Multi-institution custody, asked and answered.
- What is multi-institution custody?
- Multi-institution custody is a Bitcoin custody model in which three independent institutions each hold one key to a client’s vault and any transaction requires two of the three to sign. The client’s bitcoin sits in a segregated on-chain vault, no single institution can move or lose it alone, and the arrangement survives the failure of any one participant.
- How is multi-institution custody different from ordinary multisig?
- Technically it is built on the same primitive, a 2-of-3 multisignature vault on the Bitcoin blockchain. The difference is who holds the keys. In ordinary multisig one person or firm typically controls several keys, so key management and its failure modes stay concentrated. In multi-institution custody each key is held by a separate regulated institution in a separate jurisdiction, so no party holds a quorum and no single compromise reaches the funds.
- How is it different from collaborative custody?
- In collaborative custody the client holds the majority of keys, usually two of three, and a provider holds one as a safety net. The client keeps unilateral control and also keeps the key-management burden. In multi-institution custody the client holds no keys at all. Three institutions hold one each, which removes the operational burden and the single-person failure modes, in exchange for accepting institutional counterparties. Collaborative custody suits holders who want personal control. Multi-institution custody suits fiduciaries and institutions that need controls no individual can defeat.
- Can any one custodian freeze or lose the bitcoin?
- No. Moving funds requires signatures from two of the three institutions, so no single participant can transfer assets, and equally no single participant can block a properly authorised transaction by itself or destroy access by losing its key. The failure of any one institution leaves a functioning quorum of two, which can migrate the client’s funds to a fresh vault.
- What happens if one of the institutions fails?
- The vault keeps working. Two keys remain, which is exactly the quorum the vault requires, so the remaining institutions co-sign the migration of client funds to a new vault with a replacement key holder. This is the property single-custodian arrangements cannot offer, where a decade of insolvencies has shown that a custodied balance can legally become an unsecured creditor claim.
- Is multi-institution custody regulated?
- The model maps cleanly onto existing regulatory frameworks because each key holder is itself a regulated institution and one licensee remains wholly responsible to its regulator for client assets. In Bahrain, the Central Bank of Bahrain supervises crypto-asset custody under the Crypto-Asset Module of CBB Rulebook Volume 6, and treats third-party key holders within a licensee’s custodial arrangement as subcustodians subject to prior approval. Onramp MENA is building its custody business on this model in Bahrain, with a CBB Category-2 licence application in preparation.
- Who is multi-institution custody for?
- Holders for whom a single point of failure is unacceptable and self-managed keys are impractical: institutions, family offices, corporates, trusts, and professional investors with fiduciary duties or long horizons. For a holder comfortable managing hardware and seed phrases personally, self-custody or collaborative custody may fit better. The models solve different problems.