Em processo de adequação ao regime das SPSAV, nos termos da Resolução BCB nº 520/2025 (regime de transição do art. 88)

  • Em processo de adequação ao regime das SPSAV, nos termos da Resolução BCB nº 520/2025 (regime de transição do art. 88)

Comparisons

Custodial vs non-custodial stablecoin wallets for business

Custodial or non-custodial wallets for a business holding stablecoins: who signs, who is liable, what breaks, and which model fits payouts and treasury.

Caio Barbosa

Fundador & CO-CEO

Forbes Under 30. Uma das principais vozes em Fintech & Crypto no Brasil. Escreve semanalmente sobre stablecoins, pagamentos e o futuro da infraestrutura financeira na América Latina.

Cover image for Lumx blog article: Custodial vs non-custodial stablecoin wallets for business
Cover image for Lumx blog article: Custodial vs non-custodial stablecoin wallets for business

The difference between a custodial and a non-custodial stablecoin wallet is who can produce the signature that moves the money: in a custodial wallet the provider holds the private keys and signs on the client's instruction, and in a non-custodial wallet the client holds the keys and no transfer happens without it. Everything else that people argue about, from regulation to recovery to what happens at three in the morning, follows from that one fact.

For a business the choice is rarely ideological. A payments team wants payouts to clear without a person holding a device; a treasury team wants the balance beyond anyone else's reach; a product team wants its users to see a balance without becoming a custodian itself. Those are different jobs, and they pull toward different models. This post puts the two side by side on the questions an operator cares about, states where each one wins, and closes with a recommendation that includes the cases where the custodial model we run is the wrong pick. The custodial wallet explainer covers the definitions; this one is about choosing.

The two models on one table

Custodial and non-custodial wallets compared on the questions a payments operator asks.

Question

Custodial

Non-custodial

Who holds the private keys

The provider

The business, or its user, or a threshold of both

Who can sign a transfer alone

The provider

Only the key holder

What a lost credential means

A support ticket and an identity check

Permanent loss of the balance

Who can freeze the balance

The provider, and sometimes must

Nobody, unless the contract adds a control

Who is the regulated party

The provider, as custodian

Often nobody, or the business if it holds keys for others

Signing at 3 a.m. with no human

Yes, by policy

Only if the business runs its own signing service

Integration

One API, balances in fiat and stablecoin

Key management with signing policy, monitoring plus audit, built or bought

Counterparty risk

On the provider's solvency and on segregation

On the business's own operational security

The table is deliberately flat. Each row is a place where one model is better and the other is worse, and a business should read down the column that matches its job rather than counting wins.

What the regulators decided the line is

United States guidance settled the definition in writing. FinCEN's guidance FIN-2019-G001 of May 9, 2019, on convertible virtual currency, sets out four criteria for whether an intermediary is a money transmitter, and the decisive one is whether that intermediary has total independent control over the value. If it does, the wallet is hosted, and the provider is the regulated party. If the user controls the funds, the wallet is unhosted. A contract promising to act only on instruction does not change that reading, because the regulator looks at what the provider can do, not at what it promised.

The European Union arrived at the same place through MiCA, Regulation (EU) 2023/1114, which defines custody and administration of crypto-assets as safekeeping or controlling, on behalf of clients, the assets or the means of access to them, including private keys, and lists that activity as a licensed service. Brazil's Law 14.478 of December 21, 2022 names custody or administration of virtual assets, or of instruments that permit control over them, as one of the five services that make a company a VASP (virtual asset service provider, the FATF term), with Central Bank Resolutions 519, 520 and 521 of 2025 setting the authorization regime.

Three jurisdictions and one test: whoever controls the means of access is the custodian. That test is what makes the choice below a legal decision as much as a technical one.

Where the custodial model wins

Payouts that clear without a human. A payout can be signed the moment compliance clears, at any hour, because signing is a policy rather than a person with a device. A stablecoin off-ramp at scale depends on this.

Recovery from ordinary error. Passwords are lost, laptops are wiped, employees leave. With a custodian, each of those is an identity check. With self-custody, a lost key is a lost balance, and no amount of goodwill brings it back.

One integration instead of a security programme. Key management is a discipline in itself: hardware security modules or a multi-party signing service, a signing policy, access control with rotation plus backups, monitoring, plus an audit over all of it. A fintech that builds this is running a custody business next to its own.

