The SEC Would Let Some Funds Hold Their Own Crypto Keys. Who Checks the Custody?

state trust companiesinvestment advisersRegulated Fundscrypto custodyproposed ruleself-custodyprivate keysSEC
1 hour agoSource: crypto.news
The SEC Would Let Some Funds Hold Their Own Crypto Keys. Who Checks the Custody?

The Securities and Exchange Commission proposed a new custody framework on October 1 that would let investment advisers and regulated funds hold crypto assets themselves in specified circumstances. It is a proposal, open for comment, and it changes more than the identity of the person holding a private key. It asks what evidence a fund can produce when a transaction is irreversible, a key can be copied without a trace and the party supervising the assets is also the party controlling them.

Summary

  • The SEC proposed crypto custody changes on October 1 for registered advisers and regulated funds.
  • Conditional self-custody and state trust company custody appear in the same proposal, but carry different oversight questions.
  • The public gets 60 days to comment after Federal Register publication, not after the SEC news release.
  • A copied private key can move assets while leaving no physical break-in or custody receipt.
  • The decisive test is how an independent party reconciles onchain control, books and client entitlements.

The SEC announcement describes a tailored framework under both the Investment Advisers Act and Investment Company Act. The short version in some coverage, that the agency simply approved self-custody, skips the operative words: under certain circumstances. The release also addresses adviser audits and broker-dealer custodial services for regulated funds. A press release is a map to a proposed rule, not a substitute for its conditions.

An investor sees an account statement and a fund net asset value. The assets behind those numbers may sit in a wallet with multiple signers, in a trust company account or in an adviser-operated system. The public blockchain can show the wallet balance. It cannot identify the legal beneficiary, prove that a signer has not copied a key, or show whether an offchain pledge has encumbered the coins. That missing bridge is the custody problem.

What the Commission actually put on the table

The October 1 proposal applies to registered investment advisers and regulated funds, including registered investment companies and business development companies. According to the SEC, it would permit crypto assets to be held in self-custody in defined circumstances and permit the use of state trust companies as custodians for client and fund crypto assets. Its comment clock is 60 days after publication in the Federal Register. As of the October 2 writing date, the release alone does not establish a final compliance date or an unconditional right to self-custody.

Two older regimes meet here. The adviser custody rule is concerned with clients whose assets an adviser can access. The fund regime puts additional demands on the safeguarding of portfolio securities and similar investments. Calling both institutions a fund, or saying that a state trust company automatically solves both sets of questions, flattens distinctions the proposal is supposed to address. The agency also proposes changes involving financial statement audits for advisers and broker-dealer custodial services for funds, according to its October rulemaking docket.

There is a useful chronology. In 2025, SEC staff issued a conditional no-action position concerning certain state-chartered trust companies, covered in crypto.news reporting on the trust-company path. A staff position is different from a Commission rule. The proposed framework now invites public comment on a wider architecture, including self-custody. The earlier White House review of the custody proposal was a procedural milestone, not a rule taking effect.

The headline question is therefore conditional. Who qualifies to use a wallet directly, what safeguards are required, and how a regulator or auditor verifies them are matters to resolve from the proposing release, the comments and the final text. An adviser cannot treat a news release as its own exception.

A wallet balance is not a custody audit

Suppose a fund says it holds 10,000 units of a token. An auditor can inspect an address that contains 10,000 units at a chosen block. That proves a balance existed at a point in time. It does not prove the fund exclusively controls the address. It does not prove that 10,000 units belong to that fund rather than several clients with overlapping claims. And it does not prove that the address was not briefly filled for the snapshot.

One control test is a signed challenge: the custodian signs a unique message from the address without moving the coins. This is evidence of signing ability at the time of the challenge. It is not evidence of exclusive signing ability, of sound key storage or of an enforceable customer claim. An onchain test transfer adds evidence of transaction authority, while introducing transfer and operational risk. Neither replaces a reconciliation between the general ledger, customer subledger, wallet inventory and third-party confirmations.

