Skip to main content
Multi-institution custody | Definition

What is multi‑institution custody?

Multi-institution custody (MIC) is a Bitcoin custody model in which three independent, regulated institutions each hold one key to a client’s vault, and any movement of funds requires two of the three to sign. No single institution can move, freeze, or lose the bitcoin on its own, and the client’s assets survive the failure of any one participant.

The term is often shortened to MIC. This page defines the model, shows how it works, compares it honestly with the alternatives, and sets out how it meets regulation.

01 | How it works

Three keys, three institutions, three jurisdictions. Two must sign.

A multi-institution vault is a 2-of-3 multisignature address on the Bitcoin blockchain. Each of the three keys is generated and held by a different institution, in a different jurisdiction, under its own regulator and its own security controls. Every client holds a segregated vault, and the client retains title to the bitcoin at all times.

The three key holders carry distinct roles. A transaction coordinator operates the platform, initiates transactions, and signs first. A signing key agent independently verifies each transaction and provides the second signature in normal operations. A recovery key agent holds the third key and signs only in defined recovery events, initiated by the client, so the arrangement does not depend on any one firm continuing to exist. The quorum rule is enforced by the Bitcoin protocol, not by procedural agreement.

Across institutionsThe quorum

Onramp MENA
Transaction Coordinator
& Primary Key Signer
Bahrain
Tetra Trust
Signing Key Agent
Canada
Coincover
Recovery Key Agent
United Kingdom
2 of 3
Any two of the three must agree before anything moves
Within each institutionNo single person holds a complete key

Onramp MENA

Key split among separated custodians in Bahrain.

12345
3 of 5 to reconstruct
Tetra Trust

Key split within its own offline cold-wallet controls.

12345
3 of 5 to reconstruct
Coincover

Recovery key split within its own controls. Non-custodial.

12345
3 of 5 to reconstruct
For illustrative purposes. The key agents’ schemes stay confidential by design. Publishing them would weaken the security they provide.
Signing workflowOffline · air-gapped

01
Initiate
Withdrawal request via the Onramp MENA platform
02
Verify
Checked against the client’s authorisation policy
03
Sign first
Onramp MENA reconstructs its key and signs
04
Co-sign
One agent adds the second signature | 2-of-3 met
05
Broadcast
The signed transaction is sent to the Bitcoin network
Signing takes place offline, in air-gapped environments. Private keys never touch the internet.
Two levels of quorum: multiple people within each institution, multiple institutions for every transaction. Collusion would require compromising multiple individuals across multiple independent organisations at once. And should any one institution fail, the other two can still recover the client’s assets.
02 | Why it exists

Every other model concentrates failure in one place.

The dominant failure mode across Bitcoin’s history is not the protocol. It is the compromise or failure of whoever holds the keys. A single custodian safekeeps over 80 percent of the bitcoin behind US spot ETFs. Exchange balances are commingled and move on one firm’s authority. A decade of insolvencies has shown that a custodied balance can legally mean an unsecured creditor claim. And self-custody moves every one of those risks onto a single person with a seed phrase.

Multi-institution custody is the structural answer: distribute the keys across independent institutions so that no compromise, insolvency, or mistake at any single point can reach the funds. Containment of failure, rather than hope of avoiding it, is the design goal. The research desk’s analysis of the 2026 hardware-wallet exploit, in which correctly used air-gapped devices were drained because their keys were guessable at generation, is a study in why containment is the right goal.

03 | The comparison

The custody models, on the merits.

Exchange account Single custodian Self-custody Collaborative custody Multi-institution custody
Who holds the keys The exchange, commingled One institution The client Client majority, provider minority Three institutions, one key each
Can one party move the funds Yes, the exchange Yes, the custodian Yes, whoever holds the keys Yes, the client No party holds a quorum
Single point of failure Yes Yes Yes Reduced, key loss survivable None by design
Key burden on the holder None None Full Substantial None
If the provider fails Assets at risk, creditor queue Assets at risk, creditor queue Not applicable Client can still move funds Remaining quorum migrates funds
Best suited to Trading balances Convenience-first holders Technically confident individuals Individuals wanting control with a safety net Institutions, fiduciaries, long horizons

The honest read is that collaborative custody and multi-institution custody solve different problems. The first preserves personal control and its burdens. The second removes both, and answers to holders who need controls that no individual, including themselves, can defeat.

