Custody Architecture for Crypto Exchanges: Hot Wallets, Cold Storage, and MPC Explained

Custody Architecture for Crypto Exchanges: Hot Wallets, Cold Storage, and MPC Explained

Custody Architecture for Crypto Exchanges: Hot Wallets, Cold Storage, and MPC Explained

Every question that decides an exchange’s fate eventually runs through one room: where the keys are. 

Users ask it as “is my money safe?” Banks ask it as “how are client assets segregated?” Regulators ask it as “demonstrate your custody controls.” And attackers ask it constantly, in their own way. 

Custody architecture — how an exchange generates, stores, and uses the private keys controlling customer funds — is the least visible part of the platform and the most consequential.

This guide explains the architecture behind serious exchange custody: the wallet tiers, the key-management technologies (multi-sig, MPC, HSMs), the operational controls around them, and how the whole structure connects to the compliance and trust obligations we’ve covered across this series.

The Tier Model: Hot, Warm, and Cold

Exchange custody is organized as a temperature gradient — a deliberate trade-off between availability and attack surface.

Hot wallets are online, connected to the exchange’s systems, and used to process withdrawals in real time. Their convenience is exactly their exposure: keys that can sign automatically are keys an attacker can potentially reach. The cardinal rule of exchange custody is therefore hot wallet minimization — holding only the float needed to service expected withdrawal volume, typically a small single-digit percentage of total assets, with hard caps enforced at the system level.

Cold storage holds the majority of customer assets with keys generated and kept entirely offline — never touching an internet-connected machine. Signing a cold transaction is a deliberate, multi-person ceremony rather than an automated event, which is precisely the point: what cannot be reached remotely cannot be drained remotely.

Warm wallets sit between: online-capable but gated behind additional approvals, used to replenish hot wallets as float depletes. The replenishment flow — cold to warm to hot, with thresholds, approvals, and alerts at each hop — is where custody architecture becomes operational discipline.

The tier model’s output is a simple, powerful property: a worst-case hot-wallet compromise is a bounded, survivable loss rather than an existential one.

The Key Technologies: Multi-Sig, MPC, and HSMs

Within each tier, the question becomes how keys themselves are protected. Three technologies dominate, and they’re complements to each other as much as they are competitors.

Multi-signature (multi-sig) requires M-of-N keys to authorize a transaction — say, three of five keys held by different officers in different locations. Its strengths are conceptual simplicity and on-chain verifiability; its limitations are chain-dependence (native multi-sig support varies by blockchain) and the fact that the signing structure is visible on-chain, revealing operational patterns.

MPC (multi-party computation) achieves the same “no single point of compromise” goal cryptographically: the private key never exists whole, anywhere, at any time. Instead, key shares are distributed across parties or devices, which jointly compute signatures without ever reconstructing the key. MPC works uniformly across chains, keeps signing policies off-chain and private, and allows flexible, programmable approval policies — which is why it has become the institutional default, and the approach underpinning custody platforms like Fireblocks, which our own infrastructure integrates.

HSMs (hardware security modules) are tamper-resistant physical devices that generate and hold keys and perform signing inside certified hardware. They frequently appear in combination with the above — MPC shares held in HSMs, cold keys generated in HSM ceremonies — providing the physical-security layer beneath the cryptographic one.

The honest summary for operators: the specific technology matters less than the property it must deliver — no single person, device, or location can move customer funds alone — and the evidence that the property actually holds.

The Controls Around the Keys

Technology without process is theater. The custody controls reviewers actually probe:

Withdrawal policy enforcement. Velocity limits, address allow-listing options, and tiered approvals — small withdrawals flow automatically through screened hot-wallet paths, large ones require human maker-checker approval, and the thresholds are configuration, not convention.

Key ceremonies and recovery. Documented, witnessed procedures for key generation, share distribution, officer changes, and — the part everyone hopes never to use — recovery. An unrecoverable key protects funds from attackers and from their owners alike; institutional custody plans for both.

Segregation by design. Customer assets held structurally apart from corporate treasury, in the wallet architecture itself — the requirement regulators such as VARA make explicit, as we mapped in our VARA technology checklist.

Continuous reconciliation. An internal ledger that reconciles against on-chain holdings continuously, so the books and the chain never silently diverge — the discipline that makes proof of reserves an export rather than a project, and a recurring item in our ongoing compliance checklist.

Immutable audit trails. Every signing event, approval, and administrative change logged beyond alteration — because “who authorized this and when” is the first question after any incident and in every audit.

Why Custody Is a Platform Decision, Not a Feature

For operators launching on white label infrastructure, here’s the strategic point: custody architecture is effectively unchangeable after launch. 

Migrating live customer funds between custody models is among the riskiest operations an exchange can perform — so the architecture you launch with is, practically, the architecture you live with. That makes custody one of the few genuinely irreversible platform-selection decisions, worth more diligence than any feature comparison.

Questions to put to any provider (alongside our broader buyer’s guide): 

  • What is the hot/cold split and how is the hot cap enforced? 

  • MPC, multi-sig, HSM — and in what combination? 

  • Who holds shares, and can the operator’s own officers participate in approvals? 

  • What do the key ceremony and recovery procedures look like — documented where? 

  • Has the custody architecture passed an independent audit, and can we see the attestation? 

  • How is customer/corporate segregation implemented at the wallet level? 

  • And what does the platform export when a regulator or bank asks for evidence of all of the above?

Custody You Can Prove

The through-line of this series is that modern exchange requirements converge — and custody is where they converge hardest. 

The same architecture that survives an attacker satisfies the regulator’s segregation requirement, answers the bank’s due-diligence questionnaire, and makes independent verification possible. 

BTSE Enterprise Solutions builds its white label exchanges on exactly that architecture: tiered hot/cold custody with enforced caps, MPC-based key management with Fireblocks integration, maker-checker withdrawal controls, structural customer-asset segregation, and continuously reconciling ledgers — these are inherited by every operator on the platform from day one.

Choosing the custody architecture your exchange will live with? Talk to our team and we’ll walk through the model — keys, ceremonies, controls, and the evidence trail.

For the enterprise wallet decision—custody model, provider diligence, and implementation options—read our White Label Crypto Wallet guide.

See how BTSE Solutions can transform your business.

One simple step is all it takes to launch your digital asset business.

Fill out the form on the right and we’ll be in touch fast.

Request a demo

Copyright © 2025 btse.com

All rights reserved.

Privacy policy

Terms & Conditions

See how BTSE Solutions can transform your business.

One simple step is all it takes to launch your digital asset business.

Fill out the form on the right and we’ll be in touch fast.

Request a demo

Copyright © 2025 btse.com

All rights reserved.

Privacy policy

Terms & Conditions

See how BTSE Solutions can transform your business.

One simple step is all it takes to launch your digital asset business. Request a demo and we’ll be in touch fast.

Copyright © 2025 btse.com

All rights reserved.

Privacy policy

Terms & Conditions

See how BTSE Solutions can transform your business.

One simple step is all it takes to launch your digital asset business.


Fill out the form on the right and we’ll be in touch fast.

Request a demo

Copyright © 2025 btse.com

All rights reserved.

Privacy policy

Terms & Conditions