What the banking regulator actually decided. In July 2020 the OCC issued Interpretive Letter 1170, concluding that "a national bank may provide these cryptocurrency custody services on behalf of customers, including by holding the unique cryptographic keys associated with cryptocurrency". Its reasoning is worth knowing because it is deliberately unexciting: safekeeping is among the oldest bank powers, the OCC had already found that a bank may escrow encryption keys because "a key escrow service is a functional equivalent to physical safekeeping", and holding a private key is "an electronic corollary of these traditional safekeeping activities". The letter also records that "in most, if not all, circumstances, providing custody for cryptocurrency will not entail any physical possession of the cryptocurrency"; a bank holding crypto is taking possession of the access keys.
Two distinctions inside that letter matter to a customer. The first is fiduciary against non-fiduciary. A bank may provide custody in either capacity; a bank holding crypto as a fiduciary, "such as a trustee, an executor of a will, an administrator of an estate, a receiver, or as an investment advisor", may manage the asset as it manages other fiduciary assets and is subject to the fiduciary-activities regulations, while non-fiduciary custody "would essentially provide safekeeping for the cryptographic key". The second is the model. The letter describes banks that "offer to store copies of their customers' private keys while permitting the customer to retain their own copy", which it likens to traditional safekeeping and which leaves the customer able to move the asset, and banks that "permit customers to transfer their cryptocurrencies directly to control of the bank, thereby generating new private keys which would be held by the institution on behalf of the customer", which it likens to traditional custody and which does not. Same service name, different answer to who can move the asset tomorrow.
In March 2025 the OCC published Interpretive Letter 1183, which rescinded Interpretive Letter 1179 and with it the supervisory-nonobjection process that had required a bank to clear these activities in advance, while reaffirming that the custody, stablecoin and node-verification activities in the 2020 and 2021 letters remain permissible. The accompanying news release states that the OCC "also withdrew its participation in the joint statement on crypto-asset risks to banking organizations and the joint statement on liquidity risks to banking organizations resulting from crypto-asset market vulnerabilities". The practical effect is procedural rather than substantive: the activity was already permissible, and the step in front of it is gone.
The broker-dealer route, and why it cannot be relied on as it stands. In 2021 the Commission published a statement on the custody of digital asset securities by what it called special purpose broker-dealers, setting out circumstances in which such a firm would not face an enforcement action on the basis that it deemed itself to have possession or control of customer digital asset securities under the customer protection rule. That statement was deliberately temporary. It says, twice, that the Commission's position "will expire after a period of five years from the publication date of this statement", and explains that the five-year window was "designed to provide market participants with an opportunity to develop practices and processes that will enhance their ability to demonstrate possession or control over digital asset securities". Which date starts that clock is genuinely ambiguous: the release is dated December 2020, it was published in the Federal Register in February 2021, and its stated effective date is April 2021. On any of the three the five-year term has run, and no extension or replacement appears in the Federal Register. So the framework should not be treated as available without checking the Commission's current position.
The same statement is useful for a different reason, because it states plainly what the customer of a registered firm gets: customers who use registered broker-dealers to custody their securities "benefit from the protections provided by the federal securities laws, including the Customer Protection Rule and, in most cases, the Securities Investor Protection Act of 1970". A platform that is not a broker-dealer supplies neither of those, and it supplies no federal deposit insurance either. The crypto exchange page sets out what that absence has meant in practice.
The question nobody should pretend is answered. Where a customer's crypto sits with a platform, whether the customer owns identifiable property that a receiver must hand back, or holds a general claim against the estate alongside other creditors, depends on how the arrangement was documented and is decided case by case. It is a real fork with real money on either side of it, and the documents are where the answer starts: a lending agreement that transfers the right to use the asset points one way, and terms stating that the customer retains ownership of assets held in custody point the other. The crypto lending page covers the first case, where the platform borrowed the asset rather than held it. For the second, the honest position is that a reader should know the question exists and read what their own terms of service say about ownership, because that document, and not the word custody, is doing the work.
One regulator statement does address a narrower version of the same problem, and it is worth quoting because it shows the outcome is not hypothetical. Still in the 2021 statement, the Commission observed that "SIPA protection does not extend to all assets that may be held at a broker-dealer", so that "in a SIPA liquidation of a broker-dealer that held non-security assets, including non-security digital assets, investors may be treated as general creditors, to the extent their claims involve assets that are not within SIPA's definition of 'security'". That passage is about a registered broker-dealer, not about a crypto trading platform, so it does not answer the platform question. What it establishes is that being a customer of a regulated firm does not by itself make a crypto holding customer property: the character of the asset matters too, and general-creditor treatment is a documented possibility rather than a worst case somebody invented.