Onchain yield without leaving qualified custody
Qualified custodians can now route client assets into onchain strategies while those assets stay in custody. The combination that makes it work is a non-custodial vault plus a policy engine, and two of the largest custodians adopted it within six weeks of each other.
You can now earn onchain yield without moving client assets out of qualified custody. The assets stay in the custodian's segregated accounts. Capital deploys into a non-custodial vault, and a policy engine restricts what the operator can do with it at the chain, protocol, token and function level. Your custody arrangement stays intact, and your compliance team keeps the reporting it needs.
For most of crypto's history that wasn't available. You either kept client assets with a regulated custodian and gave up the yield, or you moved them to a counterparty and accepted the risk. Neither answer survived a risk committee. The result was that a large share of institutionally held crypto sat idle. That tradeoff started dissolving in 2026, and this piece walks through the mechanism.
What is a qualified custodian?
A qualified custodian is a regulated institution authorised to hold client assets on behalf of others. The term comes from the SEC's custody rule under the Investment Advisers Act of 1940. That rule requires registered investment advisers with custody of client funds to keep those assets with a qualified custodian, and you can read the rule text itself if your counsel wants the primary source.
The category covers banks, registered broker-dealers and certain trust companies. Each has to meet high bars on capital reserves, segregation of client assets, audited controls and reporting. Client assets sit in segregated accounts, shielded from the custodian's own creditors, with statements delivered directly to clients so holdings can be verified independently.
For digital assets, the custodian holds both the private keys and the underlying tokens. Kraken Custody runs through a Wyoming-chartered bank. BitGo Bank & Trust is an OCC-chartered non-depository national trust bank. Those charters are what let a fund's compliance team sign off.
Why do you have to use one?
For a registered investment adviser holding client money it's a legal obligation. Funds, asset managers and treasuries operating under fiduciary duty face the same expectation from auditors, limited partners and internal risk committees.
Even where it isn't strictly required, most institutions want it. A corporate treasury holding crypto, a family office, or a crypto-native fund raising from traditional LPs all benefit from the same protections. Insurance underwriters price custody arrangements into coverage. Banks assessing a counterparty look at where the assets sit. Moving assets out carries a real cost in compliance overhead, lost coverage and harder allocator conversations.
Why did onchain yield used to mean leaving custody?
Onchain yield lived somewhere the custodian wasn't. To lend stablecoins, provide liquidity or run a basis trade, assets had to leave the segregated account and move onto a venue or into a wallet the custodian didn't control. At that moment you traded one set of protections for a new set of risks.
The 2022 lending failures made the stakes concrete. Celsius froze withdrawals on roughly $12 billion in customer assets in June 2022 and later filed for bankruptcy, and Voyager and BlockFi followed within months. Each had taken customer deposits onto its own balance sheet and redeployed them into trades and counterparties depositors couldn't see or constrain. Customers who thought they were earning a modest yield had handed over unconstrained discretion.
Self-custody addressed where the funds sit, though it left open what happens once they're deployed. You could hold your own keys in a multisig and still carry smart contract risk, operational risk from manual signing, and the governance problem of who gets to move funds where. For a fiduciary it also reintroduced the exact problem the custody rule exists to prevent, because client assets were no longer with a qualified custodian.
How does the vault plus policy engine model work?
Two pieces do the work. The first is a non-custodial vault, a smart contract that holds deposited assets and deploys them into strategies while you keep a verifiable claim. Neither the infrastructure provider nor the curator can move funds to an external wallet.
The second is a policy engine, which restricts what the operator is allowed to do, enforced in code rather than by contract. Upshift's engine applies restrictions at four levels, and a transaction falling outside any of them is rejected onchain before it executes.
Level | What it constrains | What it stops |
Chain | Which networks the mandate can touch | Capital appearing on an unapproved network |
Protocol | Which venues are approved | An operator routing into an unvetted protocol |
Token | Which assets can be held or swapped | Drift into an asset outside the mandate |
Function | Which specific contract calls are permitted | An approved protocol being used in an unapproved way |
Approving a lending market without constraining which functions can be called still leaves room for positions that were never sanctioned. The risk management framework documents how these restrictions get set and changed.
Put the two together and the custody problem reframes itself. Your custodian still holds the assets. You allocate a portion to an onchain strategy through an arrangement the custodian controls, capital deploys into the vault, and the policy engine bounds what it can do. None of this makes yield guaranteed. The strategies still carry smart contract, market and credit risk that you need to evaluate.
Always make sure to do your own research and be aware of the above and any other risks before depositing.
What does "stays in custody" actually mean?
This is where the model gets misread, so it's worth being precise. The dollars don't sit still. Capital does move onchain into the vault contract, and the strategies do deploy it. What stays inside the custody perimeter is your claim on that capital.
A deposit mints a receipt token, an ERC-4626 share representing your position in the vault. Your custodian holds that token in the same segregated account structure it uses for any other asset. Redemption burns the share and returns the underlying. So the custodian's role shifts from holding a static balance to holding a claim that accrues, and the audit trail runs onchain where your reporting can read it directly.
The receipt token is not the new part. ERC-4626 has been a final standard since 2022 and vaults have been minting shares against it ever since. What arrived recently is qualified custodians agreeing to hold those shares, which took the policy-engine controls above to get comfortable with. Support is granted token by token rather than as a blanket policy, so the question for any specific vault is whether your custodian has approved that particular share.
