On August 25, 2025, the Securities and Exchange Commission transmitted a proposal to the White House Office of Information and Regulatory Affairs. The document carries a Regulation Identifier Number: 3235-AN46. It is classified as "economically significant." It is also designated as "deregulatory."
That last word matters. It is not a term the SEC uses casually. Under the current administration, every rule submission must justify itself against a burden-reduction mandate. This one does. The SEC is not adding restrictions. It is removing them.
The target is the custody rule under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. The stated rationale: eliminate investor protection obligations that are "no longer necessary" from outdated provisions. The practical effect, if finalized as proposed, is a fundamental restructuring of who can hold digital assets for institutional clients.
I have spent the last eight years auditing custody architectures. I have reviewed multisignature wallet implementations, sharded key management systems, and the governance frameworks that surround them. Here is what I know: the custody question has never been a technical problem. It is a legal one. The technology has been ready since 2018. The regulatory framework has not.
This proposal may change that. Or it may not. The gap between the submission and the final rule is where the architecture gets tested.
The Context: A Rule That Failed, and the Silence That Followed
To understand what is happening now, you have to understand what happened before.
In February 2023, under Chair Gary Gensler, the SEC proposed a custody rule that would have required registered investment advisers to place client crypto assets with a narrow set of "qualified custodians": state or federally chartered banks, trust companies, SEC-registered broker-dealers, and CFTC-registered futures commission merchants.
The intent was to close what the SEC called a "gap" in investor protection. The effect was to exclude nearly every crypto-native custodian from the compliance framework. No MPC-based wallet provider. No qualified digital asset custodian that lacked a banking charter. No self-custody solution.
The industry responded with a coordinated wave of opposition. Financial institutions argued the definition was too narrow. Crypto platforms argued it was technically incoherent. Federal agencies raised jurisdictional concerns. The proposal was withdrawn.
The withdrawal was quiet. There was no press release announcing a philosophical reversal. The rule simply disappeared from the regulatory agenda. But the silence was instructive. The SEC had learned that its traditional approach to custody—designed for bearer bonds and mutual fund shares—could not be mapped onto digital assets without breaking the industry's operational model.
Now, under Chair Paul Atkins, the SEC is attempting a different approach. Instead of narrowing the definition of qualified custodian, it is broadening the entire framework. Instead of adding investor protection burdens, it is stripping them away.
The proposal's "deregulatory" designation is not incidental. It signals a deliberate policy direction. The SEC is saying: the 1940-era custody framework was not designed for programmable assets, and forcing digital assets into that framework creates more risk than it mitigates.
The Core: What the Rule Change Actually Means for Custody Architecture
Let me be precise about what is being proposed and what is not.
The proposal revises custody rules under both the Advisers Act and the Investment Company Act. The SEC has not yet published the full text. The target date for formal proposal is October 2025. But the direction is clear from the submission memo: the SEC intends to remove requirements that are "no longer necessary" for investor protection.
What are those requirements? Based on the 2023 proposal and the subsequent pushback, the likely targets include:
First, the qualified custodian definition. The 2023 proposal restricted the universe to traditional financial institutions. The new rule is expected to expand this to include state-regulated trust companies, certain non-bank custodians, and potentially qualified digital asset custodians that meet specific technical standards.
Second, the surprise examination requirement. The 2023 proposal required investment advisers to obtain written assurances from custodians that they would be subject to surprise examinations by an independent public accountant. This is operationally difficult for digital asset custodians that use distributed key management across multiple jurisdictions. The requirement may be relaxed or made proportional to the custody model.
Third, the client notification provisions. The 2023 proposal required advisers to notify clients of custody arrangements within a specific timeframe. For digital assets, where addresses change and smart contract upgrades occur, this creates notification fatigue without meaningful protection. Expect simplification.
Fourth, the segregation of assets requirement. The 2023 proposal required custodians to segregate client assets from proprietary assets. This is straightforward for fiat and traditional securities. For digital assets, it requires wallet-level segregation, which conflicts with certain pooled custody models. The new rule may permit alternative segregation methods that achieve the same outcome.