That is the first calculation an examiner would ask for. For every asset, sum customer and fund entitlements; reconcile that sum to all controlled addresses plus unsettled receivables, less transfers already committed. Then repeat across several randomly selected dates and inspect movements around the cutoff. A one-day equality can be manufactured. A reproducible ledger with authorization records and exception logs is harder to fake. The chain supplies the outer asset count. The institution supplies the allocation, and an independent party must test it.

There is also a distinction between key control and asset availability. A wallet might require a hardware device, multiple approvals and a recovery process. A signer can be unavailable during a market dislocation; a recovery signer can become a single point of failure; an upgradeable contract can change transfer rules. An auditor needs to inspect governance, access logs, backup policy, change controls and incident exercises, not just a balance screenshot.

The copied-key problem changes the evidence

A bank vault has a door. A crypto private key is information. An employee can copy a signing secret without reducing the original, and the first observable misuse may be the transfer itself. Hardware security modules and multiparty computation can reduce exposure and divide signing authority, but they shift the audit from counting keys to inspecting the devices, software, quorum policy and administrative privileges that produce signatures.

Consider a three-of-five signing arrangement. It sounds safer than one person holding a key, but the label tells little. If three shares are stored in the same cloud tenant or controlled by administrators with a common recovery privilege, one compromised boundary may still authorize a transaction. If signers can change the quorum or whitelist, the change process becomes as consequential as the signature. An independent review should ask who can approve, who can change the approval rule, who can restore shares and who sees those events in real time.

Self-custody also changes the economics of an error. A traditional intermediary may be able to reverse a mistaken internal book entry before settlement. A signed onchain transfer that reaches finality usually cannot be recalled by an adviser. Recovery can depend on the recipient, the token issuer’s freeze power or litigation. Those are distinct remedies with different timing. A policy saying a manager will attempt to recover assets is not equivalent to a segregated account or an insurer’s enforceable promise.

The strongest case for allowing direct control is practical. Some assets are native to networks and depend on timely staking, governance, redemption or contract interactions. Forcing every operation through an unsuitable third party can add delays and new concentration risk. The SEC’s proposal responds to that mismatch. But a fund that gains operational freedom also inherits the need to show a verifier exactly how it constrains that freedom.

The state trust option moves the boundary

The proposal’s self-custody condition is narrower than the release’s shorthand. Commissioner Hester Peirce’s statement on the proposed custody rules says an adviser would first determine that no permitted custodian is available for a given crypto asset, and repeat that determination quarterly. This is a scarcity exception, not a standing election between equally available ways to hold a popular coin. It also makes the market for qualified services part of the compliance test: if a custodian later supports the asset, the adviser’s premise may change.

The repeated determination needs a paper trail. Which custodians were approached, which asset and network version were offered, what services were requested, and why each provider was unavailable? A custodian that can store an ERC-20 token but cannot process staking rewards or a bridge withdrawal may or may not meet the portfolio’s specific needs under the eventual text. The adviser should not resolve the question by silently redefining availability as convenience or price. A quarterly record allows an examiner to compare the claimed obstacle with actual market offerings at the time.

The quarter-to-quarter comparison is more demanding than an initial memo. Imagine an adviser self-custodies a newly issued token in January because no permitted custodian supports its chain. A provider adds support in March. At the next assessment, the adviser should record the provider’s actual service, whether it can safeguard the same asset and any reason migration is infeasible. It may need a documented plan to move the position, depending on the final rule. The price of migration, tax or trading consequences and operational risk are real, but the proposed threshold cannot be assumed to waive them without reading its text.

Another case is a fund holding a token through a contract that a qualified custodian can view but not withdraw from independently. Does availability mean safekeeping the receipt token, operating the contract, or only storing the asset after redemption? The answer determines whether self-custody is an exception for the asset or an exception for the investment strategy. Commenters can clarify this with concrete asset and workflow examples instead of a general request for flexibility. An examiner will need a repeatable standard, not a different definition for each profitable trade.

