Hybrid Custody Models: Balancing Cryptographic Control and Fiduciary Duty
Blockchain Council's new explainer on tokenized asset custody argues the model has already gone hybrid: wallet technology handles cryptographic control, while trustees and trust companies absorb fiduciary duties.

The piece maps how institutional custodians now connect that stack to auditors, fund administrators, and regulators. As Citi moves to launch Bitcoin custody, the practical question for allocators is no longer whether banks will build these rails — it's which custody model survives an audit cycle.
The custody stack, in three tiers
- Self-custody. Investor holds the keys, typically via a hardware wallet or a browser wallet like MetaMask. KYC and address whitelisting may still apply on the issuer side. Control is absolute; error is unforgiving. Lost seed = lost claim. Wrong chain or non-whitelisted address = failed transfer.
- Single-entity custodian. One administrator moves assets for the client. Operationally simple. Concentration risk is the variable — weak if the operator lacks dual controls, segregation, or SOC-level reporting.
- Multi-sig with trustee and auditor signers. A tokenized physical asset or private credit structure may require signatures from issuer, trustee, and an independent auditor. Mirrors traditional controls with part of the approval moved on-chain. Transparency is the upside; signer downtime is the cost.
The Council piece flags one concrete operational hazard: a transfer agent whitelisted an investor's Ethereum mainnet address while internal testing pointed at Sepolia (chain ID 11155111) instead of mainnet (chain ID 1). The contract was sound. The wiring was not.
Where this lands for institutional allocators
Self-custody fits learning accounts and smaller personal holdings. It does not fit registered investment advisers, funds, or corporate treasuries that must demonstrate segregation, approval workflows, and audit trails. A single-entity custodian may clear early pilots on small tokenized funds. For tokenized sovereign debt, private credit, or material MMF positions on-chain, the bar is segregation, insurance, dual controls, and SOC reporting — the same checks auditors apply to traditional fund administration.
Multi-sig moves closer to that bar but introduces a new failure point: a redemption or transfer can stall if one required signer is offline.
What to verify before allocation
- Confirm whether the issuer's transfer agent enforces whitelisting, and on which chain. Mainnet-vs-testnet mismatch is the failure mode the Council piece highlights.
- Read the custody agreement for dual-control language, client-asset segregation, and insurance coverage. Absence of any single item is a red flag at scale.
- Map the multi-sig signer set: identify the trustee, the independent auditor signer, and the fallback if a signer is unavailable.
- Track custody vendor overlap. Citi's Bitcoin custody launch puts another tier-one bank into the same operational footprint as existing qualified custodians — concentration risk migrates, it does not disappear.