Tokenized U.S. Treasury products represented roughly $15 billion in May 2026. It shows how quickly regulated assets are moving onto blockchain-based infrastructure. However, market growth does not reveal whether each underlying security is correctly titled, segregated, and recoverable if a custodian fails.
As explained in our pillar guide on Real-World Asset Tokenization, a token may represent direct ownership, an SPV interest, a custodial entitlement, or synthetic exposure. That distinction becomes critical when the asset behind the token is frozen, pledged, misrecorded, or trapped in an intermediary’s insolvency estate.
A wallet balance may remain intact even when the holder cannot access the underlying Treasury bill, private share, property interest, or cash reserve.
So, when the blockchain record, transfer-agent register, and custodian books disagree, which record controls, and who can recover the asset?
Custodian risk architecture is the legal, operational, and technical control system that determines whether the asset behind a token is properly owned, segregated, recorded, and recoverable. |
This article maps the legal, operational, and technical layers between the issuer, custodian, smart contract, and token holder.
What Custodian Risk Architecture Covers
Custodian risk architecture is the legal, operational, and technical system connecting a token to the asset it represents. It determines who owns the asset, where it is held, which record proves investor rights, who controls the smart contract, and how cash reaches the holder.
The architecture has four control surfaces. Asset safekeeping covers the security, cash, commodity, deed, or collateral. Legal recordkeeping covers the issuer register, transfer-agent file, fund ledger, or public title record.
Token control covers minting, burning, freezing, recovery, and forced transfers. Meanwhile, cash-flow control covers subscriptions, interest, dividends, rent, and redemptions.
Private-key security protects only token access. It cannot prove that the off-chain asset exists, is free from liens, or is legally available to investors.
How the Legal and Technical Layers Connect
Consider an allocator reviewing a token linked to U.S. Treasury bills. The wallet shows the final token balance, but several systems sit beneath it.
The Legal Layer Creates the Claim
An issuer, fund, trust, or special purpose vehicle acquires the asset and defines investor rights through offering documents. Those documents should identify the asset owner, transfer restrictions, distributions, claim priority, and treatment of default or liquidation.
A technically sound token cannot correct an incomplete asset transfer or an unclear investor agreement. Therefore, the legal structure must be established before the token is issued.
The Custody and Recordkeeping Layers Hold the Evidence
A custodian or subcustodian holds the underlying portfolio, while a transfer agent or administrator records investor interests. These records may be maintained in separately titled accounts or pooled omnibus accounts.
The blockchain can be the authoritative register where permitted by law and governing documents, form part of it, or simply instruct an off-chain register. Consequently, institutions must know which record prevails during a mismatch.
The Technical Layer Controls the Token
The smart contract records balances and enforces approved-wallet rules, holding periods, freezes, redemptions, and administrative transfers. An MPC wallet or policy engine then controls how authorized users sign transactions.
These systems usually operate in parallel.

The central risk is not always the loss of one record. Instead, several records may remain operational while showing different positions.
For example, the blockchain may show 10 million tokens in circulation while the transfer agent records 9.9 million interests. At the same time, the custodian may hold assets supporting only 9.8 million units. That difference must be identified before subscriptions, transfers, or redemptions continue.
Why Token Structure Changes the Holder’s Rights
The SEC staff’s January 28, 2026, statement separates tokenized securities into issuer-sponsored and third-party-sponsored models. It is a staff statement rather than an SEC rule, but it offers a useful framework for comparing intermediary risk.
Issuer-Sponsored Tokens
An issuer or its agent may integrate blockchain records into the master securityholder file. Under that model, a valid token transfer changes the official ownership record.
Alternatively, the token may only notify an off-chain system to update its register. Although the transaction begins on-chain, the off-chain record may remain authoritative.
This distinction affects how investors prove ownership, correct mistaken transfers, recover lost-wallet positions, and submit claims during insolvency.
Third-Party Custodial Entitlements
A third party may hold another issuer’s security and issue a token representing a direct or indirect security entitlement. The investor then depends on that intermediary’s records, account structure, financial condition, and insolvency treatment.
As explained in Main RWA Token Structures, third-party entitlements add another layer between the token holder and the underlying issuer.
The arrangement may work efficiently while markets are stable. However, during a default, investors must establish whether they own protected client property or hold a claim against the intermediary.
Synthetic Exposure
A linked security or security-based swap may track another security without giving the token holder voting, information, dividend, or property rights against the referenced issuer.
Therefore, economic exposure should not be confused with legal ownership.
Structure | Controlling record | Holder’s position | Main failure point | Evidence to review |
Issuer-sponsored token | Issuer or transfer-agent register | Directly issued security | Registry or administrator failure | Register extract and control report |
Tokenized SPV interest | SPV register and documents | Share, note, unit, or beneficial interest | Weak isolation or unclear priority | Title documents and legal opinion |
Custodial entitlement | Intermediary and custodian records | Direct or indirect entitlement | Liens, commingling, subcustody, or insolvency | Custody agreement and statements |
Synthetic token | Contract and collateral records | Payment or price exposure | Counterparty default or collateral shortfall | Contract terms and collateral reports |
Where the Architecture Can Fail Under Stress
A well-designed structure must keep working when an intermediary fails, records diverge, or administrators lose access.
