For an institution, the hard part of owning Bitcoin is no longer access. Regulated wrappers are abundant, they track spot within a few basis points, and the tax and fee questions are well understood. The hard part is custody, and the market has answered it in a way that quietly recreates the single point of failure the asset was designed to remove: one custodian now safekeeps more than 80% of the Bitcoin behind US spot ETFs, and it has disclosed that, in a bankruptcy, the customers whose coins it holds could rank as unsecured creditors.
The decision separates into two layers. The first is the exposure vehicle: an ETF, an equity proxy, direct ownership, and the options in between. The second, which only arises once an institution holds real coins, is the custody model: who controls the keys, and what happens to client assets when that party fails. The two layers meet at custody, and that is where the risk now concentrates: the dominant failure mode across the ecosystem is the compromise of private keys, not the failure of cold-storage cryptography, and a decade of insolvencies has turned that legal risk from theory into precedent.
The argument set out here is that for a fiduciary holding Bitcoin over a long horizon, the custody model is the variable that matters most, and that distributing custody across several independent institutions addresses the counterparty, single-point-of-failure and seizure risks that a single custodian cannot. This is an argument about an architecture, not a product, and it is bounded: multi-institution custody is the right default for resilience-first institutional holding, not for high-frequency trading, small balances, or holders who require client-held keys. One rubric is applied to every option so the comparison is even-handed, and the analysis concedes where the architecture costs something.
What “best” means, and why custody is the crux
Bitcoin is now large enough to sit among the major asset classes and still small enough to be early. Its supply is fixed by protocol at 21 million coins, of which roughly 95% are already mined, and its market value was about 1.3 trillion dollars in mid-June 2026 at a spot price near 66,000 dollars. It also remains volatile at institutional scale: it set an all-time high near 126,200 dollars in October 2025 and fell to about 60,000 dollars by early February 2026, a drawdown of roughly 52% and its worst correction since the post-FTX bear market. An asset that can halve in four months is one where the structure you hold it through, the fees, the tax treatment, and above all the custody, compounds into the return as much as the entry price does.
That is why “best exposure” is the wrong question if it means “closest to spot.” Two vehicles holding the same coin can deliver very different outcomes after fees and tax. US spot ETFs are grantor trusts for tax purposes, so holders are taxed as if they owned the Bitcoin directly, at the standard capital-gains rates that apply to property rather than the higher 28% collectibles rate. Futures-based ETFs receive Section 1256 treatment, a fixed 60/40 split regardless of holding period, and carry a roll cost that can drag on performance. Fees range about tenfold across spot ETFs alone, from 0.15% on the cheapest to 1.50% on the most expensive. The better question is which vehicle, and which custody model inside it, fits a given holder’s objective, horizon and operational capacity.
Access is solved. What is not solved is who holds the coins and what happens when they fail. For a long-horizon institution, that single question separates the vehicles more than tracking error ever will.
The exposure-vehicle landscape
The first decision is the vehicle. The main options are scored below across six dimensions an institutional holder actually weighs: control over the asset, counterparty and insolvency risk, resilience to a single point of failure, resistance to seizure and jurisdictional reach, cost and liquidity, and the holder each option fits. The ratings are deliberately coarse, because the honest signal is the pattern across a row, not a false precision in any one cell. Multi-institution custody appears here as one row among many, long before its own section.
| Exposure vehicle | Control | Counterparty | No single point of failure | Seizure resistance | Cost & liquidity | Best‑fit holder |
|---|---|---|---|---|---|---|
| Spot BTC ETF | Weak | Partial | Weak | Weak | Strong | Liquidity‑first allocators; trading and tax‑advantaged accounts |
| Futures‑based ETF | Weak | Partial | Partial | Weak | Weak | Short‑horizon tactical; futures‑tax users |
| Equity proxy (treasury cos, miners) | Weak | Weak | Weak | Weak | Partial | Equity‑only mandates seeking a convex proxy |
| Closed‑end trust (legacy) | Weak | Partial | Weak | Weak | Weak | Mostly historical; legacy holders |
| Wrapped / tokenized BTC | Partial | Weak | Weak | Partial | Partial | On‑chain and DeFi users needing composability |
| Self‑custody (cold) | Strong | Strong | Weak | Partial | Partial | Technically capable individuals (not fiduciaries) |
| Single‑custodian custody | Partial | Partial | Weak | Weak | Strong | Institutions wanting one regulated relationship |
| Multi‑institution custody | Partial | Strong | Strong | Strong | Partial | Fiduciary institutions holding for resilience |
A few rows carry most of the message. The spot ETF is the strongest vehicle on cost and liquidity, which is why it has become the default access route, but it scores weakly on control and resilience: the holder owns shares, not coins, cannot redeem for Bitcoin, and inherits whatever concentration sits behind the fund. Self-custody is its mirror image, strong on control and counterparty risk because there is no third party, but weak on operational resilience for a single holder, and a poor fit for a fiduciary that cannot put an estate’s assets behind one person’s key management. Single-custodian custody is convenient and regulated but remains a single point of failure. Multi-institution custody is the only row that scores strongly on counterparty, single-point-of-failure and seizure resistance together, at the cost of being partial on control, because keys are distributed across institutions rather than held by the client, and partial on cost and liquidity, because it is serviced and slower. That profile is the argument, and the next two sections are why it holds.