The technical implication is significant. If the qualified custodian definition expands to include technology-native custodians—those using multi-party computation, distributed validator technology, or hardware security module-backed key management—then the entire custody technology stack becomes subject to SEC oversight in a way it never has been before.
That is the trade. Broader access in exchange for technical accountability. The SEC is not abandoning the custody rule. It is redefining the architecture that qualifies.
From my audit experience, this is the right direction. I have reviewed custody systems that are more secure than any traditional bank vault. I have also reviewed custody systems that store private keys in plaintext on a server with an open SSH port. The difference is not the institution's charter. It is the engineering discipline. The SEC's 2023 approach assumed that institutional trust was a proxy for technical security. It is not.
The new approach—whatever its final form—should recognize that technical standards matter more than institutional categories. A bank can be a bad custodian. A technology company can be a good one. The rule should distinguish between them based on verifiable controls, not charter type.
The Market Signal: What the Pricing Tells Us
Markets are forward-looking. The question is how far forward they are looking.
The SEC's submission to OIRA was reported on August 25. The market reaction was muted. That is telling. If the market believed this proposal would be finalized quickly and without significant modification, custody-related stocks would have rallied hard. They did not move more than a few percentage points.
The muted reaction suggests the market has priced in roughly 30 to 50 percent of the expected benefit. There is optimism about the direction, but skepticism about the execution. That skepticism is justified.
Here is the timeline problem. The proposal is in OIRA review. That review can take 30 to 90 days. Then the SEC publishes the formal proposal. Then there is a public comment period, typically 30 to 60 days. Then the SEC must review comments, possibly revise the rule, and vote on final adoption. Then there is a compliance transition period.
Realistically, we are looking at 12 to 18 months before the rule is operational. That is if everything goes smoothly. If there is a legal challenge—and there will be one from consumer protection groups if the rule is too permissive—add another 12 months.
The market is not pricing in the timeline. It is pricing in the direction. That is the correct approach for a long-term position, but it creates a short-term risk of disappointment.
Consider the counterfactual. If the SEC's October proposal includes restrictions that mirror the 2023 rule—just with a slightly broader custodian definition—the market will read it as a failure. The "deregulatory" designation would be exposed as rhetorical cover for incremental adjustment. The downside risk is asymmetric.
What would change my assessment? Specific language that explicitly includes non-bank custodians, MPC-based solutions, and self-custody models within the qualified custodian framework. That language would be a clear signal that the SEC understands the technical landscape.
What would confirm my skepticism? Language that preserves the 2023 definition but adds a "or similar entity" clause. That is not deregulation. That is regulatory ambiguity disguised as flexibility.
The Contrarian Angle: Deregulation Is Not the Same as Good Policy
Here is the uncomfortable truth. The 2023 proposal was flawed. But the "deregulatory" response is not automatically correct. Removing investor protection burdens without replacing them with technical standards creates a different risk: a race to the bottom in custody quality.
Let me explain.
The current SEC framework, despite its flaws, imposes a baseline of accountability. Custodians must be subject to examination. They must maintain segregation. They must provide reporting. These are not arbitrary requirements. They are the infrastructure of trust in the traditional financial system.
If the SEC removes these requirements without substituting technical standards, what replaces them? Market discipline? We have seen how that works in crypto. The market did not discipline FTX. It did not discipline Celsius. It did not discipline any of the custodians that failed during the 2022 crash.
Efficiency without oversight is just faster risk.
The counter-argument is that the 2023 rule was so restrictive that it created a perverse incentive: institutions either used unregulated custodians or did not enter the market at all. That argument has merit. Regulatory overreach can push activity into darker corners.
But the solution is not simply to deregulate. It is to create a tiered framework. Custodians that meet higher technical standards—audited key management, insurance coverage, independent verification—should have broader market access. Custodians that do not meet those standards should be restricted to smaller client bases or specific asset types.
