Custodial vs non-custodial: who really holds your money?
Four levels of custody, what changes for security, experience and compliance, and a table against full custody. The word decides who can lose your money.
On this page
When Mt. Gox halted withdrawals in February 2014, roughly 850,000 bitcoins were reported missing. When FTX filed for bankruptcy in November 2022, the hole in customer accounts was about $8 billion. In both cases the money did not vanish from a blockchain. It vanished from a company that was holding it on customers’ behalf. That is the whole subject of this article: who holds the key, and what follows from the answer.
What does “non-custodial” actually mean?
Non-custodial means the service never holds your money. Your funds sit in a wallet that only you can sign from, and the app you use can prepare a payment, display it, even relay it to the network, but it cannot move a cent without your signature. The opposite is custodial: you hand your money to a company, it holds it in accounts under its control, and you keep a claim on it, the way a bank balance is a claim on the bank.
The word matters because it decides three things at once: what can go wrong (security), what you have to do yourself (experience), and which rulebook the company answers to (compliance). Custody is a place in the chain of who can lose your money.
Is it really custodial versus non-custodial, or a spectrum?
A spectrum. In practice there are four levels, and most of the useful conversation happens in the middle two.
| Level | Who holds the key | Typical example | What you rely on |
|---|---|---|---|
| 1. Full custody | The company, in pooled or omnibus accounts | Centralised exchange, most fintech balances | The company’s solvency and honesty |
| 2. Regulated custody | The company, in accounts segregated from its own estate | Licensed custodian, EU CASP under MiCA | The company plus a legal ring-fence and a supervisor |
| 3. Non-custodial, embedded keys | You, through a key split across your login and a secure enclave | Wallets created at sign-in with Google or Apple | The cryptography, plus your login and an export escape hatch |
| 4. Self-custody | You, alone, with a seed phrase or a hardware device | Hardware wallet, browser wallet | Yourself, entirely |
Level 3 is the recent one, and it is why this debate stopped being academic. Wallet infrastructure such as Privy splits a key into two shares: one encrypted inside a trusted execution environment (a sealed compute box even the operator cannot read), one released only against your login. Both are required to sign; neither share alone reveals anything, a scheme known as Shamir’s secret sharing. The result is a wallet that behaves like an app account (sign in with Google, no seed phrase) while remaining, cryptographically, yours: the provider cannot sign for you, and you can export the key and leave.
What changes for security?
Custody concentrates risk; non-custody distributes it. A custodian holding a million customers’ balances is a single vault with a single set of keys, which makes it a target for outsiders and a temptation for insiders. Mt. Gox lost the coins to theft over years and noticed too late; FTX lent customer deposits to a sister trading firm. Both failures were only possible because one company could move everyone’s money at once.
Non-custodial flips the threat model. There is no central pot to drain, so an attacker has to compromise wallets one at a time, and a company failure does not touch your balance: if the app disappears tomorrow, your funds are still on the network, still yours. What you take on in exchange is the responsibility for access. At level 4 that means a seed phrase, and a lost phrase is a lost balance, with nobody to call. At level 3 the responsibility shrinks to keeping your login (Google, Apple, email) and, ideally, saving an exported backup once. It is a much smaller job, but it is still yours.
- Custodial: your risk is the company. Fraud, insolvency, a hack of its systems, a frozen account.
- Non-custodial: your risk is your access. Phishing, a lost device without a backup, a signature you approved without reading.
What changes for the experience?
This is where custodial products used to win outright, and where the gap has closed. A custodial balance feels like any app: forgot your password, reset it; disputed a payment, support can sometimes reverse it; the money moves on the company’s books, instantly and for free, as long as both parties are its customers. The price is that everything happens inside the company’s walls, and leaving means asking permission to withdraw.
Classic self-custody, level 4, asked users to write down twelve words, understand network fees, and accept that a wrong click is final. That is a fine deal for a hardware wallet holding savings, and a terrible one for a payment you make at a restaurant. Level 3 exists to remove that trade-off: the wallet is created at sign-in, fees can be paid on the user’s behalf by a relayer, and the money still moves on a public network in seconds, to anyone, in any country. What remains different from a custodial app is honest and small: no support agent can move your funds for you, in either direction.
What changes for compliance?
Holding other people’s money is a licensed activity; writing software that lets people hold their own is, in most places, not. The distinction is written into the rules, not just the marketing.