Where the risk concentrates
Concentration: the choke point
The ETF era was sold as a democratisation of Bitcoin access. Underneath, it concentrated custody. Coinbase states in its own SEC-filed shareholder letters that it is the custodian for over 80% of US Bitcoin and Ethereum ETF assets, and describes itself as the “primary custodian for the vast majority of crypto ETFs.” Its total assets under custody across all clients reached 300 billion dollars at the end of the third quarter of 2025. The concentration was near-total at the start: Coinbase was the named custodian for nine of the eleven spot Bitcoin ETFs at launch in 2024, and still eight of eleven by late 2025.
| Custodian | Share of US spot‑Bitcoin‑ETF assets | Total assets under custody |
|---|---|---|
| Coinbase | over 80% (BTC and ETH ETFs, per its own SEC filings) | ~$300B (Q3 2025) |
| All other custodians (Anchorage, BitGo, Fidelity, others) | under 20% | — |
The same pattern repeats at the issuer level, and the two overlap inside a single fund. BlackRock’s iShares Bitcoin Trust holds close to half of all US spot-ETF assets, and its prospectus names Coinbase Custody Trust Company as the custodian of the trust’s Bitcoin, with Anchorage Digital as an alternate. The largest issuer and the dominant custodian are therefore the same dependency. The market has begun to diversify, slowly: BlackRock added Anchorage as a second custodian in 2025, Grayscale named Anchorage for new products in 2026, and Coinbase received OCC preliminary conditional approval in April 2026 to establish a national trust bank. None of this changes the basic picture. A regulated, “diversified” exposure rests, for most holders, on one institution.
The failure record
Theft is not a tail event in this ecosystem; it is a structural feature. More than 3.4 billion dollars was stolen through crypto hacks in 2025, the highest annual figure since 2022, though below that year’s 3.8 billion peak. The total has stayed in the billions every year since 2022, and the losses are extraordinarily concentrated: the three largest hacks accounted for 69% of all service losses in 2025, and a single breach of one exchange, Bybit, took about 1.5 billion dollars.
| Year | Crypto stolen (USD, Chainalysis) |
|---|---|
| 2022 | ~$3.8 billion (prior peak) |
| 2023 | ~$1.7 billion |
| 2024 | ~$2.2 billion |
| 2025 | over $3.4 billion (highest since 2022, below the 2022 peak) |
The detail that matters for custody design is how the money leaves. The dominant failure mode is the compromise of private keys and signing infrastructure, not the failure of cold-storage cryptography or smart-contract code. Compromises at centralised services accounted for 88% of all stolen value in the first quarter of 2025, driven by attacks on private keys and signing infrastructure, which were already the single largest category in 2024 at about 44%. The lesson is that the thing being attacked is the key, and a model that places all of an estate’s keys inside one organisation concentrates exactly the surface that is most often breached. Two regulated custodians outside the major Western jurisdictions show how total such a failure can be: DMM Bitcoin lost about 308 million dollars in 2024 (per the FBI, Japanese authorities and Chainalysis) and wound down within months, and WazirX lost about 235 million the same year (Elliptic).
One widely cited episode deserves correction, because using it loosely would weaken the argument. Coinbase disclosed in May 2025 that overseas support contractors had been bribed to exfiltrate customer personal data, at an estimated remediation cost of 180 to 400 million dollars. Its own filing is explicit that “the Incident did not involve the compromise of passwords or private keys, and at no time were any of the targeted contractors or employees able to access customer funds.” It is a serious insider-and-fraud event, and it is not a custody theft. It belongs in the record as evidence of the human and insider attack surface, not as a stolen-funds figure.
