The SEC is trying to drag crypto custody rules out of the paper era and into the private-key era. That is a real shift, but it comes with plenty of guardrails, political friction, and a very familiar regulatory question: how much flexibility is too much before “modernization” turns into a mess?
- New framework: Aimed at RIAs and regulated funds
- More custody options: State trust companies and some broker-dealer services
- Limits remain: Cybersecurity, segregation, and client protections
- Pushback is coming: Critics say it may weaken investor safeguards
On October 1, the U.S. Securities and Exchange Commission proposed a new framework to modernize crypto custody rules under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. The goal is simple enough: give registered investment advisers and regulated funds a cleaner legal path to hold crypto assets for clients, while still keeping the usual compliance machinery in place. The push comes as the SEC proposes new crypto custody rules to expand investor access without blowing up the guardrails.
For the crypto industry, custody is not a side issue. It is the gate. If regulated firms cannot legally and safely hold digital assets, they cannot offer crypto products at scale. That leaves the market stuck in a swamp of workarounds, half-measures, and “we’ll get back to you after the next legal memo.” The Commission’s broader effort also tracks with the SEC proposal to address how investment advisers and funds can custody crypto assets under federal law.
SEC Chairman Paul Atkins framed the proposal as a way to clear away the uncertainty that has built up around outdated rules. He said the agency wants to cut through the “grey of uncertainty” created by rules that no longer fit the market well.
That matters because crypto custody does not map neatly onto the old securities playbook. Traditional custody rules were built for assets held by banks, brokers, and other familiar intermediaries. Digital assets are controlled through private keys, wallets, and network permissions. That is not a tiny accounting tweak. It is a different plumbing system entirely. The SEC’s own custody overhaul also builds on the agency’s long-running framework in the Final Rule: Custody of Funds or Securities of Clients by investment advisers.
The proposal would permit crypto assets to be held in self-custody under certain circumstances and would allow state trust companies to serve as custodians. The SEC also says it is updating requirements around broker-dealer custodial services for regulated funds. In plain English: the list of entities that may be allowed to safeguard crypto is getting wider, but not exactly open season. That lines up with the agency’s broader Proposed rule: Adviser and Regulated Fund Custody Rules, which spells out the new framework in more detail.
There are still hard guardrails. The framework keeps a strong focus on cybersecurity controls, asset segregation, and customer protection rules. Asset segregation is simple but crucial: client assets have to stay separate from a firm’s own assets so they cannot be mixed, borrowed, or quietly repurposed when things get ugly.
Crypto history has already supplied enough cautionary tales here. When firms blur the line between client property and house money, the result is usually not “efficient capital allocation.” It is usually a crater.
The proposal also appears to supersede the SEC’s 2023 “Safeguarding Rule” proposal, which was withdrawn in 2025 after heavy criticism over how restrictive it was. That earlier effort was widely viewed as a bad fit for crypto custody in the real world. The new version looks like the SEC is at least acknowledging that a one-size-fits-all rule written for another era was not doing anyone any favors. The debate has been running hot for months, including in coverage of the SEC preparing new crypto custody rules for advisers and broker-dealers and the qualified custodian debate intensifying.
Still, not everyone is impressed.
Commissioner Caroline Crenshaw has argued that allowing state trust companies to act as custodians could weaken investor protections. Her criticism is blunt: state trust companies are not federally chartered banks, and they are overseen through a less consistent state-by-state framework. In her view, the SEC is carving out a crypto-specific exception that could leave investors with less protection than they would get in more traditional custody arrangements. The agency’s own explanation also reflects this tension in the statement on SEC allows state trust companies to custody crypto assets.
That objection is not just bureaucratic pearl-clutching. If a custodian is responsible for safeguarding client assets, then the quality of oversight matters. A lot. The whole point of custody rules is to reduce the chance that client assets disappear into some failure of process, controls, or basic honesty. If a new framework loosens the bar too much, the industry gets flexibility at the expense of reliability. That is not innovation. That is just risk with better branding. For a legal industry take, see also the discussion on SEC allows state-chartered trust companies to serve as crypto custodians.
