Custody Models for Institutions: Who Controls the Keys, and Why It Matters
CoinRoutes
In crypto, owning an asset means controlling the private keys that authorize moving it — so the central question of custody is always "who holds the keys?" For institutions, the custody model determines counterparty risk, regulatory standing, operational workflow, and ultimately whether assets are safe if a third party fails. This guide explains the main models and their tradeoffs.
"Not your keys, not your coins"
The phrase captures the core principle: whoever controls the private keys controls the assets. If you hold an asset on an exchange, the exchange controls the keys, and you hold a claim against the exchange rather than the asset itself. The 2022 collapses of several centralized firms made this distinction painfully real for institutions whose assets were commingled with a failed counterparty's.
Institutional custody decisions are therefore fundamentally about who can move the assets, under what controls, and what happens if that party fails.
The main custody models
1. Self-custody. The institution holds its own keys, typically in hardware security modules or cold storage with multi-signature controls. Maximum control and no third-party counterparty risk, but the institution bears full operational and security responsibility — losing keys means losing assets.
2. Exchange custody. Assets sit on a trading venue for convenience and immediate trading. Easy and liquid, but the exchange controls the keys, concentrating counterparty risk and exposing assets to the venue's solvency and security.
3. Qualified / third-party custodians. A regulated, specialized custodian safeguards assets independently of trading venues, usually with segregation, insurance, and audited controls. This separates custody from trading and is the model many institutions and regulators favor. Counterparty risk shifts to a regulated, purpose-built entity.
4. MPC and multi-sig arrangements. Multi-party computation (MPC) and multi-signature wallets split key control across multiple parties or devices, so no single point holds a complete key. This can be combined with the models above to reduce single-point-of-failure risk and enable shared institution/custodian control.
Comparing the models
| Model | Who controls keys | Counterparty risk | Trading convenience | Typical institutional use |
|---|---|---|---|---|
| Self-custody | The institution | Lowest | Lower (must move to trade) | Long-term holdings, treasuries |
| Exchange custody | The exchange | Highest | Highest | Active trading balances |
| Qualified custodian | Regulated custodian | Moderate (regulated) | Moderate | Core institutional standard |
| MPC / multi-sig | Split across parties | Reduced single-point | Varies | Layered on other models |
The custody–trading tension
There is an inherent tension: assets are safest away from trading venues, but trading requires assets at (or accessible to) venues. Historically this forced institutions to choose between safety and liquidity. Newer approaches address it through arrangements that let institutions trade against assets held in independent custody — using credit, settlement networks, or off-exchange settlement so assets don't have to sit on exchanges to be tradeable. This is also where prime brokerage and custody intersect.
Why key control matters for execution
Custody and execution are separate concerns, and keeping them separate is increasingly seen as good practice. An execution platform should route orders and seek best execution across venues without needing to take custody of client assets — the institution's keys and assets stay within its chosen custody arrangement. Separating the two reduces counterparty risk: the firm executing your trades is not the firm holding your coins.
How CoinRoutes fits
CoinRoutes is an execution platform, not a custodian. It connects to venues using securely stored exchange API credentials to route and execute orders, while assets remain within the institution's own exchange, custodian, or prime arrangements. The platform emphasizes secure handling of credentials and controlled access to secrets, keeping the execution layer cleanly separated from custody.
This article is general information, not financial, legal, security, or investment advice. Custody decisions carry significant risk; institutions should perform their own due diligence and consult qualified advisors.
Frequently asked questions
What does "who controls the keys" mean in crypto custody? Whoever holds the private keys can move the assets. If a third party holds your keys, you hold a claim against that party rather than direct control of the assets — which is why key control defines custody risk.
What is the safest crypto custody model for institutions? There's no single answer, but many institutions and regulators favor qualified third-party custodians that segregate assets from trading venues, often combined with MPC or multi-sig controls to remove single points of failure.
Why not just keep assets on the exchange where I trade? It's convenient and liquid, but the exchange controls the keys, concentrating counterparty risk. If the exchange fails or is compromised, those assets are at risk.
Does an execution platform need to hold my assets? It shouldn't. A well-designed execution platform routes and executes orders using API access while your assets stay in your own custody arrangement, keeping execution and custody separate.
Want execution that keeps custody separate? Book a demo to see how CoinRoutes connects to your venues without taking custody.
Related reading: What Is a Crypto Prime Broker? · What Is a Crypto Execution Management System (EMS)? · CeFi vs DeFi Execution for Institutions
