The U.S. Securities and Exchange Commission has proposed a tailored federal custody framework for crypto assets held by registered investment advisers and regulated funds. The proposal would amend custody requirements under the Investment Advisers Act and Investment Company Act, creating conditional routes for advisers and funds to use state trust companies as crypto custodians and, where no qualified custodian is available, for advisers to self-custody certain client crypto assets. It also addresses adviser financial-statement audits and broker-dealer custodial services.
Self-custody under proposed Release IA-7023 would require documented due diligence, private-key protections, multi-person transaction controls, segregated on-chain addresses, annual cybersecurity reviews, independent accountant reporting, and quarterly client statements. The SEC said native bitcoin, ether, and SOL are generally outside the existing adviser custody rule for non-fund clients, while regulated funds may face broader obligations. The measures remain proposed rules, with public comments due within 60 days after publication in the Federal Register.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
The SEC proposed Release IA-7023 to create crypto-specific custody options for registered investment advisers and regulated funds, including conditional self-custody when no qualified custodian is available and a route for state trust companies to act as custodians. The proposal includes safeguarding, cybersecurity, reporting, segregation, and due-diligence requirements and is subject to public comment after Federal Register publication.
An SEC staff letter conditionally allowed advisers and funds to treat certain state trust companies as banks without an SEC staff enforcement recommendation. The relief did not change the underlying law.
The SEC withdrew its 2023 safeguarding proposal, which would have expanded the investment-adviser custody rule to all client assets, including crypto assets that were neither funds nor securities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.