, dual review, and network-specific operating rules can reduce these risks, but they cannot prevent every error.

7. Withdrawal Availability Is Not the Same as Asset Security

Seeing a balance on a custody platform does not mean an enterprise can transfer the assets to its own address at any time. Withdrawals may be affected by:

  • Per-transaction or daily limits
  • Manual review times
  • Risk-control freezes
  • System maintenance
  • Blockchain network suspensions
  • Compliance investigations
  • Holiday processing rules
  • Sub-custodian service disruption
  • Custodian liquidity or operational problems

Custody security therefore concerns not only whether assets are stolen, but also whether the enterprise can access and move them when needed. Payment providers, exchanges, and market makers should test large withdrawal procedures, emergency communication channels, service-level agreements, and alternative transfer routes.

8. Blockchain and Smart Contract Risks Do Not Disappear When a Custodian Is Used

A custodian may protect signing keys, but it cannot control the underlying blockchain. Enterprises may still be affected by:

  • Block production halts
  • Node or RPC service failures
  • Chain reorganizations
  • Network congestion and rising transaction fees
  • Smart contract vulnerabilities
  • Oracle failures
  • Cross-chain bridge attacks
  • Token issuers freezing addresses
  • Stablecoin depegging or redemption suspensions
  • Protocol upgrades that change transaction behavior

A custodian’s support for a token only means that its system can hold or transfer that asset. It does not mean the token, smart contract, or underlying network is free from risk.

9. Staking, Lending, and DeFi Expand the Scope of Custody Risk

If a custodian also offers staking, lending, trading, settlement, or DeFi access, the enterprise’s exposure extends beyond safekeeping.

Staking may involve lock-up periods, validator slashing, and reward calculations. Lending can introduce counterparty and collateral risks. DeFi activity may expose the enterprise to smart contract, oracle, governance, and liquidity risks.

The Financial Stability Board recommends that crypto asset service providers maintain governance, risk management, recordkeeping, and disclosure frameworks proportionate to their size and complexity. It also highlights the conflicts of interest and combined-function risks that can arise when one service provider performs multiple activities.

Enterprises should therefore distinguish pure custody from custody combined with additional financial services. Products should not be treated as having identical risk merely because the assets are held by the same institution.

10. Custody Insurance May Not Cover Every Enterprise Loss

Some custodians maintain commercial insurance, but enterprises need to understand what the policy actually covers. Different policies may apply only to specified locations, wallet types, attack scenarios, or events that remain within the custodian’s direct control.

Insurance may not cover:

  • Takeover of the customer’s own account
  • Incorrect employee approvals
  • Incorrect destination addresses
  • Smart contract vulnerabilities
  • Token price declines
  • Stablecoin depegging
  • War or state-sponsored activity
  • Concentrated losses exceeding the policy limit
  • Events outside the custodian’s contractual responsibility

Enterprises should also determine whether the stated insurance limit is dedicated to one customer or shared across all customers. A marketing claim that assets are “insured” is not a substitute for reviewing the insurer, coverage amount, deductible, exclusions, and claims priority.

What Is the Difference Between Third-Party Custody, Self-Custody, and Hybrid Custody?

ComparisonThird-Party CustodyEnterprise Self-CustodyHybrid Custody
Private key controlPrimarily controlled by the custodianPrimarily controlled by the enterpriseDistributed by wallet or permission
Counterparty riskHigherLowerModerate
Enterprise operational responsibilityLower, but not eliminatedHigherAllocated according to architecture
System integrationDepends on custodian interfacesHighly customizableRequires integration of multiple systems
Regulatory suitabilityMay more easily satisfy certain custody requirementsDepends on the business and jurisdictionMust be evaluated separately
Withdrawal controlSubject to custodian processesManaged directly by the enterpriseDepends on where the assets are held
Recovery modelDepends on the custodian and contractDepends on enterprise backups and key sharesRequires coordination among multiple parties
Typical use casesFunds, low-frequency reserves, and regulated productsPayments, exchanges, and multichain operationsTiered reserves and daily operations

Third-party custody may suit enterprises seeking to outsource part of their security, operational, and compliance work, but it increases dependence on service providers, contracts, and withdrawal processes. Self-custody gives enterprises direct control over signing authority and system design, but it also requires them to manage key security, user permissions, node connectivity, transaction review, recovery, and business continuity.