An adviser should also preserve rejected bids and service descriptions. If a custodian offered support but the adviser declined because fees were high, the record should say so. If the custodian lacked essential withdrawal functionality, the adviser should show the limitation. Those distinctions help an independent reviewer decide whether the exception was triggered by unavailable safekeeping or by a business preference. They also protect a firm that made a defensible decision in a rapidly changing market.

Peirce’s statement also makes the scope of the self-custody debate clear: both adviser client assets and regulated fund assets are in view under limited conditions. That does not collapse their governance. In a fund, the board and service providers will need to understand why an exception applies and when it ends. A client of a separately managed account will need an intelligible disclosure of who signs and where the claim sits. A single firm could be responsible for both, but the evidence trail should identify which legal pool owns each wallet.

A state trust company may specialize in wallet operations and segregation while bringing a regulator, examination and an external corporate entity into the chain. Crypto.news covered the earlier conditional SEC staff path for this category. The October proposal would address it in rulemaking. Neither a charter nor a trust-company label proves the operational controls of a particular provider; the charter identifies the oversight regime and the firm responsible for its obligations.

An adviser using a trust company should ask who owns the wallet, who is the customer of record, whether the company commingles addresses, and how an insolvency administrator would identify client property. The answers can differ even when a web dashboard looks identical. A contract can say assets are held for clients, while operational books make it difficult to identify which tokens belong to which client. That is a legal and evidentiary problem, not a blockchain throughput problem.

The same inquiry applies if a trust company subcontracts the signing technology. A platform provider may supply wallet software, recovery services or transaction screening. The trust company can remain the named custodian, while an outsourced party has enough access to interrupt withdrawals or alter transaction policy. Regulators and advisers should map the actual control path through subcontractors. The location of a private key and the location of legal responsibility can be different.

There is a countervailing benefit. A separate custodian can provide independent statements and confirmations to an auditor. Yet independence is not automatic if the custodian relies on the adviser’s own position files and never tests the underlying wallets. A robust external confirmation identifies addresses or a verifiable inventory, customer entitlements, encumbrances and the scope of the custodian’s knowledge. A generic balance certificate leaves the hardest questions open.

A fund’s shareholders are two steps removed

In a registered fund, the shareholder owns shares, not a direct claim to a particular bitcoin output or token address. The fund owns or controls the portfolio under its governing documents, while service providers maintain custody, accounting and transfer-agent records. A shareholder asking where the assets are must traverse those layers. The chain alone answers only the last part of the route.

This is why a breakdown in custody can become a pricing event before any confirmed loss. If the fund cannot establish the inventory or its right to move it, it may face uncertainty in calculating net asset value, meeting redemptions and representing its holdings in disclosures. Liquidity on an exchange cannot repair a missing key or a disputed property claim. The proposal’s audit and fund-custody changes should be read alongside its wallet provisions because they determine how errors are detected and communicated.

Consider a token that trades around the clock while a fund strikes a daily NAV. Between the pricing cut and the audit confirmation, assets can move, smart contracts can change and a custodian can halt transfers. The controls need a defensible cutoff and subsequent-event review. A daily wallet snapshot linked to a daily ledger, with exceptions explained, is a better record than a monthly reserve claim. The amount of evidence required rises when the strategy itself moves coins between venues, validators or contracts.

The Franklin fund tokenized money market relief previously reported by crypto.news shows why the category matters: a registered fund can encounter a blockchain-recorded asset without giving each shareholder a wallet. That does not mean the SEC has endorsed every custody pattern for every token. Product-specific relief and a proposed general rule have different reach.

Control of a token can sit in its contract

Private keys do not exhaust control. A token issuer can sometimes freeze or reissue balances. A bridge administrator may be able to change the representation of an asset on another chain. A lending protocol may hold collateral subject to liquidation. A staking arrangement may prevent immediate withdrawal. For custody purposes, an address holding a token is only one line in the asset’s control map.

