Crypto custody is often described as a storage problem. That framing is too narrow for a market in which a private key can move an asset instantly, a protocol change can alter operating conditions, and a compromised interface can defeat an otherwise sound approval process.

The more useful question is not whether an institution uses cold storage. It is whether the full chain of controls can prevent an unauthorized transfer, detect a suspicious one, and preserve access when the network or the custodian is under stress.

That distinction matters in a market where the ten-asset snapshot tracked for this post represented about $2.11 trillion in combined market value at 02:07:49 UTC on August 24, 2026. Bitcoin represented about 73.0% of that basket and Bitcoin plus Ethereum represented about 86.9%. The figures describe concentration, not safety. They do show why a failure in one custody process can matter far beyond a single wallet.

Methodology keeps security claims in perspective

This analysis uses two different evidence sets. The market snapshot comes from a live quote feed covering BTC, ETH, SOL, XRP, BNB, DOGE, ADA, AVAX, LINK, and SUI. Prices, daily percentage changes, and market capitalizations were captured between 02:05:05 and 02:07:49 UTC on August 24, 2026. The combined value and concentration figures are simple sums and ratios from that snapshot.

The security evidence comes from primary-source disclosures. Bybit’s H1 2026 Risk & Security Report covers January 1 through June 15, 2026 and reports the exchange’s own operational metrics. The SEC’s December 2025 staff statement sets out the controls its Trading and Markets staff described for broker-dealers that custody crypto asset securities. The SEC’s August 18, 2026 proposal, titled Regulation Crypto Assets, is relevant because broader market access increases the importance of clear controls and investor disclosures.

These sources are not interchangeable. Bybit’s metrics are self-reported and should not be read as a ranking of exchanges. The SEC custody statement is a staff position, not a new rule, and says it creates no new legal obligations. The goal is therefore not to declare a provider safe. It is to identify the controls that an analyst should be able to test.

Custody risk is a chain of control points

A custody system has at least four linked control points.

First is authorization. The custodian must protect private keys from theft, loss, unauthorized use, and accidental use. It must also prevent a customer, affiliate, or other third party from transferring assets without the custodian’s authorization. The SEC staff statement places these expectations at the center of its discussion of crypto asset securities custody. Read the full SEC custody statement.

Second is transaction review. A valid signature does not automatically make a transfer legitimate. A robust process checks the destination, amount, asset, timing, device, user behavior, and surrounding on-chain activity before releasing funds. This is where speed and judgment have to coexist. A control that approves everything quickly is not a strong control, while a control that blocks every unusual action is not a workable operating model.

Third is network and contract assessment. The asset may be held securely while the network or a critical smart contract is exposed to a material weakness. The SEC staff statement calls for documented reviews of the relevant distributed ledger technology, governance, protocol changes, smart contracts, applications, performance, scalability, resilience, and security. In plain language, custody teams need to understand the system on which the asset depends.

Fourth is continuity. A custody plan should specify what happens after a blockchain malfunction, a 51% attack, a hard fork, an airdrop, a legal freeze order, or the failure of the custodian itself. The ability to access an asset during normal operations is not enough. A serious process also addresses transfer to a trustee, receiver, liquidator, or another appropriate party if the firm winds down.

Together, these points move the discussion from “where are the coins stored?” to “how does the system behave under pressure?”

Operational metrics are useful when their denominators are clear

Bybit’s August 18 report offers a useful example of the new security language. For the first half of 2026 through June 15, Bybit reported more than 30,000 suspicious withdrawal requests intercepted, nearly 20,000 users protected from potential losses, and more than $700 million in potential user losses intercepted. It also reported an average initial risk review time of 4.7 minutes, with 95% of initial reviews completed within 10 minutes.

The report says its monitoring covered 100% of business-relevant on-chain activity, including listed token contracts, ecosystem contracts, and the exchange’s cold, warm, and hot wallets. It reported that more than 100,000 security alerts received AI-assisted analysis, that approximately $212 million in potential fraud-linked on-chain funds were identified, and that more than 10,000 malicious addresses were blacklisted. Bybit also said it handled ten listed-token security incidents with zero resulting platform losses.

Those figures are valuable because they describe actions, not just intentions. They are also easy to misuse. “Nearly 20,000 users” and “more than 30,000 suspicious withdrawal requests” do not share the same denominator, so dividing one by the other would create a false protection rate. Likewise, “100% coverage” describes the scope of a monitoring program, not the probability that an attack will be detected or stopped.

