Operations · 10 min · Dec 9, 2025
Custody architecture for institutional Bitcoin
Keys are not a vendor logo. They are a constitution: who can move the reserve, under what quorum, after which failures.
Jonah Hale, Head of Custody & Controls
Assume the logo will fail
Institutional custody is a graph of failure modes. Exchange insolvency, administrator error, geographic seizure, key-person risk, and software supply-chain compromise are not edge cases; they are the design spec. A Bitcoin treasury that lives in a single qualified custodian has a single qualified point of failure — no matter how many SOC reports are in the data room.
The architecture we implement for clients is deliberately dull: at least two qualified custodians, client-directed withdrawal whitelists, a time-delayed policy for large movements, and a documented disaster-recovery path that a non-technical director can execute. Cold storage is the default. Trading venues hold only the float required for a scheduled purchase.
Quorum, people, and paper
Multi-signature and MPC are tools, not a strategy. The strategy is a quorum that survives vacations, departures, and subpoenas. That means named roles, not named heroes; geographic diversity of key shards; and a legal wrapper that makes it obvious who has authority to instruct a move. We rehearse the ceremony. If the first time you rotate a key is during an incident, you do not have a control. You have a hope.
Insurance is a complement, not a substitute. Policies have exclusions, waiting periods, and definitional fights. Buy them. Then design as if they will not pay.
Audit as a product
Public companies will be asked to prove the coins. Proof of reserves without proof of liabilities is theatre; proof of holdings with a transaction ledger, reconciliation to the general ledger, and an independent attestation is a product. Our reporting layer is built so that an auditor can follow a sat from OTC settlement into cold storage without a war room. That is not a nice-to-have. It is how Bitcoin becomes a line on a 10-K instead of a footnote argument.