Written by
Vin Molino
COO and Head of Operational Due Diligence
Topics
Allocators
Liquid Funds
Operational Diligence
Research
Industry Research
 |  
September 16, 2026

Self-Custody or Third-Party Custody: How To Assess the Risks?

Written by
Vin Molino
COO and Head of Operational Due Diligence
Topics
Allocators
Liquid Funds
Operational Diligence
Research

Throughout the end of August and extending into the recent weeks of September, there has been the unfortunate flow of news regarding weaknesses and breaches related to crypto self-custody hardware wallets. Examples have included Trezor reporting customer data breaches resulting from a third-party email provider having client information stolen and then used to perpetuate a false security alert under the guise of a fraudulent email. Another involved SafePal informing their customers of a flaw in an order-tracking plugin which exposed names, contact information, shipping addresses and purchase details belonging to thousands of customers. And of the potentially highest profile exploits reported in recent weeks, and noted largest hack, was the matter of Coldcard having over $130 million of customer assets (all Bitcoin) stolen in an ongoing multi-wave attack occurring just within the last week.

In short, the various risks, limitations and costs of maintaining self-custody, at least as far as using hardware wallets go, have made themselves well known.

Although it is hard to know if there is causation related to the above, there has been another interesting trend that has increased in prominence in the same period over recent weeks, which includes the appearance of in-kind creations of popular ETFs, whereby rather than purchasing ETF shares with cash (fiat), digital assets investors have been using their existing crypto holdings to buy ETFs. In fact, the largest Bitcoin ETF, BlackRock’s iShares Bitcoin Trust (Ticker: IBIT) announced a reduction in the minimum for in-kind creations and redemptions, reducing the minimum investment from $25 million to $1 million, per reporting which states the change was reflected in an updated SEC filing.

The implication here is that as investors reduce their direct crypto holdings in individual custody accounts, they are very likely creating another type of custody risk. By taking their assets out of their various respective crypto accounts, they are creating concentration risk amongst digital asset custodians, as the predominant counterparties to the largest ETFs, many of which use one, and very likely no more than two, qualified custodians.

Taking a step back and analyzing the current state of general options for crypto custody, it increasingly appears that to truly assess the risks of how to choose a means of custody, one must understand the pros and cons of self and third-party custody.

Industry Expectations and Current State of Custody

In observing the recent events detailed above, Crypto Insights Group polled dozens of institutional crypto fund managers, who collectively represented over $1.8 billion in assets under management (“AUM”) during our August 2026 survey, questioning where institutional Bitcoin custody settles within the next 24-months, as it related to the Coldcard exploit.

The results from the survey question were overwhelmingly decisive, as a clear majority, or nearly 60% of respondents, expect custody to consolidate into qualified custodians and ETF wrappers within two years. 

Further, multisignature (“multisig”) and multi-computational (“MPC”) vendor arrangements round out the second and third likeliest arrangements, with the potential recovery of hardware wallet providers, as the least likely custody arrangement into the future.

Based on the above data, some of the largest and more complex participants in the digital assets investment industry foresee a trend where third-party custody may become the standard and preference for holding crypto assets.

However, although the population of survey participants mostly took the stance of third-party custody becoming the norm, current information from the CIG FirmIQ™ dataset shows a significant percentage of crypto managers at 40% still maintaining self-custody of their clients’ assets.

Due Diligence Guidelines for Custody Risks

In assessing the risk of hardware wallets, a due diligence framework can be built around the following research and standards, which incorporates some of the lessons learned from recent events:

  • Understanding if the wallet utilizes open-source vs. closed-source firmware, and whether the secure element's internal logic is independently auditable or a vendor black box.
  • For those concerned about quantum computing risks, inquiring about key generation methodology and whether entropy sources have been independently tested.
  • Knowing about seed and key storage, whether private keys ever leave the secure element, and how signing operations are isolated from the host device.
  • Accounting for a history of side-channel or supply-chain vulnerability disclosures.
  • Following a chain of custody process once devices arrive at their intended destination.
  • Monitoring track record. Has a vendor ever experienced a publicly disclosed compromise, and how was it handled?

For third-party custody risk management, which the CIG team has direct experience with and offers as a service, due diligence should include:

  • As most natively-crypto counterparties remain private and venture capital-backed businesses, asking questions about corporate structure, ownership structure, jurisdiction of incorporation and regulatory exposure.
  • Requesting documents to evidence financial stability (i.e., funding history, revenue model, runway and if willing to disclose, providing financial statements).
  • Providing information on insurance coverage, such as errors & omissions (“E&O”), cyber, or product liability coverage, relevant to firm-wide compromise.
  • Detailing the frequency and scope of third-party penetration tests and cryptographic audits.
  • Asking about a firm's custody process and controls workflow (i.e., multi-sig quorum setup, air-gapped signing, or integration with institutional platforms).
  • Disclosing documents and providing testing details related to business continuity and disaster recovery, in particular for those companies which have centralized locations and may rely on remote work as a back-up to continuing operations.

Lastly, and as a reminder to the above risk framework with respect to third-party custodians, many still do not adhere to the U.S. SEC’s definition of a “qualified custodian” and should not be assumed to operate under such standards.

Supporting a Custody Determination

In concluding the above, it is important to note not all digital assets have the potential convenience of being held with a third-party custodian, as a vast majority of DeFi tokens still only remain available to hold custody via a hardware, desktop or mobile application. This is often a result of third-party custodians making a choice to custody crypto which is likely also traded by an affiliated broker, or that certain custodians aim to maintain their qualified custody standards, as financial regulation on the matter still remains elusive. Which makes the decision of choosing a custody method all the more important.

Despite digital asset custody having risks that are specific to the asset class, it is in carefully understanding and assessing risks that allows for the potential of achieving outsized portfolio returns by capturing unique sources of alpha.

The team at Crypto Insights Group, through our years of experience managing crypto assets, and in creating institutional research, benchmarks and due diligence, have the ability to support investors through the digital asset investment process.

Reach out to learn more about how CIG can support your crypto allocation goals.