How Do I Access My Crypto in Qualified Custody?

How do I access my crypto held in qualified custody?

To access crypto in custody, you submit a withdrawal request through your custodian's client portal or API, satisfy its authorization controls (identity verification, multi-party approval, or pre-approved address allowlisting), and wait for the custodian to settle the transaction on-chain. For a full orientation on how qualified custodians operate, see the crypto custody hub. Exact steps and settlement windows vary by custodian and asset.


What is qualified custody and why does access work differently?

Qualified custody means your digital assets are held by a regulated third party, typically a state-chartered trust company, federally chartered bank, or SEC-registered custodian, that controls the private keys on your behalf. Because the custodian holds the keys, you cannot move assets by signing a transaction yourself. Instead, every withdrawal goes through the custodian's authorization and operations layer.

This differs from self-custody, where you hold the private key and can transact directly. The tradeoff is deliberate: institutional-grade security controls, insurance coverage, and regulatory oversight in exchange for a structured access workflow.

For a detailed comparison, see qualified custody vs self-custody for crypto wealth.


How to submit a withdrawal from qualified custody

The following steps reflect common practice across institutional custodians. Your custodian's specific interface and procedures will govern; confirm details with your account representative before initiating a transfer.

  1. Log in to the client portal using multi-factor authentication (MFA). Most institutional custodians require hardware-token MFA or authenticator apps. SMS alone is generally not accepted at this tier.

  2. Navigate to the withdrawal or transfer screen for the relevant asset and account.

  3. Select or enter the destination address. Most custodians require destination addresses to be pre-approved via an allowlisting process (see below) before a withdrawal can be submitted. Ad-hoc unallowlisted addresses are typically blocked or require elevated approval.

  4. Specify the amount and asset. Review network fees, which the custodian will display or deduct from the transfer.

  5. Submit the withdrawal request. Depending on your account's governance settings, this may immediately queue for operations review or trigger an approval workflow (see authorization controls below).

  6. Complete any required authorizations. You may need to confirm via email, authenticator app, or a secondary approver depending on the threshold set in your account policy.

  7. Monitor the request status in the portal. The custodian's operations team reviews qualified withdrawals before broadcasting to the network. Once broadcast, track the on-chain transaction hash the portal provides.

  8. Confirm receipt at the destination address using a block explorer or your receiving platform.


What are address allowlisting and withdrawal authorization controls?

Address allowlisting

Allowlisting (sometimes called whitelisting) is a security control that restricts withdrawals to a pre-approved set of destination addresses. To add a new address, you typically submit it through the portal, verify ownership of the address, and wait for a custodian review period, commonly 24–72 hours, before it becomes active. This delay is intentional: it limits the damage from a compromised account credential by ensuring an attacker cannot immediately redirect funds to an unknown address.

For more on how custodians build and govern these controls, see crypto address verification policy and crypto transfer approval policy.

Multi-party authorization

Institutional accounts, particularly those held by family offices, trusts, or LLCs, commonly require more than one authorized signer to approve withdrawals above a threshold. This is a governance control, not just a security feature: it creates an audit trail and prevents unilateral movement of assets. Your custodian agreement and internal policy should document who can authorize, at what thresholds, and what happens if a primary signer is unavailable.

See crypto signer succession policy for guidance on planning for signer unavailability.


How long does it take to withdraw from qualified custody?

Settlement time depends on three layers:

Layer Typical range Notes
Custodian operations review 1 business hour – 1 business day Varies by custodian, transaction size, and risk tier. Larger or unusual withdrawals may take longer.
On-chain network confirmation Minutes – hours Depends on the asset (Bitcoin, Ethereum, etc.) and network congestion at the time of broadcast.
Receiving platform processing Varies Exchanges or counterparties may require additional confirmations before crediting funds.

Important: Custodians do not guarantee settlement times. Operational reviews, compliance holds, and network conditions can all extend the timeline. Do not commit to a settlement deadline for a third party without confirming current processing times directly with your custodian.


What security controls apply when I access custodied assets?

Beyond allowlisting and multi-party approval, institutional custodians typically employ:

  • Role-based access controls (RBAC): Different user roles (view-only, initiator, approver) limit what each person in your organization can do in the portal.
  • IP allowlisting or device enrollment: Portal access may be restricted to registered devices or IP ranges.
  • Session timeouts and re-authentication: High-value operations often require re-authentication even within an active session.
  • Out-of-band notifications: Withdrawal activity may trigger email or SMS alerts to account owners regardless of who initiated the request.
  • Custody segregation: Some custodians hold assets in segregated accounts rather than pooled, which can limit commingling of your holdings with others'. Segregation arrangements vary, confirm how your specific custodian structures accounts.