- In the European Union, MiCA treats “custody and administration of crypto-assets on behalf of clients” as a regulated service. Article 75 requires the custodian to segregate client assets from its own estate so that its creditors have no recourse to them in an insolvency, and makes it liable for losses attributable to it, capped at the market value of the asset when the loss occurred. That ring-fence is exactly what Mt. Gox and FTX customers did not have.
- In the United States, the SEC’s SAB 121 (2022) required companies safeguarding customers’ crypto to book the full value as a liability on their own balance sheet, which kept most banks out of custody. It was rescinded by SAB 122 in January 2025. The rule existed because custody is a balance-sheet event; a non-custodial app has nothing to book, because it holds nothing.
- Globally, the FATF’s 2021 guidance says providers of “unhosted” wallets and other ancillary software will not normally meet the definition of a virtual asset service provider, because anti-money-laundering duties fall on intermediaries, not on the software people use to pay each other.
- The boundary is policed where the two worlds touch. Under the EU transfer of funds regulation, a licensed provider sending more than 1,000 EUR to a self-hosted wallet must verify that the wallet really belongs to its customer. Identity checks happen at the on-ramp and off-ramp, where money becomes crypto and back, not inside every payment between two people.
The practical consequence for a user: a custodial provider must know who you are before it holds your balance, and can freeze it under a legal order, because it is the one holding it. A non-custodial app knows only what it needs to run, and cannot freeze what it does not hold. Whether that is a virtue or a gap depends on what you are trying to do.
Full custody versus non-custodial, side by side
| Question | Full custody | Non-custodial (embedded keys) |
|---|---|---|
| Who can move the money? | The company, and you through it | Only you, with your signature |
| What if the company fails? | You are a creditor; you may get part of it back, later | Nothing changes; the funds are still yours on the network |
| What if you lose access? | Password reset, identity check, support | Sign back in with your login; a saved export is the last resort |
| Can a payment be reversed? | Sometimes, by the company | No, by design |
| Where does the money move? | On the company’s ledger, visible to it | On a public network, verifiable by anyone |
| Who must know your identity? | The company, always | The on-ramp and off-ramp partner, when fiat is involved |
| What must you guard? | Your password | Your login and, once, a backup |
Which one should you actually want?
It depends on the job, and pretending otherwise is how both camps mislead. If you trade with leverage, need a broker to net positions, or want a human who can unwind a mistake, custody is the right tool and regulated custody is the right version of it. If what you want is a balance that is yours, that no company failure can touch, and that can move to anyone in the world in seconds, then non-custodial is the right tool, and the embedded-key version is the first one that does not demand a seed phrase in return.
Our own view, since we build in that second category: for everyday money between people, level 3 is the honest sweet spot. It keeps the two things users actually care about, “it is mine” and “it just works”, and it drops the thing they never asked for, a company sitting between them and their balance. That is the model behind Spliz: a group’s balances settle in USDCin one transaction, funds stay in each member’s wallet until they sign, and we never hold them. If you want the shorter, splitting-specific version of this idea, we wrote it here.
Why it matters
Every few years the industry relearns that “your balance” on a custodial platform is a promise, and that promises fail in bulk. Regulators writing rules for custodians was overdue. The news of the last two years is that the technology finally made non-custody usable by people who will never say the word. When a wallet is created by signing in with Google and the provider still cannot spend from it, custody stops being a choice between safety and convenience. It becomes a choice about who you want to be able to lose your money: you, or someone else.
Whoever can move your money without asking you is your custodian. Everything else is storage.
Sources
- Mt. Gox, withdrawal halt of 7 February 2014, bankruptcy filing of 28 February 2014, roughly 850,000 bitcoins reported lost (later revised to 650,000).
- Bankruptcy of FTX, Chapter 11 filing of 11 November 2022 and the roughly $8 billion shortfall in customer funds.
- Regulation (EU) 2023/1114 (MiCA), Article 75, custody and administration of crypto-assets on behalf of clients: segregation and liability.
- Regulation (EU) 2023/1113, transfers of funds and certain crypto-assets, the 1,000 EUR threshold for self-hosted addresses.
- SEC Staff Accounting Bulletin No. 122, January 2025, rescinding SAB 121 on safeguarding obligations for crypto-assets.
- FATF, Updated guidance for a risk-based approach to virtual assets and VASPs, October 2021, on unhosted wallets and ancillary software providers.
- Privy, wallet infrastructure architecture, 2-of-2 key shares, trusted execution environments and key export.
The shared account for your friends. Settle your next group tab in one signature.