Bermuda doesn’t treat crypto custody as an afterthought. It’s a licensed activity with a rulebook that gets into the nuts and bolts: how client assets are separated, how keys are stored, who can touch what, and what happens when something goes wrong.
If you’re a fund manager, insurer, family office, or a startup planning to be a Bermuda-licensed digital asset business, this is the guardrail you’ll be measured against. And if you’re a client, this is what should stand between your coins and someone else’s problems.
Here’s what the Digital Asset Custody Code expects in practice, how it fits with Bermuda’s digital asset regime, and what changed with the BMA’s 2026 stablecoin consultation.
| Point | Details |
|---|---|
| Client asset segregation | Off-balance-sheet treatment with clear beneficial ownership; segregated or properly sub-ledgered omnibus wallets; no mixing with firm funds. |
| Key security | Cold or warm storage by default, with strong multi-party controls (MPC/multisig), HSMs, and geographic/key-shard separation; minimal hot exposure. |
| Access and change control | Dual control, role-based permissions, whitelists, and documented approvals for wallet changes, plus real-time monitoring and alerting. |
| Reconciliations and records | Frequent on-chain-to-books reconciliation, independent checks, audit trails, and dispute/claims processes ready for use. |
| Assurance | Independent audits (e.g., SOC 2/ISAE), penetration testing, incident response drills, and appropriate insurance/financial resources. |
| Third-party oversight | Due diligence, contractual flow-down of protections, ongoing monitoring, and exit/portability plans for sub-custodians or tech vendors. |
What the custody code actually covers
Bermuda’s Digital Asset Business Act (DABA) regime treats custody as its own permission set. The custody code sits under that umbrella and focuses on how a licensed digital asset business protects client crypto in the real world. Think of it as a checklist for people, process, and technology, with accountability attached.
The themes are familiar if you’ve worked in traditional custody: segregation of client assets, strong internal controls, and clear reporting. The twist is the key material. In crypto, whoever holds the private keys holds the coins. So the code zooms in on wallet architecture, key ceremonies, recovery procedures, and the fine print around omnibus vs named segregation.
Importantly, the code also deals with dependencies. If you outsource any part of the custody stack — a sub-custodian, a wallet-as-a-service provider, cloud HSMs — you don’t outsource responsibility. The Bermuda-licensed entity stays on the hook for outcomes.
Segregation, title, and the no-surprises rule
Clients need to know two things up front: where their assets sit and what a custodian can legally do with them. The code expects client crypto to be held separately from the custodian’s own assets and for records to make beneficial ownership obvious. If omnibus wallets are used for efficiency, a reliable sub-ledger must show each client’s share at all times.
Rehypothecation is either prohibited or strictly opt-in with explicit client consent and limits. Most institutional clients won’t allow it. That’s by design — it removes a big chunk of counterparty risk. A clean legal setup makes insolvency scenarios more straightforward: client assets should not be available to the custodian’s creditors.
Pro tip: Ask the custodian to show you, in writing, how client assets are characterized under Bermuda law, how they’re recorded on the balance sheet (or not), and what the client agreement says about liens and set-off. If the language is fuzzy, assume the protections are too.
Keys, wallets, and access controls that actually hold up
This is the heart of digital asset custody. The code expects strong key management and minimal exposure to hot wallets. Cold or warm storage should cover most balances, with narrow, rate-limited hot paths for withdrawals.
Multisig and MPC
Multi-party control is not optional. Whether it’s threshold multisig on-chain or MPC at the signing layer, a single individual shouldn’t be able to move funds. Shards or keys should be split across roles and locations to cut down on insider risk. Hardware security modules are standard, and any use of cloud HSMs needs careful hardening and separation.
Wallet whitelists and policy engines
Outbound transfers should be constrained by approved address lists and policy engines. Changes to those lists are where many breaches happen, so the code leans on robust change control: maker-checker approvals, out-of-band confirmations, and clear logs.
Key ceremonies and recovery
Generating, sharding, and storing keys should follow documented ceremonies with witnesses and video or cryptographic attestations. Recovery materials must exist but shouldn’t be concentrated. Practice restores before you need them.