For a broader view of what to evaluate in a custodian's security posture, see crypto custody due diligence checklist and crypto custody SOC 1 and SOC 2 reports.


Related Questions

Can I access my custodied crypto at any time, including nights and weekends?

The on-chain network runs continuously, but custodian operations teams typically operate during business hours. Many institutional custodians have limited or no weekend staffing for non-emergency withdrawal reviews. If same-day or after-hours liquidity matters to your use case, ask prospective custodians about their operational availability and emergency protocols before signing a custody agreement.

What happens if I send a withdrawal to the wrong address?

Blockchain transactions are irreversible once confirmed on-chain. Before the custodian broadcasts, the operations team may catch a flagged address (for example, one that appears on sanctions lists), but a valid allowlisted address that turns out to be wrong will generally not be recoverable. This is why address allowlisting review periods exist, to slow down the process enough to catch mistakes. See what happens if I transfer crypto to the wrong address for more detail.

Do custodied assets earn staking rewards, and can I access those too?

Some institutional custodians offer staking or yield programs for eligible assets. Whether rewards are automatically compounded, paid out periodically, or held separately, and whether they are accessible the same way as principal, depends entirely on the custodian's program terms. Ask your custodian for the specific terms before relying on staking income as liquid.

What if my primary authorized signer is unavailable?

If the designated approver is incapacitated or unavailable, a withdrawal requiring their approval may be blocked. This is a key-person risk that should be addressed in your custody governance policy before it becomes an emergency. See crypto key person risk policy and crypto signer succession policy.


Sources

  • SEC, Custody of Client Assets. Investment Advisers Act Rule 206(4)-2, https://www.sec.gov/rules/final/2009/ia-2968.pdf (2009; verify current rule status)
  • Individual qualified-custodian client agreements and platform documentation (procedures vary by custodian; confirm current withdrawal, allowlisting, and authorization steps with your custodian directly)
  • Financial Industry Regulatory Authority (FINRA), digital asset custody guidance, https://www.finra.org (verify current publications)

Compliance Note

This page is for educational purposes only and does not constitute investment, legal, tax, or custodial advice. Custody procedures, security controls, settlement times, fees, and access workflows vary by custodian and are subject to change. No custodian guarantees settlement timing or uninterrupted access. Consult your custodian's current client agreement and account documentation, and engage qualified legal and financial professionals before making custody decisions.

Advisory services are provided by DAG Wealth, LLC, an SEC-registered investment adviser; DAG Wealth is a brand pending a Form ADV update. Registration does not imply a certain level of skill or training.

Disclosures

DAG Holdings Co is a holding company that does not provide investment advisory, brokerage, administrative, or insurance services to clients. DAG is not a law firm, does not provide legal or tax advice, and does not provide tax preparation services. Tax matters are handled through referrals to qualified independent tax professionals.

DAG Private Client services involve estate matters that require qualified independent counsel in the applicable jurisdiction. LLC formation, trust drafting, and estate planning services are provided in coordination with or by qualified independent legal counsel licensed in the applicable jurisdiction.

Asset protection structures, including Wyoming LLCs and trusts, do not guarantee protection against all claims, creditors, or losses. Outcomes depend on specific facts, jurisdiction, and applicable law.

Insurance products and services are offered through Xure Insurance or its affiliates.

Investment advisory services are offered exclusively through DAG Wealth, an SEC-Registered Investment Adviser (CRD No. 328627). Registration with the SEC does not imply a particular level of skill or training. Form ADV and Form CRS are available upon request or at www.adviserinfo.sec.gov.

Custody arrangements with third-party independent qualified custodians reduce certain risks but do not eliminate them.

Investing in digital assets involves risk, including the possible loss of principal. Digital assets are highly volatile and may not be suitable for all investors. Past performance is not indicative of future results.

Specific fee schedules, scope of engagement, conflicts of interest, and material business practices are disclosed in writing before engagement and in Form ADV Part 2A for the investment-advisory portion.

The information on this site is for general educational purposes and is not legal or tax advice.