Insights on Crypto Payments, Infrastructure, and Operations

Third-Party Custody

Pronunciation: THURD PAHR-tee KUS-tuh-dee

Definition

Third-party custody is an arrangement in which an external provider safeguards assets or signing authority on behalf of the asset owner. Operations for Third-Party Custody should connect legal entitlement with the accounts, wallets, approvals, external balances, and records used to safeguard and return the assets. Reliable operation of Third-Party Custody requires clear authority, segregation, controlled withdrawals, provider continuity, and reconciliation between external assets and internal entitlements.

Overview

The provider may control private keys, operate threshold signing, maintain ledger accounts, process withdrawals, and support settlement or reporting. Services range from retail hosted wallets to institutional custodians with formal account and governance structures.

Outsourcing reduces internal key-management work but introduces counterparty, legal, insolvency, cyber, operational, jurisdiction, and concentration risk. The provider may use omnibus accounts or sub-custodians, and customers may have limited direct on-chain control.

Due diligence should review authorization, financial condition, legal ownership, segregation, key controls, sub-custody, insurance, audits, withdrawal procedures, availability, and exit. Customers should keep independent records and avoid unnecessary balances. Contracts must define liability and incident communication. Migration and recovery should be tested before dependence becomes critical.

For Third-Party Custody, risks include key compromise, insider abuse, commingling, inaccurate books, unsupported tokens, provider insolvency, sub-custodian failure, blocked withdrawals, lost recovery material, and ambiguous liability. For Third-Party Custody, controls should combine least privilege, separation of duties, verified destinations, asset segregation, limits, monitoring, and continuity tests.

Third-Party Custody should be distinguished from investment ownership and from a software interface. For example, a provider may display an asset balance while holding pooled assets through another custodian; operations must verify contractual rights, segregation, withdrawal capability, and external evidence rather than rely on the screen alone.

Third-Party Custody works through controlled onboarding, asset receipt, internal attribution, storage-tier assignment, authorization, signing or provider instruction, monitoring, withdrawal, reconciliation, reporting, and return or migration. For Third-Party Custody, each handoff needs stable identifiers and an authoritative record of who approved and executed it.

Records for Third-Party Custody should reconcile on-chain or provider balances with customer entitlements and the internal ledger by asset, network, account, and cutoff. For Third-Party Custody, pending deposits, locked assets, staking, fees, conversions, forks, unsupported transfers, and manual adjustments require separate treatment and review.

Key Takeaway

Third-party custody transfers safeguarding duties to a provider while adding legal, counterparty, operational, and exit risks that require oversight.

Sources

  1. Bitcoin.org Documentation: Wallets — Bitcoin.org (2026-07-30)
  2. NIST Documentation: Key Management — NIST (2026-07-30)