As institutional participation in digital assets continues to grow, the conversation is no longer centred on whether institutions should hold Bitcoin and Ethereum, but how they can do so securely. Asset managers, family offices, corporate treasuries, and private banks increasingly view digital assets as part of long-term portfolios, and broader institutional interest , including from pension funds in some markets , is also emerging, creating growing demand for sophisticated custody solutions.
Unlike retail investors, institutions require more than a simple wallet. They need governance controls, regulatory oversight, operational resilience, auditability, and secure infrastructure capable of protecting significant holdings. As a result, institutional crypto custody has evolved into a specialised industry focused on safeguarding digital assets while meeting the standards expected in traditional finance.
In 2026, custody is one of the most important pillars of the digital asset ecosystem. The quality of custody infrastructure often determines whether institutions feel confident allocating capital to Bitcoin and Ethereum.
Key takeaways
- Institutional crypto custody has become a critical component of digital asset adoption.
- Bitcoin and Ethereum remain the important assets held by institutional investors.
- Security standards now extend beyond cold storage to include governance, segregation, auditing, and operational controls.
- Institutions increasingly evaluate custodians based on regulatory compliance, resilience, and risk management frameworks.
- The best custodian is not defined by size alone, but by security, transparency, operational processes, and regulatory standing, among other things.
2026 Market context: BTC/ETH custody evolution
The institutional custody landscape has matured significantly over recent years. What began as basic cold-storage solutions has developed into a sophisticated ecosystem designed to support large-scale asset management.
Several trends are shaping Bitcoin and Ethereum custody in 2026.
- Growing institutional ownership
Institutional ownership of Bitcoin and Ethereum continues to expand[AS2.1] [1]through investment funds, corporate treasury allocations, wealth management platforms, and exchange-traded products. As holdings grow larger, institutions require custody infrastructure that are likely to withstand operational, cyber, and governance risks. - Greater focus on operational resilience
The lessons from high-profile industry failures have reinforced the importance of asset segregation, independent controls, and robust risk management. Institutions now scrutinise custody arrangements far more closely than in the early years of digital asset adoption. - Ethereum’s expanding role
While Bitcoin remains the dominant digital asset for long-term strategic allocations, Ethereum has become increasingly important due to its role in tokenisation, decentralised finance, and staking, the latter carrying its own considerations around lock-up periods and protocol-driven reward variability. Custodians must now support not only secure storage but also operational processes surrounding Ethereum networks and staking participation, including these associated risks. - Regulatory progress
Jurisdictions including the EU, under the Markets in Crypto-Assets Regulation (MiCA), Switzerland, under the Swiss Financial Market Supervisory Authority (FINMA), and Hong Kong, under the Securities and Futures Commission (SFC), have introduced clearer frameworks for digital assets, creating more formal expectations for custody providers. Regulatory compliance, reporting standards, and governance practices have become key differentiators among institutional custodians. - Integration with traditional finance
Modern custody providers increasingly offer integrated solutions combining custody, trading, settlement, reporting, banking services, and treasury management. This integration allows institutions to manage digital assets through familiar operational workflows rather than separate crypto-native environments.
What to Evaluate when Choosing the Best Institutional Custodian
Choosing a custody provider involves far more than comparing technology. Institutions typically assess a broad range of factors before selecting a custody partner.
| Evaluation criterion | What it covers | Why it matters |
|---|---|---|
| Security architecture | Key generation, storage, and recovery; cold storage, HSMs, multi-signature, MPC | Minimises single points of failure in private key control |
| Asset segregation | Whether client assets are held separately from the custodian’s own and other clients’ assets | Reduces counterparty risk and improves transparency |
| Governance and access controls | Role-based permissions, multi-person approvals, audit trails | Aligns digital asset management with existing treasury governance |
| Operational resilience | Business continuity, disaster recovery, redundancy | Keeps the platform functioning through outages or market stress |
| Insurance and risk management | Scope, limits, and exclusions of any coverage | Adds a layer of protection, but varies significantly by provider |
| Service offering | Trading, settlement, staking, reporting, treasury management | Reduces operational complexity by consolidating workflows |
There is no single “best” custodian for all institutions. The appropriate choice depends on evaluating factors such as the institution’s risk appetite, investment strategy, regulatory requirements, and operational needs.