Good custody is mostly boring. If it sounds fancy but you can’t explain how a lost shard gets replaced without risking funds, it’s not production-ready.
Operational discipline: reconciliations, change control, and incident playbooks
Crypto moves fast, but books and records can’t lag. The code expects routine reconciliations between on-chain balances and the client ledger. Differences should be flagged fast and escalated with a root-cause trail. Automated monitoring helps, but human review still matters.
Change management covers more than wallet whitelists. It includes software upgrades, dependency changes (think: a new HSM firmware), and even policy tweaks. Every change should be authorized, tested in a lower environment, and rolled back cleanly if needed.
On incidents, the code looks for a clear chain of command, defined severity tiers, and notification timelines. You’ll need to show that you can contain a hot wallet compromise, pause risky flows, and communicate with clients and the regulator without guesswork.
Pro tip: Run a live-fire withdrawal test from cold to client weekly. It catches the subtle failures — an expired certificate, a drifted policy, an M-of-N set that now requires the one person on holiday.

Assurance, insurance, and resilience testing
Controls don’t mean much if no one checks them. The code expects independent audits of security and operations, which in practice often means frameworks like SOC 2 or ISAE 3402, plus regular penetration testing and red-teaming focused on the signing path.
Insurance isn’t a silver bullet, but it’s part of the stack. Expect the regulator to ask whether your policy actually covers the relevant risks and how exclusions map to your setup. Financial resources (capital, liquidity) also matter — you need to survive operational losses long enough to make clients whole.
Resilience testing goes beyond backups. Walk through regional outages, a stuck chain, a large protocol upgrade, or a stablecoin freeze. Then prove your business continuity plan, not just with a binder but with evidence of drills and recoveries within target RTO/RPO windows.
Using third parties: sub-custodians, outsourcing, and contracts
If you work with a sub-custodian or a wallet service, the code expects strong vendor management: due diligence at onboarding, contractual flow-down of custody requirements, ongoing monitoring, and a credible exit plan. You should have visibility into their controls and the right to audit or receive independent assurance reports.
Don’t ignore concentration risk. If your whole custody stack depends on one vendor, one cloud region, or one niche HSM model, that’s a single point of failure. Spread it out. Document it.
For recognized stablecoins specifically, Bermuda’s supervisor has begun to tie custody requirements directly into other regulated sectors. In July 2026 the Bermuda Monetary Authority published a consultation on stablecoins used in insurance, ILS, and funds, and invited comments through 30 September 2026 (Bermuda Monetary Authority (Consultation Paper)). The paper explicitly points back to the DABA Custody Code for any Bermuda-licensed custodian holding those stablecoins (Bermuda Monetary Authority (Consultation Paper), Appendix A: Custody, Safeguarding and Wallet Controls).
Stablecoins inside Bermuda structures: what changed in 2026
Stablecoins are no longer a side note for institutions. The BMA consultation notes that global stablecoin issuance exceeded $300 billion by mid‑2026 (Bermuda Monetary Authority (Consultation Paper)). When that much value sits on-chain, custody and wallet controls become system-level risks, not just operational details.
The consultation sets supervisory expectations for how Bermuda insurance entities handle recognized stablecoins. For Limited-Purpose Insurers (LPIs), the BMA says it would generally expect exposure to stay within 25 percent of statutory capital and surplus (or net assets), unless a higher level is agreed through the supervisory process (Bermuda Monetary Authority (Consultation Paper), Section XIV.A (LPIs)).
On custody, the same consultation ties recognized-stablecoin holdings back to DABA: if a Bermuda-licensed digital asset business is the custodian, it should follow the DABA Custody Code. That means the stablecoin stack must meet the same bar on segregation, keys, reconciliations, third-party oversight, and incident response (Bermuda Monetary Authority (Consultation Paper), Appendix A).
Practically, this nudges insurers and funds to ask harder questions about issuer risk, reserve attestation cadence, blacklisting controls, and freeze functions — and to document how those features interact with custody policies. A stablecoin that can be frozen at the smart-contract level needs a playbook in the incident binder, not a shrug.