When “custodied” means “unsecured creditor”
The deepest risk is legal, and it is the one institutions underweight. The largest US-listed crypto custodian disclosed in its own filings that, in a bankruptcy, “the crypto assets we hold in custody on behalf of our customers could be subject to bankruptcy proceedings and such customers could be treated as our general unsecured creditors.” Crypto held on a custodial platform carries no FDIC or SIPC backstop. Whether custodied coins are the customer’s property or the platform’s estate property turns on contract terms and segregation, analysed under the bankruptcy code’s broad definition of estate property.
A custodian disclosed, in its own SEC filing, that in bankruptcy its customers “could be treated as our general unsecured creditors.” Custody is not ownership unless the legal structure makes it so.
This is realised precedent, not theory. When Celsius failed, the bankruptcy court ruled that about 4.2 billion dollars of assets in its Earn programme were property of the estate and that the depositors were unsecured creditors. Its separate Custody programme fared better, but through a negotiated settlement that returned an initial 72.5% in kind, not a clean ruling that custody assets are exempt. The cleanest pure-custody failure is Prime Trust, a chartered trust company that became insolvent owing customers about 85.7 million dollars in fiat against 2.9 million on hand. Chartered status did not make it bankruptcy-remote.
Two qualifications keep this honest. First, the catastrophic losses, FTX, Celsius, BlockFi, Genesis, were failures of lending and rehypothecation (the platform re-lending or re-using customer assets), not of pure cold-storage custody; those platforms were custodians in name only. The distinction is the point: it isolates custody design as the variable that decides the outcome. Second, outcomes vary, and a freeze is not always a permanent loss; Gemini Earn users, frozen when Genesis halted withdrawals, ultimately recovered their crypto in full in kind. The regulatory response points the same way the evidence does. New York’s financial regulator now requires custodians to segregate customer assets, hold them as a fiduciary rather than a debtor, and title them for the benefit of customers, guidance updated in September 2025. The structural fix the failures imply is segregation and clear, customer-protective titling, enforced rather than promised.
Custody models compared
The custody problem has a small number of structural answers, and they are easy to confuse because the vocabulary overlaps. The comparison below applies the same rubric used for the exposure vehicles.
| Custody model | Control | Counterparty | No single point of failure | Seizure resistance | Cost & liquidity | Verifiability |
|---|---|---|---|---|---|---|
| Single‑custodian (incl. intra‑org multisig) | Partial | Weak | Weak | Weak | Strong | Attestation / audit |
| MPC (single‑org threshold) | Partial | Weak | Partial | Weak | Strong | Off‑chain (not protocol‑verifiable) |
| Collaborative custody (client + co‑signers) | Strong | Strong | Strong | Partial | Partial | On‑chain m‑of‑n |
| Multi‑institution custody | Partial | Strong | Strong | Strong | Partial | On‑chain m‑of‑n |
The distinctions are real and often blurred in marketing. A single-custodian “multisig” (several keys, of which a set number must sign) usually distributes those keys within one organisation; it addresses internal key loss but does nothing for single-counterparty risk, because the institution remains one point of failure. Multi-party computation, or MPC, splits one logical key into threshold shares so that no complete key is ever assembled. It is fast, flexible and asset-agnostic, and it removes the cryptographic single point of failure. But when one organisation holds all the shares, it does not remove the institutional one, and the scheme is off-chain: the threshold policy is not visible to or enforced by the blockchain, and the standards are still being written. On-chain multisig is different in kind: several complete, independent keys, with the m-of-n rule (you need m of the n keys to authorise a move) enforced and verifiable by the Bitcoin protocol itself. In a two-of-three, the holder can lose one key and recover, and an attacker needs two independent keys to move funds.
That last property is what makes distributing custody across independent institutions more than a slogan, and it can be put in numbers. Independent estimates put even the strongest crypto custodians at a small but non-trivial annual probability of default, clustered around 0.4% to 0.85%. If two such custodians are genuinely independent, the chance that both fail in the same year is close to the product of their individual probabilities, far smaller than either alone.
| Custodian | 12-month probability of default (Agio Ratings, Q1 2026) |
|---|---|
| Fidelity | 0.39% |
| Anchorage | 0.46% |
| BitGo | 0.46% |
| Coinbase Prime | 0.49% |
| Komainu | 0.66% |
| Copper | 0.83% |
| Gemini | 1.01% |
The arithmetic comes with a caveat that must travel with it. Two custodians at, say, 0.46% and 0.66% imply a joint probability near 0.003% only if their failures are independent. In the real world they may share banking rails, insurers, sub-custodians or a regulatory regime, and a common shock raises the joint probability above the naive product. The honest claim is therefore not that distributed custody makes failure impossible; it is that, to the extent independence is real and maintained, it converts a single sub-1% exposure into a far smaller joint one. Independence is the load-bearing assumption, which is why the next section is about how it is maintained rather than merely asserted.
