[Xangle RWA Series] Custody/KMS

1. Introduction
2. Custodial Authorization and Institutional Status
3. Custody Operating Structure
4. Vendor Comparison: Custodial Status and Operating Structure
5. Conclusion
1. Introduction
According to The Financial Grid, a 2026 study by Fireblocks of more than 600 senior decision-makers at financial institutions worldwide, 88% of financial institutions have either spent or plan to spend on digital asset infrastructure. Yet only 16% have reached the production stage. Only 15% said their custody and wallet governance capabilities were fully production-ready. These figures show that the bottleneck in digital asset adoption is not a lack of interest. It is an infrastructure design problem that requires custody architecture, wallet governance, and regulatory compliance to work together.
1-1. The Role Custody Has Played in Traditional Finance
In traditional finance, custody begins as an institutional function for safekeeping and administering client assets. Even when both are described as “entrusting” assets to another party, deposits and custody have different structures. When a customer deposits money at a bank, ownership of that money transfers to the bank, and the customer receives a claim against the bank for repayment. In custody, the legal and economic ownership of the asset remains with the client, while only safekeeping and administrative authority are delegated to the custodian.
Under this structure, the client retains ownership of the asset, while the custodian performs safekeeping and operational procedures. As a result, custody in traditional finance is more than a vault for assets. It functions as an institutional operating mechanism that allows institutions to manage assets safely and handle post-trade processes.
1-2. Why Custody Changes in Digital Assets
In digital assets, however, the object of safekeeping changes. Digital assets have no physical form. They exist as records on a blockchain or distributed ledger, and the authority to transfer or use them is exercised through cryptographic keys. For a financial institution, custodying a client’s digital assets is not a matter of placing physical property in a vault. It means managing the keys and wallet controls that determine asset transfers and access.
This difference makes custody risk much more direct. If a key is lost, the asset becomes inaccessible. If a third party steals the key, the asset can be transferred. If assets are sent to the wrong address or approval authority is misused, blockchain transactions are difficult to reverse. Digital asset custody therefore begins as a technical problem of keeping keys secure, but in actual operations it extends to who approves withdrawals, which addresses assets can be sent to, and what procedures stop and restore operations when an incident occurs.
Digital asset custody requires technical security, legal responsibility, and operating processes to be designed together. From a technical perspective, security spans the entire key lifecycle, from generation and storage to use and recovery. From an operational perspective, segregation of duties, approval workflows, audit logs, and emergency suspension procedures become critical. From a legal perspective, trust in the custody structure depends on who exercises control over client assets, whether client assets are segregated from the service provider’s own assets, and whether they can be returned to clients in the event of insolvency.
1-3. Two Layers for Understanding Digital Asset Safekeeping Infrastructure
Digital asset safekeeping infrastructure should be viewed across two layers.

The first layer is custodial status. This layer asks who holds client assets and under what institutional capacity. The supervisory framework and client asset protection obligations differ depending on whether client assets are held by a bank, trust company, virtual asset service provider, CASP, DPT service provider, or another regulated entity type.
The second layer is the operating structure. This layer looks at how client assets are actually controlled and operated. The operating structure breaks down into three components.
-
a. Key management and signing controls, which determine who can move the asset
-
b. Client asset segregation, which determines to whom client assets continue to belong
-
c. Collateral and settlement structure, which determines where assets are exposed during the trading process
This report examines the custody market through these two layers. Section 2 covers custodial status, Section 3 covers operating structure, and Section 4 applies this framework to vendor comparison.
2. Custodial Authorization and Institutional Status
Custodial status answers the question of who exercises control over client assets and under what institutional capacity that party assumes responsibility. Regulators look first at whether a company actually exercises control over client assets, before considering whether the company calls itself a technology company, an exchange, or a custodian.
License names also need to be distinguished carefully. Even when two licenses appear similar, their meaning differs depending on whether they authorize virtual asset activities or establish an institutional status for holding and administering client assets. An activity license is closer to permission for a company to conduct a business. Institutional status defines both custodial responsibility over client assets and the supervisory framework attached to that responsibility.
