Three Weeks After 1,778 Bitcoin Vanished From Hardware Wallets, the Third-Largest Custodian on Earth Announced It Will Hold Your Keys For You. Read the Part About Insurance Before You Say Yes.
Citi announced Custody+ on August 18, and the crypto press covered it as an adoption story. It is one. But look at the sequencing, because the sequencing is the story. On July 30 attackers began sweeping single-signature Coldcard wallets whose seeds had been generated by five-year-old firmware containing a randomness flaw; by early August the running total was roughly 1,778 BTC, somewhere near $130 million, taken by at least fifteen unrelated actors racing each other through the same open door. On August 7 Glassnode logged the largest weekly drop in long-term-holder supply since December 2024 — about 210,000 coins leaving dormant wallets, not into sell orders but into new ones. And on August 18 the third-largest custodian bank in the world, holding $34.5 trillion in assets under custody and administration as of June, told institutional clients that bitcoin custody goes live before the end of the year and that they will not have to manage a wallet or handle a private key. Three weeks. That is how long it took the industry's answer to a key-management failure to become: stop managing keys.
The regulatory groundwork was laid well before the sweep, which is why the banks were ready to move the moment the news gave them a reason. In January 2025 the SEC rescinded Staff Accounting Bulletin 121 through SAB 122, ending the rule that forced any firm holding client crypto to book a matching liability against its own balance sheet — a capital charge that had made custody economically irrational for institutions running trillions in traditional safekeeping without any comparable requirement. The OCC followed with Interpretive Letters 1183 and 1184, confirming that national banks may custody digital assets, may execute client orders, may use sub-custodians, and — critically — no longer need supervisory non-objection first, converting crypto custody from a privilege that had to be applied for into an ordinary banking power. The GENIUS Act, signed in July 2025, codified digital asset custody as permissible banking activity under federal law and opened trust-charter pathways that Circle, Paxos, BitGo, Fidelity Digital Assets and Ripple all used. In the eighteen months since, BNY Mellon (the world's largest custodian, $59.4 trillion, live with crypto since 2022 and expanded into Abu Dhabi in May), State Street ($51.7 trillion, Digital Asset Platform launched in January with Taurus), Standard Chartered (absorbing Zodia Custody outright, closing this month), U.S. Bank, and now Citi have all launched or committed to direct custody. Industry estimates put the digital-asset custody market at roughly $953 billion in 2026 and above $4.3 trillion by 2030. Nobody entered this business out of ideology. They entered because the fees were too large to leave on someone else's balance sheet.
Now the part almost nobody reads. In April 2026 the FDIC proposed its first custody and reserve standards for supervised institutions offering crypto safekeeping, and the proposal states plainly that digital assets will not receive deposit insurance. That single sentence does more work than every press release in this cycle combined. A dollar in a Citi account is insured by the federal government up to the limit. A bitcoin in the same account, on the same statement, inside the same reporting stack, with the same relationship manager, is not — and the resemblance is precisely the hazard, because everything about the presentation is engineered to feel identical. Private insurance does not close the gap either: only about 1% of crypto by market value carries coverage at all, the specialist market wrote roughly $1.9 billion in premiums in 2024 against a multi-trillion-dollar asset class, and leading custody programs top out somewhere between $75 million and $320 million, with a handful reaching a billion in aggregate. A custodian holding five billion in client coins against two hundred million in coverage is not insured; it is partially hedged. What actually stands behind the assets is the bank's balance sheet and its unwillingness to be the institution that lost its clients' bitcoin — which is a real form of protection, and is also an assumption rather than a contractual guarantee, and has never once been tested at scale.
There is a second thing worth saying plainly, because this publication has spent a lot of words on the concentration problem and it just got worse in a way the coverage missed. Coinbase Custody holds roughly $376 billion in institutional assets and custodies more than 80% of U.S. spot bitcoin and ethereum ETF assets — a chokepoint we have written about before. The intuitive read is that banks entering the market fixes that by adding competitors. The structural read is different: five institutions with a combined nine figures of trillions in traditional custody are about to compete for the same coins, and the winners of that race will be a handful of names, chosen for brand and bundling rather than for the independence of their failure modes. Swapping one dominant custodian for four dominant custodians reduces vendor concentration and does nothing whatsoever about the underlying architecture, which is still that a very small number of organizations hold the authority to move a very large fraction of the supply. Meanwhile the technical convergence is real — banks bring FIPS-certified hardware security modules they already run for securities, crypto natives bring years of production multi-party computation, and the 2026 default is hybrid: HSMs as the hardware root of trust, MPC on top for signing. That is genuinely good engineering. It is also, note, exactly the threshold logic this site keeps arguing for, sold at institutional prices to people who are not you.
None of which makes bank custody a bad choice, and it would be dishonest to pretend otherwise. For a pension fund, an endowment, or a corporate treasury, an audited institution with geographically split quorums, key ceremonies under dual control, entropy sources that get certified rather than assumed, and a named party who answers when something goes wrong is straightforwardly the right answer — and it is the right answer for some individuals too. If you have been carrying twelve words on a piece of paper and losing sleep, a regulated custodian is a genuine improvement over that. It also removes a threat model no cryptography addresses: nobody kidnaps you for a key you demonstrably cannot produce, which matters more than it used to in a year that has produced dozens of documented wrench attacks. What you give up is the part that made the asset different. Withdrawal at another party's discretion, counterparty and issuer risk, fees compounding against you, seizure and freeze exposure that arrives by court order rather than by burglary, no on-chain optionality, and a protection framework that resembles insured banking without being it.
So the honest framing is not custody versus self-custody. It is: which failures do you want to own? Bank custody converts a technical risk you control into an institutional risk you do not. Self-custody as most people practice it — one seed, one phrase, one location, one hour of exposure the night you write it down — converts it into a personal single point of failure that August has spent three weeks demonstrating is not hypothetical. The third option is the one this month keeps pointing at without naming: keep the authority, drop the single artifact. A quorum drawn from genuinely independent devices, so no one vendor's build-configuration error can enumerate all your keys at once. A BIP-39 passphrase, which is entropy no manufacturer's generator ever touched. And a backup that is not a complete copy sitting in a drawer waiting for a burglar, a house fire, a hidden camera, or a probate court.
That last piece is the specific thing seQRets was built for. A freshly generated seed is encrypted on your own device, split into QR-encoded threshold shares — 3-of-5, 2-of-3, whatever matches the people and places actually in your life — and distributed so that no single location, no single trusted person, and no single search warrant reveals anything at all. There are no servers, no accounts, and nothing on our side to breach, which is the whole point: we are not asking you to trade one custodian for another. Citi's clients will get a statement, a compliance workflow, and a line in the fine print explaining what is not insured. The alternative is not a worse version of that. It is a different question entirely — not who do you trust to hold this, but how do you hold it so that trusting any single party stops being necessary.