Your custodian has to support the specific receipt token, and that's an approval decision rather than a technical one. The segregation question also moves from the account level to the vault level, so you need to know whether the vault is shared with other depositors or whitelisted to you alone. Sole-depositor and whitelisted vaults are both standard configurations.
What does the Kraken Institutional arrangement look like?
Upshift works with Kraken Institutional to bring this model to qualified-custodian clients. Kraken supplies the custody relationship and the regulatory oversight. Upshift supplies the vault infrastructure and the policy engine.
A Kraken Institutional client allocates from inside the custody relationship. Capital deploys into vault strategies governed by the four control levels above, and the client keeps the reporting the custody framework requires. August Digital's prime stack sits underneath, supplying the risk engine, pricing and institutional lender network the strategies draw on.
The operational details are what a compliance team actually asks about. As of August 2026 Upshift has processed more than $550 million in deposits at peak across 50+ vaults on 30+ chains, serving more than 60,000 users, and the contracts have been through 10 audits by 6 independent firms. Redemptions process daily. Operator keys run through MPC providers Fireblocks and Fordefi rather than a single hot wallet.
Who else is building this?
Kraken and Upshift aren't alone. On 2 June 2026, BitGo Bank & Trust and Concrete announced a partnership built on the same idea: institutional clients select vetted vault strategies while the underlying assets remain in BitGo's qualified custody. Forbes covered the pattern in August 2026 under the heading that DeFi yield is moving inside BitGo custody.
When two of the larger qualified custodians reach for the same architecture six weeks apart, the pattern is becoming standard rather than experimental. The custodian holds the assets, a vault supplies the onchain rails, a policy framework enforces the mandate, and the institution earns yield without breaking the arrangement its audit function depends on.
What should your compliance team actually check?
The questions below are the ones that decide whether an allocation gets approved.
Question | Why it decides the outcome |
Can the operator move assets to an external wallet? | If yes, you're back in the 2022 model regardless of what the marketing says |
At what level are restrictions enforced? | Protocol-level allowlists leave room that function-level controls close |
Who can change the policy, and how fast? | Parameter changes are timelocked; contract upgrades are a separate question |
Will your custodian hold the receipt token? | Custodian approval usually takes longer than the technical integration |
What is the redemption lag on this specific vault? | It varies by strategy, so an average won't help you |
Is there smart contract insurance? | Upshift carries audits and no policy. Source cover separately if your mandate needs it. |
Start the custodian conversation in parallel with the technical one. Receipt-token approval runs on the custodian's timeline rather than yours.
Why is this where institutional asset management is heading?
Two longer arcs run underneath these partnerships. The first is that vaults are becoming the default wrapper for financial products. A vault is a programmable container with onchain accounting, enforceable constraints and a transferable claim, and that combination works for a retail earn tab, a fund wrapper and a treasury mandate alike. We argue that case at length in why every financial product will run on vaults.
The second is that traditional asset management is migrating onchain through the institutions that already hold the assets. Qualified custodians are the gatekeepers, and as they add onchain yield to what they offer, client capital comes with them. A policy engine that constrains an operator at the function level is what makes a fiduciary comfortable making that move. For the control frameworks allocators expect, see how traditional asset managers are controlling risk in DeFi.
Frequently asked questions
What is a qualified custodian?
A regulated institution, typically a bank, broker-dealer or trust company, authorised to hold client assets for others. Under the SEC's custody rule, registered investment advisers with custody of client funds must keep those assets with one. It provides segregated accounts, audited controls and independent reporting, and for digital assets it holds both the keys and the tokens.
Can you earn onchain yield without moving assets out of custody?
Increasingly, yes. Partnerships between qualified custodians and vault infrastructure providers let clients allocate to onchain strategies while assets remain in the custodian's accounts. A non-custodial vault supplies the rails and a policy engine enforces the mandate. The strategies still carry market, credit and smart contract risk.
What is a policy engine?
A set of programmable controls restricting what a vault operator can do with deposited capital, enforced in code. Upshift's engine applies restrictions at the chain, protocol, token and function level, so capital only touches approved protocols and calls approved functions. Anything outside the policy is rejected by the contract before it executes.
How is this different from the lenders that failed in 2022?
Celsius, Voyager and BlockFi took deposits onto their own balance sheets and redeployed them into positions depositors couldn't see or constrain. In a non-custodial vault, assets sit in a smart contract with a verifiable claim, the custodian keeps the client relationship, and the policy engine limits the operator at the code level. Mechanical per-transaction enforcement replaces unconstrained discretion.
Does non-custodial mean there's no risk?
No. It removes the risk that an operator absconds with funds and reduces counterparty exposure. Onchain strategies still carry smart contract risk, market risk and, for credit strategies, borrower default risk. The model constrains and makes visible the risks you're taking rather than eliminating them, and yield is never guaranteed.
Who holds the receipt token?
Your custodian does, on your behalf. That makes the custodian a counterparty on every deal map, and their willingness to support the token is a gating item worth confirming early.
Keep reading
- What is Upshift: how non-custodial vault infrastructure works, from deposit to strategy execution.
- Who does what in an onchain vault: the end-to-end workflow and which party owns each step.
- Upshift DeFi yield: the product types institutions and platforms can deploy.
- Upshift FAQ: custody, redemptions, fees and integrations in detail.
Create a vault with Upshift
Share your use case and we’ll get back to you shortly