That is not what the current proposal appears to do. The "deregulatory" designation suggests the SEC is removing requirements across the board, not creating a tiered system. That is a missed opportunity.
I am not arguing for the 2023 approach. I am arguing for a third path. One that recognizes technical excellence as the primary qualification for custody, rather than institutional charter or regulatory burden. The SEC has not yet signaled whether it is taking that path.
The Ecosystem Effects: Who Wins, Who Loses, Who Adapts
The custody rule revision will not affect the entire crypto ecosystem equally. The transmission chain is specific.
At the top are the rule makers. The SEC, through this proposal, is redefining what "qualified custody" means. That definition will flow down to investment advisers, who must comply with the rule when holding client assets.
Next are the custodians themselves. Traditional banks and trust companies that have been building crypto custody capabilities will see expanded competition. Crypto-native custodians—Fireblocks, BitGo, Coinbase Custody—will see expanded market access if the definition broadens. This is the direct beneficiary group.
Below that are the investment advisers. If the rule simplifies compliance, more advisers will offer direct crypto exposure to clients. This increases demand for custody services. It also increases demand for the infrastructure that connects advisers to custodians.
Finally, there are the protocol developers. If the rule expands the qualified custodian definition to include MPC-based solutions, then protocols that offer decentralized custody—safe modules, account abstraction, smart contract wallets—become more attractive to institutional users. This could accelerate the institutional adoption of DeFi.
The biggest impact, however, is on tokenized securities. Custody is the prerequisite for institutional participation in tokenized assets. If the custody rule provides a clear compliance path for tokenized securities—including the underlying collateral and the token itself—then the RWA sector gets the regulatory clarity it has been lacking.
The rule revision is not just about custody. It is about the compliance architecture for the next phase of institutional crypto adoption.
The market has not fully priced this in. The custody rule is being treated as a narrow regulatory adjustment. It is not. It is the foundation for a broader shift in how traditional finance interacts with digital assets.
Consider the recent approval of new federal trust bank charters. These charters allow institutions to operate as qualified custodians under the existing framework. The approvals are happening now, before the rule change. That suggests institutions are positioning for the post-rule environment. They expect the rule to broaden, and they want to be ready.
This is not a speculative signal. It is a structural one. The charters are being approved because the Office of the Comptroller of the Currency and state regulators see demand. The demand is coming from institutions that want to offer crypto custody but cannot do so under the current framework.
The Governance Dimension: What This Tells Us About the SEC
The SEC is not a monolithic entity. It is a collection of offices, each with its own priorities and political dynamics. The custody rule revision reflects the priorities of the current chair, not the institution as a whole.
Paul Atkins has signaled a different approach than his predecessor. Where Gensler saw crypto as a threat requiring aggressive enforcement, Atkins sees it as an innovation requiring sensible frameworks. The custody rule is the first major test of whether that philosophical difference translates into operational change.
Governance is not a feature; it is the foundation. The SEC's internal governance will determine whether this rule revision succeeds or fails.
There are reasons to be optimistic. The proposal has been designated as "deregulatory," which means it has political support at the highest levels. The OIRA review process is rigorous, but it is also predictable. The rule has a clear RIN, a clear timeline, and a clear policy direction.
There are also reasons to be cautious. The SEC's staff has been conditioned by years of enforcement-first thinking. The proposal may be diluted during internal review. The public comment period will attract opposition from consumer protection groups. The final rule may look very different from the submission.
My assessment: the proposal has a 60 percent chance of being finalized in a form that meaningfully expands the qualified custodian definition. That is not a high-confidence bet. It is a moderate one.
What would increase my confidence? A clear statement from the SEC that technical standards—rather than institutional categories—will be the primary qualification for custodians. What would decrease my confidence? A proposal that preserves the 2023 definition with cosmetic changes.
The Risk Matrix: What Could Go Wrong
The most significant risk is expectation mismatch. The market is interpreting "deregulatory" as "pro-crypto." The SEC may interpret it as "reducing regulatory burden" in a way that still maintains significant restrictions. The gap between these interpretations is where the disappointment will come.
