SEC's Quiet Deregulatory Pivot: What the Custody Rule Revision Really Signals

Partnerships | MoonMax |

Date: September 2025

On August 25, the SEC submitted a proposal to the White House Office of Information and Regulatory Affairs (OIRA) that would revise custody rules under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. The submission carries a designation that would have been unthinkable two years ago: "deregulatory."

Let's be precise about what this means. This isn't a technical upgrade. No smart contracts execute here. But for anyone tracking the institutionalization of digital assets, this administrative filing matters more than most mainnet launches.

The Context: A Two-Year Reversal

The 2023 proposal, pushed under former Chair Gary Gensler, defined "qualified custodians" narrowly: chartered banks, trust companies, SEC-registered broker-dealers, and CFTC-regulated futures commission merchants. The practical effect was to lock most crypto-native custody solutions out of the compliance framework that investment advisers must operate within.

The backlash was immediate and sustained. Financial institutions, crypto platforms, and other federal agencies all pushed back. The proposal was eventually withdrawn. Now the SEC—under new leadership—is moving in the opposite direction. The stated rationale: removing "investor protection burdens" from outdated provisions that no longer serve their purpose.

Math doesn't lie, but regulators do revise. The direction of travel here is unambiguous.

The Core Analysis: What the Rule Change Actually Unlocks

The current proposal is still in early-stage review, but the implications are structural. A broadened qualified custodian definition would permit investment advisers to custody client digital assets through a wider range of service providers—potentially including platforms built on multi-party computation (MPC) and distributed validator technology.

This is the quiet infrastructure story. The 2023 framework effectively mandated a specific custody architecture: bank-grade, centralized, audited under traditional financial standards. A revised framework would acknowledge what the market has already built—crypto-native custody solutions that are arguably more secure than their traditional counterparts, but didn't fit the regulatory mold.

Based on my experience auditing proof systems and custody architectures, I can tell you this: the security gap between a well-implemented MPC wallet and a traditional bank custody arrangement is not obvious. The regulatory distinction was never about security. It was about jurisdiction. The SEC regulates banks. It doesn't regulate smart contracts.

The timing is notable. OIRA review typically takes 30-90 days. The SEC's target for a formal proposal is October. That's a compressed timeline, suggesting the rule text is already largely drafted and the agency is confident in its direction.

The Contrarian Angle: Watch the Blind Spots

Here's what the market narrative is getting wrong.

The "deregulatory" label is being read as "anything goes." It isn't. The SEC is removing burdens it considers obsolete—but it will simultaneously define what replaces them. The new rule will still require custody standards, audit requirements, and segregation of client assets. The question is whether those standards accommodate crypto-native solutions or simply expand the club of acceptable traditional custodians.

There's a second blind spot: RIN 3235-AN48, a separate rulemaking to clarify broker-dealer crypto compliance, is also on the agenda. And the tokenized securities exemption is still pending. These aren't isolated actions. They're a coordinated framework adjustment. The custody rule is the foundation—broker-dealer rules and tokenization exemptions build on top of it.

The real signal here isn't about custody at all. It's about tokenized securities. You cannot have institutional-grade tokenized securities without a compliant custody layer. The SEC knows this. The sequencing of these rulemakings suggests the agency is methodically clearing the path.

One more observation from my audit work: the 2023 proposal's failure wasn't just political. It was architectural. The rule assumed a custody model that didn't match how digital assets actually operate. Self-custody, multi-sig arrangements, and programmatic controls didn't fit the "qualified custodian" box. Any new rule that doesn't address these realities will fail the same way.

The Takeaway: A Framework Shift, Not a Single Rule

The new wave of federal trust bank charters being approved—noted in the same regulatory ecosystem—suggests the market isn't waiting for the SEC. Institutions are finding alternative paths to compliant custody. The SEC's revision is, in part, a recognition that the ecosystem has moved beyond its 2023 assumptions.

If the October proposal matches expectations, expect a renewed focus on the "compliant custody" sector: Coinbase Custody, BitGo, Fireblocks, and the newer trust-chartered entrants. More importantly, expect the tokenized securities narrative to gain momentum. The custody question has been the bottleneck. It's being removed.

Smart contracts execute. They don't negotiate. But the rules governing how institutions interact with them are being rewritten right now. The question isn't whether this framework shift matters. It's whether the final rule text delivers what the early signals promise.

The next 60 days will tell us.