Custodial or Non-Custodial: Who Can Actually Move the Money?
Product Education

Custodial or Non-Custodial: Who Can Actually Move the Money?

22 Sept 2026 6 min read

Your finance director opens the company dashboard and sees a $500,000 stablecoin balance.

The obvious question is: How much money do we have?

The more important question is: Who can move it?

Can one employee send everything? Does the provider have to approve the transaction? What happens if the person responsible for the wallet leaves? If the provider becomes unavailable tomorrow, can the business still access its funds?

A login is not control. A dashboard is not control. Control sits with whoever has the authority to approve and sign a transaction.

These are custody questions. They sit behind the words custodial and non-custodial, and they matter to any business planning to receive, hold or send stablecoins.

The distinction affects everyday operations. It determines who can sign, how approvals work, what happens when access is lost and which party the business must trust.

For a fuller explanation of addresses, private keys, signing, broadcasting and confirmations, read the anatomy of a crypto wallet. This article focuses on one decision: who controls the authority to move the assets?

First, what does a private key do?

A private key is secret information used to create a digital signature. That signature proves that a transaction was authorised by the party controlling the relevant account or funds.

The assets are recorded on the blockchain's ledger. The key provides the authority to make a valid instruction that changes that record.

This is why wallet security is not mainly about hiding a balance on a screen. A balance may be public. What must be protected is the ability to authorise movement.

In simple terms:

· The wallet address is where assets can be received.

· The private key or signing system authorises outgoing transactions.

· The blockchain checks the signature before accepting the instruction.

Now let’s examine the two custody models.

What is a custodial wallet?

With a custodial wallet, a service provider controls the signing system on behalf of a business.

The business does not handle the private key directly. Instead, the business logs in, passes the required security checks and submits an instruction. The provider's protected signing system approves the blockchain transaction according to the agreed account controls.

This can make daily operations easier. The provider can manage the difficult work of key protection, transaction construction, network connections and account recovery. If an authorised user loses access, there may be a process to restore it after the required checks.

But the convenience has a trade-off. The business depends on the provider's systems, policies, controls and continued availability. The provider may be able to approve, delay or restrict a transaction under its terms, security procedures or legal obligations.

That does not make custodial wallets automatically unsafe. It means trust sits with the custodian.

What is a non-custodial wallet?

With a non-custodial wallet, the user or business retains control of the signing authority. The infrastructure provider should not be able to move the assets independently.

A provider may still help the business create wallets, prepare transactions, apply policies, connect to blockchain networks and monitor activity. But a valid outgoing transaction must ultimately be authorised through signing infrastructure the business controls.

This reduces one kind of dependency. A custodian cannot unilaterally use the key if it does not possess or control it.

It also creates responsibility. If a business loses access to its signing authority and has no recovery method, a provider may not be able to reset access. If signing credentials are compromised, an attacker may be able to create a valid transaction. The blockchain checks whether the signature is valid, not whether the person who produced it was authorised by the business.

For an individual, non-custodial ownership may mean protecting a seed phrase or hardware wallet. For a serious business, it should not mean writing twelve words on paper and handing them to the founder.

Enterprise non-custodial systems may use secure hardware, external key-management systems, multiple signatures, distributed key shares, several approvers and recovery policies. The aim is to keep control with the organisation without making one person, one device or one secret the entire security model.

Non-custodial does not mean “no provider”

This is one of the most common misunderstandings.

A business may use software, APIs, blockchain nodes, monitoring, transaction policies, compliance tools and support from an infrastructure provider while still retaining the relevant signing control.

Think about online banking. The fact that software helps an employee prepare a payment does not tell us who has authority to release it. The interface and the approval authority are separate layers.

The same is true here. A wallet provider may coordinate the experience without being the party that can independently sign.

A company wallet is not one person's pocket

A company bank account usually has rules. One person may create a payment. Another approves it. Larger amounts may require extra sign-off. Some beneficiaries may need to be added in advance.

A business wallet should reflect the same idea. There are four separate layers to map.

1. Access to the application

Who can log in, view balances, create wallets or prepare transactions?

Access should match job responsibilities. Someone who can view reports may not need permission to initiate a payment.

2. Control of the signing authority

Who or what can produce the valid signature?

In a custodial model, this may be the provider's protected signing system. In a non-custodial model, the business may control keys through its own systems or an agreed distributed arrangement.

3. Transaction approval policy

Which rules must be satisfied before signing?

Examples include amount limits, approved addresses, allowed networks, time restrictions and requirements for two or more authorised people.

4. Recovery and emergency authority

What happens if a device is lost, an employee leaves, a key manager fails or suspicious activity is detected?

Recovery is part of custody design, not an afterthought. A system that is secure during normal operation but impossible to recover safely is not ready for business use.

Which model is better?

Neither model wins in every situation.

A custodial wallet may suit a business that wants a managed experience and does not want to operate cryptographic infrastructure. The business still needs to assess the provider, understand account controls and decide whether the model fits its regulatory and operational responsibilities.

A non-custodial wallet may suit an organisation that needs to retain signing control, apply its own governance and integrate wallet operations into a larger treasury or product system. That organisation must be ready to own more of the key-management, approval and recovery responsibility.

The wrong choice is not always “custodial” or “non-custodial.” The wrong choice is a model the business cannot explain, govern or recover.

The decision should follow the use case. A small exporter receiving occasional customer payments has different needs from a bank creating thousands of customer wallets. A payment service provider handling payouts has different risks from a treasury team holding reserves.

A wallet is a tool. A key or signing system provides authority. Custody tells you who controls that authority.



Did you find this article helpful?

Related posts

The world is open. Get started today.