top of page

Securing the Future: A Legal Overview of Crypto Asset Custody in the UAE

  • Writer: Steffen Feike
    Steffen Feike
  • Sep 25, 2024
  • 4 min read

Open, Sesame! The demand for secure storage solutions has grown exponentially. Custodians ensure that digital assets are protected against theft, loss, or unauthorized access. The UAE have implemented regulations to govern the sector, ensuring both innovation and investor protection. This article outlines crypto custody, the UAE’s legal framework, and areas where more regulatory clarity is needed.

ree

What is Crypto Custody?

Wealth Storage in the Digital Age

Crypto custody is analogous to traditional wealth storage solutions, like freeports or vaults. Just as valuable physical assets need safekeeping, so too do digital assets. Crypto custodians safeguard the private keys that allow owners to access their cryptocurrencies. Without these keys, the assets are irretrievable, making secure custody essential for investors.


Although crypto assets are digital in nature, we will see that crypto custody still involves secure vaults, physical devices and operational protection.


The Role of Private Keys

In the cryptocurrency world, private keys are the most important asset. Whoever holds the private key controls the digital asset. Losing the private key is equivalent to losing control of the asset, so proper key management is fundamental to custody solutions.


Hot vs. Cold Storage

Crypto custody solutions typically fall into two categories: hot storage, where keys are stored online, and cold storage, where keys are kept offline. Hot storage provides faster access but comes with greater security risks, as it’s more vulnerable to hacking. Cold storage, on the other hand, is considered safer because it’s disconnected from the internet, but it’s less convenient for frequent access.


Different Custody Solutions

At its most basic level, private keys could be store in a person's mind by memorizing a so called seed phrase (so called mnemonic seed phrase). Since this is a non-redundant and otherwise risky solution, professional custody solutions have been developed over the years. 


Custodians offer a range of solutions depending on the level of security and control required. In sole custody, the custodian maintains full control over the assets. Meanwhile, collaborative custody involves shared control between multiple parties, usually through multi-signature wallets, which require multiple approvals before transactions can be executed. 


As an example, a company could opt for a 2-out-of-3 authorization threshold, where at least two of three authorized signatories must validated a transaction (e.g. CFO + CEO or COO+CFO or COO+CEO). This provides for redundancy while maintaining a four-eyes-principle.


The Legal Framework in the UAE

Mainland UAE

In mainland UAE, the Securities and Commodities Authority (SCA) governs crypto-related activities. Under Decision No. 23 of 2020, any entity providing crypto asset services, including custody, must obtain a license from the SCA. The regulation emphasizes capital requirements, risk management, and cybersecurity standards. In addition, recent rules introduced by the Central Bank of the UAE (CBUAE) outline specific licensing requirements for custodians dealing with payment tokens, specifically stable coins.


Abu Dhabi Global Market (ADGM)

ADGM has created a more comprehensive framework for crypto activities. Custodians operating in ADGM must comply with the Financial Services Regulatory Authority (FSRA), which mandates strict asset segregation, regular audits, and governance standards. ADGM’s regulations are widely regarded as being closely aligned with international best practices.


Dubai International Financial Centre (DIFC)

Firms looking to provide crypto custody services in the DIFC are required to obtain the relevant licenses from the DFSA. This process reflects the regulatory oversight designed to ensure custodians adhere to strict standards in terms of asset security, client confidentiality, and operational integrity. The DFSA’s framework, particularly its Crypto Token Regime, aims to strike a balance between protecting investors and fostering innovation within the sector.Areas Where More Clarity is Needed


Liability for Key Loss

Although custodians are required to implement stringent key management systems, there is limited guidance on liability in the event of key loss or theft. The legal framework does not explicitly address how custodians should be held accountable in such scenarios, leaving gaps in investor protection.


Crypto Insurance

While insurance products for crypto custody are available in the UAE, the regulatory framework does not clearly define whether custodians can rely on foreign insurers. Given the evolving nature of crypto insurance, clearer regulatory guidance is necessary to ensure adequate coverage and enforceability of such policies under UAE law.


Cross-Jurisdictional Issues

With custodians often operating across multiple jurisdictions, the lack of regulatory harmony can create challenges. Coordinating regulations between mainland UAE, ADGM, and DIFC, along with foreign jurisdictions, is essential for ensuring seamless operations. The UAE needs to focus on developing a consistent and unified approach to crypto custody regulation.


Cold Storage Standards

Although cold storage is the most secure option for crypto custody, there is little regulatory clarity on the technical requirements for custodians using such storage methods. Establishing clear guidelines will help enhance investor confidence and ensure that custodians meet international security standards.


Conclusion

As the crypto industry continues to grow in the UAE, custodians will play an increasingly important role in ensuring the safety and security of digital assets. While the regulatory frameworks in mainland UAE, ADGM, and DIFC provide a strong foundation, there are areas that require further clarity, particularly around liability, insurance, and cross-border operations. By addressing these issues, the UAE can further cement its status as a global leader in the crypto space.



THIS IS NOT LEGAL ADVICE. DO YOUR OWN RESEARCH OR CONSULT ME IN MY PROFESSIONAL CAPACITY.

 
 
 

Comments


bottom of page