The Three-Sentence Memo
Julian Sawyer has stepped out of the corner office at Zodia Custody and into an advisory chair. He is staying in the building, which is the corporate equivalent of a chess player sliding a piece sideways rather than off the board. Nobody was fired. Nobody was promoted into a vacuum. The press release had the flat, careful grammar of something written by three lawyers and one communications consultant who were told to keep it short.
I have read that kind of memo before. Twice as an operator, once as an auditor, and several more times as the person on the other end of the phone asking a dev team why their treasury multisig had four signers in one co-working space.
The instant read from the timeline was predictable: another crypto company wobbling, another executive cashing out before the next winter. That read is lazy. The more interesting read is that a specific thesis, one that has been sold to shareholders of major banks for four years, has quietly changed shape โ and the person who was hired to execute the old version of that thesis is no longer the person best positioned to execute the new one.
Here is the claim I want to test over the next several thousand words.
Institutional custody is not a technology problem that a bank can solve by hiring better engineers. It is a distribution problem dressed in a hardware security module, and the solution is increasingly to buy the distribution rather than build the vault.
That sounds like a business observation. It is actually a philosophical one, and I want to walk through why.
We built the utopia, then audited the ruins.
When I was twenty-four, I co-founded a decentralized collective with four thousand members and a treasury of five hundred ETH. We governed everything through snapshot votes because we believed governance was a solved problem once you removed the middlemen. It collapsed in under a year, not because the code failed but because the humans stopped showing up and the ones who did show up started voting in coordinated blocs. I interviewed a hundred former members afterward, and the pattern that emerged was not about cryptography at all. It was about attention. People will not read a proposal if reading it costs them nothing and changes nothing.
Zodia Custody is the mirror image of that experiment. It is the most centralized thing you can build in this industry โ a regulated vault run by a bank โ and its hardest problem is also attention, except here the attention belongs to risk committees, compliance officers, and the clients who take eighteen months to decide whether to sign a custody agreement.
One of these organizations failed because governance was too easy. The other is slow because trust is expensive. Both of them are being run on the same naive assumption: that the hard part is the architecture.
It is not. The hard part is the arithmetic.
What Zodia Actually Is
Strip the branding and Zodia Custody is a vault with a banking license's shadow behind it. It was incubated inside Standard Chartered's venture arm, spun out to operate as an independent company, and structured so that the parent's name does the heavy lifting in every sales meeting. Along the way, a consortium of institutional names took minority positions โ Northern Trust among the early backers, SBI Holdings in the Asian expansion, and a separate regional vehicle in Australia in which a domestic bank took a stake. The corporate family tree is more spread out than the marketing suggests, which matters, because the strategy question I am about to describe is being decided in more than one boardroom.
The company operates under a patchwork of regulatory registrations rather than one monolithic license. In the United Kingdom, it is registered with the financial regulator under the money laundering regulations, which is the standard gate for crypto businesses that are not yet banks. In the European Union, the new markets-in-crypto-assets regime is reshaping what "passporting" even means. In Asia and Australia, it works through local entities with local partners. This is not a criticism. It is the actual shape of every serious custody business on earth: a legal mosaic glued together by vendor risk assessments and mutual recognition agreements that took longer to negotiate than the software did.
Now the part that gets left out of the pitch deck.
A custodian's job, functionally, is to take something that was designed to be held by an individual with no intermediary and hand the responsibility to an institution with an endless appetite for paperwork. The private key does not care who holds it. The regulator does. The insurer does. The client's board does. Every one of those three parties adds a line item to the cost base, and none of them add a single line of code.
Custody is a sales business wearing an engineering costume.
That is not a dig at Zodia specifically. It is a structural fact of the category. Coinbase Custody is really a distribution arm of an exchange. BitGo built its name on multi-signature wallets and insurance relationships before anything else. Fireblocks built a network of institutional connections and wrapped the cryptography around the network, not the other way round. Anchorage built a charter. The technology in each case is real and competently executed; the moat in each case is something else entirely โ a client funnel, a legal status, a network effect.