This distinction creates two entry paths into custodial status. One is an incorporation path that connects the institutional status of existing financial institutions, such as banks and trust companies, to virtual asset custody. A national trust bank, a Limited Purpose Trust Company, and the notification path under MiCA Article 60 fall into this category. The other path is to obtain an activity-specific authorization for virtual asset services themselves. New York’s BitLicense, EU CASP authorization, and Korea’s VASP registration fall into this category.
This distinction matters because an entity that only holds an activity license may be authorized to conduct that business, but it does not automatically assume the full custodial responsibility of holding client assets. Some jurisdictions, such as New York, also maintain both activity licenses and institutional status. For vendor analysis, the more important question is not simply where a vendor is licensed, but what type of authorization it holds. The next two sections examine each path in turn.
2-1. Incorporation Through Existing Financial Institutions
This is the path in which institutions already supervised by financial regulators, such as banks, trust banks, and investment firms, add digital asset custody on top of their existing authorization. Regulators have already examined these institutions’ capital, internal controls, audits, and client asset protection frameworks. When reviewing new digital asset custody activities, they also consider how those activities connect to the existing supervisory framework.
In the United States, the OCC and NYDFS represent this approach. The OCC has interpreted the safekeeping and administration of virtual assets on behalf of clients as part of banks’ existing custody functions. The national trust bank status is the representative form of this approach. It is a nationwide bank status authorized around trust and custody functions, not a general commercial bank centered on deposits and lending. With this status, a provider can offer digital asset custody as a custody activity supervised under banking law, not merely as a technology service.
NYDFS provides two paths for virtual asset businesses. BitLicense is an activity license for conducting businesses such as virtual asset trading, transfer, and custody in New York. A Limited Purpose Trust Company is an institutional status that allows an entity to perform trust and custody functions for client assets. In the institutional custody market, the latter is used more directly to explain client asset safekeeping responsibility and qualified custody requirements.
Qualified custody refers to a custody arrangement required by investment advisers, asset managers, ETF issuers, and prime brokerage clients. It is a structure that shows assets are segregated by a regulated entity and managed in line with ledger, audit, and reporting standards.
Custody entities and trading or technology entities can be separated even within the same brand. Coinbase states that institutional clients’ custody assets are held by a separate entity, Coinbase Custody Trust Company. Fireblocks is known as a wallet and policy engine infrastructure company, but it separately operates Fireblocks Trust Company, which received a trust company charter from NYDFS. This distinction becomes important in the vendor comparison in Section 4. The relevant comparison unit is not the brand, but the legal entity that holds client assets and that entity’s regulatory status.
In the EU, MiCA sets out a relatively clear entry path for existing financial institutions. General service providers must obtain CASP authorization, while MiCA Article 60 allows existing financial institutions, such as credit institutions, central securities depositories, investment firms, electronic money institutions, and fund managers, to enter virtual asset services through a notification procedure to their supervisory authority. Under this structure, the capital, internal controls, audits, and client asset protection frameworks of existing financial institutions are linked to the review of virtual asset services.
The advantage of this path is regulatory credibility and institutional investor compatibility. When a bank or trust company is already inside the financial supervisory framework, clients can assess not only wallet technology, but also capital, audits, internal controls, conflict management, and client asset protection using the familiar language of financial supervision.
2-2. Dedicated Virtual Asset Service Provider Authorization
The dedicated virtual asset service provider path enters custody through authorization or registration for virtual asset services themselves, without relying on bank or trust company status. Korea’s VASP registration, EU CASP authorization, activity-based licenses under Dubai VARA, and Singapore’s DPT service rules fall into this category. Names differ by jurisdiction, but they commonly impose requirements such as client asset segregation, ledger management, cold wallet storage, limits on rehypothecation, and responsibility when losses occur.
Korea is closest to this model. The Act on Reporting and Using Specified Financial Transaction Information treats the safekeeping and administration of virtual assets within the virtual asset service provider framework. Digital asset custodians therefore enter the regulated perimeter through FIU registration and anti-money laundering, information security, and user protection requirements, rather than through a separate trust bank charter. User cash deposits must be managed through segregated bank deposits or trusts, while user virtual assets must be segregated from the service provider’s own assets, with a certain minimum proportion held in cold wallets.