Controls that regulators and auditors expect. Transaction limits, address allowlists, four-eyes approval on large payouts and a freeze on a suspicious account are natural to implement where the signing lives. The institutional wallet guide covers how to structure them.

A named counterparty. When something goes wrong, there is a regulated entity with a licence, a contract and a compliance team on the other side. That is what a Head of Payments can put in front of a board.

Where the non-custodial model wins

Assets that must be provably beyond anyone's reach. A reserve held as a public commitment, collateral that cannot be freezable, or a treasury whose policy says no third party may hold it. The non-custodial model is the only one that satisfies that policy, and the operational burden is the price of it.

Counterparty risk that the business refuses to carry. A custodial balance depends on the provider staying solvent and honest, and on how client assets are segregated. A business that has been burned by a failed intermediary, or whose risk committee will not accept another one, has a legitimate reason to hold its own keys.

Users who are meant to own the asset. If the product is a wallet the user controls, a self-custody app, or an exchange withdrawal to the user's own address, then custody by the business would defeat the product. The non-custodial model here is the product, and the business avoids becoming a custodian of other people's assets, which is a licensing question in every jurisdiction above.

Independence from one provider's networks. A custodied balance moves on the networks the custodian supports. A self-custodied one moves wherever the business can sign.

The hybrid that is sold as both

Multi-party computation and threshold schemes let a key be split so that no single party can sign alone, and many providers market this as non-custodial. The FinCEN test still applies: if the provider's share plus its own recovery share is enough to sign, the provider has control, and the arrangement is custodial in substance. If the business holds enough shares to sign alone and the provider cannot, it is self-custody with better tooling. If neither can sign alone, it is a shared arrangement, and the answer to who is the custodian depends on the threshold and on who holds the recovery path.

The practical advice is to ask the provider one question and to get the answer in the contract: can you move the client's funds without the client's participation. A yes is custodial. A no is non-custodial. Anything longer than one word is the hybrid, and it deserves a lawyer's reading before a product decision.

The question I am asked most about our own wallets is whether the client can hold the keys, and the answer is no: Lumx is custodial, has always been custodial, and I would rather say that in the first minute of a call than have a security team discover it during an integration. I am not neutral about the trade. Custody by the provider is what lets a payout clear at three in the morning without waking anyone, and it is also the arrangement where the client trusts a company rather than a signing policy it wrote itself. Both are true at once. A provider that tells a prospect only the first half is selling, and a prospect that hears only the second half is going to build a custody programme it did not budget for. What I ask is that the client read where the assets sit and who can move them, then decide whether it wants to carry that operational weight itself.

When a custodial wallet is the wrong choice

When the business is the custodian. A company whose product is holding assets for other people needs its own custody stack or a custody specialist, not a payments provider's wallet, because it will be the regulated party either way.

When the asset must be unfreezable. Reserves, collateral and public commitments argue for self-custody, and a custodian that promises never to freeze is promising something the law may not let it keep.

When the regulator in the client's own market forbids it. Some licensed entities cannot place client assets with a third-party custodian that lacks a specific authorization. That is a licensing question, and no product answers it.

When the amounts are small and the flow is rare. Onboarding, contracting and integration cost more than they return. A dashboard or an exchange account is the honest recommendation there.

And the mirror case, where the non-custodial model is wrong: a payments business whose users see a balance in an app the business is responsible for, whose payouts must run unattended, and whose finance team wants a counterparty with a licence. That business will end up rebuilding custody, badly, on top of a wallet that was never designed for its job.

What custody looks like on Lumx

Lumx is stablecoin payments infrastructure for businesses that move money between Latin America and the rest of the world: one API to collect, hold, convert, and pay out in BRL, MXN, COP, USD, EUR, and GBP or in USDC and USDT, over local rails such as PIX, SPEI, PSE, ACH, FEDWIRE, SEPA, and Faster Payments, with SWIFT and on-behalf-of payments and collections (POBO and COBO) in USD, EUR, and GBP, plus named virtual accounts, custodial wallets, and KYB/KYC built in.