So when a CEO who came out of digital banking and a major exchange departs after roughly a three-year run, the useful question is not "what went wrong." The useful question is: which of those moats was the hiring committee buying in 2021, and is it the same moat they need now?
In 2021, the moat was legitimacy. A bank-branded vault that could pass a vendor risk assessment was the whole product. In 2026, legitimacy is table stakes. Every large financial institution either has a custody arm, a custody partner, or a signed letter of intent with one. The scarce resource has shifted from "can you be trusted" to "can you reach the client before your competitor does."
Those are different jobs. They are rarely done by the same person.
The Business That Wears an Engineering Costume
Let me get concrete, because vague strategic talk is how people lose money.
Institutional crypto custody charges a basis-point fee on assets under custody. Depending on the client, the asset mix, and how much the client negotiated, that fee has compressed over the last three years to a range that would make a traditional asset servicer wince. Large strategic clients push toward the low single digits. Some of the largest are rumored to be sitting at or near zero on core safekeeping, with the custodian making the actual margin on adjacent services โ staking, financing, collateral movement, settlement, FX conversion.
That is a normal evolution in asset servicing. Custody of traditional securities has been a famously thin business for decades, and the winners there are the ones who attach a dozen other revenue lines to the account. Crypto is now walking the same road at roughly ten times the speed.
The trouble is that the cost base did not compress at ten times the speed. It compressed at roughly the speed of a committee meeting.
Consider what it costs to run a credible institutional vault. You need hardware security modules that meet the relevant federal information processing standards at the highest practical security level โ physically tamper-resistant devices, each costing tens of thousands of dollars, deployed in redundant configurations across geographically separated facilities. You need disaster recovery sites that actually function during a disaster, which means rehearsal, which means flying key ceremony participants from three time zones into a room where phones are surrendered at the door and every action is witnessed and logged on paper. You need a SOC 2 Type II audit annually, penetration tests more often, a legal team that reads sanctions lists the way a sommelier reads a wine list, a twenty-four-hour operations desk, insurance that may or may not pay out in the event of a hack depending on policy language nobody has fully litigated, and a compliance function that grows with regulation rather than with revenue.
Add it up honestly and a mid-sized regulated custodian is running a fixed cost base in the tens of millions per year before a single client signs.
Now divide.
At five basis points, one billion dollars of assets under custody generates five hundred thousand dollars of annual revenue. At four basis points, it generates four hundred thousand. That does not pay for a good engineering team, let alone a compliance department, let alone both. Break-even on a serious operation requires tens of billions of dollars in custody, and there are maybe a handful of firms on the planet that clear that bar โ most of them attached to an exchange or a global bank.
This is the arithmetic that quietly kills the independent-custodian thesis: the product is priced like a commodity, the cost base is priced like a regulated utility, and only the owner of a large client book can survive the gap between the two.
Which brings us back to the memo. A company that cannot reach break-even on fees alone has three options. It can attach enough adjacent revenue to raise the effective yield per client. It can find a parent willing to subsidize the business as a strategic loss leader. Or it can sell itself to someone whose existing distribution turns the same fee schedule into a profitable business overnight.
Two of those options are corporate strategy. The third is an exit. And exits frequently require a different kind of chief executive than the one who built the thing.
The Buy Side of the Ledger
Banks spent the first half of this decade announcing that they would build.
That announcement was not a lie; it was a forecast made by people who had never tried it. Building a custody business means hiring people who understand key management, which is a small global talent pool. It means standing up an operations desk that can run unattended at three in the morning. It means negotiating insurance in a market with almost no actuarial data. It means waiting in a licensing queue whose length is set by a regulator with no incentive to be fast. It means a product roadmap measured in quarters while the market moves in weeks.
The alternative is to buy a company that already solved those problems, or rent the capability through a partnership, and spend the internal political capital on integration instead of invention.