The advantage of this path is design tailored to digital asset operations. Systems can be built from the outset around wallets, key management, on-chain deposits and withdrawals, staking, and collateral management. Holding a license alone, however, does not complete the trust required by institutional clients. Providers still need to separately explain how client assets are segregated from company assets, what legal structure protects clients in the event of insolvency, and who controls signing authority.
2-3. What the Two Paths Leave Different
Both paths are ways to conduct digital asset custody within the regulated perimeter, but they speak to institutional clients in different languages of trust. The existing financial institution path is anchored in a tested financial supervisory framework, fiduciary and custodial responsibility, audits, and internal controls. The dedicated virtual asset service provider path is anchored in operating designs tailored to digital assets, such as on-chain deposits and withdrawals, multichain wallets, staking, exchange connectivity, and policy-based withdrawal approvals.
This difference appears directly in vendor due diligence. Banks and asset managers tend to use institutional statuses such as national trust bank, Limited Purpose Trust Company, and MiCA Article 60 to verify regulatory credibility and qualified custody requirements. Hedge funds and market makers evaluate custodial status as well, but place greater weight on deposit and withdrawal speed, supported chains, collateral mobility, and exchange connectivity. This is why due diligence questions differ by client type, even for the same custodian.
Custodial status is the starting point for vendor evaluation. Bank or trust company status explains legal responsibility and the supervisory framework, but it does not automatically show how client assets are segregated at the wallet level. Dedicated virtual asset service provider authorization is useful for on-chain operations, but auditability, return mechanics in insolvency, and custodial responsibility must be demonstrated separately. The next section examines how client assets are controlled and segregated through actual products, accounts, and operating structures.
3. Custody Operating Structure
The custody operating structure is how legal responsibility is implemented in actual operations. Most digital asset custody incidents occur at this layer. Even with legal status, weak withdrawal approval policies can lead to misdirected asset transfers. If client-level ledgers do not match on-chain balances, the scope of return in insolvency becomes unstable. Even when off-exchange settlement is used, unclear collateral and settlement failure rules can reduce exchange deposit risk while creating new counterparty risk.
3-1. Authority to Transfer Assets: Key Management and Signing Controls
The first component is key management and signing control. This area determines who can actually move client assets. Key management refers to the entire process of generating private keys, storing them, using them to sign transactions, and recovering them when an incident occurs. A private key is an electronic signing instrument that allows assets on a blockchain to be transferred. Because the party with the key can move the asset, the key management structure is not only a security function. It is a structure for asset control.
Traditional key management has long used HSMs and KMSs. HSM stands for Hardware Security Module. It is dedicated hardware designed to generate and store keys inside the device. Its strength is preventing keys from leaving the device, which is why it has been widely used in banking, payments, and authentication systems. KMS stands for Key Management Service. It is a system that manages the key lifecycle, including key generation, access authorization, usage logging, rotation, and destruction.
In digital asset custody, MPC has also become an important approach. MPC stands for Multi-Party Computation. It creates signatures using key shares distributed across multiple participants, rather than keeping one complete key in a single place. When signing, each participant uses only its own share, and the complete key is never assembled in one location. This structure reduces the risk of an entire key being stolen and can require multiple approvers or systems to sign together before a transaction is executed.
Using MPC does not by itself determine the nature of the custody structure. The responsibility structure depends on who holds the key shares. If the custodian controls all shares, the arrangement is custodial, with the client delegating asset transfer authority to the custodian. If the client and custodian each hold shares, the arrangement becomes joint control or hybrid. If the client holds the shares entirely and the service provider only provides software, the structure is non-custodial. If the holder of the key shares is unclear, recovery authority and responsibility also become unclear when an incident occurs.
