Logo
My Crypto News AI

When Crypto Exchanges Freeze: Why Institutions Are Rethinking Where They Store Digital Assets

Custody is no longer a back-office checkbox; it's become a front-line defense against exchange failures and infrastructure attacks. When AscendEX ceased operations on July 1, 2026, and shifted to manual withdrawal reviews with no timing guarantees, it exposed a hard truth: even routine operations can freeze without notice, leaving institutions scrambling to recover funds. Meanwhile, a bridge operator on Arbitrum tied to AFX Trade lost approximately 24.15 million USDC after attackers compromised hot validator keys, then moved the funds to Ethereum and swapped them into ETH. These incidents, happening within weeks of each other, have pushed custody from a compliance afterthought into the center of institutional risk management.

What Are the Three Main Types of Crypto Custody?

Custody describes how close your private keys are to the internet and what legal protections surround them. Understanding the trade-offs between speed, security, and control is essential for anyone managing digital assets at scale.

  • Hot Wallets: The signing key is online and can authorize transactions in seconds to minutes. This enables instant settlement and market access, but puts infrastructure directly in the line of fire for remote attacks. Exchanges, traders, and decentralized finance (DeFi) market makers typically use hot wallets.
  • Cold Storage: The signing process stays offline, with approvals batched and workflows intentionally slower. This dramatically reduces the remote attack surface. True cold storage uses air-gapped devices, controlled rooms, and human approvals. Treasuries and long-term holders favor this approach.
  • Qualified Custody: Assets are held with a regulated entity, typically a bank or trust company, authorized to hold client property under a specific legal framework. This provides enforceable segregation, bankruptcy-remote structures, and auditability. It's not a guarantee against loss, but it offers legal recourse that an operating exchange wallet usually cannot match.

Each custody type sits on a spectrum of control versus convenience. Hot custody is fastest but riskiest. Cold custody is slowest but most isolated. Qualified custody trades immediacy for process and legal protection.

How Do Regulators View Custody Risk Right Now?

Europe's securities watchdog is making custody a priority. In July 2026, the European Securities and Markets Authority (ESMA) launched a coordinated review of crypto firms' operational resilience with a specific focus on custody processes and digital resilience across crypto-asset service providers. The exercise runs into 2027 and will end with a public report. This is a significant signal that custody is where supervisors will push hardest in the coming years.

The regulatory focus reflects a shift in market behavior. Convenience bias had pulled assets into hot paths for speed and liquidity, but recent loss events and regulatory pressure are forcing a swing back toward controlled latency and verifiable segregation. Regulators are getting specific about what they expect to see in custody operations.

Steps to Build a Defensible Custody Strategy

  • Segregation and Reconciliation: Maintain clear evidence of client asset segregation and regular reconciliations. When regulators or auditors ask, you need to show exactly where every asset is and who owns it.
  • Incident Response Planning: Document detection timelines, containment procedures, and notification protocols. When something breaks at 3 a.m., your team needs a playbook, not a panic.
  • Key Ceremonies and Change Control: Enforce dual-control on key management, code reviews, and policy changes. Hardware security modules (HSMs) protect key material at rest and in use, but they're not magic shields; you still need policies around who can trigger a signing job and how you test disaster recovery.
  • Business Continuity and Failover Testing: Know your restore times, test backup systems regularly, and practice failovers. A custody strategy that hasn't been tested under stress is a liability waiting to happen.
  • Third-Party Dependency Mapping: Identify every vendor and service your custody stack depends on, and have an exit plan for each one. The AscendEX shutdown showed that even major platforms can become unavailable with little warning.

Most teams end up with a mix of custody types rather than relying on a single approach. Exchange wallets offer speed and liquidity but carry counterparty risk. Third-party qualified custodians provide clearer segregation and bankruptcy-remote setups in some jurisdictions, though at the cost of some immediacy. Self-custody gives maximal control but requires hiring, secure facilities, HR controls, audit, key ceremonies, vendor risk management, and continuity planning.

What's Driving the Industry Shift Toward Better Custody?

The Bitcoin Security Consortium, formed in July 2026 by a group including BlackRock, Coinbase, and Fidelity Digital Assets, pledged 15 million dollars across three years for Bitcoin security research and post-quantum cryptography work. While this consortium is focused on Bitcoin-specific security rather than custody per se, advances in security research tend to trickle down into wallet design and standards that custodians adopt across the industry.

The real driver, however, is loss. When a bridge loses 24 million dollars in a single night, or an exchange freezes withdrawals indefinitely, institutions stop asking whether they need a custody strategy and start asking whether their current one will survive the next attack. The AscendEX incident and the AFX Trade bridge compromise are not outliers; they're data points in a pattern that regulators, boards, and risk teams are now taking seriously.

For institutions managing digital assets at scale, the message is clear: custody is no longer optional, and the choice between hot, cold, and qualified options is no longer academic. It's a business continuity decision that will be tested when something breaks.