You can see the pattern in the deals that did happen. A major distributed-ledger payments firm acquired a Swiss custody technology house for a quarter of a billion dollars and absorbed the engineering team wholesale. A European banking group took a stake in a custody technology vendor and shipped a product on top of it rather than writing its own stack. A global bank in Asia launched institutional digital asset custody by licensing infrastructure rather than building from scratch. An American custodian bank partnered with a technology platform and got to market in a fraction of the time a from-scratch build would have required.
None of those decisions were made because the banks lacked engineers. They were made because the banks correctly calculated that the marginal dollar spent on integration buys more speed than the marginal dollar spent on invention.
Code is not law; it is a negotiation โ and nowhere is that truer than in custody, where the code is the cheapest part of the negotiation.
Here is the part that rarely gets said out loud, though it is whispered in every vendor risk meeting. The technology that a bank would be buying is, in most cases, replicable. Multi-party computation libraries are open source. Hardware security modules are a purchase order. The key ceremony liturgies are documented in public after-action reports from the companies that got them wrong. A determined bank with a competent CTO and eighteen months could rebuild almost any custody stack in existence.
What a bank cannot rebuild quickly is the client list, the insurance relationships, the regulatory posture, and the team that has already lived through an incident. Those are the assets. The software is scenery.
Which means that if Standard Chartered and its co-investors are re-evaluating the build-versus-buy decision inside their own portfolio company, the honest answer is that what they own is a client book and a compliance posture, not a technology moat. And those are precisely the things a bank can manufacture internally better than almost anyone else โ given enough patience.
The patience is the variable. The patience is always the variable.
What a Key Ceremony Actually Costs
I want to spend a few paragraphs on something that almost never makes it into strategy documents, because it is the thing that actually determines whether a custody business works.
In the winter of 2022, when three quarters of the market I had been writing about had evaporated and I was clinically depressed in a flat in South London, I started auditing smart contracts for small DeFi protocols for almost nothing. Three of them, all struggling, all with founders who were sleeping on couches. In a yield aggregator I found a reentrancy vulnerability that would have drained roughly two hundred thousand dollars of user funds. The fix took four lines. The gratitude from the dev team lasted months and is still, honestly, the thing that dragged me out of that winter.
Every bug is a lesson, and most of them are lessons about humans, not machines.
Custody is the same discipline at a different layer. The most dangerous findings I have ever seen were never in the code. They were in the ceremony.
A quorum policy that required three of five shards to sign โ except that three of the five shard holders worked in the same office and took the same elevator to the same bomb-proof door. A hardware security module firmware update with no tested rollback path, scheduled for a Friday. A disaster recovery site that shared a power feed with the primary site, connected by a river with a long history of flooding. A backup shard stored in a safe deposit box whose key was held by the person most likely to be on a plane when it was needed. A recovery drill that took nineteen hours, revealing that the documented procedure had six undocumented steps.
None of those are exotic failures. All of them are expensive to fix, because fixing them requires paying senior people to sit in a room and rehearse for days on end, on an ongoing basis, forever.
That is the cost structure nobody puts in the pitch deck. It is not the HSM. It is not the MPC library. It is the permanent, unglamorous, unbillable rehearsal.
Idealism without audit is just gambling โ and in custody, the audit is a line item that never stops accruing.
Now consider the implication for a CEO. Your job is not to invent. Your job is to keep a liturgy running. That is closer to running a cathedral than a startup, and it is a genuinely different personality than the one that gets hired to build something new. I have watched three executives move through this transition in different companies, and the pattern is consistent: the builders leave, the operators arrive, and the company stops making announcements it cannot keep.
That is not a failure. It is a phase change. But it is frequently reported as a failure, because the reporting frame is startup-shaped and custody is not a startup.
The Compliance Cost Curve, and the Theater On Top of It
Compliance is the strangest expense in this entire industry, because it is fixed, it is non-negotiable, and it barely correlates with the risk it claims to reduce.
