Qualified custodians for onchain yield: how it works
For Institutions & Asset Issuers
20 Aug 2026

Qualified custodians for onchain yield: how it works

Ethan Luc
Written by Ethan Luc
Institutional
Non-custodial
Risk Management
Vaults
Regulation

Qualified custodians now let institutions route client assets into onchain strategies while the assets stay in custody. A non-custodial vault plus a policy engine makes it work, and two of the largest custodians adopted the model within six weeks of each other.

Institutions can now earn onchain yield without moving client assets out of qualified custody. The assets stay in the custodian's segregated accounts, capital deploys into a non-custodial vault, and a policy engine restricts what the operator can do with it at the chain, protocol, token and function level. The custody arrangement stays intact, and the compliance function keeps the reporting it needs.

For most of crypto's history that option didn't exist. An institution either kept client assets with a regulated custodian and gave up the yield, or moved them to a counterparty and accepted the risk, and neither answer survived a risk committee. A large share of institutionally held crypto sat idle as a result, until custodians started adopting the vault model for institutional DeFi in 2026.

What is a qualified custodian?

A qualified custodian is a regulated institution authorised to hold client assets on behalf of others. The term comes from the SEC's custody rule under the Investment Advisers Act of 1940. That rule requires registered investment advisers with custody of client funds to keep those assets with a qualified custodian, as set out in the rule text.

The category covers banks, registered broker-dealers and certain trust companies. Each has to meet high bars on capital reserves, segregation of client assets, audited controls and reporting. Client assets sit in segregated accounts, shielded from the custodian's own creditors, with statements delivered directly to clients so holdings can be verified independently.

For digital assets, the custodian holds both the private keys and the underlying tokens. Kraken Custody runs through a Wyoming-chartered bank. BitGo Bank & Trust is an OCC-chartered non-depository national trust bank. A fund's compliance team signs off on the strength of those charters.

Why is a qualified custodian required?

For a registered investment adviser holding client money it's a legal obligation. Funds, asset managers and treasuries operating under fiduciary duty face the same expectation from auditors, limited partners and internal risk committees.

Even where it isn't strictly required, most institutions want it. A corporate treasury holding crypto, a family office, or a crypto-native fund raising from traditional LPs all benefit from the same protections. Insurance underwriters price custody arrangements into coverage. Banks assessing a counterparty look at where the assets sit. Moving assets out carries a real cost in compliance overhead, lost coverage and more difficult allocator due diligence.

Why did onchain yield used to mean leaving custody?

Onchain yield lived somewhere the custodian wasn't. To lend stablecoins, provide liquidity or run a basis trade, assets had to leave the segregated account and move onto a venue or into a wallet the custodian didn't control. At that point the institution traded one set of protections for a new set of risks.

The 2022 lending failures made the stakes concrete. Celsius froze withdrawals on roughly $12 billion in customer assets in June 2022 and later filed for bankruptcy, and Voyager and BlockFi followed within months. Each had taken customer deposits onto its own balance sheet and redeployed them into trades and counterparties depositors couldn't see or constrain. Customers who thought they were earning a modest yield had handed over unconstrained discretion.

Self-custody addressed where the funds sit, though it left open what happens once they're deployed. An institution could hold its own keys in a multisig and still carry smart contract risk, operational risk from manual signing, and the governance problem of who gets to move funds where. For a fiduciary it also reintroduced the exact problem the custody rule exists to prevent, because client assets were no longer with a qualified custodian.

How does the vault plus policy engine model work?

Two pieces do the work. The first is a non-custodial vault, a smart contract that holds deposited assets and deploys them into strategies while the depositor keeps a verifiable claim. The curator can only make the calls the policy allows, and none of those calls can send funds to an outside wallet.

The second is a policy engine, which restricts what the operator is allowed to do and enforces those limits in code. Upshift's engine applies restrictions at four levels, and a transaction falling outside any of them is rejected onchain before it executes.

Level

What it constrains

What it stops

Chain

Which networks the mandate can touch

Capital appearing on an unapproved network

Protocol

Which venues are approved

An operator routing into an unvetted protocol

Token

Which assets can be held or swapped

Drift into an asset outside the mandate

Function

Which specific contract calls are permitted

An approved protocol being used in an unapproved way

Approving a lending market without constraining which functions can be called still leaves room for positions that were never sanctioned. The risk management framework documents how these restrictions get set and changed.

Combined, the two pieces keep the custodian in place. The custodian still holds the assets, the institution allocates a portion to an onchain strategy through an arrangement the custodian controls, capital deploys into the vault, and the policy engine bounds what it can do. Yield is never guaranteed: the strategies still carry smart contract, market and credit risk that each allocator has to evaluate.

Always make sure to do your own research and be aware of the above and any other risks before depositing.

What does "stays in custody" actually mean?

Capital moves onchain into the vault contract, and the strategies deploy it. What stays inside the custody perimeter is the institution's claim on that capital.

A deposit mints a receipt token, an ERC-4626 share representing the depositor's position in the vault. The custodian holds that token in the same segregated account structure it uses for any other asset. Redemption burns the share and returns the underlying. So the custodian's role shifts from holding a static balance to holding a claim that accrues, and the audit trail runs onchain where reporting systems can read it directly.

ERC-4626 has been a final standard since 2022, and vaults have minted shares against it ever since. The 2026 development is qualified custodians agreeing to hold those shares, a step the policy-engine controls above made possible. Custodians approve support one token at a time. A specific vault is covered only once the custodian has approved its share token.

