On August 25, 2025, the SEC submitted a new custody rule proposal to the White House for review.
The timing is precise. The classification is explicit. The direction is — for the first time in years — deregulatory.
According to the regulatory agenda filing, the proposal carries the designation "deregulatory" and has been flagged as "economically significant." The target for a formal proposal: October 2025. The rule number assigned: RIN 3235-AN46.
This is not a minor technical adjustment. This is the SEC reversing course on a 2023 proposal that was withdrawn after an avalanche of opposition. The 2023 iteration, pushed under Gary Gensler's leadership, would have restricted qualified custodians to a narrow set of institutions: chartered banks, trust companies, SEC-registered broker-dealers, and CFTC-regulated futures commission merchants.
The new direction — led by current SEC Chair Paul Atkins — appears to move in the opposite direction. The SEC's stated rationale: remove "investor protection burdens that are no longer necessary in outdated provisions."
If you've been tracking the custody landscape, you know what this means. The infrastructure layer of institutional crypto is about to get a compliance overhaul.
The Custody Problem: Why This Rule Matters at the Code Level
Let me give you the technical context, because custody rules aren't just legal text — they dictate architectural choices.
When I audited institutional custodial wallet solutions in 2024, I saw a recurring pattern. Major asset managers claimed "institutional-grade security" in their marketing materials. The reality inside the implementation was messier. Threshold signature schemes had key-share distribution gaps. MPC protocols had timing side channels. The gap between the public narrative and the cryptographic reality was substantial.
The custody rule determines which of these solutions are legally permissible for investment advisers.
Under the 1940 Investment Advisers Act and the 1940 Investment Company Act, advisers managing client assets must use a "qualified custodian." The 2023 proposal would have frozen out many crypto-native custody providers. The practical effect: investment advisers would have been forced into a narrow set of banking and trust relationships, many of which had limited crypto custody expertise.
The 2023 proposal collapsed under pressure from financial institutions, crypto platforms, and federal agencies. But the withdrawal didn't solve the underlying problem — it left the custody question unresolved. Investment advisers managing crypto assets have been operating in a gray zone.
What a Deregulatory Shift Actually Unlocks
The new proposal doesn't just relax standards. If the direction holds, it potentially opens the qualified custodian definition to include a broader range of custodians — including technology-driven custody models.
Based on my work auditing MPC implementations and threshold signature schemes, here's what I'm watching:
Multi-Party Computation (MPC) wallets — these split private key shares across multiple parties, reducing single-point-of-failure risk. The 2023 proposal's narrow custodian definition would have pushed advisers toward traditional banks, many of which still rely on legacy key management. A broader definition could legitimize MPC-based custody.
Distributed Validator Technology (DVT) — for staking operations, DVT distributes validator keys across independent nodes. This matters for advisers managing staked ETH. If the rule revision accommodates these architectures, it changes which custody providers can serve institutional staking demand.
Hardware Security Module (HSM) standards — the rule revision may implicitly set expectations for audit requirements around key management infrastructure. This is where compliance meets cryptography. I've seen too many implementations where the HSM was a checkmark on a slide deck, not an integrated security boundary.
The bottom line: the new rule could pull technology-driven custody solutions into the regulatory perimeter rather than pushing them out.
The significance here goes beyond compliance. It's about which custody architectures get institutional capital flows. Banks with legacy infrastructure. Crypto-native firms with modern MPC and threshold signature implementations. The competitive landscape shifts based on who gets the regulatory stamp of approval.
The Deeper Pattern: This Is a Systematic Reset
What's happening with the custody rule is not isolated. It's part of a coordinated regulatory reset. Consider the adjacent items on the SEC's agenda:
- RIN 3235-AN48: clarifying broker-dealer compliance requirements for crypto
- Tokenized securities innovation exemptions: still pending
Three moving parts, one direction: integrating crypto into the traditional financial system with reduced friction.
This isn't deregulation for its own sake. It's a recognition that the 2023 framework was built on assumptions that don't match how crypto custody actually works — or how the market was already solving the problem.
Look at the market signals. A wave of new federal trust bank charters has been approved, expanding the custodian pool beyond the traditional banking system. The market was already finding alternative paths. The SEC is now adjusting its rules to catch up with reality.
The Contrarian Angle: Compliance Is the New Attack Surface
Here's where the security engineer in me gets uncomfortable.
Everyone is celebrating the deregulatory direction. The narrative: "SEC is becoming crypto-friendly under Atkins." But let me raise a concern that nobody on the marketing side wants to discuss.
A broader custody rule doesn't just expand options — it expands the attack surface.
When more custody providers enter the regulated perimeter, the regulatory burden doesn't disappear. It gets distributed. And distributed compliance is harder to audit than centralized compliance.
Consider what happens when a custody provider with weaker cryptographic practices gets "qualified custodian" status. The regulatory stamp of approval doesn't fix a flawed key-shares distribution protocol. It masks it.
Based on my 2024 audit work, I can tell you this: institutional custody products vary wildly in their actual security posture. I found three potential attack vectors in threshold signature aggregation processes across major providers. I reported them privately. But the market sees marketing claims, not implementation details.
The risk: the SEC's relaxation could create a false sense of security for advisers who assume the qualified custodian label implies cryptographic soundness.
This is the gap between regulatory compliance and actual security. Compliance frameworks evaluate documented procedures, not implementation quality. A custody provider can be fully compliant and still have exploitable key management vulnerabilities.
What I'm Tracking Next
The OIRA review is the first gate. If the office requests significant modifications, the October target could slip. I'm watching that timeline closely.
The formal proposal text is the second gate. That's when we see the actual qualified custodian definition. That's when the market reprices — and when custody providers start scrambling to position themselves within the new perimeter.
The tokenized securities angle is the third gate. If custody rules broaden while tokenized security exemptions advance, we get a clear pathway for RWA adoption. Compliance custody is the prerequisite for tokenized securities to move from pilot projects to institutional scale.
Here's my forward-looking take, based on the patterns I've observed across the regulatory cycles since 2021:
This custody rule revision is the first domino in a sequence that determines whether institutional crypto in the US becomes a bank-dominated market or a technology-competitive one.
The 2023 proposal would have consolidated power in legacy institutions. The 2025 reversal potentially redistributes it.
But here's the thing about redistribution: it creates winners and losers. The winners aren't determined by the rule text. They're determined by implementation quality.
The custody providers that benefit most won't be the ones with the best lobbying. They'll be the ones whose MPC implementations survive adversarial review, whose key-shares distribution holds under attack, whose audit trails are genuinely forensically sound.
Regulation opens the door. But in crypto, the security bar is set by mathematics — not by legal text.
Math doesn't negotiate.