A policy engine must operate alongside this. A policy engine predefines who can send which assets, when, to which addresses, and up to what amount, and applies those rules during transaction approval. For example, withdrawals above a certain amount can require approval from two or more people. Transfers to addresses outside a pre-registered address list can be blocked. Different approval procedures can be applied based on chain, asset, or counterparty. If keys are the technical authority that moves assets, the policy engine is the operating mechanism that restricts that authority so it is used only in line with internal organizational rules.
This structure matters because blockchain transfers are difficult to reverse. Once a transaction signed to the wrong address is finalized, recovery is difficult. Evaluation therefore needs to cover not only who holds the key, but also under what conditions signatures are created. Even if keys are stored securely, weak approval policies make it difficult to prevent insider abuse or incorrect withdrawal instructions.
3-2. Asset Ownership and Recoverability: Client Asset Segregation
The second component is client asset segregation. This area determines to whom client assets continue to belong and whether they can be returned in a crisis. Client asset segregation is the mechanism that prevents client assets from being commingled with the service provider’s own assets. It works only when the legal structure, account structure, wallet structure, and ledger structure are aligned.
First, the legal character of client assets must be clear. Risk changes depending on whether the client continues to hold the substantive rights to the asset after entrusting it, whether the custodian only performs safekeeping and administration, and whether the custodian can use the asset for its own purposes. If the custodian can lend, pledge, or manage client assets, the client assumes not only safekeeping exposure but also the custodian’s credit and operating risk. This is why regulatory frameworks restrict unauthorized use and rehypothecation of client assets.
Next, the account structure matters. One approach uses separate wallets for each client. Another pools multiple clients’ assets in one wallet or a group of wallets, while separating client balances through an internal ledger. The former is a segregated wallet structure, while the latter is an omnibus structure. A segregated wallet structure makes client assets easier to identify, but increases operating costs and address management burden. An omnibus structure is operationally efficient, but it requires strict controls to keep internal ledgers and on-chain balances aligned.
In an omnibus structure, the key requirement is that the aggregate on-chain amount matches each client’s rights recorded in the internal ledger. When several clients’ assets are held together in one on-chain address, outsiders only see the combined balance. If the internal ledger is inaccurate, it may become unclear how much must be returned to a particular client. Conversely, even if client balances appear correct in the internal ledger, an insufficient actual wallet balance raises the question of whether the custodian truly holds the assets. Reconciliation is the process of comparing and matching client balances in the internal ledger with actual on-chain balances. This is why reconciliation is critical to segregation structures.
Wallet operations also affect the level of protection. A cold wallet stores keys in an environment separated from the internet. A hot wallet is connected online to process deposits and withdrawals. Institutional custody combines these methods depending on withdrawal demand, trading frequency, security standards, and regulatory requirements. What matters here is not simply the cold wallet ratio. The more important questions are which assets are in which wallets, who has signing authority over those wallets, and how frequently they are reconciled with internal ledgers.
Sub-custody also needs to be checked. Sub-custody is a structure in which a custodian delegates part of client asset safekeeping or operations to another custodian or infrastructure provider. In this case, the custodian with which the client contracts may differ from the party that actually controls the keys. If a hack, withdrawal suspension, accounting error, or custodian insolvency occurs, the client’s ability to recover assets depends on the legal structure, wallet segregation, reconciliation cycle, and whether sub-custody is used.
3-3. Asset Exposure During Trading: Collateral and Settlement Structure
The third component is the collateral and settlement structure. This area determines where client assets remain during trading, what counterparty risks they are exposed to, and how trade outcomes are finalized and settled. Here, collateral refers to assets required by an exchange to provide trading limits or cover potential position losses. Settlement is the process of determining and executing who must deliver how much to whom based on trade results.
The most familiar method for institutional investors trading digital assets is pre-depositing assets, or pre-funding. Assets are sent to an exchange in advance so that trading can take place. This method is simple, but if the exchange is hacked, becomes insolvent, or blocks withdrawals, the investor also bears deposit risk that is not directly related to the trade itself.
A representative solution for reducing this deposit risk is OES. OES stands for Off-Exchange Settlement. It is a structure that allows users to access exchange liquidity and settle trade results without directly depositing assets at the exchange. Under OES, client assets remain with a custodian or in a separate collateral wallet, while only collateral allocation or trading limit information is communicated to the exchange. Once trades are executed, profit and loss, collateral, and final settlement amounts are processed according to pre-agreed cycles or conditions.
