Cold Custody
Pronunciation: KOHLD KUS-tuh-dee
Definition
Cold custody is a custody model that keeps the private keys or signing shares for protected assets offline except through tightly controlled transaction procedures. Operations for Cold Custody should connect legal entitlement with the accounts, wallets, approvals, external balances, and records used to safeguard and return the assets. Reliable operation of Cold Custody requires clear authority, segregation, controlled withdrawals, provider continuity, and reconciliation between external assets and internal entitlements.
Overview
A custodian using cold custody may generate keys in isolated hardware, store them across secure locations, and require multiple people or devices to authorize movement. Online systems can monitor balances and prepare unsigned transactions without obtaining direct signing access.
Offline storage reduces remote attack exposure but increases operational complexity and withdrawal latency. Physical compromise, insider collusion, damaged media, unavailable signers, flawed ceremonies, and unsafe transfer of transaction data remain possible. Not every asset or smart-contract action is compatible with the same cold process.
The custody design should document key generation, storage, quorum, access logging, transaction verification, backup, recovery, rotation, and emergency availability. Organizations also need enough operational liquidity outside cold custody. Cold controls are effective when the full signing workflow remains secure and usable, not merely when a key-bearing device lacks internet access.
Cold Custody should be distinguished from investment ownership and from a software interface. For example, a provider may display an asset balance while holding pooled assets through another custodian; operations must verify contractual rights, segregation, withdrawal capability, and external evidence rather than rely on the screen alone.
Cold Custody works through controlled onboarding, asset receipt, internal attribution, storage-tier assignment, authorization, signing or provider instruction, monitoring, withdrawal, reconciliation, reporting, and return or migration. For Cold Custody, each handoff needs stable identifiers and an authoritative record of who approved and executed it.
The operating model for Cold Custody should map legal ownership, beneficial entitlement, technical control, account structure, asset segregation, supported networks, signing policy, provider roles, contractual duties, and insolvency treatment. For Cold Custody, these dimensions can belong to different parties and must not be inferred from a wallet label.
Key Takeaway
Cold custody reduces online exposure, but its security depends on physical protection, signer governance, recovery, and carefully controlled transaction handling.
Sources
- NIST Documentation: Key Management — NIST (2026-07-30)
- NIST Key Management Guidelines — NIST (2026-08-02)