Multi-institution custody in depth
The topology is the starting point. In a two-of-three across independent institutions, each party holds one complete key, and any two can authorise a transaction. No single institution can move funds alone, and no single institution’s insolvency, seizure or breach can either capture the assets or freeze them: the surviving two route around the third. A key-share held by one institution is not a claim on the coins that an estate can absorb, which is precisely the failure mode that turned Celsius and Prime Trust depositors into creditors.
Normal operations follow a fixed, offline sequence:
- Initiate. A withdrawal is requested through the platform.
- Verify. It is checked against the client’s authorisation policy.
- Sign. The first institution reconstructs its key and signs.
- Co-sign. A second institution adds its signature, and the two-of-three threshold is met.
- Broadcast. The signed transaction is sent to the Bitcoin network.
Signing takes place offline, in air-gapped environments; private keys never touch the internet. And within each institution the same logic repeats one level down: the institution’s key is itself split among separated holders, so no single person holds a complete key. Collusion would therefore require compromising multiple individuals across multiple independent organisations at once, and should any one institution fail, the other two can still recover the client’s assets.
Independence is the property that makes this work, and it is not automatic. It has to hold across several axes at once: ownership, so the institutions are not under common control; jurisdiction, so no single court or coercive authority reaches a quorum; regulator; technology and vendor, so a single software defect cannot compromise more than one key; personnel; physical location; banking relationships; and auditors. Where any of these collapse into a shared dependency, the joint-probability benefit erodes, because failures become correlated. This is the discipline behind the model: independence is designed in and then maintained, and it is audited, not assumed.
The model also makes the legal and verifiability questions easier to answer well. Because the keys sit with separate institutions under segregation and customer-protective titling, the structure aligns with exactly what regulators now require after the insolvency wave, that customer assets be held as a fiduciary and for the benefit of customers rather than as the platform’s own. And because the m-of-n rule is enforced on-chain, holdings can be verified against the Bitcoin blockchain rather than taken on a custodian’s attestation. Several institutional custodians already market on-chain segregated and bankruptcy-remote structures (legally arranged so client assets are not the custodian’s property if it fails) with independent proof of reserves and withdrawal time-locks, and at least one statutory regime, Bermuda’s Digital Asset Business Act, has been tested in court to confirm that customer assets held by a licensed custodian are not the property of the custodian in its insolvency. These are noted as evidence that the properties are achievable and being built, not as endorsements of any provider.
The honest tradeoffs
A model that genuinely earned a strong score in every column would be a sales document, not an analysis. Multi-institution custody costs something real. It is slower and more operationally involved than handing assets to one custodian: a transaction needs a quorum, and coordination across independent institutions takes time and process. It is partial on control in this rubric because the client does not hold a key directly; control is distributed across institutions rather than retained by the holder, which is the right trade for most fiduciaries but the wrong one for a holder who insists on personally controlling a key. It introduces coordination overhead and governance complexity. And its central benefit depends entirely on independence being maintained over time, which is an operational commitment, not a one-time design choice. These are the reasons the model is a default for one kind of holder and not a universal answer.
Matching the model to the holder
The two layers resolve into a single decision once a holder is honest about objective, horizon and operational capacity. The table below reads the rubric back as guidance rather than scores.
| Holder and objective | Exposure vehicle | Custody model | Why |
|---|---|---|---|
| Liquidity or trading mandate, short horizon, no operational capacity | Spot ETF | Custodian-managed (inherited) | Cost and liquidity dominate; concentration is an accepted cost |
| Technically capable individual, sovereignty first | Direct ownership | Self-custody or collaborative | Control is the objective; the holder can own the key-management risk |
| Fiduciary institution, resilience over a long horizon | Direct ownership | Multi‑institution custody | Counterparty, single-point-of-failure and seizure risk dominate the decision |
| Institution prioritising one simple regulated relationship | Direct ownership | Single-custodian qualified custody | Accepts single-counterparty risk for operational simplicity |
The cost of resilience
The table begs the obvious question: what does the resilient option cost, and is it worth it? Multi-institution custody is not the cheap choice. A single qualified custodian charges on the order of 10 to 50 basis points a year and is operationally simplest; distributing custody across independent institutions adds a premium on top, because more parties are involved and every transaction needs a quorum. What it buys is a change in the shape of the tail risk, not a marginal efficiency.
| Single‑custodian | Multi‑institution | |
|---|---|---|
| Annual cost | ~10 to 50 bps; operationally simplest | a negotiated premium on top; serviced, slower |
| What impairs the assets | one institution fails (~0.4% to 1% a year) | roughly two independent failures in a short window (far lower joint probability) |
| Recovery if it does | uncertain; historically near-total loss to substantially whole | segregation plus the surviving quorum route around any single failure |
| Right when | cost and simplicity dominate | the cost of a tail event dominates |
So the question is not whether multi-institution custody is cheaper. It is not. It is whether the reduction in tail risk is worth a measured premium, and for a fiduciary holding for resilience over a long horizon, where a single custodian’s failure is the loss that matters most, it is. The figures above are illustrative and the premium is holder-specific; the point is the shape of the trade, not a precise price.