A regulated custodian's onboarding process for an institutional client runs through layers of documentation that would embarrass a mortgage application. Proof of incorporation. Proof of beneficial ownership. Source-of-funds narratives. Accredited or professional investor attestations. Auditor letters. Sanctions screening. Politically exposed person checks. Periodic reviews that repeat most of this annually because the regulation requires periodic review, not because anything has changed.
The cost of that apparatus is real, and it is borne by the client in the form of fees, delay, and duplication. The security it provides is real but bounded. What it mostly provides is a paper trail that allows everyone involved to say, in the event of an enforcement action, that they did the thing.
Most of the friction in institutional crypto onboarding is theater, and the ticket price is paid entirely by honest participants.
Here is what I mean, stated as precisely as I can without being irresponsible. An actor determined to move value through an institution must clear a documented threshold of holdings and identity verification. The cost of that verification is enormous. The marginal cost of structuring around it โ spreading positions across wallets and counterparties, using intermediaries whose own attestations are stacked like dominoes โ is comparatively small. The result is a system where the compliant pay for the appearance of compliance, and the determined pay a modest structuring fee for the same access.
I have watched this dynamic up close while translating blockchain concepts for traditional finance people during my year inside a London fintech. I built presentations that turned zero-knowledge proofs into risk-mitigation language for people whose job was capital adequacy. The most common question in those rooms was never "how does this work." It was "what will the regulator accept." That question shapes the entire product roadmap, and it means the industry spends an enormous share of its engineering capacity producing evidence rather than security.
None of this is an argument for light-touch regulation. It is an argument for honesty about what regulation actually buys. It buys a documented chain of responsibility. It buys reversibility after a mistake. It does not buy immunity from a determined adversary, and pretending otherwise leads to security budgets being spent on binders instead of on redundancy.
The custodians know this. The ones I respect will tell you, off the record, that their real risk controls are procedural and their real defense is that nobody has tried hard enough yet. That is a sobering thing to hear from the person holding your keys. It is also the most honest sentence in the industry.
Custody Is a Short Volatility Position
I spent six months of my master's program deriving the constant product formula behind the largest automated market maker, not because I wanted to trade but because I could not stop looking at it. The formula is a hyperbola, and the loss that liquidity providers experience when prices move is not a flaw in the design โ it is a geometric consequence of the shape. I wrote a long thread arguing that impermanent loss should be understood as a hedge rather than a risk, and it went further than anything I had written before. It is also the reason I abandoned a doctorate and went to work on this industry full time.
I bring it up because custody is the same kind of object, and almost nobody prices it correctly.
An institution that provides safekeeping for a fee believes it is running a stable, fee-generating service business. Functionally, it is doing the opposite. It is collecting a small, steady premium in exchange for writing a put option on catastrophic events. If nothing goes wrong, the premium compounds and the business looks like an annuity. If a private key leaks, a counterparty is sanctioned, a client is frozen, or a jurisdiction reinterprets a rule, the payoff is binary and enormous, and no year of accumulated fees covers it.
That is why custody businesses look deceptively profitable on a spreadsheet and terrifying on a risk register. It also explains an apparently irrational behavior among banks: they want the fee income and they do not want the tail risk, which is a combination that cannot be satisfied by building the vault yourself.
You can only have both if you rent.
Or, to say it more precisely: the ideal structure for a bank that wants fee income without tail risk is a white-label arrangement where a licensed third party holds the keys and the bank owns the customer relationship. In that structure the bank books revenue, the custodian books the liability, and the client never sees the seam. That is a much more natural end state than either a pure build or a pure acquisition, and it is the outcome that the "banks will buy custodians" narrative tends to skip past.
The Subsidy That Isn't a Business Model
The current price of institutional custody is not a market price. It is a subsidized price.
