Skip to main content

On 1 October 2026 the Securities and Exchange Commission proposed the rules that let an investment adviser hold a client’s crypto asset itself, with no third-party custodian in the middle. Release Nos. IA-7023 and IC-36353, 700-odd pages, 60 days of comment once it hits the Federal Register. Chairman Paul Atkins called it “replacing the grey of uncertainty created by custody rules crafted for a bygone era”. It is, on the whole, good, and the industry has been asking for it for years.

Everyone is reading the proposal for the question it answers: is self-custody safe enough to allow? The conditions attached to that answer are serious, and we will go through them. But the permission does not actually turn on them. It turns on a separate threshold test, stated in a single clause, which asks something else entirely: is there anybody else willing to do this instead of you?

That is not a safety standard. It is a market survey. And it means your lawful custody arrangement can become unlawful without one byte of it changing, because a company you have never dealt with published a supported-assets page.

TL;DR

  • The SEC’s proposed adviser self-custody rule requires a written determination, per asset and at least quarterly, that “no qualified custodian will maintain the crypto asset”. Self-custody is only permitted while that stays true.
  • When a qualified custodian becomes available, the adviser must hand the asset over “as soon as reasonably practicable”, with the economic analysis describing a ceiling of “no more than one quarter”. The alternatives listed are selling the client’s asset or giving it back.
  • Cost is explicitly excluded from the test. A custodian that will hold the asset at a terrible price still counts as available, which puts the trigger in the vendor’s hands and the price negotiation afterwards.
  • The Commission’s own cost analysis concedes the forced move can mean “less effective safeguarding” and “lower quality” services, because the adviser may know the network better than the custodian does.
  • The lesson for on-chain gaming: a guarantee that is a property of the artefact survives anything. A guarantee that is a property of the market around the artefact can be ended by a stranger’s product launch, and nobody has to revoke it.

Give the Commission its due first

The gap this fixes is real and it was the Commission’s own doing. The 2023 safeguarding proposal, as Commissioner Mark Uyeda put it in his statement on Thursday, “would have required advisers to maintain crypto assets with a qualified custodian, while simultaneously casting doubt on whether any qualified custodian could demonstrate exclusive control over those assets”. That is an unusually blunt thing for a sitting commissioner to say about his own institution, and it is accurate.

The new proposal does three useful things. It admits state-chartered trust companies as permitted custodians, which ends a silly situation where an adviser had to run a fact-specific analysis of state and federal law to work out whether its custodian counted as a “bank”. And it gives advisers a compliant route to hold assets nobody else will hold.

The self-custody conditions are not window dressing either. The adviser must document its safeguarding expertise for each asset, require joint authorisation of transactions by at least two people, keep each client’s assets in addresses holding only that client’s assets, review its cybersecurity controls annually, obtain an internal control report from an independent public accountant, send quarterly account statements, and agree in writing with the client to treat the asset as a “financial asset” under state law. That is a real burden aimed at real failure modes.

Commissioner Hester Peirce, in one of her last acts before departing the Commission, objected to the vocabulary rather than the substance: the proposal “uses the term in a way that does not reflect true self-custody by investors”, and she would have preferred “shelf-custody”, since what is permitted is an adviser holding somebody else’s coins. She is right, and it matters for what follows. Nothing here is about you holding your own keys.

The threshold condition

Before an adviser may self-custody anything, it must make what the release calls a QC determination. The text is worth reading slowly. The adviser must determine in writing, “prior to taking self-custody of each crypto asset and no less frequently than quarterly thereafter, that the adviser has a reasonable basis, after due inquiry, for believing that no qualified custodian will maintain the crypto asset”.

Per asset. The release is explicit that “an adviser would not be allowed to make a blanket QC determination covering all types of crypto assets”. In writing, and retained as a required record under the amended books-and-records rule. Re-made every quarter for as long as the asset sits there.

And the consequence of the answer changing is immediate: “an adviser that determines a qualified custodian has become available to maintain a client’s crypto asset would be required to place such crypto asset with the qualified custodian as soon as reasonably practicable”. Not at the next review. Not at a renewal date. The release adds that the obligation “would arise when an adviser discovers a newly available qualified custodian from its quarterly reassessment of its QC determination as well as when the adviser becomes aware of an available qualified custodian between quarterly reassessments”. The economic analysis describes the outer bound as “limiting the period of self-custody to no more than one quarter after a qualified custodian becomes available”.

