Regulations

Swiss Crypto Custody Rules in 2026: Segregation, Insolvency and Custodian Risk

SIX Group H1 2026 income hit CHF 806.6m as custody surged. Swiss rules on segregation, insolvency and cross-border risk are shifting under new EU measures.

Swiss Crypto Custody Rules in 2026: Segregation, Insolvency and Custodian Risk

Swiss crypto custody has grown up fast. Banks offer vault-like services. Fintechs pitch nimble key management. Family offices just want clean segregation and quick withdrawals. The hard questions land in the same place: what happens to your coins if the custodian fails, and how do Swiss rules try to protect you?

This piece walks through how segregation actually works in Switzerland, what insolvency looks like in practice, and where custodian risk still lives. We will also flag new cross-border frictions from the EU that can bleed into Swiss setups, especially for clients served out of Zurich but domiciled in the bloc.

One backdrop worth noting: institutional custody demand has been strong. SIX Group said its Securities Services unit delivered a very strong performance in H1 2026, supported by high assets under custody, with net operating income at CHF 806.6 million (SIX Group media release / Interim Report 2026). That momentum makes the legal plumbing matter even more.

Point Details
Segregation is the anchor Swiss practice expects client crypto to be held off balance sheet with wallet and ledger segregation that allows timely return to clients.
Insolvency rights hinge on control and records Your ability to claim coins directly depends on legal terms, key control, and the custodian’s books and wallet mapping.
Omnibus vs segregated wallets Omnibus is cheaper but creates pooling risk and pro rata shortfall sharing. Segregated wallets cost more but simplify asset return.
Staking and yield features change risk Delegation, rehypothecation, or on-chain activity can alter legal treatment and increase loss or clawback risk.
EU pressure is rising ESMA launched a CSA on operational resilience of custody, and new EU restrictive-measures rules extend prohibitions to CASPs, affecting cross-border Swiss providers.
Operational resilience is now a headline Key management, cold-warm-hot tiers, and independent controls need real evidence like SOC/ISAE reports, not slideware.

What Swiss law actually says about custody

Switzerland is not the EU, and it shows in the way rules are framed. Instead of a single crypto law, crypto custody gets stitched into banking and financial market regulation, private law concepts around ownership and segregation, and FINMA practice.

Banks vs non-banks

Swiss banks and securities firms that provide crypto custody sit under the Banking Act and related ordinances. They follow strict segregation, capital, operational risk and audit standards. Several fully licensed banks now custody crypto alongside traditional assets.

Non-bank custodians can operate too, but licensing and activity boundaries matter. Holding client crypto off balance sheet with clear segregation and without using it for own account is a recurring theme. Start adding leverage, deposits, or credit risk, and you creep into banking territory. FINMA will look at how the service is structured, not what you call it.

Off balance sheet is the goal

When client crypto is truly off balance sheet, the client should not be an unsecured creditor if the custodian fails. That means the provider’s records and wallet architecture must let an insolvency administrator identify and return assets to clients. If coins are mixed without accurate mapping, expect delays and possible shortfalls shared pro rata.

Pro tip: Ask your custodian to show you where, in their audited financials and notes, client crypto sits. Off balance sheet is not a slogan. It must tie to an accounting policy and a control report.

Segregation in practice: how wallets are structured

Segregation is not one thing. It is a set of choices that trade simplicity, cost and privacy against operational friction.

Model How it works Pros Cons When it fits
Omnibus pooled Client coins pooled per asset in a shared wallet or cluster, tracked internally by the custodian’s ledger. Low cost, simple funding, efficient rebalancing. Shortfall shared pro rata, more forensic work in insolvency, on-chain transparency issues. Retail or low-balance accounts where fees matter more than legal isolation.
Segregated sub-wallets Each client has a dedicated address or deterministic branch, still controlled by the custodian. Cleaner legal mapping, faster asset return, better AML traceability. Higher cost, more key material to manage, possible privacy leakage. Family offices, funds, corporates with audit needs.
Dedicated vault Completely separate cold wallet set per client, often with bespoke quorum and address space. Strongest separation and governance, easiest segregation in failure. Highest fees, slower access, more coordination for movements. High value, low velocity mandates, treasuries, long-term holdings.

