Start here: pick a lane
This is a decision map, not a reading list. Choose your custody model, scan its matrix column, and open only the linked sheets for decisions marked YOU or SHARED. If something is already broken, jump straight to the incident router.
Which of these nine sheets do I actually need?
The matrix answers that. Follow the linked decisions that your selected model leaves with you.
What does buying custody actually remove?
The signing primitive and some of its audit burden. Ledger, deposit, reconciliation, compliance-placement, and withdrawal decisions remain elsewhere in the system.
Why is “who owns this” the first question?
Unassigned decisions become incidents. Vendor documentation naturally describes what the vendor does, not the gaps around it.
I have an incident, not an architecture question.
Use the symptom router. First record what you know before changing, retrying, or re-sending anything.
If you remember one lineA custody model decides who signs. It never decides who is responsible.
The complete surface at a glance
Every figure counts this page's own rows. The values change only when the routing map changes.
Choose the column before the product
A hybrid design reads as two rows at once. Do not invent a sixth model that hides where one arrangement ends and the other begins.
| Model | Who holds signing material | What the chain sees | The failure you keep | What you cannot outsource here | Start at |
|---|---|---|---|---|---|
| Self-custody, single key | One organization, one signing key | One ordinary signature | One compromised or unavailable key | Key ceremony evidence and tested recovery | Key ceremony script |
| Self-custody, on-chain multisig | Several independent key holders | The chain-enforced quorum | Correlated holders or an unavailable quorum | Holder independence and recovery topology | Primitive decision matrix |
| Self-run threshold / MPC | Your organization owns shares and signer nodes | One ordinary signature | Correlated nodes, shares, or control plane | Share topology, liveness, and resharing | Share custody topology |
| Custody platform | Vendor infrastructure; you hold a share or callback | One ordinary signature | A valid but hostile request getting signed | Intent verification and the exit package | Policy callback |
| Qualified / third-party custodian | The vendor holds the keys and custody posture | The custodian's signature | Your books, instructions, assets, and provider dependency | Ledger truth, oversight, and an executable exit | Assurance landscape |
The custody responsibility matrix
Pick a mobile column, then read every red or amber token as an owner you must name in the design. Desktop shows all five models side by side.
| Decision | Single key | Multisig | Self-run MPC | Platform | Custodian | If nobody owns it |
|---|---|---|---|---|---|---|
| A · Key material · 6 decisions | ||||||
| Key or share generation ceremony and evidenceOrigin and integrity of signing material cannot be proved. | YOU | YOU | YOU | VENDOR | VENDOR | Origin and integrity of signing material cannot be proved. |
| Signing primitive selectionThe trust model exists only in sales language. | YOU | YOU | YOU | SHARED | SHARED | The trust model exists only in sales language. |
| Share topology and quorum choiceOne correlated event can disable or control the quorum. | N/A | N/A | YOU | SHARED | VENDOR | One correlated event can disable or control the quorum. |
| Share refresh and resharing cadenceDeparted holders or stale shares retain authority. | N/A | N/A | YOU | VENDOR | VENDOR | Departed holders or stale shares retain authority. |
| Backup material and a tested restoreThe backup exists but cannot recreate the wallet. | YOU | YOU | YOU | SHARED | VENDOR | The backup exists but cannot recreate the wallet. |
| Signer loss and media-failure triageEvidence is overwritten before recovery feasibility is known. | YOU | YOU | YOU | SHARED | VENDOR | Evidence is overwritten before recovery feasibility is known. |
| B · Authorization · 4 decisions | ||||||
| Transaction rules and terminal default-denyAn unmatched request becomes silently allowed. | YOU | YOU | YOU | SHARED | SHARED | An unmatched request becomes silently allowed. |
| Approval quorum and policy-change controlOne actor can authorize value or rewrite the gate. | YOU | YOU | YOU | SHARED | SHARED | One actor can authorize value or rewrite the gate. |
| Independent intent verificationValid credentials produce a valid hostile signature. | YOU | YOU | YOU | SHARED | SHARED | Valid credentials produce a valid hostile signature. |
| Destination allow-list and activation delayNew attacker-controlled destinations become immediately spendable. | YOU | YOU | YOU | SHARED | VENDOR | New attacker-controlled destinations become immediately spendable. |
