There is no single best institutional crypto custodian. The right answer depends on your mandate: what assets you hold, which regulator you answer to, whether you need a qualified custodian on paper, and how much control you are willing to hand to a third party.
But the way you find that answer does not change. Every credible evaluation tests the same properties, and a provider either has them or it does not. Get the criteria right and the shortlist writes itself.
This post lays out those criteria, the categories of provider you will meet in the market, and how to run an evaluation that holds up under audit.
The criteria that actually matter
Most custody comparisons get distracted by feature lists. The properties below decide whether client assets are safe, recoverable, and provable. Score every provider against all of them.
- Asset segregation.Are client assets held in distinct, individually verifiable accounts, or pooled into one omnibus wallet with ownership tracked on an internal ledger? Per-client segregation means your holdings can be confirmed without trusting the provider’s books. Omnibus commingling means you cannot.
- Proof of reserves. Can you verify on-chain that the assets backing your position exist and are where they should be, on demand, rather than waiting for a quarterly attestation? A signed statement is a promise. On-chain proof is evidence.
- Key management. How are signing keys held and split? Multisig (for example 2-of-2 or 2-of-3) and hardware or HSM signing mean no single party can move assets alone. Single-key or fully delegated signing is a concentration risk.
- No rehypothecation. Is the no-reuse guarantee a clause in a contract, or a property of the architecture? A clause is audited after the fact. An architecture rules reuse out.
- Regulatory posture. Does the provider hold the licenses and qualified-custodian status your mandate requires in your jurisdiction? This is often the gating criterion for regulated institutions.
- Open vs. black-box architecture. Can the security model be inspected, or are you trusting a closed system on reputation alone? Open, formally verifiable foundations let your own engineers and auditors check the claims.
The categories of provider
The market sorts into roughly three models. None is universally best; each trades something for something else.
Full-service qualified custodians
These firms hold assets on your behalf under a custody license, often with insurance and a familiar legal wrapper. They are the easiest fit for a mandate that requires a named qualified custodian. The trade-off is control and visibility: assets sit with the provider, and many operate on omnibus models where you rely on internal records rather than on-chain proof.
MPC and key-management platforms
Multi-party computation platforms split signing across parties so no single key exists in one place. They are flexible and integrate well with trading and treasury workflows. The trade-offs vary by vendor: confidentiality, asset-level compliance rules, and on-chain verifiability are not guaranteed by MPC itself, so you have to check each one against the criteria above.
Self-custody with policy infrastructure
Here you hold your own keys, and a policy layer enforces approvals, limits, and whitelists. This maximizes control and removes counterparty risk entirely. The trade-off is operational burden and the need for a governance and recovery model you are prepared to run yourself.
Well-known names span these categories, and several tokenization and securities platforms now bundle custody with issuance. Each design tends to trade away at least one of three things: Bitcoin-anchored settlement, native confidentiality, or HSM-enforced compliance at the asset level. There is no shame in that; it is just the trade space you are choosing within.
How to run a custody evaluation
Treat custody selection like any other vendor risk decision, with evidence rather than demos.
- Write the mandate first. List your assets, jurisdictions, qualified-custodian requirement, and the controls your compliance team needs. The mandate is the rubric.
- Score against the six criteria. Make every provider answer each one with a demonstrable fact, not a brochure claim.
- Ask for a live proof of reserves. If a provider cannot show you reserves on-chain on demand, you are relying on its word.
- Probe the failure modes. What happens if the provider is compromised, insolvent, or unresponsive? Who can move assets, and can you recover without them?
- Read the architecture, not just the policy. Prefer guarantees enforced by design over guarantees enforced by contract.
The best custodian is the one whose claims you can verify yourself, not the one with the most reassuring statement.
Where verifiable, Bitcoin-native custody fits
One model worth knowing in 2026 is verifiable custody built on open Bitcoin infrastructure. On the Liquid Network, an open-source Bitcoin sidechain run by a federation of more than 80 members, custody can combine the properties above in one architecture.
Blockstream Enterprise is the HSM-based custody platform built on this foundation. Client assets sit in segregated per-client UTXOs rather than a commingled pool, so each holding is distinct and verifiable. Reserves can be confirmed on-chain, with Confidential Transactions letting a holder prove balances to an auditor or regulator through selective blinding-key disclosure rather than public exposure. Signing uses 2-of-2 or 2-of-3 multisig with HSM and hardware devices including Blockstream Jade, so no single party moves assets alone. Reuse is ruled out by the architecture, not a contract clause. Full-custody, hybrid, and self-custody options let you place the trust boundary where your mandate needs it.
The bottom line
Pick the model that fits your mandate, then test it against segregation, proof of reserves, key management, no rehypothecation, regulatory posture, and openness. The provider that can prove all six, rather than promise them, is the best one for you.
See what verifiable, Bitcoin-native custody looks like. Institutional Custody →