A hybrid model can place long-term reserves, operational funds, and customer assets in different systems. However, this also increases the complexity of reconciliation, policy coordination, and emergency response.

How Should Enterprises Choose a Custody Model?

Enterprises should select an architecture based on the purpose of the funds instead of placing every asset under the same custody model.

Large, low-frequency reserves may prioritize segregation, strict approval, and recovery. Customer withdrawal wallets may prioritize automation, transaction limits, address controls, and availability. DeFi wallets require transaction decoding, smart contract permission controls, and more extensive on-chain risk analysis. Funds and regulated investment products must first determine whether local law requires a particular type of custodian.

An enterprise may also implement a tiered structure in which:

  • A third-party custodian holds part of the long-term reserves.
  • Self-custody wallets handle daily operations and automated transactions.
  • Cold wallets store large, low-frequency reserves.
  • Independent emergency wallets support asset migration during service disruptions.
  • Different custodians and wallet systems provide alternative exit routes.

Diversifying custody arrangements can reduce the impact of a single service provider failure. However, diversification is only effective if the enterprise can continuously reconcile balances, test withdrawals, and maintain recovery procedures across every system.

What Should Enterprises Check Before Selecting a Custody Service?

Before choosing a custody model or provider, an enterprise should confirm the contracting entity, applicable licenses, regulatory scope, and legal status of customer assets. It should examine whether assets are segregated from those of the custodian and its affiliates and whether the contract permits lending, pledging, rehypothecation, or sub-custody. The enterprise should also determine who holds the private keys or key shares, whether any employee, custodian, or technology provider can transfer assets independently, and whether transaction creation, approval, policy modification, and cryptographic signing are separated. Due diligence should also cover supported blockchains, tokens, transaction types, APIs, automation policies, address allowlists, transaction limits, audit logs, reconciliation between on-chain activity and internal books, insurance coverage, service-level agreements, and incident notification procedures. Finally, the enterprise should test whether it can recover wallets, suspend transactions, export records, and migrate assets if a device is lost, an employee leaves, a custodian stops operating, a network becomes unavailable, or a system is compromised.

How Does Safeheron Help Enterprises Reduce Crypto Custody Risk?

Safeheron MPC Self-Custody helps enterprises establish an MPC-TSS-based self-custody wallet and transaction approval system. Independent participants hold separate key shares and jointly generate blockchain-valid signatures through threshold signing, without requiring a complete private key to be assembled during routine transaction signing.

Enterprises can assign separate roles for:

  • Transaction initiators
  • Finance and compliance approvers
  • Key-share participants
  • Wallet administrators
  • Policy administrators
  • Auditors and read-only users

Enterprises can also configure transaction policies based on assets, addresses, amounts, wallets, and business types while maintaining separate wallets for customer deposits, automated withdrawals, merchant settlement, fund sweeping, DeFi activity, and large reserves.

For enterprises that want to control all key shares, deploy signing infrastructure in their own environment, or build proprietary wallet products, Safeheron MPC Node Suite provides privately deployable MPC-TSS middleware and SDKs for multichain wallets, isolated-network signing, transaction automation, and custom approval workflows.

Safeheron is not a traditional third-party asset custodian. Its core purpose is to help enterprises build self-custody infrastructure for key management, transaction signing, and permission governance. Whether an enterprise also requires an external qualified custodian depends on its jurisdiction, customer type, and specific business requirements.

