Bitcoin Custody for $500K to $10M: What Your Options Actually Are
Jackson Mikalic | Head of Business Development
For a position from roughly $500,000 to $10 million there are four real options: self-custody multisig, where you hold every key and carry the burden permanently; collaborative custody (Casa, Unchained, about $250/yr), where you hold most keys and a provider holds a backup; a qualified custodian, where one institution holds everything; and multi-institution custody, where three institutions each hold a key and you hold none. The right answer turns on whether you want to run keys for decades.
Someone worth a hundred million dollars who holds one bitcoin has an interesting position. Someone whose entire net worth is one bitcoin has a life-altering one. Same holding, completely different question.
The right custody model tracks the consequence of losing it, not exclusively the size of the balance. So read the dollar figures on this page as shorthand for an amount whose loss would change your life, and adjust them to your own situation.
Once you are past that point, whatever it is for you, three things start to matter that did not before: what happens if the company holding your bitcoin fails, what happens if you die, and whether you personally want to be responsible for cryptographic key management for the next thirty years.
One honest caveat before the comparison. Consequence and cost do not move together. If your position is small in absolute terms but enormous in personal terms, a flat annual fee is a meaningful percentage of the asset every year, and the fact that losing it would be devastating does not change that arithmetic. Well-executed self-custody or collaborative custody is often the better answer at that size, and this page will tell you how to think about both.
That said, it is a judgment call rather than a rule. We have clients holding well under a bitcoin who chose this deliberately, because for them the inheritance path or the protection against coercion was worth more than the fee. Entry pricing below the standard tier has also been available at times. If the architecture is what you want and only the cost is in the way, it is worth asking rather than assuming.
There are four real models. Each is a genuine answer for some people. Here is what each actually is, what it costs, and who it fits.
1. Self-custody multisig
You hold every key. A 2-of-3 or 3-of-5 setup across hardware wallets from different manufacturers, ideally stored in different physical locations.
Cost: a few hundred dollars in hardware, once. Nothing recurring.
What you get: complete sovereignty. No company can freeze, lose, or be compelled to hand over your bitcoin. No counterparty exists.
What you take on: everything, permanently. Firmware updates and verification. Seed backups protected against fire, flood, theft, and your own forgetting. Passphrase discipline. Replacement ceremonies when a vendor has an incident, which happens. The 2026 Coldcard entropy vulnerability meant every key generated on affected firmware had to be treated as compromised and replaced. Descriptor and configuration backups stored alongside the keys, because a multisig setup without its configuration is unrecoverable even with the keys.
And the part that quietly breaks most setups: your heirs have to be able to execute it. Writing instructions a non-technical spouse can follow under grief and time pressure is a harder problem than it sounds when you are building the vault.
Fits: technically capable holders who genuinely enjoy this, have a realistic inheritance plan, and want zero counterparties. That is a legitimate and respectable choice, and for a meaningful share of people at this level it is the right one.
Does not fit: two different people, and either one alone is disqualifying. First, anyone who is not genuinely confident they can build and maintain this correctly themselves. Multisig done badly is more dangerous than a single hardware wallet done well, because it adds failure modes most people do not discover until they try to recover. Second, anyone whose honest answer to "could my family recover this without me" is no. Being technically capable yourself does not help your heirs, and having a technical family member does not help if you are the one who makes the mistake.
2. Collaborative custody
Casa and Unchained are the two established options. You hold most of the keys; the provider holds one as a backup and co-signs when you ask.
Cost: Unchained vaults are free the first year and $250/year after, with no deposit or withdrawal fees and $20 per cosignature on collaborative withdrawals. Casa Standard is $250/year for a 2-of-3 where you hold two keys and Casa holds a recovery key; Casa Premium is $2,100/year for a 3-of-5 with hardware included, video-verified support, and family co-management for inheritance.
What you get: most of self-custody's sovereignty with a real safety net. Lose one key and you are not ruined. Both companies are credible and have operated for years. Unchained additionally offers loans and an IRA against the same vault, which makes it the most financially complete option in this category. Casa's Sovereign Recovery is a real failsafe worth understanding: recovery instructions are emailed to you every time you create a keyset, and you can import the vault into open-source tools like Sparrow, Electrum, or Specter and sign with two of your three keys, with no Casa software involved. It is explicitly designed on the assumption that Casa itself has disappeared.
What you take on: you are still running keys. The operational burden is reduced, not removed, and it still lasts decades. Your family still needs technical knowledge to recover the bitcoin, roughly comparable to self-custody, with the meaningful difference that there is a provider they can call for help rather than being entirely on their own.
