The SEC's Custody Reversal: Why the 2023 Rule Failure Is Now the Blueprint for 2025

Directory | 0xHasu |

On August 25, the SEC submitted a proposal to the White House Office of Information and Regulatory Affairs. RIN 3235-AN46. Marked "economically significant." Marked "deregulatory."

That last word is the tell. The same agency that spent 2023 trying to force crypto assets into a narrow custodial box is now drafting rules to dismantle that box. The proposal targets the custody rules under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. The target date for formal publication: October.

This is not a policy shift. This is a documented reversal, and the mechanics of that reversal deserve more scrutiny than the headline.

The 2023 Failure Nobody Wants to Revisit

Let's establish the baseline. In February 2023, under Chair Gary Gensler, the SEC proposed rules that would have defined "qualified custodian" as a narrow set of entities: state or federal chartered banks, trust companies, SEC-registered broker-dealers, and CFTC-registered futures commission merchants.

That definition was a wall. Most crypto-native custodians β€” the firms actually building the infrastructure for digital asset safekeeping β€” didn't fit. The rule would have effectively forced investment advisers to route client crypto assets through traditional financial institutions that, in most cases, had no operational capability to custody digital assets securely.

The pushback was immediate and bipartisan. Financial institutions objected to the compliance burden. Crypto platforms objected to the market exclusion. Federal agencies raised jurisdictional concerns. The proposal collapsed under its own weight and was withdrawn.

But here's what the market missed: the failure wasn't a defeat for the SEC. It was a data point. The agency learned exactly where the resistance lines were, and the 2025 proposal is calibrated to avoid them.

What the Deregulatory Designation Actually Means

A "deregulatory" designation under Executive Order 13771 means the SEC is not just revising rules β€” it's actively identifying provisions that impose "unnecessary investor protection burdens" and removing them. That language appears in the current proposal's stated intent: to remove protections from "outdated provisions" that no longer serve their purpose.

Let's translate that into operational terms.

The 2023 rule treated crypto assets as a special risk class requiring special restrictions. The 2025 approach treats them as assets that existing custody frameworks can accommodate with adjustments. That's a fundamental epistemological shift in how the SEC views the asset class.

The practical implications are significant:

First, the definition of "qualified custodian" is likely to expand beyond the 2023 list. The question is how far. Will it include state-regulated entities beyond banks and trust companies? Will it include federally regulated non-bank custodians? Will it acknowledge the role of qualified crypto custodians that maintain specific security standards?

The second question is technical standards. If the SEC broadens the custodian definition, it must also define what constitutes acceptable custody practices for digital assets. The 2023 rule was silent on technical specifics β€” no mention of private key management, cold storage requirements, multi-signature thresholds, or audit standards. That silence was itself a problem. A bank chartered to hold securities isn't automatically equipped to hold digital assets, and the 2023 rule provided no guidance on what "equipped" means.

Based on my audit experience with institutional custody solutions, this is where the real work happens. I spent part of 2024 analyzing the multi-signature threshold logic and MPC implementations used by major asset managers entering the spot Bitcoin ETF market. The gap between marketing claims and actual cryptographic security was substantial. Three potential attack vectors in threshold signature aggregation processes surfaced during that work. The SEC's rule, if it specifies technical standards at all, will need to address these real-world implementation issues rather than relying on entity-type designations as a proxy for security.

The Broader Regulatory Stack

The custody proposal doesn't exist in isolation. RIN 3235-AN48 is moving in parallel β€” a rule that will clarify broker-dealer custody requirements for crypto assets. And the SEC's tokenization exemption β€” which would provide regulatory clarity for tokenized securities β€” remains pending.

This is a coordinated strategy, not a series of isolated actions. The SEC is building a compliance stack: custody rules for advisers, custody rules for broker-dealers, and an exemption framework for tokenized securities. Each piece addresses a different friction point in the institutional adoption pipeline.

Consider the tokenization angle. A tokenized security needs a compliant custodian. If the custody rule expands the qualified custodian definition, it removes a structural barrier to tokenized securities issuance. The pending tokenization exemption then addresses the securities law side. Together, they create a pathway that didn't exist before.

