Custody is the question: why who controls the keys decides the licence
A crypto wallet is not one thing in law. What matters is who can move the assets, and what else the software does. In each of the five jurisdictions we cover (the European Union, the United Kingdom, Switzerland, the United States and Canada), the main licensing line is drawn at custody: control of the user's assets, or of the keys that move them. This piece sets out the test, how each jurisdiction words it, and the designs that make the answer hard.
By Sergio Maldonado Elvira — Founder & Principal Attorney • CIPP/E · CIPP/US · CIPT · FIP
Law stated as of September 28, 2026. General information, not advice on any product.
Key Considerations
- →Who can move or block the assets: alone, jointly, or never
- →How five jurisdictions word the custody test
- →Shared control, key recovery and embedded wallets
- →Each built-in feature is a separate question
Six kinds of wallet, one question
The same word covers very different products. A non-custodial software wallet is an app or browser extension where the user alone holds the private key. A hardware wallet is a device that stores keys offline and signs transactions. A custodial wallet is one where the provider holds the keys or can move the assets for the user, as with a wallet hosted by an exchange. Shared-control wallets split the keys, through multi-party computation or multiple signatures. Smart-contract wallets place the assets under on-chain logic, often with recovery guardians, session keys or spending limits. Embedded wallets are infrastructure supplied to another business to place in its own app, and the keys may sit with the infrastructure provider, the business or the end user. The question that sorts them is the same each time: can the provider move or block the user's assets alone, jointly with others, or never? A provider that never holds or can rebuild the user's keys, and cannot move or block the assets, is generally outside the custody trigger. That is our reading of the texts below, which use different words for the same idea.
The European Union and the United Kingdom
Under the Markets in Crypto-Assets Regulation (MiCA), custody is "the safekeeping or controlling, on behalf of clients, of crypto-assets or of the means of access to such crypto-assets, where applicable in the form of private cryptographic keys" (Art. 3(1)(17)). Recital 83 adds: "Hardware or software providers of non-custodial wallets should not fall within the scope of this Regulation." In the United Kingdom, the rule in force is registration under the Money Laundering Regulations 2017. A custodian wallet provider is a business that provides services "to safeguard, or to safeguard and administer" cryptoassets "on behalf of its customers", or private cryptographic keys on behalf of its customers "in order to hold, store and transfer cryptoassets" (reg. 14A(2)). There is no express carve-out for non-custodial wallets. The conclusion that a provider which never holds keys or assets is outside rests on the words "safeguard" and "on behalf of its customers".
Switzerland, the United States and Canada
The Swiss financial regulator, FINMA, asks whether the provider has power of disposal. In its published position, a provider of non-custodial wallets has neither legal nor actual power of disposal over third-party assets, because the client alone has access to the private keys, and so is not subject to the Anti-Money Laundering Act; a provider that holds clients' assets in its own wallets and controls the keys is. In the United States, FinCEN's 2019 guidance says the treatment of a wallet intermediary "depends on four criteria: (a) who owns the value; (b) where the value is stored; (c) whether the owner interacts directly with the payment system where the CVC runs; and, (d) whether the person acting as intermediary has total independent control over the value." Hosted wallet providers are "account-based money transmitters". In Canada, the federal test turns on activity: registration with FINTRAC applies to dealing in virtual currency, which covers exchange and transfer services, and FINTRAC has published no text by wallet type. For securities law, the Canadian Securities Administrators have said that where a platform delivers the crypto asset immediately to a wallet over which it has no control, securities legislation generally does not apply (Staff Notice 21-327).
SourcesFINMA, list of crypto services·FinCEN FIN-2019-G001·FINTRAC, money services businesses·CSA Staff Notice 21-327
Where the answer gets hard: shared control
Multi-party computation and multi-signature designs split control between the provider and the user, or among several parties. The question becomes whether the provider can cause a transfer on its own, or can on its own prevent one. A provider that holds a share sufficient to move or block the assets is likely to be treated as a custodian; a co-signer that cannot act alone and cannot deny the user access is closer to a non-custodial provider. FinCEN's guidance is the most explicit text on the point: "If the multiple-signature wallet provider restricts its role to creating un-hosted wallets that require adding a second authorization key to the wallet owner's private key in order to validate and complete transactions, the provider is not a money transmitter because it does not accept and transmit value." The same guidance adds that a provider which "maintains total independent control of the value" is a money transmitter. Elsewhere, the answer is an application of the general test to the facts. FINMA's guidance of January 12, 2026 on the custody of crypto-based assets does not address multi-party computation, multiple signatures or non-custodial software.
Recovery, smart-contract and embedded wallets
A recovery mechanism deserves close attention. If the provider, its guardians or its backup service can rebuild or reset the user's key, the provider may be able to regain control of the assets, and a product that is non-custodial in name may be custodial in substance. The same reasoning applies to smart-contract wallets: recovery guardians and session keys can shift effective control, while a paymaster that sponsors transaction fees need not touch the assets at all. For embedded wallets, look through to who ends up controlling the keys. An infrastructure provider that holds or can rebuild keys for end users is likely to be custodial; a software kit that generates keys held only by the end user is closer to software. In Canada, for example, our reading is that a provider holding recovery, upgrade or co-signer keys that let it move a client's virtual currency is likely to be performing a transfer service, and so dealing in virtual currency.
Custody is the first question, not the last
A wallet that is only a key store may be out of scope while a feature added to it is in scope. Each built-in feature is analysed on its own, and the question is who performs it: the wallet provider, or a third party that the wallet only displays. Swaps run by the provider are an exchange service; in the United Kingdom, exchanging one cryptoasset for another is itself a registrable activity (reg. 14A(1)). Fiat on-ramps and off-ramps bring in exchange rules and, for the money side, payment rules. Staking may be a simple link to a protocol or a custodial service, and its treatment is contested. Lending and yield products usually fall under separate regimes. Some rules apply whatever the custody answer. OFAC's guidance states that "sanctions compliance obligations apply equally to transactions involving virtual currencies and those involving traditional fiat currencies", and it names wallet providers among the industry participants it addresses. The app stores also draw their own lines. As seen on September 28, 2026, Google Play's policy states that "Non-custodial wallets are out of scope of the Cryptocurrency Exchanges and Software Wallets policy", while Apple's guideline 3.1.5(b) addresses wallets generally: "Apps may facilitate virtual currency storage, provided they are offered by developers enrolled as an organization."
SourcesMLR 2017 reg. 14A·OFAC virtual currency guidance (2021)·Google Play policy·Apple App Review Guidelines
What is settled and what is not
Settled, in all five jurisdictions: a provider that holds users' keys, or can move their assets on its own, is within the custody or money-transmission rules and must be licensed, authorised or registered as each jurisdiction requires. Not settled: whether a purely non-custodial software wallet stays outside the United Kingdom's new safeguarding activity when it commences on October 25, 2027, which turns on the final wording and on the FCA's consultation on perimeter guidance (CP26/13); how genuinely decentralised deployments are treated in the United States; and how shared-control designs are treated anywhere, which remains a question of fact.
SourcesSI 2026/102·FCA CP26/13
Six questions to answer before building
Who can move the assets: alone, jointly, or never? Does the provider receive, hold or transmit value or orders? Which built-in features exist, and who performs each? Where are the users, and how are they reached? What does the revenue model show? Spreads on swaps, custody fees and staking commissions often reveal the regulated activity a product really performs. And can anyone other than the user rebuild or reset the key? The answers decide which rules apply, and in which jurisdictions.
A question about your own product?
The answer depends on the facts of the product. The crypto and digital-assets practice page explains how we work and how an engagement starts.
Crypto and digital assets