The banking lobby is also pushing back. The Bank Policy Institute, along with the Association of Global Custodians and the Financial Services Forum, has urged the SEC to keep custody standards strong. Their argument is straightforward: banks already safeguard enormous sums, they have decades of experience handling client assets, and any crypto custodian should face strict segregation, ongoing oversight, and prudential standards equivalent to existing qualified custodians. Their position is laid out in Banks urge SEC to apply proven safeguards to crypto custody.
A qualified custodian is simply a regulated entity legally allowed to hold client assets under securities law. Banks want the SEC to stick close to that model rather than improvising a crypto-specific shortcut. The SEC is also being asked to square its proposal against the expanded role of state trust companies, which is why the issue keeps circling back to the same core question: who gets to hold the keys, and why should anyone trust them?
They also oppose self-custody by investment advisers. That concern is easy to understand. If an adviser recommends crypto, routes the trade, and holds the assets too, the conflicts of interest start stacking up fast. Trust me, “we can police ourselves” is rarely the line that calms regulators or clients.
The real tension here is not innovation versus no innovation. It is how much trust the system should place in new custody models, and how much proof should be required before those models are allowed to scale.
Crypto-native firms will say they understand the technology better than legacy institutions. Banks will say custody is custody, and that decades of controls, audits, and segregation rules still matter more than ideology. The SEC seems to be trying to split the difference: expand the pool of eligible custodians, but keep the compliance screws on tight. The policy direction is also being watched closely alongside the SEC chair Paul Atkins crypto custody roundtable signaling a broader regulatory shift.
That balance is delicate. Too much restriction and crypto stays boxed out of mainstream finance. Too little and the agency could repeat old mistakes under a shinier blockchain wrapper, including weak segregation, concentration risk, and thin insolvency protections. That is how “flexibility” becomes somebody else’s cleanup bill.
For advisers, regulated funds, and investors, the practical impact could be significant if the final framework stays broad enough. More compliant custody options would make it easier to offer crypto exposure without relying on awkward legal workarounds. That could expand investor choice, which is exactly what the SEC says it wants.
The proposal is now in a 60-day public comment period after publication in the Federal Register. After that, the SEC will review feedback, revise the language if needed, and vote on a final version before any guidelines become binding. A related proposal, Regulation Crypto Assets, is also moving through the process.
Final timing is still uncertain. The SEC has not locked in a fast path here, and the outcome will depend on what the agency decides after the comment period. In other words, this is an important step, not the finish line.
What matters most is the direction of travel. The SEC is no longer pretending crypto custody can be governed cleanly by a system built for paper certificates and old market structures. Whether this becomes a smart modernization or a messy exception will depend on how much the agency tightens the details before the ink dries.
Key questions and takeaways
-
Why does crypto custody matter so much?
Because regulated advisers and funds cannot offer crypto at scale unless they have a legal and operational way to safeguard client assets. Custody is the plumbing under institutional adoption. -
What is the SEC trying to change?
The SEC wants to update custody rules under the Investment Advisers Act of 1940 and the Investment Company Act of 1940 so they work better for digital assets, while still requiring safeguards like cybersecurity and asset segregation. -
Will advisers be able to self-custody crypto?
In limited circumstances, yes. But this is not a blanket approval, and the final conditions will matter a lot for how useful the rule becomes in practice. -
Who could serve as a crypto custodian under the proposal?
The SEC says state trust companies may be able to serve as custodians, and it is also updating rules around broker-dealer custodial services for regulated funds. -
Why are critics pushing back?
Some critics, including Commissioner Caroline Crenshaw and banking groups, argue the framework could weaken investor protections by lowering custody standards for crypto compared with traditional assets. -
What happens next?
The proposal enters a 60-day comment period, after which the SEC will review feedback, make revisions if needed, and vote on a final version before it becomes binding.