The sequencing matters. Custody first, then broker-dealer rules, then tokenization. Each step reduces uncertainty for the next. This suggests the SEC is thinking in terms of system architecture, not individual rulemakings.

The New Charter Wave

There's another data point that's been underreported: the recent approval of federal trust bank charters. These approvals expand the pool of regulated entities capable of providing crypto custody services.

This is the market solving the problem before the regulator does. New charter approvals mean more entities can legally custody digital assets under existing frameworks. The SEC's rule revision, in this context, is partly a recognition of market reality β€” the agency is adjusting its rules to match what's already happening on the ground.

It's also a competitive signal. If the SEC finalizes a broader custodian definition, traditional banks and trust companies will have to compete with crypto-native custodians that have been building digital asset infrastructure for years. The competitive dynamics of the custody market are about to shift.

The custody market is one of the few areas in crypto with real revenue and real institutional demand. The 2023 rule threatened to consolidate that market into a few traditional players. The 2025 direction points toward a more competitive landscape.

The Contrarian Angle: Deregulation Is Not De-Risking

Now let me push against the prevailing narrative. The market reads "deregulatory" as "fewer restrictions." That's not necessarily accurate.

A rule that expands the qualified custodian definition while simultaneously imposing specific technical standards could create more compliance burden for a wider set of entities. The total regulatory surface area might increase even as the entry barriers decrease.

Consider what happened with the spot Bitcoin ETF approvals. The SEC approved the products but imposed surveillance-sharing requirements that forced exchanges to restructure their operations. The approval wasn't deregulation β€” it was regulation with different terms.

The custody rule could follow the same pattern. The SEC might broaden the custodian definition while imposing specific requirements around audit trails, segregated accounts, and disclosure obligations. The entities entering the market would face new compliance costs, not fewer.

The second blind spot is the "responsibility transfer" problem. When the SEC narrows the custodian definition, it's making a judgment about which entities are trustworthy. When it broadens that definition, it's implicitly transferring risk assessment responsibility from the regulator to the investment adviser. The adviser must now conduct due diligence on a wider range of custodians, with less regulatory guidance on what constitutes acceptable security.

That's a real burden shift. The SEC is saying, in effect: "We'll tell you who's qualified, but we won't tell you what qualified means."

The third angle is enforcement. The SEC under Paul Atkins is friendlier to crypto, but the enforcement division still has cases pending against major platforms. A more permissive custody rule doesn't change the SEC's position on unregistered securities or market manipulation. The regulatory direction has shifted, but the enforcement machinery remains intact.

The "deregulatory" label might be a misdirection. What's actually happening is a reallocation of regulatory responsibility. The SEC is reducing its own oversight burden while increasing the due diligence burden on advisers and the operational burden on custodians.

The Institutional Adoption Signal

Let's return to the market implications. The custody rule revision is a necessary condition for deeper institutional participation in crypto markets. Without clear custody rules, institutional capital stays on the sidelines. The 2023 rule would have kept it there. The 2025 direction opens the door.

The transmission mechanism works through multiple channels:

Investment advisers can now consider crypto assets as part of client portfolios without navigating undefined custody requirements. That's a demand-side shift.

Custodians can now invest in technical infrastructure with clearer regulatory expectations. That's a supply-side shift.

And the tokenization pathway becomes more credible, which matters for the broader RWA narrative.

The timing aligns with the market cycle. We're in a bear market, and the market is focused on survival. But regulatory infrastructure is being built for the next expansion. The custody rule is part of that infrastructure.

From my work on the 2021 LUNA collapse and the Anchor Protocol audit, I learned that financial models are only as secure as their underlying code. The same principle applies here. Regulatory frameworks are only as sound as their underlying technical assumptions. A custody rule that doesn't account for the actual mechanics of private key management, multi-signature thresholds, and MPC implementation will create risks that the rule was designed to prevent.

Code is law, but bugs are reality. The SEC is drafting legal code, but the custodians will be implementing technical code. The gap between those two layers is where the risks will concentrate.