So the thing that ends your permission is not a finding about you. It is an announcement by somebody else.

A permission denominated in the market

Every custody rule ever written tests an arrangement. Is the asset segregated, is there independent oversight, can the party holding it move it unilaterally, is there an audit. Those questions are all about the thing in front of you, and the answers change only when the thing changes.

The QC determination is a different kind of test, and the difference is the whole post. It is denominated in the state of a market. Your key management can be flawless and improving. Your internal control report can be clean. Your two-person authorisation can have worked perfectly for eight quarters. None of that is what the clause is measuring. The clause measures whether a third party you have no contract with has decided to offer a product.

When that third party ships, the asset must move. Not because anything got less safe, and not because anybody decided you had done something wrong. The permission is not revoked. It lapses, quietly, on a date nobody set, triggered by an event you do not control and cannot schedule.

This series has taken apart the opposite failure recently. In the eighty-second instalment, the problem was a security property written in the future tense: Dogecoin will verify those proofs, once strangers who have agreed to nothing decide to act. Here the tense is inverted and so is the harm. The property you already have is the one that ends, and it ends precisely when the strangers do act, by offering to help you. The arrival of the alternative is the event that takes the arrangement away.

Cost is not a factor, which hands the trigger to the vendor

Here is the part that should worry anyone who has negotiated with an infrastructure provider. The release states that the rule “would not permit the adviser to make the QC determination based on the costs associated with engaging a qualified custodian”, because “the cost of utilizing a custodian is not relevant to whether a custodian has the appropriate capabilities to custody and safeguard client assets”.

The reasoning is coherent. Price is not a safety property, and a rule that let advisers self-custody whenever custody looked expensive would be a rule with no content. Take it seriously as written.

Now look at what it does. A custodian that announces support for an asset ends every self-custody arrangement for that asset, at any price it likes, and the price conversation happens afterwards with counterparties who are no longer permitted to walk away. The adviser absorbs the price or passes it to the client. There is no third option, because the one that existed last quarter stopped being legal when the press release went out.

And note what “available” actually resolves to. The Commission, sensibly, refuses to demand the impossible: it does “not intend for the proposed adviser self-custody rule to require an adviser to conduct boundless analysis or the identification of every possible custodian to confirm no qualified custodian exists”. So the standard lands instead on due inquiry into “whether custodians generally known in the custodial marketplace provide custodial services for a crypto asset in question”.

Generally known. That is the operative variable, and it is not a technical one. A custodian with the capability but no marketing does not end your permission. A custodian with the same capability and a newsletter does. The rule is triggered by publicity, which is the one input in this entire framework that is purchasable.

The Commission says out loud that the move can be worse

The strongest evidence that this condition is not a safety test is that the SEC does not claim it is one. Read the economic analysis. On what happens when a custodian appears: “an adviser would have to transfer the asset to the custodian, sell the client asset, or, depending on the type of client, transfer the asset to the client”. A vendor’s launch can force the sale of a client’s position.

On whether the destination is better: transferring “could result in less effective safeguarding, including potential risks associated with transferring the asset”, and custody at a qualified custodian “may result in the safeguarding services being of lower quality (for example, because the adviser has specific knowledge about the asset and the associated crypto network infrastructure that the custodian does not have)”.

That is the Commission conceding that the rule can require an asset to be moved from a party that understands the network to a party that does not, at a worse price, with transfer risk in between, and that the trigger is a commercial announcement. It is not a drafting error. It is a deliberate preference for independent oversight over asset-specific competence, defensible as policy, and simply not the thing the headline conditions are measuring.

One more admission, three paragraphs later, is the sharpest in the document: “the possibility of a qualified custodian becoming available after an adviser undertakes the investment to develop the systems necessary for self-custody also limits the degree to which we anticipate advisers planning to offer strategies for which no qualified custodian is currently available”. The permission’s own expiry discourages building for it. A right you may lose next quarter is not something you staff a team around.

What this has to do with a coin flip

Strip the securities law out and a general shape is left. Some guarantees are properties of the artefact. Others are properties of the circumstances surrounding it. They are written in the same font on the same page and they behave completely differently over time.

