The exchange loses $400 million in customer funds. The post-mortem reveals the cause: a single employee held the private keys, their laptop was compromised, and the attacker drained the hot wallet in 20 minutes.
This is not a hypothetical. It is the most common failure mode in digital asset security. Not smart contract bugs. Not protocol exploits. Key management.
At Metaluxo we advise blockchain and crypto businesses on the governance and custody arrangements that regulators expect. MiCA in the EU and FCA registration in the UK both require demonstrable key management before authorisation is granted.
What regulators actually check
When the FCA or a national MiCA authority assesses your custody arrangements, they do not ask about blockchain architecture. They ask:
- Who generates the keys?
- Where are they stored?
- Who can access them?
- What happens if that person leaves?
- What happens if the hardware fails?
- How do you prove no single person can move funds?
These are operational governance questions, not technical cryptography questions.
The four layers of key management
Layer 1: Generation
Keys must be generated in a secure environment, using hardware security modules (HSMs) or certified secure enclaves. The generation process must be documented, witnessed, and logged.
Regulatory expectation: A policy that specifies the generation environment, the algorithms used (e.g., BIP-32/39/44 for hierarchical deterministic wallets), and the personnel involved.
Layer 2: Storage
Hot wallets (connected to the internet) hold operational funds. They must use multi-signature or MPC so that no single key can authorise a transaction.
Cold wallets (offline) hold the majority of reserves. They must be stored in physically secure locations with access controls, environmental monitoring, and dual-control requirements.
Regulatory expectation: A custody policy that defines the hot/cold split, the security controls for each, and the maximum balance permitted in hot storage.
Layer 3: Access control
No single individual should be able to move funds. Common arrangements:
- Multi-signature (multi-sig): 2-of-3 or 3-of-5 schemes where multiple signatures are required
- Multi-party computation (MPC): Cryptographic technique where key shards are distributed across parties
- HSM with role-based access: Hardware module enforces approval workflows
Regulatory expectation: An access control matrix showing who can initiate, approve, and execute transactions, and the thresholds that trigger additional approvals.
Layer 4: Recovery
If keys are lost, stolen, or the keyholder is incapacitated, you must still be able to recover funds. Common approaches:
- Shamir’s Secret Sharing: Split a recovery key into shards distributed to trusted parties
- Geographic distribution: Recovery materials stored in multiple secure locations
- Time-locked recovery: Funds can be recovered after a delay with additional verification
Regulatory expectation: A documented recovery procedure, tested annually, with named recovery officers and secure storage locations.
The custody policy
Regulators expect a formal custody policy that covers:
- Key generation procedures
- Hot and cold wallet architecture
- Transaction approval workflows
- Access control and segregation of duties
- Backup and recovery procedures
- Incident response for key compromise
- Regular auditing and reconciliation
This policy is not a technical document. It is a governance document. It should be readable by a non-technical regulator and specific enough to be audited.
Common mistakes
- Using a single hardware wallet for all funds. This is not custody governance. It is a single point of failure.
- Storing recovery phrases in password managers. Password managers are not designed for cryptographic material. They are subject to breaches and subpoenas.
- No reconciliation process. If you do not reconcile on-chain balances against internal records daily, you will not detect a compromise quickly.
- Treating key management as an IT issue. It is a governance and risk issue. The board must understand and approve the custody policy.
At Metaluxo we write custody policies and key management frameworks for digital asset businesses preparing for MiCA authorisation or FCA registration. If your compliance team is asking for a custody policy and you are not sure where to start, book a free 30-minute consultation and we will scope exactly what your regulator needs.
Common questions
Do we need a custodial licence to hold crypto assets?
In the EU under MiCA, crypto-asset service providers need authorisation. In the UK, the FCA requires registration. Both require evidence of secure custody arrangements.
What is the difference between hot and cold storage?
Hot wallets are connected to the internet for transactions. Cold wallets are offline for long-term storage. Most firms use both: hot for daily operations, cold for the majority of reserves.
Can one person hold the private keys?
No. Regulators require multi-signature or multi-party computation (MPC) arrangements where no single individual can move funds alone.