Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Policy

SEC's Crypto Custody Rule Is Public and Self-Custody Is a Last Resort

An adviser could hold client crypto itself only after determining in writing, and again every quarter, that no permitted custodian is available for that asset. Transactions would need two people to authorize them, and the comment period runs 60 days from Federal Register publication.

By MiningPool Staff··3 min read
SEC's Crypto Custody Rule Is Public and Self-Custody Is a Last Resort

Key Points

  • An adviser could hold client crypto itself only after determining in writing, and again every quarter, that no permitted custodian is available for that asset.
  • Transactions would need two people to authorize them, and the comment period runs 60 days from Federal Register publication.

The Securities and Exchange Commission proposed a crypto custody framework for registered investment advisers and regulated funds on Thursday, publishing the text of a rewrite that went to review in August without anyone outside the agency reading it. The proposal carries Release Nos. IA-7023 and IC-36353 under File No. S7-2026-35, and it would let an adviser hold client crypto assets itself in narrow circumstances while adding state trust companies to the firms permitted to serve as custodians.

Self-custody is built as a fallback rather than a choice. Under the proposing release, an adviser would have to determine in writing, when it first takes custody and again every quarter, that "a permitted custodian is not available to maintain the crypto asset." The adviser would also have to document its own expertise in safeguarding each specific asset it holds that way, and operate systems built to prevent loss, theft, misuse and misappropriation.

Those systems carry named requirements. Private key management would have to require "joint authorization of any crypto asset transactions by at least two people," and client assets would have to sit at network addresses dedicated to them. Cybersecurity controls would need review "no less than annually." An adviser would owe an internal control report within six months of taking custody and annually after that, and would have to send clients quarterly statements identifying the addresses holding their assets, the holdings and every transaction.

Advertisement

728×90

One condition reaches outside the securities laws. The adviser and the client would have to agree in writing to treat the crypto assets as financial assets under applicable state law. The scope also covers registered investment companies and business development companies, and for a regulated fund the determination has to clear the board: directors would have to find that the assets are protected with reasonable care, and would have to review the adviser's conclusion that no permitted custodian is available every quarter.

The state trust company route has its own conditions. A trust company would have to show that its state banking authority has approved it to provide crypto custody services, keep written policies "reasonably designed to safeguard crypto assets and related cash/cash equivalents from theft, loss, misuse, and misappropriation," submit to annual reviews of its audited financial statements and its internal control reports, and keep client crypto assets separate from its own. Banks have meanwhile been adding capacity on their own terms, with Deutsche Bank naming the five assets its custody service will hold last month.

Beyond crypto, the proposal updates financial statement audit requirements for registered investment advisers and the standards for broker-dealer custodial services used by regulated funds. It would also create an exception from the surprise examination requirement for advisers whose custody arises only from standing letters of authorization.

Chairman Paul S. Atkins framed the rewrite around the age of the rules it would replace. The existing requirements "predate the internet; they were designed to protect the assets of advisory clients" but "contemplate the custody and safekeeping only of traditional assets," he said in a statement issued with the proposal, and "with newly developed crypto assets, custodial capabilities may lag an asset's deployment by many months." In the announcement he described a market that has grown "from a niche curiosity into a multi-trillion-dollar asset class" since the advent of Bitcoin in 2008, and said the proposal would give advisers and funds a compliant pathway where none existed before.

The agency withdrew its 2023 safeguarding proposal and started the rulemaking again, and when the replacement went to review in August nobody outside the SEC had read it, leaving US institutional crypto custody running on a staff letter with no legal force. The Commission has been filling other gaps by rule in the same stretch, proposing Regulation Crypto with $5 million and $75 million offering tiers in August and giving tokenized stock venues five years and tight caps in September.

None of it binds anyone yet. The comment period runs 60 days from publication in the Federal Register, and neither the announcement nor the docket entry gave a timetable for adopting a final rule. Until one exists, the conditions above describe what the SEC has asked about rather than what an adviser may do.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Comer Widened the Insider Trading Probe to Hyperliquid and Crypto.com
Policy

Three letters dated Tuesday also go to Aristotle Exchange, which runs PredictIt, and each sets the same return date of October 13. The Hyperliquid letter's central example is not an event contract but a leveraged short on bitcoin and ether perpetuals, and the $1.1 billion figure attached to it sits in a footnote citing a press column.

·MiningPool Staff
SEC Staff Made a Working Network the Test for Buybacks and Upgrades
Policy

The Division of Corporation Finance's updated crypto FAQs answer buyback, maintenance and marketing questions the same way: once a system is functional, none of it counts as the essential managerial effort that makes a token an investment contract. The staff attached the reverse warning to networks that do not yet work, and noted the answers have no legal force.

·MiningPool Staff
Democrats Sought a Hearing as Kalshi Met Banking Republicans Privately
Policy

Seven Senate Banking Democrats wrote to Chairman Tim Scott asking that prediction markets be examined in a public, bipartisan hearing rather than the Republican-only roundtable held Wednesday morning with Kalshi's chief executive. Their letter points at Cboe's request to list all-or-nothing options on corporate earnings, a product they argue could reach the SEC's jurisdiction.

·MiningPool Staff
The SEC Gave Tokenized Stock Venues Five Years and Tight Caps
Policy

Venues can trade tokenized National Market System stock without registering as exchanges, on notice rather than approval. A venue may list at most 75 Tier 1 names, a tier that takes in S&P 500 and Russell 1000 stocks, and trade no more than 0.25 percent of a name's average daily volume in the prior month.

·MiningPool Staff
House Panel Kept the 20-Year Bitcoin Lock and Cut Reporting to Yearly
Policy

The Financial Services Committee approved H.R. 8957 by 28 votes to 21 on Wednesday, but on a substitute text that replaced the bill Nick Begich introduced in May. The 20-year holding period survived; the quarterly proof-of-reserve report in the original became an annual one.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.