How Asset Managers Can Securely Handle Digital Assets
Client demand for digital asset exposure is no longer a niche request. Asset managers and family offices are increasingly expected to handle digital assets with the same level of security, oversight, and reporting they already apply to every other asset class. The challenge is that most of the infrastructure available today was not built with that expectation in mind.
Why is handling digital assets harder for asset managers than traditional assets?
Digital assets are harder to handle because control of an asset comes down to control of a private key: there is no central authority to fall back on if something goes wrong, and no institution to call to reverse a transaction. For an asset manager, that raises a practical question that traditional custody never had to answer: who actually holds the keys, and what happens if that party makes a decision the manager doesn't agree with, freezes an account, changes its terms, or exits the market altogether.
The market reflects this shift: between January 2025 and January 2026, the share of institutional decision-makers citing security and key-signing protocols as a key factor in choosing a custodian rose from 8% to 66%, according to the 2026 Institutional Digital Assets Survey by Coinbase Institutional and EY-Parthenon.
What options do asset managers have today, and why do they fall short?
Asset managers have three conventional paths, and each one breaks something the manager needs:
| Option | How it works | Where it breaks |
|---|---|---|
| Third-party custodian | Clients' assets sit with an external custodian; the manager gets API access at most | The manager cannot act without the client and is structurally disintermediated from the relationship |
| Becoming a licensed custodian | The firm acquires its own custody licence | Capital, governance structures, and ongoing regulatory obligations that are hard to justify unless custody is the core business |
| Client self-custody | The client holds a hardware wallet or single-signer setup | No audit trail, no shared oversight, and one lost device or forgotten password away from the client losing everything |
What does securely handling digital assets actually require?
Secure handling means the asset manager can act on a client's behalf, within an agreed mandate, without ever being the only party who could move funds, and without losing the operational speed clients expect. It also means every action is recorded and reportable, so if a regulator, auditor, or the client themselves asks what happened to a position, there is a clear answer.
This is where the underlying technology matters. Rather than one party holding a full private key, the key is split into several shares held by separate parties, so no single share is ever enough to move funds on its own. A movement only goes through when enough of the right parties agree, which means the asset manager can operate day to day, the client keeps the ability to step in and stop anything they don't approve of, and there's no need for the asset manager to become a licensed custodian just to offer this service.
How does the hybrid custody model work in practice?
The Vault supports asset managers through a hybrid custody model built around three parties, where any movement needs at least two of the three to agree, so no party, including The Vault, can act alone. The client holds a share and can veto any movement. The asset manager initiates and signs day-to-day operations within the mandate the client has set. The Vault holds a share as the regulated party and applies KYC, AML, sanctions, and Travel Rule checks on every transaction.
Compliance is built into this flow rather than added on top of it. Every transaction carries its own KYC, sanctions screening, and Travel Rule check, and every action across every wallet is logged with who initiated it, who approved it, and when, giving the firm a complete record ready for an auditor or regulator without extra reporting work.
Can asset managers start without deploying their own infrastructure?
Yes. For firms that want to move quickly, the model runs as a managed SaaS setup with nothing to deploy. For firms with their own technical team and a mandate for full in-house control, the same model can run on-premise inside their own infrastructure, and moving from one to the other later is designed to be a smooth transition rather than starting over.
If you're weighing how to offer digital assets to clients without taking on the risk of self-custody or the burden of a custody licence, contact us. We're happy to answer your questions and book a demo for you.
Frequently asked questions
Do asset managers need a custody licence to handle client digital assets?
Not necessarily. In a hybrid custody model, the manager holds only one share of a split signing key and can never move funds alone, while a regulated custodian co-signs every transaction. The manager operates within the client's mandate without taking custody of the assets.
What is hybrid custody?
Hybrid custody is a model in which the signing key for a wallet is split into shares held by the client, the asset manager, and a regulated custodian. A transaction goes through only when enough of these parties agree, so no single party controls the assets.
What happens if a client disagrees with their asset manager's decision?
The client holds their own key share and can veto any movement. Because the manager's share alone is never enough to sign a transaction, nothing can happen to the client's assets without a second party agreeing.
Why is client self-custody risky for an asset manager?
Self-custody through a hardware wallet or single-signer setup leaves no audit trail and no shared oversight, and a single lost device or forgotten password can mean total loss. It also gives the manager no compliant way to act on the client's behalf.
How is compliance handled when an asset manager operates client wallets?
In a hybrid model the regulated custodian co-signs every transaction and applies KYC, sanctions screening, and Travel Rule checks in the signing flow itself. Every action is logged with who initiated and approved it, producing a regulator-ready record automatically.