A verified Chainlink VRF proof is a property of the artefact. The coordinator checked it on-chain before the callback executed. That check happened, it is recorded, and it is re-checkable by a stranger in four years with no cooperation from us. No competitor’s launch invalidates it. No vendor’s supported-assets page changes what it says. Nothing outside the transaction is load-bearing, which is exactly why nothing outside the transaction is needed to check it.

Now take the claims that dominate gambling marketing. “Funds held with a licensed third-party custodian.” “Certified RNG.” “Licensed in X.” Each of those is a statement about circumstances. The custodian’s supported-asset list is a business decision it can revise. The certification depends on the certifier’s accreditation, which depends on a body you have never heard of. Each can change to your detriment without a single line of the operator’s code changing, and when it does there is no diff to read and often no announcement at all, because from every party’s own side nothing happened.

The test that falls out of this is short and worth memorising. If a competitor shipped a product tomorrow, would this guarantee still mean exactly what it means today? If the answer is no, you are not holding a guarantee. You are holding a market condition that is currently in your favour.

This is also where the axis separates from the rest of the series. The eightieth instalment was about who authors the number you hold. The fifty-second was about collateral being in two places at once. Proofs do not change hands was about what survives a corporate restructuring. This one is narrower and stranger: a permission that exists only in the absence of a commercial alternative, and is extinguished by the alternative appearing.

Where Satoshie actually stands

Our claim is deliberately small. The contract is deployed on Base. ticketsMinted is readable before you buy, so the odds are arithmetic over public state rather than a number we tell you. Your stake is escrowed by the contract when you enter. The Chainlink VRF coordinator verifies the proof on-chain before the callback runs. Resolution and payout happen in the same transaction. There is no admin key over a draw in flight.

Not one clause in that paragraph is conditioned on what another company offers next quarter. That is not because we are clever. It is because we never took custody of anything in the first place: there is no account, no balance held between rounds, and therefore nothing for a custody regime to attach to. We dodge this entire problem by scope, not by virtue, and a platform that avoids a hazard by not operating in its vicinity does not get to call that a security feature.

Honest limits

Our availability is market-conditioned even though our fairness is not. Base runs a single sequencer operated by Coinbase, our front end is an ordinary web app, and we read the chain through RPC providers we pay. Every one is a third party whose decisions we do not control, and if they change you may be unable to play. The distinction we defend is narrow: no claim we make about whether the draw was honest depends on anyone’s commercial roadmap. Claims about whether you can reach the draw at all absolutely do.

Our best claim is a negative, and negatives are weak. “No admin key” is the same species of statement as “no qualified custodian will maintain this asset”. As the forty-third instalment put it, verifying an absence is a weaker and stranger guarantee than verifying a proof: a VRF proof validates or it does not, while an absence requires reading the whole contract and finding nothing, which is harder to do and easier to get wrong. We are asking you to perform, on our code, the sort of exhaustive search the Commission concedes is unreasonable to demand of an adviser. The honest version is that the search is bounded in our case, because the contract is small, immutable and verified, and you can finish reading it.

We have never had to comply with any of this. A project that has never been examined does not get to feel superior to one that has. And we should be straight about the incentive: the custody gap this rule addresses exists because the market is immature, and arguments that depend on the market staying broken deserve to lose. If every asset is well custodied in five years, the self-custody clause becomes a dead letter and that will be a good outcome. Our position should not improve when other people’s infrastructure gets worse.

Three questions

Is this guarantee a property of the thing or of the market around the thing? Ask it about every protection you are offered. If the sentence contains a third party’s name, you are in the second category, whatever font it is printed in.

What event ends it, and who gets to cause that event? Expiry dates are easy, because you can read them. The dangerous version is a condition with no date, discharged by somebody else’s decision.

Can I check it without anyone’s cooperation, today and in four years? A guarantee that requires the operator, the certifier or the custodian to still exist and still be willing to answer is a relationship. Only the ones you can re-derive from public state on your own are proofs.

The Commission has given advisers a real, workable route to hold crypto assets, and it deserves credit for that. It has also written a permission that ends when a salesperson succeeds. Nobody will revoke it. One quarter it is there, and the next quarter a trust company in Wyoming adds a token to a list, and it is not.

Play a provably fair raffle or coinflip on Satoshie, where the only thing standing between you and the result is a proof you can check yourself.

📷 Photo by Douglas Cioffi on Unsplash

Valentina Ní Críonna

Author Valentina Ní Críonna

More posts by Valentina Ní Críonna