Most crypto rulebooks devote more attention to custody than to trading. The reason is that the failures which cost customers the most were failures of safekeeping rather than of market conduct.

Segregation separates client money from company money

The core requirement is that assets belonging to clients are held apart from the operator's own, in accounts identifiable as client property.

Without that separation, client holdings sit on the company's balance sheet and are available to its creditors if it fails. Customers become unsecured claimants in a queue.

Segregation does not stop a firm losing money. It determines who owns what remains, which is the question that matters after an insolvency.

Commingling on-chain is operationally convenient

Exchanges pool client deposits into shared wallets because giving every account its own on-chain address multiplies fees and key management burden enormously.

Ownership is then tracked in an internal ledger, and the chain shows only aggregate balances that reveal nothing about individual entitlements.

Rules therefore focus on the quality of that internal record and on regular reconciliation against on-chain holdings, since the ledger is the only evidence of who owns what.

Rehypothecation is where the disputes concentrate

Lending out client assets to fund other activity generates revenue, and it converts a custody relationship into a credit relationship the client may not have understood.

Rules generally require explicit consent, clear disclosure and often outright prohibition for retail clients, because the risk is invisible until it materialises.

Firms that blurred this line typically did so gradually, using client balances for short-term operational needs before the practice became structural.

Key management becomes a supervised process

Because assets are controlled by keys, custody rules extend into how keys are generated, split, stored and used, which is unusual territory for financial regulation.

Requirements typically cover multi-party control, geographic distribution of backups, and documented procedures for rotation and recovery.

The effect is to turn a technical decision into a supervised control, with the same audit expectations applied to a vault.

Proof of reserves is partial by nature

Publishing cryptographic evidence of holdings shows what an exchange controls, and users can check their own balance is included in the total.

What it cannot show is liabilities, since borrowings and obligations do not appear on-chain. Assets without liabilities describe one side of a balance sheet.

Requirements are consequently moving toward audited attestations covering both sides, with the cryptographic proof serving as supporting evidence rather than as the whole answer. Specific obligations vary by jurisdiction and change over time.