Two more levers sit underneath all of this: key management and environment. Custodians mix hardware security modules, multi party computation, and tiered cold-warm-hot stacks to meet different latency and risk profiles. The end state you want is simple to say and hard to achieve: assets mapped cleanly to clients, and keys governed so no single insider or compromise can move funds.

If your Swiss custodian fails: how the return of assets should work

This is the uncomfortable bit. You do not want to discover the legal mechanics during an insolvency notice.

  1. Stay-or-go decision: A regulator or court-appointed administrator steps in. Client assets are identified and ringfenced in the estate.
  2. Segregation assessment: The administrator relies on the custodian’s books, wallet maps, and controls testing to decide which assets can be delivered back directly and which are part of the bankruptcy mass.
  3. Shortfalls, if any: If assets are pooled and a hole exists, clients with claims to that pool may share losses pro rata. That is the classic pooled custody risk.
  4. Timing and costs: Even with good records, expect procedural delay, KYC refresh, and operational fees deducted as allowed by law.
  5. Disputes: Forks, airdrops, staking rewards, and tokens held via smart contracts may trigger specific determinations about who bears which risks.

The practical lesson is boring and vital. The quality of segregation you pay for upstream drives how fast and complete your recovery looks downstream.

Pro tip: Ask for the custodian’s latest insolvency playbook and the name of the appointed back‑up administrator. If that draws a blank stare, treat it as a red flag.

Cross-border friction: EU pressure that touches Swiss custody

Even if your custodian is Swiss, your risk is not sealed at the border. Two fresh moves from the EU matter.

  • Operational resilience scrutiny: In July 2026, ESMA launched a Common Supervisory Action on the digital operational resilience of crypto custodians and other CASPs, with national authorities reviewing a risk-based sample from late 2026 through mid 2027 (ESMA). Swiss firms serving EU clients or running EU branches will feel this, directly or through client due diligence.
  • Restrictive-measures expansion: Also in July 2026, the Council adopted Decision (CFSP) 2026/1849. From 25 August 2026, prohibitions extend to any legal person providing other crypto-asset services in defined contexts. That is not MiCA, but it changes the sanction perimeter and can hit Swiss custodians with EU touchpoints (EUR-Lex).

Layer that with normal MiCA onboarding expectations for EU institutions, and Swiss providers will keep tightening segregation, incident response, and reporting to satisfy counterparties. None of this is a reason to avoid Switzerland. It is a reminder that cross-border means dual compliance, not regulatory arbitrage.

A practical due diligence checklist for Swiss crypto custody

Here is a straight list of the questions that actually move risk. If your provider answers well, you have a baseline. If not, shop around.

  • Wallet model: Omnibus, segregated, or dedicated? Show how that maps to the general ledger and on-chain addresses.
  • Off balance sheet treatment: Where is this disclosed in financials? Do you have an ISAE 3402 or SOC 1 Type II report covering reconciliation and segregation controls?
  • Key governance: HSM or MPC? What are quorum thresholds, dual control, and emergency procedures? Who holds shards and where?
  • Tiering and latency: Cold, warm, hot split. Who approves movements between tiers? How many transactions hit hot daily?
  • Cyber and DDoS: Evidence of red team tests, incident response drills, and time to revoke compromised keys or sessions.
  • Insurance: Crime or specie policies in force. Named insured vs blanket. What exclusions apply to smart contract loss or social engineering?
  • Staking and rehypothecation: Are client assets ever delegated, lent, or used in liquidity programs? If yes, how do legal terms and risk disclosures change?
  • Forks, airdrops, and unsupported chains: Who decides support and on what timeline? What happens to value you cannot access?
  • Withdrawal SLAs: Maximum time from instruction to settlement across tiers, and who can pause withdrawals.
  • Business continuity: Geography of data and key shards, recovery time objective, and tested failover.
  • Regulatory scope: Which FINMA license and what permissions? Any EU registrations or branches subject to local oversight?

Isolation Switch Cuts Custodian Risk

Technology and operational risk you should not wave away

Custody is now a software and process business as much as a legal one. The weak links are familiar: misconfigured HSMs, poorly implemented MPC, and humans with admin rights they should not have.