Fits: holders who want to keep direct key participation and are honestly committed to managing it long term, and who want a backstop against single-key loss.
Does not fit: several situations, and they are worth separating.
Anyone who wants the job finished rather than reduced. You are still buying and maintaining hardware, still protecting backups, still performing replacement ceremonies when a device fails or a vendor has an incident, and still holding most of the signing authority. That means you personally have to remain available and competent for as long as you hold the position, which for most people here is decades.
Anyone whose concern is incapacity rather than death. Because you hold the majority of keys, a collaborative provider generally cannot act on your behalf if you are alive but unable to sign. That gap catches people who planned carefully for dying and not at all for a stroke.
Entities, trusts, and businesses, where signing authority needs to sit with institutions under a governance structure rather than with one individual and their devices, and where an auditor or a co-trustee needs to see something more legible than "the principal has two hardware wallets."
Anyone who needs their family to inherit by designation rather than by execution. A named beneficiary receiving legal title is a different thing from an heir who must locate keys, follow a recovery procedure, and get it right the first time. Collaborative custody makes that procedure easier and gives them someone to call. It does not remove it.
3. A single qualified custodian
Coinbase Custody, Fidelity Digital Assets, BitGo, Anchorage, Gemini. One regulated institution holds everything on your behalf.
Cost: typically a percentage of assets, negotiated, often with minimums that put the smaller end of this range out of reach.
What you get: you do nothing operationally. These are serious institutions with real security programs, and several hold trust charters or federal bank charters. For an entity that needs a recognized qualified custodian for regulatory or fiduciary reasons, this is often the only category that qualifies.
What you take on: one institution holds the keys. That is the entire risk in one sentence. If it fails, freezes withdrawals, faces a regulatory action, or is compromised, your access depends on what happens to that one company. Your bitcoin may also be pooled in an omnibus account rather than held in a wallet titled to you, which matters enormously in an insolvency. A claim against a company is a different instrument from property that is yours. Percentage-of-assets pricing also means your fee grows as bitcoin appreciates, which over a long holding period compounds against you.
Fits: institutions with a regulatory requirement for a named qualified custodian, and holders who value single-relationship simplicity above eliminating single-institution risk.
4. Multi-institution custody
Three independent institutions each hold one key. Two signatures are required to move anything. You hold none.
One clarification first, because "an institution holds a key" does a lot of work in that sentence. This is not a hardware wallet in somebody's desk drawer. Each key is generated in an air-gapped ceremony on purpose-built infrastructure and then split internally, so no individual employee at any of the three institutions holds anything spendable. There is no one person at any of these companies who could walk out with your bitcoin, because there is no one person who has it.
This is the model Onramp operates, so read the rest with that in mind. Keys sit with Onramp, BitGo Trust, and CoinCover, generated on air-gapped institutional hardware, with each institution sharding its key internally so no individual employee anywhere holds spendable material. Your bitcoin sits in its own segregated on-chain wallet, titled to you, verifiable on any block explorer at any time. Moving funds without you would require coordinated fraud across multiple people at independent companies in different jurisdictions.
Cost: a flat annual fee tiered by bitcoin quantity, not a percentage of assets. The entry tier is $2,400/year for up to 10 BTC. Because tiers are denominated in bitcoin, the dollar fee stays fixed as the price rises, unlike a percentage fee that grows with the asset. Insurance is included rather than sold as an add-on.
What "no single point of failure" means concretely. The phrase gets used loosely across the industry, so here is the arithmetic. Two signatures move funds, so an attacker needs two of the three institutions to fail together. And because each institution splits its key internally, "compromising an institution" is not a matter of turning one person. It means coordinated fraud among many people, at two independent companies, in different jurisdictions, at the same time, with none of them defecting or being noticed. Compare that with the number of people who have to fail at a single custodian, which is one. That gap is the entire product, and it is the scenario the Lloyd's policy is written against.
What you get beyond the vault. Multi-institution custody is the foundation, but the practical value for most holders is what sits on top of it:
- Inheritance that does not require your family to understand bitcoin. You name beneficiaries with percentage allocations directly on the account. No seed phrases, no signing devices, no instructions to write. Legal title transfers rather than your heirs hunting for a key. For most clients this is the single reason they moved.
- Insurance included, not sold as an add-on. Custody operations are insured through Canopius, a Lloyd's of London syndicate, under a $50 million active policy underwritten up to $100 million, at no cost to clients. Two things make that worth more than the headline number. It is bundled rather than an upsell, which is unusual in this category. And the underwriting is itself a form of due diligence you did not have to perform: the world's most established insurance market only underwrites custody architectures it considers low-risk, which is why single-custodian models rarely qualify for comparable coverage.