| C · Tiering and float · 3 decisions | ||||||
| Tier structure and hot-float sizingLoss exposure and withdrawal capacity are unbounded. | YOU | YOU | YOU | SHARED | VENDOR | Loss exposure and withdrawal capacity are unbounded. |
| Sweep and rebalance schedulingFunds strand on the wrong side of demand. | YOU | YOU | YOU | SHARED | VENDOR | Funds strand on the wrong side of demand. |
| Velocity limits and value-at-risk policyOne valid path can drain the entire float. | YOU | YOU | YOU | SHARED | VENDOR | One valid path can drain the entire float. |
| D · Ledger and accounting · 3 decisions | ||||||
| Ledger authority, precision, and balance representationBooks round, drift, or cannot explain customer liabilities. | YOU | YOU | YOU | YOU | YOU | Books round, drift, or cannot explain customer liabilities. |
| Wallet-boundary invariantHoldings and liabilities diverge without an alarm. | YOU | YOU | YOU | YOU | YOU | Holdings and liabilities diverge without an alarm. |
| Proof-of-reserves construction and liabilitiesAsset evidence is mistaken for solvency evidence. | YOU | YOU | YOU | SHARED | SHARED | Asset evidence is mistaken for solvency evidence. |
| E · Chain operations · 7 decisions | ||||||
| Deposit detection and address attributionA real transfer is credited to the wrong account. | YOU | YOU | YOU | YOU | YOU | A real transfer is credited to the wrong account. |
| Confirmation and finality policy per chainCredits reverse after value already left. | YOU | YOU | YOU | YOU | YOU | Credits reverse after value already left. |
| Nonce sequencing and address shardingOne nonce gap blocks every later withdrawal. | YOU | YOU | YOU | SHARED | VENDOR | One nonce gap blocks every later withdrawal. |
| UTXO selection and change managementFees spike, privacy collapses, or dust becomes stranded. | YOU | YOU | YOU | SHARED | VENDOR | Fees spike, privacy collapses, or dust becomes stranded. |
| Gas funding for token sweepsToken deposits cannot pay to leave their addresses. | YOU | YOU | YOU | SHARED | VENDOR | Token deposits cannot pay to leave their addresses. |
| Withdrawal idempotency and retry semanticsA timeout becomes a duplicate transfer. | YOU | YOU | YOU | SHARED | SHARED | A timeout becomes a duplicate transfer. |
| Reconciliation and break taxonomyUnexplained differences accumulate into an accepted balance. | YOU | YOU | YOU | YOU | YOU | Unexplained differences accumulate into an accepted balance. |
| F · Compliance placement · 4 decisions | ||||||
| Compliance gate placement relative to signingA prohibited transfer is signed before the stop. | YOU | YOU | YOU | SHARED | SHARED | A prohibited transfer is signed before the stop. |
| Travel Rule transmission and IVMS101 payloadRequired counterparty data is missing or misrouted. | YOU | YOU | YOU | SHARED | SHARED | Required counterparty data is missing or misrouted. |
| Ongoing rescreening of cleared addressesA prior approval outlives the evidence behind it. | YOU | YOU | YOU | YOU | SHARED | A prior approval outlives the evidence behind it. |
| Blocked-property handling and filingsFunds move while the escalation has no owner. | YOU | YOU | YOU | SHARED | VENDOR | Funds move while the escalation has no owner. |
| G · Assets held · 3 decisions | ||||||
| Issuer, reserve, and freeze-authority exposureCustody controls cannot contain asset-level failure. | YOU | YOU | YOU | YOU | YOU | Custody controls cannot contain asset-level failure. |
| Native versus bridged asset selectionThe wrong claim is accepted as the intended asset. | YOU | YOU | YOU | YOU | YOU | The wrong claim is accepted as the intended asset. |
| Depeg and redemption-queue responsePayments continue while the settlement asset fails. | YOU | YOU | YOU | YOU | YOU | Payments continue while the settlement asset fails. |
| H · Assurance, exit, and long horizon · 4 decisions | ||||||
| Control evidence and attestation scopeA badge substitutes for evidence about the actual system. | YOU | YOU | YOU | SHARED | VENDOR | A badge substitutes for evidence about the actual system. |
| Vendor exit test and key-export packageThe vendor relationship becomes an irreversible dependency. | N/A | N/A | N/A | YOU | YOU | The vendor relationship becomes an irreversible dependency. |
| Address-reuse and quantum-exposure inventoryThe riskiest holdings stay invisible to migration planning. | YOU | YOU | YOU | SHARED | VENDOR | The riskiest holdings stay invisible to migration planning. |
| Signature-scheme agility behind an interfaceConsensus change forces a custody-system rewrite. | YOU | YOU | YOU | SHARED | VENDOR | Consensus change forces a custody-system rewrite. |
17 of 34 decisions remain YOU or SHARED in every model. Hybrid designs read as two columns at once.