I have watched this pattern before at a different layer of the stack. Rollups spent years offering transaction fees that were effectively decoupled from the cost of the resource they consumed, because a shared data layer was absorbing the difference. That works beautifully until the shared resource saturates โ and when a shared resource saturates, the price of everything downstream reverts to the cost of the underlying constraint, sometimes violently. The cheap era was never a business model. It was a grant, made by whoever owned the scarce resource, and it expired on a schedule nobody controlled.
Custody is running the same play. The low fees institutional clients enjoy today are funded by venture capital, strategic capital, and parent-company patience. Standard Chartered does not need Zodia to be profitable this quarter; it needs Zodia to be positioned when the market matures. That is a rational use of a bank's balance sheet. It is also a subsidy, and subsidies have end dates.
When the subsidy window closes, three things happen at once. Fees rise for clients who have no alternative. Marginal custodians exit or consolidate. And the remaining players discover that the fee schedule was never the competitive variable โ the client relationship was.
I do not know when the window closes. I am fairly confident it is sooner than the industry's own roadmaps assume, because the cost base I described earlier is not shrinking and the market is not growing fast enough to outrun it.
Settlement Rails Nobody's Risk Committee Will Approve
There is one more technology question worth addressing, because it is where a lot of custody roadmaps quietly point.
The long-term prize is not safekeeping. Safekeeping is a commodity. The prize is settlement โ moving assets and collateral between institutions without a correspondent bank in the middle, in minutes rather than days.
This is where a certain kind of enthusiast reaches for a certain kind of network, and where I have to be the person who says the unwelcome thing.
Payment channels are a beautiful design and a fragile product. The idea that value can route itself through a mesh of bilateral liquidity commitments works in simulation and struggles in production, because routing requires liquidity to be in the right place at the right time, and liquidity providers are not charities. A network that requires active channel management, rebalancing, and node operation to function has a permanent operational overhead that no compliance committee will ever sign off on as a settlement path for institutional flow. The seven-year track record is not a story of failure. It is a story of a prototype that works well enough to be interesting and not well enough to be load-bearing.
Banks do not want probabilistic settlement. They want finality, reversibility under defined conditions, and an audit trail that a regulator will accept on the first read. That is a specification for an orchestration layer over existing ledgers, not for a routing mesh.
So when I look at a custody company's roadmap and see "settlement network," I read two very different possibilities. One is a genuine orchestration product that connects institutional books and settles atomically against collateral. The other is a narrative asset designed to support a valuation. The technical difference between them is enormous. The marketing difference is nearly zero.
Discerning which one you are looking at is exactly the kind of work that gets skipped when the story is about a CEO's title change.
What Is Actually For Sale
Let me inventory the assets in a custody company, ranked by how hard they are to replicate.
At the bottom: the software. Multi-party computation, hardware security modules, wallet architecture, and API design are all well-trodden. Competent teams build these. The open-source ecosystem means the frontier moves faster than any single vendor's roadmap.
Above that: the operational playbooks. The ceremony procedures, the incident runbooks, the recovery drills. These take years to get right and are almost entirely undocumented in public, because they are the closest thing the industry has to trade secrets. This is a real asset, and it lives in the heads of a small number of people.
Above that: the insurance relationships. Coverage for digital asset custody is scarce, expensive, and negotiated relationship by relationship. A custodian that has held a policy for three years without a claim has something a startup cannot buy at any price.
Above that: the regulatory posture. Registrations, supervisory history, the accumulated credibility of never having been the subject of an enforcement action. This is slow to build and instant to destroy.
At the top: the client book. Contracts with institutions that took a year and a half to sign, governed by risk committees that will not repeat that process for a competitor unless something goes badly wrong.
Now look at the list and ask which items a large bank already possesses. The client book: yes, at a scale no custodian can match. The regulatory posture: yes, though not for crypto specifically. The insurance relationships: partially, and negotiable. The operational playbooks: no. The software: no, but buildable.