Suppose a fund deposits tokens into a smart contract and receives a receipt token. The wallet no longer holds the original asset. The ledger must explain the exchange and the fund’s enforceable claim against the contract. The auditor needs to know whether redemption is permissionless, whether a third-party administrator can halt it and whether the fund has counted the original token and the receipt as two assets. Double counting is possible if reports splice incompatible units.

An examiner can test this with a transaction trace: start at the fund’s acquisition, follow the token into the contract, inspect the contract’s current state and reconcile the receipt to the portfolio accounting entry. A chain explorer makes the trace possible. It does not decide whether the accounting classification or legal characterization is correct. Crypto.news’ coverage of adviser status for Securitize illustrates how adviser, tokenization and custody roles can coexist without becoming interchangeable.

The same lesson applies to staking. A validator operator may run infrastructure without possessing withdrawal credentials. A custodian may possess withdrawal credentials but delegate operational signing. If assets are slashed or locked, the economically relevant loss may occur without a key theft. A custody rule that recognizes crypto should prompt firms to document each kind of authority separately.

The first examination should follow a failed transfer

A dry run can expose more than a polished controls memo. Pick an ordinary withdrawal instruction and simulate a failed signer, a suspected compromised device and a destination address changed at the last minute. Which approval stops the payment? Which person can switch signers? How long does the fund remain unable to meet its own redemption or settlement obligations? The answer is measurable in minutes, access rights and signed records. That makes it a useful examination question whether the custodian is external or the adviser itself.

Now test the opposite: an unauthorized transfer has already reached the chain. The incident log should show the detection timestamp, the transactions affected, the remaining wallets at risk and the entity authorized to inform the board, clients and regulator. A fund that holds the same asset on three networks must identify all three, not just the address where the alert fired. If the token contract has an issuer freeze function, who contacts the issuer and on what authority? If it does not, the recovery plan cannot promise a freeze.

The key-recovery plan deserves the same skepticism. A recovery path can return control after a lost device, but the party able to invoke it may also be able to seize control from the legitimate holder. A meaningful test covers authorization of the recovery itself, independent notification and a period in which a disputed change can be stopped. Record the actual outcome of an exercise, including failed steps. An assertion that a wallet is multisignature is not a substitute.

These procedures cost money and can make the limited exception unattractive for smaller advisers. That is a legitimate concern in the comments. The comparison, though, is with the cost of safeguarding a financial client’s assets, not the price of a consumer hardware wallet. A lighter regime could be proportionate for some assets or structures, but its boundary needs a reason visible to a client and an examiner.

The opposing case is regulatory friction

The SEC says its existing rules were built before this asset class and have inhibited advisers from providing crypto-related advice. Chairman Paul Atkins framed the proposal as a compliant path where the framework had not kept pace. That is a serious point: an investor may seek an adviser with fiduciary duties, documented controls and public fund disclosures, while current ambiguity pushes exposure toward less transparent arrangements.

An overly narrow qualified-custodian list can concentrate assets in a handful of providers, too. If one service has an outage or imposes a broad freeze, many funds can be affected together. A conditional route for direct custody might spread operational risk, provided firms can meet clear and testable standards. The benefits of broader choice are real even if no single design is best for every portfolio.

The answer is not to assume that extra entities always reduce risk. It is to compare the complete loss path. A specialized custodian can fail by cyberattack, insolvency, bad records or an outsourced technology failure. An adviser can fail by weak segregation, conflicted personnel or deficient recovery. A rule can demand evidence from both and let clients see which arrangement they are buying. Public comments should focus on the testing burden and disclosure that turn a custody claim into something independently checkable.

A firm may point to a policy as proof that assets are safe. The policy is a contract with limits, exclusions and conditions, not a copy of the missing coins. An investor needs to know the insured party, the covered wallets, the covered events and the aggregate limit. A policy protecting a service provider’s own losses may offer a fund only an indirect claim. A limit shared by many customers can be exhausted before one fund’s loss is fully paid. Insurance can soften an incident; it cannot verify routine custody or cure a failed property claim.