Second is timeline risk. The October target for the formal proposal is ambitious. OIRA review often takes longer than expected. If the proposal slips to December or January, the market will lose patience. The narrative will shift from "regulatory clarity" to "regulatory delay."
Third is legal challenge risk. Consumer protection groups have already signaled they will challenge any rule that reduces investor protections for digital assets. The challenge will likely be filed in a friendly jurisdiction—likely the D.C. Circuit or the Second Circuit. The litigation could take two to three years to resolve.
Fourth is international competition risk. The EU's Markets in Crypto-Assets Regulation (MiCA) is already in effect. Singapore has a comprehensive digital asset framework. Hong Kong is positioning itself as a crypto hub. If the U.S. takes 18 months to finalize a rule and then faces a legal challenge, other jurisdictions will have a significant head start.
In the crash, only structure survives the chaos. The structure of the U.S. regulatory process is both a strength and a weakness. It provides certainty, but it is slow.
The final risk is technical obsolescence. The custody technology landscape is evolving rapidly. MPC is becoming standard. Distributed validator technology is maturing. Account abstraction is changing how assets are held. If the SEC takes 18 months to finalize a rule based on the current technical landscape, the rule may be outdated before it takes effect.
The Opportunity: What the Rule Change Unlocks
The opportunity is not in the custody sector itself. It is in what custody enables.
If the qualified custodian definition expands, the immediate beneficiaries are the existing crypto custodians. They gain access to the $20 trillion investment adviser market. That is the direct, measurable opportunity.
The indirect opportunity is larger. Expanded custody access means more institutions can hold digital assets. More institutions holding digital assets means more demand for trading, lending, and derivatives. That demand will flow through to exchanges, prime brokers, and DeFi protocols.
The tokenized securities opportunity is the largest of all. Custody is the choke point for tokenized securities. If the custody rule provides a clear compliance path, the RWA sector gets the regulatory clarity it needs to scale. This is not a speculative narrative. It is a structural requirement.
The ledger remembers what the community forgets. The custody rule will determine which assets can be held, by whom, and under what conditions. That determination will shape the next five years of institutional crypto adoption.
The timing is favorable. The proposal comes at a moment when institutional interest in crypto is recovering. The ETF approvals of 2024 opened the door. The custody rule revision will determine whether institutions walk through it.
The risk is that the rule is too narrow. If the SEC preserves the 2023 definition with minor adjustments, the opportunity is limited. If the rule is too broad, the risk is a race to the bottom in custody quality. The optimal outcome is a tiered framework that rewards technical excellence while providing clear compliance paths.
That is not what the "deregulatory" designation suggests. But it is what the industry should advocate for during the comment period.
The Takeaway: A Structural Turning Point, Not a Market Event
This is not a market event. It is a structural turning point.
The SEC's custody rule revision is the first major regulatory action of the Atkins era. It will define the compliance architecture for institutional crypto adoption. It will determine which custodians can operate, under what standards, and with what oversight. It will shape the development of tokenized securities, the institutional adoption of DeFi, and the integration of digital assets into traditional finance.
None of this happens quickly. The proposal is in OIRA review. The formal proposal is expected in October. The comment period will follow. The final rule is likely 12 to 18 months away. Legal challenges may extend that timeline further.
The market is pricing the direction, not the timeline. That is the correct approach for long-term positioning. It is also the source of short-term risk.
My recommendation is straightforward. Watch the October proposal. Read the specific language. If the qualified custodian definition expands to include non-bank custodians and technology-native solutions, the rule is a genuine turning point. If it preserves the 2023 definition with cosmetic changes, it is a missed opportunity.
Trust the code, but verify the architecture. The code is the custody technology. The architecture is the regulatory framework. Both must work together. This proposal is the first test of whether they can.
The question is not whether the SEC will deregulate. It is whether it will regulate better. Those are different things. The industry should demand the latter.
The ledger remembers what the community forgets. We will remember what this rule actually says, not what the press release claims. The verification starts when the text is published. Until then, the architecture is still under construction.