Bybit itself cautions that the figures are based on internal systems, are self-reported, and should not be interpreted as a guarantee of future performance or a comparative exchange ranking. That caveat is not a weakness in the disclosure. It is a reminder to pair operational metrics with independent testing, incident history, control design, and evidence of remediation. Read the full Bybit H1 2026 security report.

A worked example separates exposure from control quality

Consider the live market snapshot first. The tracked basket had a combined market capitalization of about $2.11 trillion. Bitcoin’s market capitalization was about $1.54 trillion, while Ethereum’s was about $293.7 billion. Bitcoin therefore made up about 73.0% of the basket, and Bitcoin plus Ethereum made up about 86.9%.

The calculation is simple. Add the market capitalizations of the ten assets. Divide Bitcoin’s market capitalization by that total to get its basket share. Add Bitcoin and Ethereum together and divide by the same total to get the two-asset share. This is an exposure measure. It is not a custody score, a volatility forecast, or a claim that larger assets are safer.

Now apply a separate control test to a hypothetical $10 million digital asset mandate. The analyst tests four controls and gives each one equal weight:

1. Private-key access is governed by documented authorization and separation of duties.

2. The relevant networks and smart contracts have a documented, current risk assessment.

3. Withdrawals are screened with real-time behavioral and on-chain monitoring.

4. The custodian has a tested disruption and wind-down plan.

If three controls pass and one is missing, the control coverage is 75%. That result does not mean the portfolio has a 25% chance of loss. It means one of four tested control categories remains unverified. The missing category should drive the next diligence request, especially if it concerns key access or continuity.

This two-part example is the point. Market concentration tells an allocator where exposure is concentrated. Control testing tells an allocator how that exposure is governed. A large market capitalization can increase the consequence of a custody failure without telling us whether the custodian’s process is strong.

What the data does and does not tell us

The data tells us that custody is becoming an operating discipline with measurable inputs: review time, monitoring coverage, alert volume, response sequence, key controls, network assessments, and continuity arrangements. It also tells us that regulators are focusing on the same practical questions. The SEC’s custody statement discusses private-key protection, distributed-ledger assessment, material security or operational weaknesses, and plans for disruptions such as forks or attacks.

The SEC’s August 18 proposal would create a tailored offering regime for certain investment contracts involving crypto assets. It proposes a one-time exemption for offerings up to $5 million over a four-year period and another exemption for offerings up to $75 million in each 12-month period, alongside narrative disclosures and, for the larger exemption, financial statements and ongoing reporting. The public comment period is set to remain open for 60 days after publication in the Federal Register. The details are in the SEC Regulation Crypto Assets proposal.

The data does not tell us that an exchange with fast reviews will prevent every loss. It does not prove that an asset with a mature network has no smart-contract or governance risk. It does not turn self-reported controls into independent assurance. And it does not make a custody decision for an investor whose legal, operational, and liquidity needs may be different.

Security quality will shape market structure

As digital asset products reach more institutions, custody controls become part of market structure. Key management influences settlement. Network assessment influences which assets can be supported. Monitoring influences whether liquidity can move during a crisis. Continuity planning influences whether customer assets remain accessible when a firm, protocol, or jurisdiction changes conditions.

This is also why regulation and security cannot be treated as separate tracks. The SEC’s proposed framework may affect how assets are offered and reported, while the SEC staff’s custody discussion shows the operational detail required once a regulated intermediary takes responsibility for possession. A larger market needs both clear rules and controls that can be audited in practice.

For allocators, the next diligence meeting should include specific requests. Ask for the approval path for a high-value withdrawal. Ask who can change a transaction policy and how that change is logged. Ask when the network and smart-contract assessment was last refreshed. Ask how the firm handles a fork, freeze order, outage, or wind-down. Finally, ask which metrics are independently tested and which are management reports.

Presolt helps turn market signals into decisions

Presolt brings market data and risk context into a single research workflow so investors can separate exposure, liquidity, and operational risk instead of treating them as one headline. Explore the platform at Presolt.com.

Compliance disclaimer

This post is for informational and educational purposes only. It is not investment advice, a recommendation, an offer, or a solicitation to buy or sell any digital asset or financial instrument. Digital assets involve substantial risk, including loss of principal, custody failure, cyber risk, smart-contract risk, liquidity risk, regulatory risk, and operational risk. Market data may be delayed, incomplete, or subject to change. Past performance does not guarantee future results. Consult qualified legal, tax, and financial professionals before making decisions.