- Brokerage that settles straight into the vault. You can buy bitcoin and have it land directly in your multi-institution wallet, rather than buying on an exchange and then performing a withdrawal you have to get exactly right. That removes the most common self-inflicted loss in bitcoin: a mistyped address or a botched transfer. If you want a second set of eyes, someone from the team will get on a call and check the address with you before you send anything.
- A Bitcoin IRA included with a standard account, alongside the taxable account, so retirement holdings sit in the same architecture instead of a separate custodian you now have to evaluate separately.
- Onramp Guardian controls at no extra cost: time delays on withdrawals, per-transaction and per-period limits, and duress words. Time delays in particular are the defense against physical coercion, not just remote attack. A thief who has you in a room cannot get your bitcoin if the transaction cannot execute for days.
- Bitcoin-backed loans against the same holdings, so accessing liquidity does not require selling and triggering capital gains.
- A human being who knows your account. Named contacts, reachable directly. This is not a support-ticket relationship, and for people managing a life-changing position it consistently matters more than any single feature.
- Recovery that works without Onramp. If Onramp ceases to exist, CoinCover and BitGo Trust execute the documented process together after a defined waiting period. Every client holds a recovery kit.
What you give up: direct key control. You are choosing institutional protection over personal sovereignty, and that is a real trade, not a free upgrade. Withdrawals involve identity verification, a recorded video call, and independent verification with BitGo Trust before the second signature. That friction is deliberate. It is the wrong product for anyone who wants to move funds quickly, and the right one for anyone whose main fear is an irreversible mistake or a coerced transaction.
It is also worth saying that this is not an all-or-nothing decision, and most clients do not treat it as one. Plenty of them keep bitcoin in self-custody alongside what they hold here, typically a hardware wallet for a working balance they touch regularly with the generational position secured institutionally. Splitting across models also splits your failure modes, which is a reasonable thing to want.
Fits: holders with meaningful positions who do not want to operate keys for decades, who need an inheritance path a non-technical family member can execute, or who need segregated client-titled custody for a trust, business, or entity.
The comparison, plainly
| Self-custody multisig | Collaborative | Single qualified custodian | Multi-institution | |
|---|---|---|---|---|
| Who holds keys | You, all of them | You hold most, provider holds one | One institution | Three institutions, you hold none |
| Annual cost | ~$0 after hardware | ~$250 (Casa Premium $2,100) | % of assets, negotiated | $2,400 at entry tier, flat, BTC-tiered |
| Single point of failure | Your own operations | Reduced | Yes, the institution | No |
| Your ongoing job | Everything, forever | Reduced but permanent | None | None |
| Segregated and titled to you | Yes | Yes | Often pooled, verify | Yes, verifiable on-chain |
| Family can recover the bitcoin | Requires technical knowledge | Requires technical knowledge, provider can assist | Varies by institution's process | Named beneficiaries, no technical knowledge required |
On the price gap, since it is the obvious objection: collaborative custody at $250/year and multi-institution at $2,400/year are not really competing on price, they are competing on who does the work. With Casa or Unchained you are paying a small fee and doing part of the job yourself, forever. With multi-institution you are paying institutions to do all of it, plus carrying insurance, plus maintaining an inheritance path. If you want to run keys, collaborative is cheaper and it is a genuinely good product. If you do not, the comparison is not $250 against $2,400, it is $2,400 against thirty years of a job you did not want.
Flat pricing also prices poorly at the bottom of this range and well at the top. At $500,000 the entry tier is roughly 0.5% a year. At $5 million it is a fraction of that. Below roughly $100,000 the arithmetic usually points elsewhere, though not always, and entry pricing below the standard tier has been available at times. Current tiers are on the pricing page.
What actually changes as the position grows
Read these as proportions rather than thresholds. The same dollar figure means something different depending on what else you own.
At $500K, all four models are defensible. The deciding question is usually an honest self-assessment about operational discipline and inheritance, not cost.
At $1M to $5M, single-point-of-failure risk starts to dominate the arithmetic. A 1% chance of total loss is now a $10,000 to $50,000 expected cost per year, which reframes what any of these fees actually mean. This is also where flat-fee pricing crosses over and starts beating percentage-of-assets pricing, and the gap widens every year bitcoin appreciates.
Past $5M, and especially for entities, trusts, and family offices, the questions become structural: whose balance sheet is this on, what does an insolvency proceeding do to it, who can sign, and what happens on the day the principal dies. Those are the questions that push people toward segregated, client-titled, multi-institution arrangements, and they are worth asking before you need the answers.