The institutional direction of travel runs toward the factors this analysis favours. In a 2026 survey, 73% of institutions planned to increase digital-asset allocations, two-thirds accessed Bitcoin through regulated wrappers, and custodian selection was increasingly driven by regulatory compliance and key-signing controls rather than brand. As more of the decision rests on how custody is actually engineered, the case for distributing it strengthens.
The conclusion here is narrow on purpose. For a fiduciary institution holding Bitcoin for resilience over a long horizon, multi-institution custody is the right default, because it is the only model that addresses counterparty, single-point-of-failure and seizure risk together, and because its costs, slower and serviced operations, and distributed rather than client-held control, are the right ones to pay for that holder. It is not the right answer for high-frequency trading, for small balances where the operational overhead is disproportionate, or for holders who require a personally held key. The market solved access. The open question is custody, and the resilient answer is to stop trusting one institution to hold everything.
Outlook
The concentration this report describes is unlikely to resolve on its own. The forces that produced it, the convenience of a single integrated custodian and the economics of scale, are still in place, and the diversification underway is slow. At the same time, the regulatory architecture is moving toward segregation, customer-protective titling and federal supervision, which makes well-structured independent custody easier to build and to evidence. The gap between “custodied” and “owned” is likely to narrow in law and widen in practice, and resilience-first holders are likely to lead the move toward distributing trust rather than concentrating it. The companion report in this series, Gold, the dollar, and bitcoin, ends where this one begins: for a long-horizon institution the operative question is less whether to hold Bitcoin than how to hold it safely, and that turns on custody.
Frequently asked questions
Who custodies the Bitcoin behind US spot ETFs?
By its own SEC-filed disclosures, Coinbase is the custodian for over 80% of US Bitcoin and Ethereum ETF assets, and was the named custodian for eight of the eleven US spot Bitcoin ETFs as of late 2025. BlackRock's iShares Bitcoin Trust, which holds close to half of all US spot-ETF assets, names Coinbase Custody Trust Company as its custodian, with Anchorage Digital as an alternate. The largest issuer and the dominant custodian are, for most holders, the same dependency.
If a crypto custodian goes bankrupt, do customers keep their coins?
It depends on the contract terms and on whether assets are properly segregated. The largest US-listed crypto custodian has disclosed in its own filings that, in a bankruptcy, custodially held crypto could be treated as property of the estate and customers as general unsecured creditors. Crypto custody carries no FDIC or SIPC backstop. The Celsius and Prime Trust insolvencies turned that risk from theory into precedent, so custody is not ownership unless the legal structure makes it so.
What is multi-institution custody?
It is an arrangement in which several independent institutions each hold one complete key to the same Bitcoin, with an on-chain m-of-n rule (for example, two of three) enforced by the Bitcoin protocol itself. No single institution can move the funds alone, and no single institution's insolvency, seizure or breach can capture or freeze them, because the surviving quorum routes around the failed one.
How is multi-institution custody different from MPC or single-custodian multisig?
Single-custodian multisig usually distributes keys within one organisation, so the institution itself remains a single point of failure. MPC splits one logical key into threshold shares, but when one organisation holds all the shares it removes only the cryptographic single point of failure, not the institutional one, and it is off-chain. Multi-institution custody distributes complete, independent keys across separate institutions, and the quorum is verifiable on-chain.
How should an institution decide how to hold Bitcoin?
Match the exposure vehicle and custody model to objective, horizon and operational capacity. Liquidity-first or trading mandates favour spot ETFs; sovereignty-first individuals favour self-custody; and for a fiduciary holding for resilience over a long horizon, multi-institution custody is the strongest fit, because it is the only model that addresses counterparty, single-point-of-failure and seizure risk together, at the cost of being slower and serviced.
This article is published as research and analysis. It does not constitute legal, regulatory, financial, or investment advice and should not be relied upon in connection with any specific transaction or licensing strategy. Readers should seek their own qualified counsel. Where specific products, providers or jurisdictions are named, they are referenced factually on the basis of public information, for analysis, and not as endorsements.