Chart of total stablecoin market cap and coin breakdown (Jan–Jul 2026) showing ~ $305B total and concentration in a few issuers — useful context for why the BMA's custody and safeguarding expectations focus on stablecoin custody and segregation. — Source: CoinGecko — 2026 Q2 Crypto Industry Report (Slide, hosted on SlideShare)
How clients can assess a custodian: a quick checklist
- Show me the legal stance: client asset characterization, segregation model, and insolvency treatment in the client agreement.
- Walk me through the wallet map: hot/warm/cold split, policy engine, whitelists, and emergency controls. Prove dual control.
- Evidence of reconciliations: frequency, who signs off, and how breaks are resolved.
- Independent assurance: latest SOC 2/ISAE report scope and exceptions; recent pen test focused on the signing path.
- Insurance and financial resources: what’s covered, what’s excluded, and how you backstop operational losses.
- Key ceremonies and recovery: documented processes, last successful restore test, and shard custody locations.
- Third-party oversight: sub-custodian contracts, right-to-audit, performance SLAs, and vendor exit plans.
- Withdrawal drill: run a live test with us, end-to-end, and measure time-to-cash.
Pro tip: Ask for a sample client statement tied to specific on-chain addresses. Look for deterministic mapping and time stamps you can verify yourself.
Common mistakes that still trip firms up
- Letting hot wallets grow unchecked because client withdrawals are “temporary.” Temporary balances become permanent risk.
- Omnibus without a real sub-ledger. If a client can’t see their exact position at any time, you’ll lose trust when it matters.
- Single-region cloud dependencies for key infrastructure. Regional outages shouldn’t take you offline.
- Weak change control on whitelists and policy engines. Most high-quality heists start here, not in the HSM.
- No portability plan. If your sub-custodian halts service, how fast can you move wallets and update client disclosures?
- Ignoring asset-specific quirks. A frozen or blacklisted token needs a different incident response than a lost shard.
Frequently Asked Questions
What is Bermuda’s Digital Asset Custody Code?
It’s a rulebook under Bermuda’s DABA regime that sets concrete expectations for how licensed firms hold client crypto. It covers segregation, key management, access controls, reconciliations, incident response, third-party oversight, and assurance. It’s designed so client assets aren’t exposed to a custodian’s own risks.
Does the code allow rehypothecation of client crypto?
Only if a client explicitly agrees to it under tightly defined terms. Many institutional clients forbid it outright. The baseline assumption is client assets are not to be used for the custodian’s purposes and are protected from the custodian’s creditors.
Are MPC wallets acceptable, or does it have to be on-chain multisig?
Either can be acceptable if the implementation enforces multi-party control, uses hardened hardware, and meets the code’s standards on separation, approvals, and auditability. What matters is provable control separation and a safe recovery path.
What kinds of audits does the regulator expect?
Independent security and operations assurance is the norm. Many firms use SOC 2 or ISAE 3402, supported by targeted penetration testing and red-teaming against the signing flow. The focus is whether controls actually operate, not just how they’re written.
How are stablecoins treated in Bermuda’s institutional setups?
In July 2026, the BMA proposed guidance for recognized stablecoins used in insurance, ILS, and funds, with comments open until 30 September 2026. It ties custody of those stablecoins to DABA standards and notes that stablecoin issuance topped $300 billion by mid‑2026, reflecting their systemic weight. For LPIs, the BMA generally expects exposure within 25 percent of statutory capital and surplus unless higher levels are agreed through supervision (Bermuda Monetary Authority (Consultation Paper)).
Can a Bermuda insurer or fund use a non-Bermuda custodian?
The consultation focuses on cases where a Bermuda-licensed digital asset business is the custodian for recognized stablecoins and points to the DABA Custody Code. Using non-Bermuda custodians may be possible subject to the structure and supervisory review, but the BMA will still expect equivalent safeguards and clear oversight.
What happens if a custodian fails or there’s a major incident?
Controls around segregation, legal title, and incident response are intended to protect clients and support an orderly process. You should see pre-defined playbooks, notification protocols, backups, and portability plans to another custodian. The aim is to preserve client assets and restore access with minimal disruption.