Every onboarded customer receives a custodial wallet on each supported network, provisioned with the customer and enabled once verification is approved. The wallet holds USDC or USDT between an on-ramp and a payout, so a client can fund it once and run many payouts against the same balance; each payout debits that customer's own wallet to a destination registered under that customer, with the holder relationship declared, because pooling funds for parties Lumx has not onboarded is not allowed. Compliance runs before signing, so a payout that will be held is held before the tokens move, and every state change arrives as a webhook with its reason. The wallet address is a real address on Ethereum, Polygon, Base or Tron, so a client that wants some of its balance in self-custody transfers it out to its own address through the same API, which is the pragmatic answer to a treasury policy that wants both models.

Methodology and sources

The FinCEN test comes from guidance FIN-2019-G001, read from the document published on fincen.gov on September 24, 2026. The European definition is quoted from Regulation (EU) 2023/1114 as published in the Official Journal; the eur-lex page did not serve a readable body on the day of writing, so it is cited by number and not linked. Brazil's definition follows Article 5 of Law 14.478/2022 on planalto.gov.br, read on the same date. Lumx wallet behaviour is taken from the Stablecoin Wallets and Nested Payments pages at docs.lumx.io, read on September 24, 2026. Provider-specific custody terms change, so the comparison with a named provider, including where custody is parity rather than a difference, lives on the Lumx vs Bridge page and not here.

Verified on September 24, 2026. Operational context, not legal, tax, or investment advice.

Cover photo: Konstantin Planinski on Unsplash.

  • Is a non-custodial wallet safer than a custodial one?

    It removes one risk and adds another. A non-custodial wallet cannot be frozen or lost to a provider's failure, and it can be lost outright to a mistake in the business's own key handling. A custodial wallet cannot be lost to a mistyped backup, and it depends on the custodian's solvency, on segregation, and on its controls. Safer depends on which risk the business is equipped to manage.

  • Can a business use both models at the same time?

    Yes, and many do. A custodial wallet carries the operating balance that pays out unattended, and a self-custodied address holds reserves the policy says no third party may touch. The transfer between them is an ordinary transfer on a shared network, and a provider whose wallet is a real address makes that split simple.

  • Does an MPC wallet count as non-custodial?

    Only if the provider cannot sign without the business. If the provider holds enough shares, including any recovery share, to move funds alone, the regulators' control test makes it custodial regardless of the label. Ask for the answer in the contract.

  • Which model does a payments provider usually offer?

    Custodial, because unattended payouts and compliance holds before signing require the provider to control the key. Providers that offer a non-custodial option are usually selling wallet infrastructure rather than payments, which is a different product with a different licence.

Fique por dentro do que a Lumx está desenvolvendo.

Inscreva-se para recebê-los por e-mail.

Compartilhe nas redes sociais:

custodial-vs-non-custodial-stablecoin-wallets-for-businesses

A

custodial-vs-non-custodial-stablecoin-wallets-for-businesses

Custodial vs non-custodial stablecoin wallets for business

Copiar link

Copiado!

custodial-vs-non-custodial-stablecoin-wallets-for-businesses

FALE COM NOSSO TIME

Pronto para transformar seu negócio com stablecoins?

Descubra como nossa infraestrutura pode integrar stablecoins às suas operações financeiras de forma rápida, segura e eficiente.

Comparisons

Nesta página

©2026. Todos os direitos reservados.

A LUMX SOCIEDADE PRESTADORA DE SERVIÇOS DE ATIVOS VIRTUAIS LTDA., pessoa jurídica de direito privado, inscrita no CNPJ/MF sob o nº 42.887.120/0001-00, (“Lumx”) atua como prestadora de serviços de ativos virtuais e encontra-se em processo de adequação ao regime regulatório das Sociedades Prestadoras de Serviços de Ativos Virtuais (SPSAV), nos termos da Resolução BCB nº 520/2025, estando atualmente sujeita ao regime de transição previsto em seu art. 88.

A Lumx não é banco, instituição financeira, instituição de pagamento ou custodiante de recursos de clientes. Determinados serviços disponibilizados por meio da Plataforma poderão ser prestados por parceiros terceiros devidamente autorizados e regulados, nos termos da legislação aplicável.

Consulte os Termos de Uso e o Aviso de Privacidade da Lumx para obter mais informações sobre as condições de utilização da Plataforma e o tratamento de seus dados pessoais.