MPC is not magic

Multi party computation spreads risk, but it is not a free pass. You still need change management, shard rotation, and a way to detect rogue signers. Ask for a copy of the threat model that matches their MPC setup.

Cold is colder when documented

Real cold storage is disconnected, physically controlled, and surprisingly bureaucratic. Access ceremonies with named roles, offsite backups, and tamper-evident materials matter. If the custodian cannot show ceremony logs and attendee attestations, assume the process is theoretical.

Resilience is being tested

EU supervisors are explicitly probing digital operational resilience for custody through the ESMA CSA from H2 2026 to H1 2027, which will raise the bar for evidence, not just intentions (ESMA). Even if your custodian is Swiss only, expect clients to ask for similar proof.

Staking, DeFi, and rehypothecation change the legal picture

Many Swiss custodians offer staking, or they integrate with DeFi protocols for yield. The legal and operational risk jumps when assets leave a static vault.

  • Slashing and downtime: If the validator mishandles operations, who eats the slashing? Some terms push that to clients. Others cover it up to a cap.
  • Smart contract risk: Once tokens are in an on-chain contract, loss paths multiply. Insurance often excludes this.
  • Title and use: If assets are delegated, lent, or otherwise encumbered, segregation and insolvency rights can blur. You may end up with a claim, not a clean separation right.
  • Tax and accounting: Rewards classification varies by canton and foreign jurisdiction. Your auditor will care about timing and recognition.

Pro tip: Treat staking like a different product. Demand a fresh risk disclosure and a standalone custody schedule in the contract.

Insurance, audits, and reporting that actually help

Insurance does not fix bad controls, but it is a useful signal. Ask for policy letters that name your custodian and specify covered assets and limits. Crime and specie policies are common. Exclusions are where the bodies are buried.

Independent control reports are stronger than marketing decks. ISAE 3402 or SOC 1 Type II looks at financial reporting controls like reconciliation. SOC 2 looks at security, availability, confidentiality, and privacy. Both are useful. Read them, not just the cover page.

Finally, ask for operational reporting. Daily or weekly reconciliation summaries, exception logs, and a register of pending withdrawals are far more practical than a quarterly webinar.

One last macro note. The Swiss market infrastructure is busy. SIX’s securities services arm highlighted strength in assets under custody alongside robust H1 2026 income, underscoring the institutionalization trend (SIX Group media release / Interim Report 2026). That momentum is why legal hygiene is not optional anymore.

Frequently Asked Questions

Are client crypto assets at a Swiss bank covered by depositor protection?

No. Depositor protection applies to cash deposits. Crypto held in custody is typically not a deposit. The protection you want is segregation and off balance sheet treatment, not deposit insurance.

Does a segregated wallet guarantee full recovery in insolvency?

It improves your odds but does not guarantee it. You still depend on correct records, access to keys, and the absence of operational losses or hacks. Segregation narrows the paths to loss and speeds up return.

How do the new EU restrictive-measures rules affect a Swiss custodian?

From 25 August 2026, prohibitions under Council Decision 2026/1849 extend to entities providing other crypto-asset services in specified contexts. A Swiss custodian with EU clients or activities may need to tighten screening and possibly wind down certain relationships.

What is the ESMA CSA on custody and why should I care?

It is a coordinated supervisory review of the operational resilience of EU crypto custodians running from H2 2026 to H1 2027. If your Swiss provider has EU operations or clients subject to EU rules, this will raise evidence demands around security, continuity, and incident response.

Is an omnibus wallet ever acceptable for institutions?

Yes, if the pool is well governed and small enough that reconciliation is tight. Many institutions still prefer segregated sub-wallets for legal clarity and faster asset return.

Do staking rewards belong to the client or the custodian?

It depends on the contract. Some custodians pass through rewards net of fees. Others sweep and allocate later. Read the custody schedule and the staking annex. This can affect your tax position and your rights in a failure.

What documents should I request before onboarding?

License details, financial statements, ISAE or SOC reports, insurance certificates, a segregation memo that maps wallets to the ledger, and the insolvency playbook with contact details for the back-up administrator.

Investment Disclaimer

Share this story

X LinkedIn

Related Stories