The market should be watching the technical details of the final rule, not just the direction. Does the rule specify security standards? Does it require third-party audits? Does it address the specific risks of MPC implementations β€” particularly the key-share distribution protocols that I found problematic in my institutional audits? Does it distinguish between custody models (full control vs. multi-party control vs. sub-custody arrangements)?

The answers to these questions will determine whether the rule actually improves the custody landscape or simply shifts the risk surface.

The International Dimension

The SEC's move doesn't happen in a vacuum. The EU's MiCA framework provides a comprehensive regulatory structure for crypto assets. Singapore and Hong Kong are competing for crypto business with their own frameworks. The US has been losing ground in this competition, and the custody rule revision is partly a response to that competitive pressure.

If the US wants to attract and retain crypto businesses, it needs a regulatory framework that doesn't penalize legitimate participants. The 2023 rule would have done exactly that. The 2025 direction is a correction.

But the international competition isn't just about regulatory friendliness. It's about regulatory clarity. MiCA provides detailed rules that market participants can plan around. The US approach, by contrast, has been characterized by enforcement actions and piecemeal rulemakings. The custody proposal is an opportunity to provide the kind of clarity that institutional participants need.

The question is whether the SEC will seize that opportunity or continue the pattern of ambiguity. The "deregulatory" designation suggests a willingness to reduce burdens, but clarity is a different thing from deregulation.

The Path Forward

The timeline is now the critical variable. The proposal is at OIRA for review. The formal proposal is targeted for October. After that comes the public comment period, then final rule, then implementation.

Each step carries uncertainty. OIRA could request changes. The October timeline could slip. The public comment period could surface objections. The final rule could differ materially from the proposal.

The market is pricing in a positive outcome β€” the "deregulatory" designation and the Atkins leadership have created expectations of a more permissive framework. If the final rule disappoints, the correction could be sharp.

Based on my experience building a zkSNARK proof generator from scratch in Rust during the 2022 bear market, I've learned that the gap between design and implementation is where the real challenges live. The same applies to regulatory frameworks. The design intent is clear β€” broader custodian definitions, reduced compliance burdens, a more accommodating posture. The implementation will determine whether that intent survives contact with the technical realities of digital asset custody.

Privacy is a feature, not a bug. The same could be said of regulatory clarity. A rule that provides clear standards, realistic requirements, and workable definitions is a feature for the industry. A rule that provides vague principles and shifting expectations is a bug that will manifest in operational uncertainty and compliance failures.

The next three months will tell us which one we're getting.

What the Market Is Missing

The custody rule is being framed as a crypto story. It's not. It's a traditional finance story. The primary beneficiaries are not crypto-native firms β€” they've already built their custody infrastructure. The primary beneficiaries are traditional banks, trust companies, and broker-dealers that have been waiting for regulatory permission to enter the market.

That's the shift that matters. When traditional financial institutions enter the crypto custody market, they bring their own compliance cultures, risk management frameworks, and client relationships. The competitive dynamics of the custody market will change fundamentally.

The crypto-native custodians that survive will be those that can demonstrate security standards exceeding what traditional institutions can achieve. The traditional institutions that succeed will be those that can adapt their compliance frameworks to the technical realities of digital assets.

The intersection of these two groups is where the next generation of custody infrastructure will be built.

The Bottom Line

The SEC's custody rule revision is the most consequential regulatory development for crypto since the spot Bitcoin ETF approvals. It addresses the structural bottleneck that has limited institutional participation: the absence of clear, workable custody rules.

The direction is right. The timing is favorable. The leadership is aligned. But the details are unknown, and the details are where regulatory frameworks succeed or fail.

The market should be paying attention to the technical specifications of the final rule, not just the deregulatory framing. The question is not whether the SEC will broaden the custodian definition β€” that seems likely. The question is what standards will attach to that broader definition.

That's where the real risk and opportunity lie.

Math doesn't negotiate. Neither does regulatory reality. The custody rule will either work with the technical mechanics of digital asset custody or it will create new problems while solving old ones.

We'll know by October. Watch the details.