Segregated vs co-mingled vault accounts
What each structure means for who owns what, how losses travel between depositors, and which one a regulated allocator can actually use.
A co-mingled vault pools every depositor's assets into one contract and issues shares representing a pro-rata claim on the whole. A segregated structure keeps one client's assets in an account that only that client has a claim on. The difference determines whether one depositor's loss can reach another's balance, and whether the position survives an audit.
Most onchain yield vaults are co-mingled by default. ERC-4626, the tokenised vault standard most implementations build on, describes a single pool with a single share price, which is efficient and is what makes a $10,000 deposit earn the same strategy as a $10M one. For a retail Earn product that's the right structure. For a fund allocating client money under a mandate, it often isn't.
How each structure works
Co-mingled | Segregated | |
Where assets sit | One contract holding every depositor's capital | A vault or account with a single depositor, or a per-client subaccount |
What you hold | Shares representing a pro-rata claim on the pool | A claim on identifiable assets |
Whose performance you get | The pool's, including the effect of other depositors entering and exiting | Your own, attributable to your mandate |
Loss mutualisation | A strategy loss hits every share proportionally | Contained to the account that held the position |
Liquidity | A shared buffer serves all redemptions, so exits are usually faster | Your own liquidity, unsubsidised by other depositors |
Typical cost | Lower. One deployment, one set of audits, shared operations | Higher. A separate deployment and its own monitoring |
Loss mutualisation is the decisive row. In a co-mingled vault, a position that goes wrong reduces the share price for every holder, including those who deposited after the position was opened and had no visibility into it. For a consumer product that outcome is tolerable and disclosed. For a manager holding a fiduciary duty to an identified client, it is a mandate problem rather than a disclosure one.
Why a regulated allocator usually needs segregation
Client asset rules in most jurisdictions require a firm to keep client money identifiable and separate from both the firm's own assets and other clients' assets. The UK's CASS 7 client money rules, the EU's MiFID II safeguarding requirements and the SEC's custody rule all work from that principle. A pro-rata claim on a shared pool can satisfy those rules in some structures and fails them in others, which is a question for counsel rather than a vendor.
Three practical consequences come up repeatedly:
- Insolvency treatment. If the operator fails, a segregated account is easier to identify and return. A co-mingled pool can leave depositors as general claimants on a single pot, and the onchain position is only as good as the enforceability of the claim.
- Performance attribution. A mandate with a target and a benchmark needs returns traceable to the decisions taken for that client. Pool-level share price movement includes the effect of other depositors' flows.
- Concentration and eligibility limits. A mandate restricting exposure to a protocol or counterparty can't be enforced at pool level, because the pool's allocation reflects every depositor's mandate at once.
Always make sure to do your own research and take your own legal advice before relying on any structure described here.
How segregation gets built onchain
Segregation onchain comes in degrees rather than as a binary, and the term gets used loosely. Four patterns are common.
Pattern | How it works | What it gives you |
Whitelisted vault | A co-mingled vault whose depositor list is restricted to approved addresses | Control over who you're pooled with. Assets are still shared |
Sole-depositor vault | A vault deployment with exactly one depositor | Full segregation at the vault level, with the cost of a dedicated deployment |
Per-client subaccount | Capital routes from the vault into a separate account per client or strategy | Position-level separation and attribution, while sharing the vault's operations |
Separate share class | One pool, several share classes with different fees or terms | Commercial separation. No separation of assets or risk |
A whitelisted vault and a sole-depositor vault are frequently both described as "segregated", and only one of them is. If a provider says segregated, ask which of these four they mean and get it in writing.
What to ask a provider
- Is the capital held in a contract shared with other depositors? If so it is co-mingled, whatever else the structure is called.
- If another depositor's strategy takes a loss, does this balance change? The answer establishes mutualisation directly, whatever the structure is called.
- Who else can deposit, and can that list change without depositor consent? A whitelist the operator edits unilaterally is a weaker control than the term suggests.
- In an insolvency, what identifies the assets as belonging to one client? Request the specific contract state or legal instrument that performs the identification.
- Can mandate limits be enforced at the account level? A concentration cap or a protocol exclusion has to be enforced somewhere. In a shared pool the allocation reflects every depositor's mandate at once, so a client-specific limit has nothing to bind to.
- What does redemption look like with a single depositor? Segregation removes the shared liquidity buffer, so exits can be slower rather than faster.
Segregation costs liquidity
Segregation costs liquidity. A co-mingled pool nets one depositor's redemption against another's deposit, so most exits are served without unwinding a position. A sole-depositor vault has no offsetting flow, so every redemption becomes a real unwind at whatever the market offers that day.
That reverses the usual assumption. Segregation removes exposure to other depositors' losses and removes the liquidity they provide. Which dominates depends on whether the mandate's binding risk is a strategy impairment or a redemption arriving into a thin market.
Frequently asked questions
Is a co-mingled vault the same as a fund?
Structurally they're close. Both pool capital, issue a claim on the whole and price it off a single NAV. The difference is the legal wrapper and the disclosure regime around it, which is where the regulatory treatment comes from.
Does a whitelisted vault count as segregated?
No. A whitelist controls who can join the pool. Everybody in it still shares the assets and the losses, so it's a co-mingled vault with an access list.
Can losses from one strategy reach my deposit in a co-mingled vault?
Yes. A loss on any position reduces the vault's total assets, which reduces the share price for every holder, whenever they deposited.
What is a subaccount in this context?
An account that sits between the vault and the strategy venues, holding capital for one client or one mandate. It allows position-level attribution and lets limits bind at the account rather than the pool.
Which structure has better liquidity?
Co-mingled, usually. A shared redemption buffer nets deposits against withdrawals, so fewer exits require unwinding a position.
Do I need segregation to meet client asset rules?
It depends on the jurisdiction, the wrapper and the nature of the claim. This is a question for counsel. A provider answering it definitively for a specific mandate is overreaching.
Keep reading
- Who does what in an onchain vault. The roles of depositor, curator, operator and owner.
- How onchain yield vaults are secured. Policy engines, permitted protocol sets and the threats they address.
- Onchain yield in qualified custody. Earning without assets leaving a qualified custodian.
- How to tier vault strategies by risk. Framing risk so a committee can approve it.
Create a vault with Upshift
Share your use case and we’ll get back to you shortly