A bank buying a custodian is buying two years of operational scar tissue and a set of client contracts it could probably have won on its own. That is a real but narrow justification for an acquisition, and it explains why the deals that happen look less like conquest and more like hiring at scale.
Which is, if you think about it, exactly what an advisory role is.
The Arithmetic of Buying Versus Building
I want to put a rough model on the page, clearly labeled as illustrative, because the shape of the arithmetic matters more than the specific numbers.
Suppose a custodian holds thirty billion dollars of assets at an effective blended fee of four basis points after negotiation. That is twelve million dollars of annual revenue. Suppose the operating cost base โ engineering, compliance, operations, insurance, legal, audits, sales โ is twenty-five million. The business is losing thirteen million a year, funded by investors who believe the loss is temporary.
Now suppose the same thirty billion sits inside a global bank's custody division, sharing the bank's compliance department, its legal department, its insurance relationships, its client relationship managers, and its balance sheet. The marginal cost of servicing that book is a fraction of the standalone cost, because almost every function is already paid for. The same twelve million in revenue is suddenly profitable, not because the fees changed but because the denominator did.
That is the entire build-versus-buy argument in two paragraphs. It has nothing to do with cryptography.
And it cuts both ways. It means an independent custodian is structurally disadvantaged against a bank that builds in-house, which is an argument for selling. It also means a bank has less reason to pay a premium for a technology it could replicate, which argues for a lower acquisition price. The two forces meet somewhere in the middle, and the result is a market where custody companies are worth more to a specific buyer than to the public market โ a classic condition for consolidation, and a classic condition for strategic drift while everyone waits for the price to clear.
That is the space Zodia occupies right now, whether or not anyone in the building would describe it that way.
Where the Contrarian Case Gets Hard
Now let me argue against myself, because the "banks will buy instead of build" thesis is fashionable and fashionable theses are usually half wrong.
The strongest counterargument is that buying does not actually work. Integration is where value goes to die. I have watched this happen from inside an organization: a bank acquires a technology company, promises independence, and then eighteen months later the acquired team has lost two-thirds of its engineers to competitors who can pay in equity, the product roadmap has been frozen pending a risk assessment that will never conclude, and the platform has become an internal system of record with no external customers. The bank paid for velocity and received a maintenance contract.
That pattern is not unusual. It is the default. Acquisitions of technology companies by regulated institutions succeed when the acquirer is buying distribution or a license, not when it is buying innovation. And in this specific case, the acquirer would be buying a business that is, by construction, not innovative โ it is a vault. Vaults are supposed to be boring.
So the buy thesis may be right about the direction and wrong about the mechanism. The most likely outcome is not an acquisition spree. It is a wave of white-label and partnership arrangements where the bank owns the client and the custodian owns the keys, because that structure requires no integration of cultures, no retention of engineers, and no transfer of regulatory responsibility. It is the least dramatic option, which is why it is probably the correct one.
Maybe the Job Was the Problem
Here is the second counterargument, and it is the one that keeps nagging at me.
Maybe the CEO transition has nothing to do with strategy at all.
Consider what the job actually is. You run a company whose product is an assurance. Your days are spent in regulator meetings, vendor risk assessments, insurance renewals, and sales cycles measured in quarters. Your engineering organization ships slowly by design, because shipping fast in a vault is a liability, not an asset. Your best possible outcome in any given year is that nothing happens. There is no product launch that changes your trajectory, no viral moment, no growth loop. There is a liturgy, and you are the person who keeps it running.
That is a specific temperament. It is not the temperament that gets hired to build something new, and it is not the temperament that most operators with a digital banking background find satisfying for a decade.
Moving from chief executive to advisor can be a demotion or a graduation. From the outside, both look identical in a press release. I do not have enough information to distinguish between them here, and I want to be honest about that rather than construct a narrative that flatters my own thesis.
What I can say is that the industry's talent pool for this specific job is tiny. There might be a few hundred people on earth who can credibly run a regulated digital asset custodian, and they rotate among a handful of firms the way central bankers rotate among central banks. A departure from one chair is frequently an arrival in another, and the rotation itself tells you where the demand is pointing even when the individual story is unremarkable.