When assessing a collateral and settlement structure, three questions should be checked. First, do client assets move to the exchange wallet, or do they remain in the custodian wallet? Second, what rights does the exchange have over those assets? Client asset risk differs depending on whether the exchange only verifies trading limits or can demand collateral transfer or liquidation when losses occur. Third, when are profits and losses settled after trading, and what procedures apply if settlement fails?
OES is designed to structure these three points differently from the exchange deposit model. Client assets are kept inside the custodian instead of being continuously left at the exchange, while trading limits and settlement are connected. OES does not eliminate risk by itself. Client risk changes depending on whether collateral reuse is permitted and how settlement failures between the exchange and custodian are handled.
Representative examples of OES include Copper ClearLoop, BitGo Go Network, Anchorage Atlas, Zodia Interchange, and Komainu Connect. They share the goal of reducing exchange deposit risk, but use different legal mechanisms, such as trust structures, qualified custody, or inter-institution settlement networks. Section 4 compares these differences by vendor.
3-4. Summary

The custody operating structure breaks down into key management, client asset segregation, and collateral and settlement. Key management covers the authority to move client assets. Client asset segregation covers asset ownership and returnability. Collateral and settlement cover exposure arising during the trading process. The next section compares vendor differences using these three components.
4. Vendor Comparison: Custodial Status and Operating Structure
The sequence for applying the two layers above to vendors is straightforward. First, determine whether the vendor directly holds custodial status. If it does, it is a regulated custodian that directly bears ultimate custodial responsibility for client assets. If it does not, and only provides key management and wallet operation tools, it is technology infrastructure that helps institutions build their own operating systems. Custodial status is the primary classification criterion. The three components of the operating structure do not define the category. Instead, they show how vendors differ within the same category. Providers that do not fit neatly into either category are addressed separately in the final subsection.
This section does not recommend any particular vendor. Its purpose is to organize how providers in the same custody market differ in legal responsibility and operating structure. Vendors closer to embedded wallets or user onboarding, such as Privy and Web3Auth, are excluded here because they are better addressed in a separate wallet infrastructure report.
4-1. Regulated Custodians
Regulated custodians are vendors that directly assume custodial status and provide key management, asset segregation, and collateral and settlement themselves. The starting point for comparison is which legal entity holds client assets and under which authorization. In December 2025, the OCC approved the conversion of BitGo’s and Fidelity Digital Assets’ state trust companies into national trust banks and granted new charters to Ripple and Circle. In the United States, this made the convergence of regulated custodians toward federal trust bank status clearer. Coinbase’s application, however, was not included in this group, so Coinbase Custody continues to operate under New York trust company status. Gemini Trust Company is also a qualified custodian with limited purpose trust company status under New York Banking Law, and is a subsidiary of Gemini Space Station, Inc., which listed on Nasdaq under the GEMI ticker in September 2025.
Their profiles also differ by origin and region. Zodia Custody, Komainu, and Sygnum Bank provide digital asset custody through the language of traditional financial institutions or regulated financial institutions. Anchorage Digital, BitGo, Coinbase Custody, Gemini Trust Company, Fidelity Digital Assets, and Fireblocks Trust Company explain institutional custody requirements through positions such as U.S. trust company, national trust bank, and NYDFS trust company. Hex Trust is a regionally focused custodian that has grown around Asian and Middle Eastern regulatory hubs such as Hong Kong, Singapore, and Dubai. Copper is a regulated MPC custodian registered with the UK FCA, without a bank charter.

Even among regulated custodians, operating methods differ. Key management spans Anchorage’s HSM and biometric authentication, BitGo’s multisig and MPC, MPC at Fireblocks Trust, Sygnum, and Copper, and Komainu’s optional MPC and HSM models. Asset segregation also differs between omnibus ledgers and on-chain individual segregation.
