MiCA’s custody provisions are part of the post-transition operating framework for authorised crypto-asset service providers in the European Union. Article 75 applies to providers that custody and administer crypto-assets on behalf of clients and sets out contractual, recordkeeping and asset-protection duties. The existence of a rule is not evidence that a particular provider meets it in practice. EUR-Lex: Regulation (EU) 2023/1114, Article 75—custody and administration
Follow the evidence
Trace how the event could reach markets, then inspect a competing explanation.
Compare explanations
Switch lenses to see what each account explains—and what remains uncertain.
MiCA gives clients a framework for checking agreements, position records and handling of assets.
MiCA gives clients a framework for checking agreements, position records and handling of assets.
A rule cannot guarantee immunity to outages, security incidents or asset-price losses.
Article 75 starts with the client relationship and records
Article 75 requires a written agreement between the custody provider and its client, describing the parties’ duties and responsibilities. It also requires the provider to maintain a register of positions opened in each client’s name. These provisions give customers and supervisors a defined record of the service, but the agreement and firm systems determine how the controls work day to day. EUR-Lex: Regulation (EU) 2023/1114, Article 75—custody and administration
The article requires a custody policy and procedures for safe custody of clients’ crypto-assets and means of access. Providers must facilitate clients’ rights attached to assets, return assets or access as soon as possible when requested, and prevent use of client assets for the provider’s own account. Client holdings must be distinguished from the provider’s own assets. EUR-Lex: Regulation (EU) 2023/1114, Article 75—custody and administration
MiCA also addresses liability for loss of crypto-assets or access where an incident attributable to the provider occurs. Article 75 contains a market-value-based limit and an exception for events beyond the provider’s control. The legal text should be read in full; this summary is not a determination of liability in an individual case. EUR-Lex: Regulation (EU) 2023/1114, Article 75—custody and administration
Translate legal duties into operational questions
Ask which legal entity holds the custody relationship and whether it is authorised for custody and administration. Read the client agreement for the asset scope, service description, custody policy, communications arrangements, security systems and fees. A general website statement about “institutional-grade custody” is less useful than a precise answer tied to the contracting entity and client agreement.
Clarify how the provider records positions, reconciles wallet balances and distinguishes customer assets from its own. Ask whether assets can be lent, pledged, rehypothecated or moved through a third party, and what the agreement says about those activities. Article 75 creates obligations; it does not mean every provider uses the same wallet architecture or that customers can inspect every ledger.
Understand the route for withdrawals and access recovery. Which steps require a provider employee, what happens during a chain outage, and how are instructions authenticated? MiCA requires an appropriate custody policy and safe-keeping procedures, while detailed implementation depends on the firm’s systems and the assets. Any assurance should be supported by current documents and a named accountable entity. EUR-Lex: Regulation (EU) 2023/1114, Article 75—custody and administration
Authorisation and segregation are controls, not insurance
A regulatory duty does not remove volatility, blockchain, cyber or counterparty risk. Segregation can make ownership and records clearer, but it cannot guarantee that a network will operate, an asset retain value or recovery be immediate after an incident. Avoid describing a MiCA-authorised provider as risk-free or implying that crypto-assets receive the same protection as a bank deposit.
For due diligence, compare the written policy with company disclosures and incident history. Check whether an auditor or assurance provider explains the scope of an attestation, which wallets or entities it covers and the snapshot date. A proof-of-reserves page may support a balance claim, but by itself may not show liabilities, legal title or every off-chain obligation.
ESMA published new MiCA Q&As in July 2026, including questions concerning authorised providers’ custody or transfer services. These interpretations can affect how firms apply the framework, so use the current regulation, ESMA material and competent-authority register. Treat this article as a reading guide, not legal advice or an endorsement of a custodian. ESMA: July 2026 MiCA Q&As on custody and transfer services