Incident router: start from the symptom
Record the current state first. The table routes the first check and the first restraint; the linked register owns the investigation.
| Symptom | First thing to check | Do not do this first | Go to |
|---|---|---|---|
| A deposit did not credit | Confirmed chain transfer and owned attribution | Do not re-send or credit manually | Break taxonomy |
| A deposit credited twice | Event identity and ledger idempotency key | Do not delete either posting | Ledger rules |
| A withdrawal is stuck pending | Provider sub-status and chain observation | Do not create a replacement intent | Failure sub-status |
| A withdrawal was sent twice | Internal intent and provider idempotency history | Do not rewrite the audit trail | Idempotency register |
| A nonce gap blocks every later withdrawal | Lowest missing nonce and replacement state | Do not submit higher nonces | Nonce runbook |
| A token is stuck with no gas | Native-asset balance at the deposit address | Do not sweep the token again | Gas-station hazards |
| Balances disagree with the chain | Which wallet-boundary crossing lacks a pair | Do not resume withdrawals | Wallet boundary |
| A reorg reversed a credited deposit | Stored block hash and finality state | Do not relabel it as confirmed | Finality register |
| A transfer landed in a frozen address | Screening result, list version, and gate timing | Do not attempt an improvised onward transfer | Blocked-property runbook |
| A bridged asset will not redeem at par | Exact token contract and movement rail | Do not treat tickers as identity | Rail comparison |
| A stablecoin is off peg during payments | Exposure by issuer, rail, and pending state | Do not continue automatic conversion | Treasury checklist |
| A sanctioned address surfaced after sending | Original and current screening evidence | Do not alter the historical decision record | KYT and sanctions |
| The Travel Rule counterparty is unreachable | Protocol state and authenticated fallback path | Do not sign before the gate resolves | Travel Rule register |
| A seed phrase is incomplete | Known positions, words, format, and checksum constraints | Do not upload it to a website | Recovery triage |
| The wallet shows a zero balance | Chain, account, script type, path, and passphrase state | Do not assume the funds moved | Path diagnosis |
| A signer device or share holder is gone | Remaining quorum and tested recovery material | Do not change policy during the outage | Business continuity |
Lifecycle order of operations
Resolve these bands in order. Each gate is evidence that the band is ready to hand to the next one.
| Stage | Band | The gate that ends it | Sheet that governs |
|---|---|---|---|
| 1 · Choose | Key material | A documented primitive, topology, ceremony, and restore succeeds | MPC architecture |
| 2 · Authorize | Authorization | An unlisted test destination is refused by the policy engine | Policy controls |
| 3 · Fund | Tiering and float | Demand and loss bounds produce named balances and transfer gates | Float math |
| 4 · Book | Ledger and accounting | Every boundary crossing preserves the continuous invariant | Exchange boundary |
| 5 · Operate | Chain operations | Every terminal and retry state reconciles to one ledger outcome | Operations taxonomy |
| 6 · Gate | Compliance placement | No signed bytes exist before every required gate passes | Gate placement |
| 7 · Hold | Assets held | Issuer, rail, freeze, and depeg responses have named owners | Asset incidents |
| 8 · Prove and exit | Assurance and horizon | Evidence is scoped, exit is rehearsed, and exposure is inventoried | Exit register |
Common mistakes & anti-patterns
These are routing failures. Each one leaves a decision between teams or hides it behind a product label.
