Buy now

For twenty years the phrase qualified custodian has been a piece of plumbing almost nobody outside compliance had to think about. It names the bank, broker or trust company that an investment adviser must park client assets with, and the rule behind it assumes somebody else is always available to hold the thing. Crypto broke that assumption, because for plenty of assets no regulated institution will take the job at all.

On 1 October 2026 the Securities and Exchange Commission proposed a fix, and the shape of it is worth a holder's attention even though none of it applies to you. Under the proposal, an adviser who cannot find a custodian may hold the keys itself, which makes this the first time a US regulator has written down what it thinks competent key custody looks like.

What the qualified custodian rule changes

The amendments sit under the Investment Advisers Act of 1940 and the Investment Company Act of 1940, and they move on two fronts at once. State-chartered trust companies would be added to the list of firms that can serve as a qualified custodian for crypto, widening a pool that has been narrow enough to create the problem in the first place. Alongside that, registered advisers and regulated funds would get a conditional route to self-custody: holding client crypto directly when no permitted custodian will maintain it.

SEC Chair Paul Atkins framed the exercise as catching up, saying the agency's rules "have not kept pace" with a multi-trillion-dollar asset class. Commissioner Hester Peirce went further and put the principle in plain terms, arguing that regulators should protect an investor's right to hold their own assets rather than push everybody toward a third party.

The conditions attached to professional key custody

This is the part worth reading slowly, because the list is long and each item exists for a reason somebody learned the hard way. An adviser has to make a written determination that no qualified custodian will maintain the asset and refresh that finding at least quarterly, and cost alone cannot justify the decision. Once a custodian becomes available, the assets have to move as soon as reasonably practicable.

The definition of control is blunt. An adviser holding any portion of an asset's key material counts as having self-custody, which rules out splitting keys with clients or vendors and limits multisignature arrangements to the adviser's own designated staff. Transfers need joint authorisation from at least two named people, one of them a manager, and each client's holdings have to sit at addresses used for that client alone.

Then come the checks. Cybersecurity risk assessments run annually. An independent accountant has to report on the design and effectiveness of the controls within six months of the adviser taking custody and every year after, including confirming that the reported holdings reconcile against the blockchain. Clients receive quarterly statements listing addresses, balances and transactions, which the SEC expects them to verify against the network themselves.

What the rule leaves alone

Nothing here reaches an individual. The proposal covers registered investment advisers, registered investment companies and business development companies, and a person holding coins in their own wallet falls outside all three categories. No filing obligation lands on you, no inventory of your addresses gets created, and no part of it limits what you are allowed to hold or move.

The comment window runs 60 days from publication in the Federal Register, and the release carries file number S7-2026-35 with more than 330 questions attached, so the final text may look different from the proposal. One open point is already visible: the proposal drops a contractual ban on rehypothecation that earlier staff guidance had included, leaving whether a custodian may lend out client crypto as a question the SEC is asking rather than answering.

The checklist read from the other side

Strip the legal machinery away and the SEC has described a set of habits. Know who holds the key material and make sure that set of people is small. Don't let one person move assets alone. Keep separate holdings separate. Verify what you believe you own against the chain rather than against a screen that claims it. Have somebody who isn't you confirm that the arrangement works, and do it on a schedule instead of when you remember.

Most of that translates to a household. The piece that translates worst is the two-person rule, because an individual holding their own coins is usually the only pair of hands involved, and the standard answer to that gap has been to write twelve or twenty-four words on a card and hide it well. A card does raise a thief's bar. It also makes one object the whole wallet, and the regulator's instinct to spread authority across several people is pointing at something the card cannot do.

How we spread recovery across more than one thing

TapSafe Recovery was built around that instinct. We split recovery with our own implementation of Shamir's Secret Sharing, so the Recovery Tag holds half and your paired phone holds the other half, encrypted into your own iCloud or Google Drive instead of living on the handset. Optional Recovery Contacts hold a quarter each, set up in person over NFC, and they learn nothing about what you hold or what it is worth.

No single component opens the wallet, which is the household version of the rule that no single employee should be able to move client assets. Losing one share turns into a repair rather than a loss, and your seed phrase stays readable on the device as a last resort under the BIP-39 standard, so you keep an exit that does not depend on us existing.

Why the device still decides the outcome

A rule about who may hold keys is only as good as the thing holding them, which is the same test a holder faces at home. On the Ryder One the private key is generated inside an EAL6+ certified Infineon SLC38 secure element and never leaves the chip, so no copy sits on a laptop for malware to find. Each transaction appears in full on the 1.6-inch AMOLED touchscreen before you approve it, receive addresses are verified on the device against clipboard-swapping attacks, and the authorising button is wired directly to the secure element so nothing signs without your finger. Communication is NFC only, with no Bluetooth radio and no Wi-Fi, and Halborn published a full independent audit of the firmware.

Setup takes three taps and about 60 seconds. The Starter Combo is 149 USD and the Super Safe Combo is 179 USD, each with the Recovery Tag, a Qi wireless charger and a pouch included. Supported assets are Bitcoin, Ethereum, Solana and a growing list of top ERC-20 and SPL tokens, so check your own holdings against that list before buying any hardware, ours included. Get your Ryder One.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More