- Security architecture
Institutions should evaluate how private keys are generated, stored, protected, and recovered. Strong custodians typically use multiple layers of defence that may include cold storage environments, hardware security modules, multi-signature frameworks, or advanced cryptographic techniques such as multi-party computation.The goal is to minimise single points of failure while ensuring secure access under controlled conditions. - Asset segregation
Segregated custody structures help ensure client assets remain clearly separated from the custodian’s own assets and from those of other clients. This can may reduce operational and counterparty risks while providing greater transparency. - Governance and access controls
Leading custody providers offer role-based permissions, multi-person approvals, transaction policies, and detailed audit trails. These controls help align digital asset management with existing treasury and investment governance frameworks. - Operational resilience
Business continuity plans, disaster recovery procedures, backup systems, and redundancy measures all contribute to operational resilience. A robust custody platform should continue functioning even during technology failures or market stress. - Insurance and risk management
While insurance should not replace strong security practices, it can may provide an additional layer of protection. Many providers offer insurance against specific risks such as cyber theft or internal fraud, giving an added layer of financial protection — though the level and scope of insurance varies with each provider. Institutions should understand the scope, limitations, and structure of any insurance arrangements, rather than relying solely on headline coverage figures. - Service offering
Many institutional investors prefer providers that offer more than storage alone. Integrated services such as trading, settlement, banking, lending, staking, reporting, and treasury management may improve operational efficiency and reduce complexity.
The regulatory compliance and security standards for institutional custodians
Institutional custody requires adherence to standards similar to those expected within traditional financial services.
- Regulatory authorisation
Depending on jurisdiction, this may include banking licences, trust charters, crypto-asset service provider authorisations such as the Markets in Crypto-Assets Regulation (MiCA), or other forms of financial supervision. The scope of services and investor protections differs between these licence types, so regulatory oversight can may contribute to stronger governance, risk management, and transparency. But the specific licence held matters as much as the fact of being licensed at all.Jurisdiction Regulatory framework Regulator Licence type European Union Markets in Crypto-Assets Regulation (MiCA) National competent authorities under MiCA Crypto-Asset Service Provider (CASP) authorisation Switzerland Swiss supervisory framework Swiss Financial Market Supervisory Authority (FINMA) The applicable authorisation depends on the custody structure and services provided, such as banking licence etc. Hong Kong Securities and Futures Ordinance Securities and Futures Commission (SFC) Type 1, 4, and 9 licences United States Fragmented state and federal frameworks Varies by state and federal agency State money transmitter licences, trust charters, and others Note: licence types are not interchangeable , a crypto-asset service provider authorisation and a banking licence carry different capital requirements, prudential standards, and depositor protections. This table is a high-level overview only. Regulatory requirements and licence types vary by jurisdiction, custody structure, and services provided. This does not constitute legal, regulatory, investment, or other professional advice. Readers should obtain independent professional advice and verify the current regulatory position with the relevant competent authority before relying on any regulatory classification.
- Anti-money laundering and financial crime controls
Institutional custodians are expected to maintain robust anti-money laundering (AML) and know-your-customer (KYC) procedures. These frameworks help safeguard financial systems while supporting institutional compliance obligations. - Independent audits
Independent audits have become increasingly important in digital asset custody.Regular assessments of security controls, operational processes, and governance frameworks provide institutions with additional assurance that custody infrastructure is operating as intended. - Cybersecurity standards
Custodians are expected to maintain rigorous cybersecurity programmes. These may include:- Continuous monitoring and threat detection
- Penetration testing and vulnerability assessments
- Access management controls
- Encryption standards
- Network segmentation
- Incident response procedures
Cybersecurity is no longer viewed as a technology issue alone; it has become a core operational risk management function.
- Asset protection and custody controls
Strong custodians establish clear controls around asset movement, key management, recovery processes, and transaction authorisation. The objective is not only to prevent unauthorised access but also to minimise operational mistakes and internal risks. - Transparency and reporting
Institutional investors require detailed reporting, record keeping, and auditability. Custodians increasingly provide comprehensive reporting capabilities to support portfolio oversight, accounting requirements, compliance monitoring, and internal governance processes.
Conclusion
As digital assets become more integrated into institutional portfolios, custody has evolved from a technical consideration into a strategic decision. The strongest institutional custodians in 2026 are not simply those offering secure storage. They are providers capable of combining security, governance, regulatory compliance, operational resilience, and seamless integration with broader financial services.