That approval is a policy decision on the custodian's side, separate from the technical integration. The segregation question also moves from the account level to the vault level: whether the vault is shared with other depositors or whitelisted to a single one. Sole-depositor and whitelisted vaults are both standard configurations.

What does the Kraken Institutional arrangement look like?

Upshift works with Kraken Institutional to bring this model to qualified-custodian clients. Kraken supplies the custody relationship and the regulatory oversight. Upshift supplies the vault infrastructure and the policy engine. The Kraken case study covers how the vaults were built for Kraken's institutional clients.

A Kraken Institutional client allocates from inside the custody relationship. Capital deploys into vault strategies governed by the four control levels above, and the client keeps the reporting the custody framework requires. August Digital's prime stack sits underneath, supplying the risk engine, pricing and institutional lender network the strategies draw on.

Compliance teams ask first about the operational details. As of September 2026 Upshift has processed more than $550 million in deposits at peak across 50+ vaults on 30+ chains, serving more than 66,000 users, and the contracts have been through 11 audits by 6 independent firms. Redemptions process daily. Operator keys are held with the MPC providers Fireblocks and Fordefi, and each vault's owner role sits with a multisig.

Who else is building this?

On 2 June 2026, BitGo Bank & Trust and Concrete announced a partnership built on the same idea: institutional clients select vetted vault strategies while the underlying assets remain in BitGo's qualified custody. Forbes covered the pattern in August 2026 under the heading that DeFi yield is moving inside BitGo custody.

Two of the larger qualified custodians reaching for the same architecture six weeks apart suggests the model is becoming standard. The custodian holds the assets, a vault supplies the onchain rails, a policy framework enforces the mandate, and the institution earns yield without breaking the arrangement its audit function depends on.

Keeping assets in qualified custody? See how treasuries earn onchain yield from a whitelisted vault with their custody account as the depositor. The Upshift team walks through custodian support for the receipt token, depositor whitelisting and the policy engine setup.

Talk to the Upshift team

What should a compliance team check?

Six questions decide whether an allocation gets approved.

Question

Why it decides the outcome

Can the operator move assets to an external wallet?

If yes, the structure is back in the 2022 model

At what level are restrictions enforced?

Protocol-level allowlists leave room that function-level controls close

Who can change the policy, and how fast?

Timelocks cover some parameter changes, such as management fees; contract upgrades go through the owner multisig

Will the custodian hold the receipt token?

Custodian approval usually takes longer than the technical integration

What is the redemption lag on this specific vault?

It varies by strategy. A platform average says little

Is there smart contract insurance?

Upshift carries audits and no policy. Cover has to be sourced separately where a mandate requires it.

Receipt-token approval runs on the custodian's timeline. Start the custodian conversation alongside the technical one.

Why is this where institutional asset management is heading?

Two longer arcs run underneath these partnerships. The first is that vaults are becoming the default wrapper for financial products. A vault is a programmable container with onchain accounting, enforceable constraints and a transferable claim, and that combination works for a retail earn tab, a fund wrapper and a treasury mandate alike. We argue that case at length in why every financial product will run on vaults.

The second is that traditional asset management is migrating onchain through the institutions that already hold the assets. Qualified custodians are the gatekeepers, and as they add onchain yield to what they offer, client capital comes with them. A policy engine that constrains an operator at the function level gives a fiduciary the comfort to make that move. For the control frameworks allocators expect, see how traditional asset managers are controlling risk in DeFi.

Frequently asked questions

What is a qualified custodian?

A regulated institution, typically a bank, broker-dealer or trust company, authorised to hold client assets for others. Under the SEC's custody rule, registered investment advisers with custody of client funds must keep those assets with one. It provides segregated accounts, audited controls and independent reporting, and for digital assets it holds both the keys and the tokens.

Can you earn onchain yield without moving assets out of custody?

Increasingly, yes. Partnerships between qualified custodians and vault infrastructure providers let clients allocate to onchain strategies while assets remain in the custodian's accounts. A non-custodial vault supplies the rails and a policy engine enforces the mandate. The strategies still carry market, credit and smart contract risk.

What is a policy engine?

A set of programmable controls restricting what a vault operator can do with deposited capital, enforced in code. Upshift's engine applies restrictions at the chain, protocol, token and function level. Capital only touches approved protocols and calls approved functions. Anything outside the policy is rejected by the contract before it executes.

How is this different from the lenders that failed in 2022?

Celsius, Voyager and BlockFi took deposits onto their own balance sheets and redeployed them into positions depositors couldn't see or constrain. In a non-custodial vault, assets sit in a smart contract with a verifiable claim, the custodian keeps the client relationship, and the policy engine limits the operator at the code level. Mechanical per-transaction enforcement replaces unconstrained discretion.

Does non-custodial mean there's no risk?

It removes the risk that an operator absconds with funds and reduces counterparty exposure. Onchain strategies still carry smart contract risk, market risk and, for credit strategies, borrower default risk. The model constrains those risks and makes them visible, and yield is never guaranteed.

Who holds the receipt token?

The custodian holds it on the client's behalf, which makes the custodian a counterparty in every allocation. Its willingness to support the token is a gating item to confirm early.

Keep reading

Share this post:

Launch a vault with Upshift

Upshift builds custom, permissioned vaults for custodians, exchanges, neobanks and asset managers. Tell us what you are building and the team will follow up.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.