Safeheron’s Technical Boundaries

MPC-TSS can reduce complete private key exposure and the risk of a single person controlling assets, but it cannot eliminate compromised endpoints, stolen identities or accounts, insider collusion, incorrect approvals, phishing, address replacement, malicious transaction signing, blockchain failures, smart contract vulnerabilities, cross-chain bridge attacks, token issuer risks, or business continuity risks. If the remaining key shares cannot meet the signing or recovery threshold, Safeheron cannot bypass cryptographic rules to recover the assets. If a malicious transaction has received sufficient authorization and been confirmed by the blockchain, MPC-TSS cannot unilaterally reverse it. Self-custody infrastructure may also be unable to replace a qualified custodian when one is required by applicable law. Enterprises must therefore combine it with independent legal analysis, endpoint security, personnel governance, transaction review, backup verification, node monitoring, disaster recovery, and emergency exit procedures.

Frequently Asked Questions

What Is Crypto Custody Risk?

Crypto custody risk is the risk that an enterprise may suffer losses while storing, controlling, or transferring crypto assets because of private key exposure, incorrect transaction authorization, custodian failure, inadequate asset segregation, system disruption, or recovery failure.

Is Third-Party Crypto Custody Safe?

Third-party custodians may provide professional key security, operational processes, and compliance support. However, they still introduce risks related to service provider compromise, suspended withdrawals, inadequate asset segregation, sub-custody, insolvency, and concentration. Enterprises need to evaluate the specific institution and contractual terms instead of relying only on a “regulated custodian” label.

Can Custodian Insolvency Affect Customer Assets?

Yes. The impact depends on how assets are segregated, what the customer agreement states, how the custodian actually uses the assets, the applicable law, and the insolvency proceedings. The fact that assets can be seen on-chain does not necessarily mean customers can recover them immediately or receive priority treatment.

Is Self-Custody Riskier Than Third-Party Custody?

Not necessarily. Self-custody reduces dependence on external custodians but transfers responsibility for key security, permission management, transaction review, recovery, and business continuity to the enterprise. Whether it is safer depends on the enterprise’s technical capabilities and governance maturity.

Can Cold Wallets Eliminate Custody Risk?

No. Cold wallets can reduce exposure to online attacks, but they remain vulnerable to lost backups, damaged devices, insider collusion, incorrect addresses, malicious signing, and recovery failures.

Does Custody Insurance Cover Every Crypto Asset Loss?

Usually not. Insurance coverage is often limited by the policy amount, event type, wallet scope, exclusions, and claims conditions. Enterprises should review the actual policy and contract rather than relying solely on insurance amounts displayed in marketing materials.

Can Enterprises Use Both Third-Party Custody and Self-Custody?

Yes. An enterprise can place long-term reserves with a third-party custodian while using self-custody wallets for daily operations, or select different models for different networks and business activities. However, the enterprise must maintain unified reconciliation, permission governance, risk limits, and emergency exit procedures.

How Can Enterprises Reduce Crypto Custody Risk?

Enterprises should distribute critical control, separate transaction creation, approval, and signing permissions, implement address allowlists, transaction limits, abnormal transaction monitoring, and audit records, and regularly verify key backups, asset reconciliation, withdrawal channels, disaster recovery, and service provider exit procedures.

Conclusion

Crypto custody risk extends beyond private key theft. It also includes transaction authorization, custodian creditworthiness, asset segregation, sub-custody, account security, operational errors, blockchain networks, smart contracts, system availability, and disaster recovery. Third-party custody, self-custody, and hybrid custody allocate these risks differently. Enterprises should choose an approach based on asset use, transaction frequency, regulatory requirements, and internal capabilities while ensuring that no single employee, device, or service provider can independently control all assets without the required review.

Request a Safeheron product demo to learn how to build MPC-TSS self-custody wallet infrastructure around your enterprise’s asset scale, blockchain networks, transaction processes, and permission structure.

Book a Demo
Leave your details and a Safeheron expert will get back to you shortly.
SHARE THIS ARTICLE
联系我们