For institutions allocating Bitcoin and Ethereum, selecting the right custody partner is one of the most important risk management decisions they will make. The focus should not be on brand names alone, but on the underlying controls, infrastructure, regulatory standing, and operational processes that protect assets over the long term.
Institutional digital asset custody should meet the standards investors expect from modern financial institutions: secure, transparent, operating under applicable regulatory frameworks, and built to support long-term participation in the evolving digital asset economy.
FAQs
How do crypto custodians secure Bitcoin and Ethereum?
Institutional custodians typically use a combination of cold storage, advanced cryptography, governance controls, multi-person approvals, continuous monitoring, and independent audits to safeguard client assets. Security focuses on protecting private keys while maintaining operational resilience.
What should institutions look for when choosing a crypto custodian?
Institutions should evaluate security architecture, regulatory status, asset segregation, governance controls, operational resilience, reporting capabilities, and the broader service offering. Custody should fit within the organisation’s overall risk management framework.
Which crypto custodian is best for institutional investors?
There is no single “best” custodian for every institution. Rather than focusing on rankings, institutions may assess custodians based on security standards, regulatory oversight, operational controls, reporting capabilities, and how well the provider’s model aligns with their specific risk and governance requirements.
What makes a custody provider “institutional-grade”?
Institutional-grade custody typically combines robust custody controls, asset segregation, governance processes, and integrated digital asset services designed to support professional and institutional investors, underpinned by operation under one or more recognised regulatory frameworks.
Disclaimer, Research and Educational Content
This document has been prepared by AMINA Bank AG (“AMINA”). AMINA is a Swiss licensed bank and securities dealer with its head office and legal domicile in Switzerland. It is authorised and regulated by the Swiss Financial Market Supervisory Authority (“FINMA”).
This document is published solely for educational purposes; it is not an advertisement nor a solicitation or an offer to buy or sell any financial investment or to participate in any particular investment strategy. This document is for publication only on AMINA website, blog, and AMINA social media accounts as permitted by applicable law. It is not directed to, or intended for distribution to or use by, any person or entity who is a citizen or resident of or located in any locality, state, country or other jurisdiction where such distribution, publication, availability or use would be contrary to law or regulation or would subject AMINA to any registration or licensing requirement within such jurisdiction.
Research will initiate, update and cease coverage solely at the discretion of AMINA. This document is based on various sources, incl. AMINA ones. In preparing this document, AMINA may have made limited use of artificial intelligence enabled tools to assist with research, summarisation, and drafting, with all content subject to human review and validation.
No representation or warranty, either express or implied, is provided in relation to the accuracy, completeness or reliability of the information contained in this document, except with respect to information concerning AMINA. The information is not intended to be a complete statement or summary of the subjects alluded to in the document, whereas general information, financial investments, markets or developments. AMINA does not undertake to update or keep current information. Any statements contained in this document attributed to a third party represent AMINA’s interpretation of the data, information and/or opinions provided by that third party either publicly or through a subscription service, and such use and interpretation have not been reviewed by the third party.
Any formulas, equations, or prices stated in this document are for informational or explanatory purposes only and do not represent valuations for individual investments. There is no representation that any transaction can or could have been affected at those formulas, equations, or prices, and any formula(s), equation(s), or price(s) do not necessarily reflect AMINA’s internal books and records or theoretical model based valuations and may be based on certain assumptions. Different assumptions by AMINA or any other source may yield substantially different results.
Nothing in this document constitutes a representation that any investment strategy or investment is suitable or appropriate to an investor’s individual circumstances or otherwise constitutes a personal recommendation. Investments involve risks, and investors should exercise prudence and their own judgment in making their investment decisions. Financial investments described in the document may not be eligible for sale in all jurisdictions or to certain categories of investors. Certain services and products are subject to legal restrictions and cannot be offered on an unrestricted basis to certain investors. Recipients are therefore asked to consult the restrictions relating to investments, products or services for further information. Furthermore, recipients may consult their legal/tax advisors should they require any clarifications.
At any time, investment decisions (including, among others, deposit, buy, sell or hold investments) made by AMINA and its employees may differ from or be contrary to the opinions expressed in AMINA research publications.
This document may not be reproduced, or copies circulated without prior authority of AMINA. Unless otherwise agreed in writing, AMINA expressly prohibits the distribution and transfer of this document to third parties for any reason. AMINA accepts no liability whatsoever for any claims or lawsuits from any third parties arising from the use or distribution of this document.
©2026 AMINA, Kolinplatz 15, 6300 Zug