The same is true of a proof-of-reserves attestation. It may verify that an observed pool of assets met a stated balance at a particular instant. It may not test liabilities, control throughout the period, offchain encumbrances or customer-level allocation. The scope paragraph matters as much as the large number. If an attestor tests a sample of addresses supplied by management, the report should say so. If it tests the full population against an independent ledger, that is stronger evidence. Neither format silently becomes a financial-statement audit.

For a fund investor, the assurance stack has at least four layers. Onchain holdings show assets at addresses. Signed challenges or independent custodian records connect an entity to control. Fund books allocate those assets to a portfolio and reflect payables or obligations. Legal documents identify the beneficial owner and rights if a service provider fails. A defect in one layer cannot be patched by doubling the evidence in another. Two extra block explorer screenshots do not repair a missing segregation agreement.

This is where the proposal’s reference to adviser audits matters. Changing the custody perimeter while altering audit obligations could either strengthen the evidence chain or leave gaps between the people testing it. Commenters should ask which independent professional confirms each assertion and which assertion is outside the engagement. An investor deserves a straight answer about the coverage of a report before treating its seal as a guarantee.

What the draft cannot settle on October 2

The SEC has proposed rules, not adopted them. A Federal Register publication starts the 60-day comment period; a final rule could change conditions, effective dates and transition provisions. Litigation or subsequent agency action could alter the framework. The market should not price a press release as immediate permission for a particular fund to take its assets out of an existing custodian.

Nor does a federal custody rule erase state property law, bankruptcy claims, contract terms, fund governance or insurance exclusions. A firm’s technical proof of control is useful only alongside those legal facts. There is no public evidence in the announcement that any particular trust company or adviser fails to safeguard assets. This is a design question for a proposed system.

The most revealing disclosure may be mundane: a schedule that ties client entitlements to verifiable wallets and identifies who can change the signers. If the final framework makes that record independently testable, it can expand access without asking investors to trust an uninspected black box. If it leaves the reconciliation opaque, moving the private key inside the fund will mostly move the place where the same question is asked.

What to watch

  • Federal Register publication: The actual publication date starts the SEC’s 60-day comment clock; check the final docket deadline.
  • Self-custody conditions: Read which advisers or funds qualify and whether third-party examinations, segregation and recovery tests are mandatory.
  • State trust treatment: Check the final definition, examination standards and treatment of subcontracted wallet operations.
  • Fund disclosures: Look for specific descriptions of signers, encumbrances, withdrawal gates and material custody incidents.
  • Independent reconciliation: Ask whether an auditor can match customer entitlements to controlled addresses over time, including assets in contracts.

FAQ

Has the SEC already authorized funds to self-custody crypto?

No. On October 1 it proposed conditional changes. The eventual requirements depend on the rulemaking process, and existing obligations remain relevant until a final rule and any transition take effect.

What is a qualified custodian?

It is an entity that meets specified custody-rule criteria for holding assets for advisory clients. Whether a particular state trust company qualifies under a future rule depends on the rule’s text and the firm’s circumstances.

Can a public wallet address prove a fund owns the crypto?

It proves the observed balance at a block. Legal ownership, exclusive signing power, customer allocation and liens require additional evidence.

Why does a copied key matter if the coins have not moved?

A copy may enable a later unauthorized signature without leaving a visible mark when it was made. Firms need controls that limit, detect and recover from that possibility.

Does a three-of-five multisignature wallet solve custody risk?

It can divide authority, but the storage locations, recovery powers and ability to change the signing rule determine how independent the five signers really are.

Are state trust companies automatically safer than advisers?

They add a separate legal entity and oversight regime, but each provider’s segregation, audit trail, outsourcing and recovery processes still need testing.

When does the SEC comment period close?

The SEC says 60 days after Federal Register publication. The October 1 press-release date is not itself the start of that period.

What should an investor ask a fund about its crypto custody?

Ask who holds signing authority, how holdings reconcile to shareholder records, which assets are locked or pledged, and who independently tests those claims. This is educational analysis, not investment advice.