Home /

Custody Vaults Explained: Multisig and Collaborative Custody

Quick answer: A custody vault is a structure for holding crypto where control of an account is split across multiple keys instead of one. In a multisignature (multisig) vault, moving funds requires several independent keys to approve. In a collaborative-custody version, the client holds the majority of those keys, so the custodian cannot move or lend out the assets without the client’s consent. That design removes the single point of failure that makes one private key so fragile.

Updated 07/17/2026. By Jake Claver. Educational content, not investment advice.

Custody is one of the most overlooked risks in digital assets. It is easy to focus on which asset to hold and skip the harder question: after you buy it, who actually controls the keys, and what can they do without asking you? Custody vaults exist to make that answer explicit rather than a matter of trust.

How a multisig vault works

A multisig vault splits signing authority across several distinct keys, and a transaction is only valid when a defined threshold of them signs, for example two of three or three of five. The rule is enforced by the blockchain itself, not by a company’s internal policy, so no single key can move funds alone. That is a structural guarantee rather than a promise.

In a collaborative-custody arrangement, the keys are distributed so the client holds a majority. A common pattern is a two-of-three vault where the client holds one key, the custodian holds one, and an independent third party holds the last. Because the custodian holds a minority of keys, it cannot unilaterally move the assets, and the client cannot be locked out by the custodian alone. Control is shared by design.

Why splitting keys matters

The clearest benefit is that the custodian cannot rehypothecate, meaning it cannot lend out or repurpose client assets, without the client’s signature. Several 2022 failures involved firms that treated customer deposits as their own to lend, then could not return them. When client keys are required to move funds, that behavior is not possible in the first place.

The failure question is worth asking directly of any custodian: if the firm itself goes bankrupt, what happens to your holdings? A structure where the client controls a majority of keys keeps the assets from being freely moved into someone else’s balance sheet. This is a different posture from arrangements where a single institution holds full control and the client relies on disclosure and good faith. The Commodity Futures Trading Commission’s digital assets resource hub is candid that much of the market is lightly regulated and fraud is a real risk, which is exactly why the structural protections matter.

Cold storage and the security process

Vault security is a process, not a single feature. Cold-storage multisig keeps the signing keys offline, out of reach of remote attackers, so exposure to exchange hacks and phishing is limited in a way that hot-wallet custody generally cannot match. Strong custody follows the same lifecycle the NIST Cybersecurity Framework describes for any critical system: identify the assets and risks, protect the keys, detect anomalies, respond to incidents, and recover. Applied to keys, that means offline storage, strict authorization controls, monitoring, and a tested plan for what happens when something goes wrong.

The banking system is moving in a compatible direction. The Office of the Comptroller of the Currency has confirmed, in its May 2025 News Release 2025-42, that national banks and federal savings associations may provide crypto-asset custody, provided they do so in a safe and sound manner, which pushes the whole field toward documented controls rather than informal key handling. The broader OCC guidance treats custody as a supervised activity.

Key loss, recovery, and support

A multisig vault also changes what happens when a client makes a mistake. Because more than one key exists, losing a single key is not automatically catastrophic. The remaining threshold of keys, together with the custodian’s involvement, can be used to recover access and re-secure the vault. The recover function is not a marketing add-on; it is the part of the security lifecycle that turns a single human error, a lost device, a phishing attempt, into a recoverable event rather than a permanent loss.

Who this applies to

The same structure works across account types, whether the assets belong to an individual, a trust, an enterprise, or a small business. The threshold and the distribution of keys can be tuned to the responsibility involved, which matters most when a fiduciary is legally accountable for someone else’s assets and needs a documented custody chain rather than a private key on a laptop.

Why this matters

Custody decides who can move your assets and what happens if the people holding them fail. A vault that splits keys turns “trust us” into a structural constraint you can verify. The practical payoff is that entire categories of loss, rehypothecation, exchange failure, remote hacks, and a single fatal mistake, are reduced by the design itself rather than by hoping a single custodian behaves well. That is why the vault structure, not any single provider’s brand, is the part worth understanding.

Common questions

What is a custody vault?

A custody vault is a way of holding crypto where control of an account is split across multiple keys instead of one. Moving funds requires a defined threshold of those keys to approve, which removes the single point of failure created by one private key.

What is collaborative custody?

Collaborative custody is a multisig arrangement in which the client holds a majority of the keys and a custodian holds a minority. Because the custodian cannot reach the signing threshold alone, it cannot move or lend the assets without the client’s consent, and the client cannot be locked out by the custodian by itself.

How does multisig prevent rehypothecation?

Rehypothecation is when a firm lends out or repurposes client assets. In a multisig vault, moving funds requires the client’s key, so the custodian cannot lend or move the assets on its own. The protection is structural and enforced by the blockchain rather than by policy.

What happens if I lose one of my keys?

Because a multisig vault uses more than one key, losing a single key is generally not catastrophic. The remaining threshold of keys, often with the custodian’s assistance, can be used to recover access and re-secure the vault, which is why key recovery and support are part of a sound custody setup.

What should I ask a crypto custodian?

Ask whether the custodian can move your assets without your consent, how many keys it controls, whether assets can be rehypothecated, what happens to your holdings if the firm becomes insolvent, and how key loss is handled. Clear answers to those questions reveal how much protection the structure actually provides.

This content is educational only. It is not tax, legal, or investment advice. Check primary sources and speak with a qualified professional before making financial decisions.


Sources

    Jake Claver

    Written by

    Jake Claver

    Family office professional working on how substantial holdings are held, structured and passed on. Qualified Family Office Professional. Finance degree, University of North Texas. Board member, Arkansas Blockchain Council. Author of Wealth in Numbers and Infinite Banking for Crypto Investors.