Holding and controlling the private keys that authorize transactions, and keeping a record of who the assets belong to. Those are two separate jobs. The key decides who can move an asset; the record decides who owns it. Custody arrangements differ mostly in who performs each job and what evidence exists afterward that they did.
Part of our guide: Digital Asset Custody.
Digital asset custody: the short version
- A key is a capability. Ownership is a claim established by records and documents. Nothing in the technology joins them.
- Wyoming’s statute defines a private key entirely by possession, as data “held by a person” (W.S. 34-29-101(a)(v)), and never says the holder owns anything.
- Custody models sit on a spectrum from sole self-custody to a regulated custodian, and the meaningful differences are who can sign and what a third party can verify.
- “Qualified custodian” is a regulatory category, not a security rating.
- No arrangement removes risk. Each one exchanges a set of risks for a different set.
The two jobs
Controlling the key. Whoever can produce a valid signature can move the asset, immediately and irreversibly. There is no institution able to block or reverse it, because the design removed the party who would have done so.
Establishing ownership. Separately, someone has to be able to demonstrate whose assets these are: a custody agreement, an account titled to a person or entity, contribution records, a trust instrument. None of it lives on-chain.
Custody is the practice of managing both, and most failures come from doing one well and the other not at all. A perfectly secured key with no ownership record leaves an estate unable to prove anything. Immaculate records with a lost key leave assets that are provably yours and permanently unreachable.
Wyoming’s drafting acknowledges the split:
“‘Private key’ means a unique element of cryptographic data, or any substantially similar analogue, which is: (A) Held by a person; (B) Paired with a unique, publicly available element of cryptographic data; and (C) Associated with an algorithm that is necessary to carry out an encryption or decryption required to execute a transaction.”
Wyo. Stat. Ann. § 34-29-101(a)(v)
Held by a person. Not owned by, entitled to, or belonging to. The legislature described a capability and left ownership to be settled elsewhere.
The models
Sole self-custody. One person holds the key. Maximum control, and every risk concentrated in one place: loss, damage, coercion, death, and an unrehearsed recovery.
Self-custody with distributed control. Multi-signature or split recovery material across people or locations. Removes the single point of theft and introduces quorum risk, which is the failure that occurs more often in practice.
Custodial account. A provider holds keys and you hold an account. You gain a process for death, incapacity, and change of authority, and a third party who can attest that the account is yours. You take on counterparty risk.
Qualified custodian. A custodial account where the provider fits a category defined in the SEC’s custody rule. Worth understanding precisely, because the label describes charter status rather than competence. See what “qualified” actually means.
Mixed. What most families holding meaningful amounts end up with: a custodian for the bulk, self-custody for a working balance, each with its own documented procedure.
What the choice actually turns on
Not security in the abstract. Three practical questions.
Who can sign today? Count the people. If the answer is one, that is a single point of failure regardless of how good the hardware is.
Who can sign if that person is unavailable? Not who inherits, which is a slower question. Who signs in three weeks.
What could a stranger verify? If a lawyer had to establish ownership from documents alone, what exists? A custodial account produces third-party evidence. Self-custody produces whatever you wrote down.
Those three do more to predict outcomes than any comparison of storage technology.
What I actually see with digital asset custody
Custody is discussed as a technology decision and experienced as an administrative one. People compare hardware and seed-phrase schemes, then lose assets to a forgotten passphrase, an unrehearsed recovery, or an estate that could not establish what belonged to whom.
The tell is the rehearsal. Setups that have never been exercised by the person who would have to exercise them almost always contain a defect, and the rehearsal is how it is found while it is still cheap to fix.
The second thing worth saying plainly: convenience and recoverability trade against each other, and most people optimize the wrong one. An arrangement so secure that only one person can navigate it has converted a theft risk into a mortality risk, and mortality is the certainty.
Where digital asset custody goes wrong
The key and the record drift apart, and nobody notices until someone outside the household has to make sense of it.
The recurring failures: assets held personally while the paperwork describes an entity. A passphrase that exists only in memory, which turns a well-designed multi-sig back into a single point of failure. Wallets nobody wrote down, so an estate cannot know what to look for. And the assumption that a custodian’s involvement means the ownership question is handled, when the account title is what handles it.
The decision rule for digital asset custody
Match the model to who needs access, and write down both halves.
- Count who can sign today. If the answer is one, make sure that was chosen rather than inherited.
- Name who signs if they cannot, and confirm that person knows.
- Title accounts to whoever is meant to own them, because third-party verification beats anything you write yourself.
- Keep a current inventory of wallets and accounts that contains no secrets.
- Rehearse the recovery with the people who would perform it.
- Split by tier rather than choosing one model for everything.
If the arrangement depends on you being available to explain it, it is not finished.
Where digital asset custody fits
Custody is one of four decisions that have to agree, and this is the overview of it. Custody for an entity covers titling and onboarding. What “qualified” means covers the regulatory category. What happens if a custodian fails covers the counterparty risk you take on. Succession covers the half that decides whether any of it survives you.
The through-line across all of them: the technology decides who can move assets, and the paperwork decides who owns them. Both have to be right.
Sources
- Wyoming digital asset statutes, Wyo. Stat. Ann. §§ 34-29-101 to 34-29-102 (Wyoming Legislature, Title 34)
- 17 CFR 275.206(4)-2, Custody of funds or securities of clients by investment advisers
- NIST, Special Publication 800-57, Recommendation for key management
- IRS, Digital assets
- CFTC, Digital assets
- FDIC, Deposit insurance
Related
- What is a qualified crypto custodian?
- Crypto custody for LLCs
- What happens if a crypto custodian fails?
- Private key succession planning
- Can a Wyoming LLC own a crypto wallet?
- Crypto custody
Last updated: 3 August 2026.
This article is general education, not legal, tax, or investment advice. Custody arrangements can reduce certain risks but do not eliminate them, and outcomes depend on your facts, your provider, and your documents. Talk to a qualified attorney about your own situation.