The objection worth taking seriously: not your keys, not your coins
If you have been in bitcoin for years, everything above ran into one sentence in your head, and it deserves a direct answer rather than a dodge.
The principle is correct. Whoever holds the keys controls the bitcoin. The question is what "you" means when the bitcoin has to outlive you, survive your own mistakes, and be recoverable by people who do not know what a seed phrase is.
In a single-signature setup, "your keys" means one device and one backup, and the failure modes are yours alone: a fire, a burglary, a forgotten passphrase, a vendor's firmware bug, or the simple fact that you are the only person on earth who can access it. In a multi-institution arrangement, no single party can move your bitcoin, including the institutions. You are not handing your keys to a company. You are distributing them so that no one, including you under duress, is a single point of failure.
Both are real answers to the same problem. Self-custody optimizes for sovereignty and accepts operational risk. Multi-institution custody optimizes for survivability and accepts that you are not the sole signer. If sovereignty is what you value most, self-custody is genuinely the right answer and you should not let anyone talk you out of it.
Two other objections come up constantly and are worth naming:
"What if the institutions collude?" This is the correct question to ask, and the answer has two parts. The first is the arithmetic above: it takes coordinated fraud at two independent companies in different jurisdictions, involving many people at each, all defecting at once with none of them noticed. Compare that to the number of people who need to fail for a single custodian to lose your bitcoin, which is one.
The second part is that this is not left to arithmetic alone. Keyholder collusion is precisely the tail risk the Lloyd's policy is written to cover. An underwriter looked at this exact scenario, judged how likely it was, and put capital behind that judgment.
"What if all three jurisdictions turn hostile at the same time?" A fair edge case, especially for non-US holders. There is no arrangement that survives every scenario, and anyone who claims otherwise is selling. What multi-institution custody gives you is that no single government, regulator, or court order reaches all three keys, which is meaningfully better than one company in one jurisdiction and meaningfully worse than keys you hold personally in a country you choose. Weigh it honestly against your own situation.
Frequently asked questions
What is the safest way to hold a $1M bitcoin position without self-custodying?
The two options that avoid personal key management are a single qualified custodian and multi-institution custody. The meaningful difference is that a qualified custodian concentrates all risk in one institution, while in multi-institution custody three independent institutions protect your bitcoin and no single failure at any of them reaches it. Ask any provider whether your bitcoin sits in a wallet titled to you that you can verify on-chain, or is pooled in an omnibus account, because that distinction decides what you own in an insolvency.
Is institutional custody better than self-custody for large amounts?
Neither is universally better. Self-custody eliminates counterparties and gives you complete control, at the cost of permanent operational responsibility and an inheritance problem most people underestimate. Institutional custody removes that burden and adds insurance, at the cost of direct key control. The right answer depends on your technical capability, your time horizon, and whether your family could recover the bitcoin without you.
What does bitcoin custody cost for a large position?
It varies by model. Collaborative custody runs about $250 a year at Casa and Unchained, with Casa Premium at $2,100. Institutional qualified custodians typically charge a percentage of assets, negotiated. Onramp's multi-institution custody is a flat annual fee tiered by bitcoin quantity, starting at $2,400 for up to 10 BTC, which means the dollar cost stays fixed as bitcoin appreciates rather than growing with it.
Can I use more than one model at once?
Yes, and many holders at this level do. A common arrangement is a hardware wallet or collaborative vault for a working balance you touch regularly, with the long-term generational position in institutional or multi-institution custody. The models are complements, not rivals, and splitting across them also splits your failure modes.
What happens to my bitcoin if I die?
This depends entirely on the model, and it is the question most large holders underestimate. With self-custody, your family needs the keys, the passphrase, the multisig configuration, and enough technical knowledge to use all three under the worst circumstances of their lives. Collaborative custody asks for comparable technical knowledge, with the real difference that a provider is there to walk them through it rather than leaving them alone with it. With multi-institution custody, you name beneficiaries with percentage allocations on the account and legal title transfers to them, with no seed phrases or signing involved. The honest test for any arrangement is not whether it is secure. It is whether the person you love most could actually execute it on the worst day of their life.
Can I buy bitcoin directly into custody, or do I have to transfer it in?
Both are possible with Onramp. You can transfer existing holdings in, or buy through the brokerage and have it settle directly into your multi-institution wallet, which avoids the withdrawal step where most self-inflicted losses happen. Recurring buys carry no Onramp trading fee after the first.