The largest difference in collateral and settlement is whether OES is provided. Anchorage Atlas, BitGo Go Network, Zodia Interchange, Komainu Connect, Copper ClearLoop, and Fidelity’s Collateral Account Suite provide OES that settles without depositing assets at exchanges. Gemini, Fireblocks Trust Company, and Hex Trust do not separately provide OES, so trading depends on other methods such as pre-funding. Coinbase vertically integrates custody, trading, and prime services within its own ecosystem, while Sygnum processes settlement through a settlement network called Sygnum Connect. Both structures differ from OES for external exchanges.
Even among vendors that provide OES, the legal mechanisms differ. Copper ClearLoop establishes an English Law Trust over dedicated accounts and Copper holds assets as a security trustee, creating bankruptcy remoteness while collateral does not leave Copper custody. BitGo’s Go Account does not use a trust structure. It processes settlement on top of BitGo’s custodial status and off-chain ledger. OES should therefore be compared using the criteria outlined in Section 3-3: where the assets remain, what rights the exchange has over the collateral, and how the settlement cycle and failure handling work.
The same brand can also be divided into custody entities and trading or technology entities. Coinbase Custody and Coinbase Prime, as well as Fireblocks Trust Company and Fireblocks Platform, are examples. The table should therefore be read at the entity level, not the brand level.
4-2. Technology Infrastructure
Technology infrastructure vendors provide tools that institutions use to build their own key management and wallet operating systems, without holding custodial status. Because these vendors are not the ultimate custodians, component b (asset segregation) and component c (collateral and settlement) are generally designed by the institutions using the infrastructure. OES assumes custody, so these vendors cannot provide it on their own. The comparison criterion is therefore not licensing status, but who holds key shares and how signing approval and recovery authority are designed.

Their key management models differ from the start. Fireblocks Platform uses MPC-CMP to distribute key shares across the client, Fireblocks infrastructure, and an independent recovery partner. Turnkey uses a non-custodial model in which the complete key does not leave a TEE such as AWS Nitro Enclaves. Dfns distributes keys across MPC nodes and offers options to store key shares in HSMs, enclaves, or on-prem environments. GK8 combines an air-gapped cold vault that is not connected to the internet with an MPC wallet for high-frequency trading. Taurus-PROTECT adds MPC support to a Thales HSM base to provide custody and tokenization infrastructure for banks.
Here, Fireblocks Platform is technology infrastructure in this table and is a different entity from Fireblocks Trust Company in Section 4-1. Providing powerful key management tools and legally custodying client assets are different layers of the problem.
4-3. Providers Excluded from the Tables
The two tables above include vendors that directly provide the operating structure for digital asset custody or sell the tools for it. This subsection covers two categories that were excluded from the tables but that institutions encounter when designing custody. The reason they are excluded itself shows what the two-layer framework groups together and what it separates.
General-purpose KMS products such as AWS KMS, Google Cloud KMS, and HashiCorp Vault are general infrastructure for generating and storing keys and secrets and controlling access to them. They provide component a (key management) in the operating structure, as defined in Section 3-1, namely lifecycle management for key generation, access, rotation, and destruction. However, they are not built specifically for digital assets. They do not provide the policy engine that controls on-chain transfer authority, component b (asset segregation) that separates client assets from provider assets, or component c (collateral and settlement) that manages exposure during trading. A general-purpose KMS is therefore not a custody solution by itself. It is a component that institutions can insert as the key management backend when building their own custody framework. In practice, infrastructure providers such as Dfns use these KMS products as a key storage layer. They are excluded from the table not because they lack functionality, but because they fill only one of the three components, component a (key management).
Fuze is a VASP authorized by VARA for Broker-Dealer Services, not Custody Services. It is B2B2C infrastructure that helps banks and fintechs embed digital asset products into their own apps. It does not provide custody itself, but integrates with regulated custodians such as Hex Trust through partnerships. The reason Fuze is excluded from the table differs from the reason general-purpose KMS products are excluded. A general-purpose KMS provides at least one component of the operating structure. Fuze does not itself hold custodial status or provide the operating structure. It delegates both to external custodians and focuses on access and distribution. Fuze is therefore viewed separately as an access and distribution layer that does not belong to either of the two categories.