The Branding Paradox
There is a deeper strategic tension in this whole category that I have not seen articulated well, and it deserves a section of its own.
A custody business has to decide whether it wants to be a brand or plumbing.
A brand custodian sells trust directly to institutions, competes on reputation and regulatory standing, and captures the client relationship. A plumbing custodian sells infrastructure to other financial institutions, competes on reliability and integration speed, and is invisible to the end client. The economics are wildly different. Brands pay for sales teams, marketing, and relationship management and earn a margin on trust. Plumbing pays for engineering and uptime and earns a margin on volume.
The thing is, in custody the plumbing business is bigger, stickier, and less competitive than most people assume. The largest institutional custody technology platform in the world does not hold the most assets โ it connects the most institutions. Its moat is not a vault; it is a network, and networks get stronger with every additional participant in a way that vaults do not.
A company incubated inside a bank has a natural brand advantage and a structural plumbing disadvantage, because a bank's instinct is to own the customer and to keep the infrastructure close. Choosing to become plumbing means telling your parent that your best future involves serving its competitors. That is a difficult conversation, and it is often exactly the conversation that a leadership change is designed to have.
I am not claiming to know which path Zodia is on. I am claiming that the question is live, that it is bigger than any individual executive, and that the announcement everyone read as a personnel story was almost certainly downstream of it.
What I Would Actually Watch
Three signals, in order of how much they would change my thinking.
First, the successor's background. If the next chief executive comes from a technology M&A or platform integration background, the buy-and-integrate thesis is being validated from the inside. If the next chief executive comes from a regulatory or institutional sales background, the company is doubling down on brand custody and the strategy has not changed at all. Those are opposite conclusions drawn from the same press release, and the difference will be visible within two quarters.
Second, where the headcount moves. Watch hiring patterns. A company that is shifting from build to buy will stop growing its engineering organization and start growing partnerships, corporate development, and integration. That is a slow signal, but it is a much harder one to fake than a strategic announcement.
Third, and most decisive, whether the parent company acquires anything. If Standard Chartered and its co-investors buy a custody technology asset in the next eighteen months, the thesis is confirmed and the entire category reprices. If they do not, the most likely explanation is that everyone concluded the build was fine and the timing was the problem.
For investors watching the sector โ and I hold no position in any company named in this article, for what it is worth โ the practical implication is that the interesting assets are not the branded vaults. They are the integration layers: the companies whose value increases when a bank decides to buy rather than build, because they are what gets bought.
The Question Underneath the Question
I started this piece with a memo and I want to end it with a structure, because the real story here is not a person.
Custody occupies a strange position in the ideology of this industry. It is the most centralized service in a movement built on removing centralization, and it exists because the alternative โ asking every institution to manage its own keys โ is not an option the law will permit. That tension is not a bug. It is the price of admission for institutional capital.
The people who built this industry spent a decade insisting that code would replace trust. What actually happened is that trust got productized. It got a fee schedule, a compliance department, an insurance policy, and a hardware budget. That is not a betrayal of the original vision. It is what the original vision looks like when it has to survive contact with a risk committee.
The build-versus-buy question is really a question about where that productized trust should live. Inside a bank, where it shares the cost base of an institution that has been doing this for two hundred years in other asset classes? Or inside a specialist, where it is priced honestly and sold to whoever needs it?
Both answers are defensible. Only one of them survives the arithmetic.
I have spent enough time in vaults to know that the most dangerous moment is never the breach. It is the quiet period afterward, when everyone relaxes because nothing went wrong, and the rehearsals stop, and the ceremony becomes a formality, and the person who used to insist on the fourth shard holder being in a different building gets promoted into a job where they no longer get to insist.
The advisory chair is a fine place to sit. But somebody still has to count the shards.
Trust no one, verify everything, build always.