An institution cannot hold crypto the way an individual does. Fiduciary duties, audit requirements and in many cases explicit rules oblige a fund, an insurer or a listed company to place assets with a qualified custodian, and the practices that follow look much more like securities custody than like a hardware wallet in a safe.
The technical core is eliminating any single person or device that can move funds. Two approaches dominate. Multi-signature arrangements require signatures from several independent keys before a transaction is valid, with the requirement enforced by the blockchain itself. Multi-party computation splits a single key into shares held separately and never assembled anywhere: signing is a joint computation among the shareholders, so the complete key never exists at any moment, including during use. MPC is chain-agnostic and leaves a smaller on-chain footprint; multi-signature is transparent and verifiable on-chain. Both are chosen over a single key for the same reason — the failure of one holder should not be the failure of the arrangement.
Around that sits a tiering of storage. Cold storage keeps keys entirely offline, with signing performed in a physically controlled environment, and is where the large majority of assets sit; the trade is that a withdrawal takes hours rather than seconds. Warm and hot tiers hold working balances for operational flow, with lower balances and tighter limits. The governance around them is where most of the actual security lives: policy engines that enforce which addresses may be paid, transaction limits, mandatory delays on new destinations, dual approval, and hardware security modules certified to a published standard.
The legal structure matters at least as much and is easier to get wrong. Are client assets segregated from the custodian's own, and held in a manner that keeps them out of the estate if the custodian fails? That question — not the key management — is what separated recoverable from unrecoverable positions in the failures of the last cycle. A trust company holding assets in a bankruptcy-remote structure is a materially different counterparty from a company holding an omnibus balance on its own balance sheet, whatever the marketing says about cold storage.
The rest is diligence with well-worn answers. Which regulator supervises the entity, and under what licence? Is there an independent controls audit, and how recent? What insurance exists, what does it actually cover — theft of keys is not the same as employee collusion or protocol failure — and what are the limits against the assets held? Can assets be recovered if the custodian ceases to operate, and has that path been tested? What is the process for staking or lending held assets, and does participation change the legal character of the holding?
One structural point is worth noting for anyone reading the market rather than buying custody. A small number of custodians hold the assets behind most institutional products, including the exchange-traded ones. That is a concentration of ownership rather than of block production, and it is a different shape of centralisation from the one the sector usually argues about.