4-4. Summary of the Comparison
Vendors in the same custody market solve different problems. The primary criterion that separates vendors is custodial status. Regulated custodians that directly bear legal responsibility for client assets and technology infrastructure vendors that only provide key management and wallet operation tools without that responsibility perform fundamentally different functions. Within each category, the three components of the operating structure distinguish vendors from one another. Regulated custodians may share custodial status, but their key management models range from HSMs and biometric authentication to multisig, MPC, and air-gapped cold storage. Their asset segregation differs between omnibus and on-chain individual segregation. Their collateral and settlement structures differ based on whether they provide OES and which legal mechanisms they use. Vendor comparison is therefore not a matter of choosing a brand. It begins by dividing the market by custodial status, then examining how each vendor solves specific problems across key management, asset segregation, and collateral and settlement.
5. Conclusion
Digital asset custody is infrastructure that combines legal custodial responsibility, key management, wallet operations, client asset segregation, exchange connectivity, and collateral and settlement structures. In traditional finance, custody supports safekeeping, settlement, ledger management, and rights processing. In digital assets, cryptographic keys, on-chain wallet control, withdrawal approval policies, and exchange deposit risk management are added to that role.
When institutions review custody, they must first decide who will bear legal responsibility for client assets. The first decision is whether to use an external custodian, build internal infrastructure, or combine a custodian with technology infrastructure. At this stage, statuses such as national trust bank, New York trust company, qualified custodian, VASP, and CASP become meaningful. These labels do not all indicate the same level of custodial responsibility, so institutions need to verify the entity that actually holds client assets and the supervisory framework that applies to that entity.
Next, they need to examine the operating structure. In practice, larger differences arise from who controls asset transfer authority, how client assets are segregated from company assets, and how exchange deposit risk and collateral and settlement are managed. Even among vendors with the same custodial status, the risk structure changes depending on whether they use HSM or MPC, whether they use segregated wallets or omnibus ledgers, and whether they provide OES or rely on pre-funding.
The same implications apply to Korean institutions. They should not look only at the license names of overseas vendors. They need to examine what custodial responsibility each license implies, how client assets are segregated, who holds key and approval authority, and where assets remain during trading. Digital asset custody is not a matter of selecting a vendor name. It is a matter of deciding how to allocate legal ownership, transfer authority, operating controls, and settlement risk.
For this reason, the institutional custody market is unlikely to evolve into a market where a single winner replaces every function. Regulated custodians, custody operating infrastructure, trading and settlement networks, and wallet and KMS technologies are likely to perform different roles and be combined in different ways. Custody vendor comparison should begin by decomposing that structure.
Disclaimer
I confirm that I have read and understood the following: The information contained in this article is strictly the opinions of the author(s). This article was authored free from any form of coercion or undue influence. The content represents the author's own views and does not represent the official position or opinions of CrossAngle. This article is intended for informational purposes only and should not be construed as investment advice or solicitation. Unless otherwise specified, all users are solely responsible and liable for their own decisions about investments, investment strategies, or the use of products or services. Investment decisions should be made based on the user’s personal investment objectives, circumstances, and financial situation. Please consult a professional financial advisor for more information and guidance. Past returns or projections do not guarantee future results.
Xangle or its affiliated partners own all copyrights of the written or otherwise produced materials and content provided on the platform. Any illegal reproduction of such content, including, but not limited to, unauthorized editing, copying, reprinting, or redistribution will result in immediate legal actions without prior notice.

![[Xangle RWA Series] Tokenized Alternatives](https://resource.xangle.io/files/content/4CC9F01B59B75EE060E1CED81479662A_1784708136454.webp)
![[Xangle RWA Series] Tokenized Bonds](https://resource.xangle.io/files/content/B0441837E0B8CB1A38F95639330AAAE7_1783499602150.webp)
![[Xangle RWA Series] Tokenized Stocks](https://resource.xangle.io/files/content/CFCAFEC4A99C7A00EDE70BA3198A8D7B_1782366959101.webp)