04 | Regulation

A model regulators can supervise.

Multi-institution custody maps onto existing regulatory frameworks because every key holder is itself a regulated institution, and one licensee remains wholly responsible to its regulator for client assets. In Bahrain, the Central Bank of Bahrain supervises crypto-asset custody under the Crypto-Asset Module of Rulebook Volume 6, requires prior approval of a licensee’s custodial arrangement, and treats third-party key holders within it as subcustodians. The Gulf more broadly is building institutional frameworks for digital-asset custody, and the research desk’s comparative analysis of the CBB’s Category-2 framework against ADGM, DFSA, and VARA sets out how the regimes differ.

Onramp MENA is an independent Bahraini firm building institutional Bitcoin custody on this model, with a CBB Category-2 licence application in preparation. The full architecture, parameter by parameter, is on the custody page.

05 | Questions

Multi-institution custody, asked and answered.

What is multi-institution custody?
Multi-institution custody is a Bitcoin custody model in which three independent institutions each hold one key to a client’s vault and any transaction requires two of the three to sign. The client’s bitcoin sits in a segregated on-chain vault, no single institution can move or lose it alone, and the arrangement survives the failure of any one participant.
How is multi-institution custody different from ordinary multisig?
Technically it is built on the same primitive, a 2-of-3 multisignature vault on the Bitcoin blockchain. The difference is who holds the keys. In ordinary multisig one person or firm typically controls several keys, so key management and its failure modes stay concentrated. In multi-institution custody each key is held by a separate regulated institution in a separate jurisdiction, so no party holds a quorum and no single compromise reaches the funds.
How is it different from collaborative custody?
In collaborative custody the client holds the majority of keys, usually two of three, and a provider holds one as a safety net. The client keeps unilateral control and also keeps the key-management burden. In multi-institution custody the client holds no keys at all. Three institutions hold one each, which removes the operational burden and the single-person failure modes, in exchange for accepting institutional counterparties. Collaborative custody suits holders who want personal control. Multi-institution custody suits fiduciaries and institutions that need controls no individual can defeat.
Can any one custodian freeze or lose the bitcoin?
No. Moving funds requires signatures from two of the three institutions, so no single participant can transfer assets, and equally no single participant can block a properly authorised transaction by itself or destroy access by losing its key. The failure of any one institution leaves a functioning quorum of two, which can migrate the client’s funds to a fresh vault.
What happens if one of the institutions fails?
The vault keeps working. Two keys remain, which is exactly the quorum the vault requires, so the remaining institutions co-sign the migration of client funds to a new vault with a replacement key holder. This is the property single-custodian arrangements cannot offer, where a decade of insolvencies has shown that a custodied balance can legally become an unsecured creditor claim.
Is multi-institution custody regulated?
The model maps cleanly onto existing regulatory frameworks because each key holder is itself a regulated institution and one licensee remains wholly responsible to its regulator for client assets. In Bahrain, the Central Bank of Bahrain supervises crypto-asset custody under the Crypto-Asset Module of CBB Rulebook Volume 6, and treats third-party key holders within a licensee’s custodial arrangement as subcustodians subject to prior approval. Onramp MENA is building its custody business on this model in Bahrain, with a CBB Category-2 licence application in preparation.
Who is multi-institution custody for?
Holders for whom a single point of failure is unacceptable and self-managed keys are impractical: institutions, family offices, corporates, trusts, and professional investors with fiduciary duties or long horizons. For a holder comfortable managing hardware and seed phrases personally, self-custody or collaborative custody may fit better. The models solve different problems.
06 | Go deeper

The research behind this page.