Qualified Custody Does Not Settle Ownership
SEC Rule 206(4)-2 applies to registered or required-to-be-registered investment advisers that have custody of client funds or securities.
Where it applies, assets generally must be maintained with a qualified custodian in a separately named client account or an account containing only client assets. The rule also covers notices, account statements, and independent verification, subject to stated exceptions.
However, qualified-custodian status does not prove that a specific token holder owns the underlying asset. It also does not establish that the account is free from liens, that rehypothecation is prohibited, or that each subcustodian offers equivalent protection.
Institutions must still review the custody agreement and the legal relationship between the asset owner, custodian, issuer, and investor.
This is a U.S. investment-adviser custody rule, not a universal rule for every RWA issuer or tokenized product
Bankruptcy Remoteness Depends on the Documents
A smart contract cannot make an asset bankruptcy remote. Protection depends on valid asset transfers, separate accounts, limited-purpose provisions, governance controls, and enforceable agreements.
A segregated account usually provides a clearer ownership trail. By contrast, an omnibus account contains assets for several clients and relies more heavily on the custodian’s internal records.
Omnibus custody is not automatically unsafe. However, incomplete books can make it harder to trace assets and separate client property from the custodian’s estate.
Institutions should examine:
- Custodian liens
- Rights of set-off
- Asset reuse permissions
- Rehypothecation terms
- Subcustody arrangements
- Governing law
- Asset location
- Perfection of security interests
If the custodian fails, the issuer should already have procedures to pause activity, reconcile records, identify client property, appoint a replacement custodian, and distribute assets according to claim priority.
MPC Protects Authority
Multi-Party Computation divides signing power into separate key shares so the complete private key is not assembled in one place. It can also enforce approval quorums, destination rules, transaction limits, and separation of duties.
Therefore, MPC can reduce single-key compromise and unilateral insider action. It may also allow institutions to rotate key shares without changing the public wallet address.
However, MPC cannot correct a defective title, prevent off-chain commingling, or remove insolvency exposure.
Fireblocks, for example, states that its infrastructure can support custody operations while the customer controls the key shares. The technology provider does not automatically become the legal custodian of those assets.
Reconciliation Exposes Record Breakers
A token reconciliation process should compare tokens minted, burned, and outstanding with:
- Transfer-agent records
- Custodian statements
- Bank balances
- Subscriptions and redemptions
- Income distributions
- Collateral or title records
Strong controls include dual approval for minting, independent exception review, stale-data limits, circuit breakers, and tamper-evident audit histories.
Proof of reserves may confirm that an asset balance existed at one point in time. Nevertheless, it does not by itself prove ownership, segregation, absence of liabilities, or solvency.
How Institutions Should Evaluate the Full Architecture
Institutional buyers should begin with ownership rather than token features.
First, identify the legal owner of the underlying asset and the record designated as authoritative. Next, confirm how the custody account is titled, whether it is segregated or omnibus, and whether the custodian can assert liens or reuse assets.
Then trace every subcustodian and jurisdiction. Review who can mint, freeze, upgrade, recover, or force-transfer tokens. Finally, test how often records are reconciled and what happens if the custodian, transfer agent, servicer, or contract operator becomes unavailable.
BlackRock’s BUIDL structure shows why these roles must remain distinct. BlackRock manages the fund, while Securitize performs tokenization and transfer-agent-related functions, and BNY Mellon provides custody and fund-administration services. The token is part of the operating architecture. It does not replace the fund, underlying custody, or investor register.
Before allocation, institutions should request:
- Offering documents
- Custody agreement
- Legal opinion
- Account-control agreement
- Audited financial statements
- Internal-control reports
- Insurance terms
- Reconciliation policy
- Business-continuity plan
- Replacement-custodian procedure
Use this evaluation order:
Legal title → authoritative register → account segregation → insolvency treatment → reconciliation → smart-contract permissions → wallet security
Minimum investment comes from the offering terms, not token divisibility alone.
Liquidity should remain classified as restricted until executable trading depth or redemption capacity is demonstrated.
Freezing, recovery, and forced-transfer functions improve operations, but they do not establish ownership.
A token is dependable only when each legal and technical layer leads back to an identifiable, protected, and recoverable asset.
Disclaimer: This article is for educational purposes and does not constitute legal, investment, tax, or regulatory advice.
FAQs
What happens if a custodian defaults
Recovery depends on account segregation, ownership evidence, liens, subcustody, governing law, and insolvency treatment. A replacement-custodian clause may support continuity, but it cannot guarantee immediate recovery.
Does a token balance prove ownership?
Not automatically. The blockchain may be the authoritative register, part of a wider recordkeeping system, or only evidence of an entitlement maintained elsewhere.
Must tokenized securities use a qualified custodian?
Not in every structure. The answer depends on the regulated entity, asset, activity, and jurisdiction. SEC Rule 206(4)-2 applies specifically to covered investment advisers with custody, subject to its provisions and exceptions.
How are tokenized Treasuries held off chain?
A fund, SPV, or intermediary generally holds Treasury securities through established custody and book-entry systems. The token usually represents a fund share, vehicle interest, or security entitlement.
Does MPC remove custodian risk?
No. MPC strengthens signing and key management. It cannot establish legal title, prevent asset commingling, or determine how a court will treat assets during insolvency.