- Choosing the vendor before the model. Name the trust boundary first, then evaluate products inside it.
- Reading VENDOR as “not our risk.” It identifies the operator, not who bears the outcome.
- Calling a hybrid a sixth model. Read both relevant columns and assign the seam explicitly.
- Accepting a responsibility matrix without an exit test. Contract language is not an executable export.
- Letting each team keep its own transaction identity. Route the break to the shared ledger intent before retrying.
- Using this hub as implementation guidance. Open the row's deep link; the hub deliberately does not teach the control.
What this cluster refuses to answer
This is engineering decision support, not legal, compliance, investment, or vendor-selection advice.
| Question | Why there is no answer here | What you get instead |
|---|---|---|
| Which custody vendor is best? | “Best” changes with threat model, chains, controls, and exit constraints. | A testable due-diligence register |
| What does custody cost? | A price without scope, volume, asset, and exit terms is not comparable. | The contract surfaces to make comparable |
| Is our setup compliant in jurisdiction X? | Applicability is a legal conclusion and local rules differ. | An architecture map for placing enforceable gates |
| When is Q-day? | Nobody has a date, and supplying one would be invention. | A quantum-exposure inventory you can build now |
| Can you guarantee my wallet is recoverable? | Feasibility depends on the surviving constraints, not confidence. | A stop/go recovery triage |
| Is proof of reserves proof of solvency? | Asset control alone does not establish complete liabilities or other claims. | The exact construction and missing claim |
The nine reference sheets
One question and one landing anchor per sheet. The matrix is the primary router.
| Sheet | The one question it answers | Land here first |
|---|---|---|
| Blockchain Deposits & Withdrawals | What state does this chain operation actually occupy? | Finality register |
| Crypto Compliance Architecture | Where must a compliance decision run before value becomes irreversible? | Gate placement |
| Crypto Exchange Architecture | Where do chain effects meet the authoritative customer ledger? | Wallet boundary |
| Custody Provider Integration | How does a vendor API become a bounded component? | Provider object map |
| Institutional Crypto Custody | Which controls bound loss across custody tiers? | Custody tier register |
| MPC Wallet Architecture | What trust and liveness model does threshold signing create? | Threshold model |
| Post-Quantum Custody Migration | Which holdings and dependencies need a migration path? | Exposure inventory |
| Stablecoin Payment Infrastructure | Which issuer, asset, and movement-rail risks sit below custody? | Reserve and controls |
| Wallet Recovery Forensics | Is recovery feasible with the evidence that survived? | Feasibility triage |
Standards and routed source registers
The hub's numbers count its own rows. Standards are named only to identify the linked control surfaces; the nine sheets carry the underlying source detail.
- CCSS v9.0 detailsCurrent C4 control structure named by the assurance row.
- FATF virtual-asset guidanceRecommendation 16 context named by the compliance routing rows.
- NIST FIPS 204Final ML-DSA standard named by the migration sheet.
- NIST FIPS 205Final SLH-DSA standard named by the migration sheet.
- Deposits and withdrawals sourcesFinality, chain operations, and reconciliation evidence.
- Compliance architecture sourcesKYT, sanctions, Travel Rule, and IVMS101 evidence.
- Exchange architecture sourcesLedger, matching, wallet boundary, and reserves evidence.
- Provider integration sourcesAPI, webhook, policy callback, and provider-state evidence.
- Institutional custody sourcesTiering, controls, key ceremony, and assurance evidence.
- MPC architecture sourcesThreshold protocols, topology, lifecycle, and liveness evidence.
- Post-quantum migration sourcesStandards, exposure, chain proposals, and migration evidence.
- Stablecoin infrastructure sourcesIssuer, reserve, movement-rail, and treasury evidence.
- Wallet recovery sourcesFormats, search math, tools, and forensic workflow evidence.