Hardware Wallet vs. Institutional Custody: Consumer-Grade and Institutional-Grade Security
Jackson Mikalic | Head of Business Development
A hardware wallet company and an institutional custodian both call themselves secure, but they mean different things. A hardware wallet is consumer-grade security: a well-built device that relies on its owner to operate it properly and competently. Institutional-grade security is hardware with controls and processes around it: key material created in controlled ceremonies, no single employee able to reach it, independent audits, and every withdrawal verified by trained staff.
A hardware wallet company and an institutional custodian both call themselves secure, but they mean different things. A hardware wallet is consumer-grade security: a well-built device that relies on its owner to operate it properly and competently. Institutional-grade security is hardware with controls and processes around it: key material created in controlled ceremonies, no single employee able to reach it, independent audits, and every withdrawal verified by trained staff.
Self-custody is a legitimate way to hold bitcoin, and hardware wallet makers such as Ledger and Trezor do serious engineering. Nothing here argues otherwise. The point is narrower: when the word "secure" comes from a device maker, it describes a product. When it comes from an institution, it describes hardware with a set of controls and processes around the keys, run by people whose job is nothing else.
What Consumer-Grade Security Covers
A hardware wallet company is responsible for its product. That includes the chip and firmware design, how the device generates a seed, how it signs a transaction without exposing the key to your computer, and how it reaches you without being tampered with.
What the claim does not cover is everything after setup. The company never sees your seed phrase, by design, so from that moment the owner is the whole security operation:
- Key creation. The seed is generated on one device, under your circumstances and control.
- Backups. The seed phrase and any copies you make, written or stamped, stored wherever you decide, and protected against fire, flood, and theft by you.
- Access controls. Anyone with the device and PIN, or the seed, can move the bitcoin. Access depends on your security.
- Incidents. When a vendor discloses a vulnerability, the owner decides whether it applies and, if it does, moves to new keys. In 2026, a hardware wallet vulnerability meant keys generated on affected firmware had to be treated as compromised and replaced. A vendor can ship a fix. It cannot move your bitcoin for you.
- Threats to you. Phishing, fake support agents, lookalike apps, and physical attacks, including home invasions and kidnappings, all target the owner, not the device.
- Inheritance. Your heirs have to find the backup, understand it, and use it correctly, once, without you there.
None of this reflects badly on the device or on the people who use one. Many self-custodians run this well for years. It is the job that comes with being the only operator.
What Institutional-Grade Security Covers
Institutional-grade security is built so that no one person can ever move the bitcoin alone. The practices differ by firm, but the serious ones share a pattern:
- Key creation is a ceremony, not a setup screen. Key material is generated offline on dedicated institutional hardware, never on a consumer device, in a controlled environment, under documented procedures, often with multiple people present.
- No single employee can access key material. Access requires several people acting together, so one compromised or coerced employee cannot move anything.
- Backups are engineered. Key material is protected in more than one secured location, with recovery procedures that are documented and tested.
- Independent examination. Outside auditors review the controls, and qualified custodians are supervised by regulators.
- Withdrawals are verified by people trained to spot fraud. Requests are checked against identity, device, and behavior before anything moves.
- Incident response is a team. Monitoring, escalation, and recovery are someone's full-time job, not something you research on a weekend.
That is the difference the word "secure" hides. A hardware wallet protects what is on the device very well. Institutional-grade security also protects the backups, the people, and the processes around the key material.
The Catch: One Institution Is Still One Point of Failure
Institutional-grade controls at a single institution, such as an exchange or a single qualified custodian, still put every key in one place. That institution's controls, its people, and its solvency become the single point of failure. A breach, an insider, or a bankruptcy at that one firm can reach every client's bitcoin at once, and in an insolvency a court may have to decide whose bitcoin it is before anyone can withdraw.
Multi-institution custody keeps the institutional-grade operation and removes the single institution. In Onramp's Multi-Institution Custody, three institutions protect your bitcoin. No one of them can lose it, move it, or use it, and nothing moves without your permission.
Multi-institution custody works like a bank vault that needs two keyholders to open: it takes two of the three (Onramp, BitGo Trust, and CoinCover) to move your bitcoin.
Here is where the consumer and institutional contrast is sharpest. Multi-institution custody uses an industry-standard 2-of-3 multisig quorum: each institution generates and secures its private key offline, through an institutional-grade key generation ceremony, never on a consumer device. You never hold a key, a seed phrase, or a hardware wallet. Each institution also shards its own key internally, so no single employee holds spendable material.
Around that quorum:
- Withdrawals are verified twice. You start a withdrawal in the dashboard, pass a liveness check that matches a live selfie to your government ID with AI deepfake analysis, then complete separate video calls with Onramp and with BitGo Trust. The bitcoin is typically on its way within 24 to 48 hours. Optional Onramp Guardian controls add withdrawal delays, monthly limits, and in-person verification.
- Outside examination. Onramp has been issued a SOC 2 Type I report: an independent CPA firm examined the design of the security controls behind Multi-Institution Custody. A Type II examination is underway, and controls are monitored in Onramp's public Trust Center.
- A qualified custodian in the quorum. Onramp is a custody solution, not a custodian. BitGo Trust is the qualified custodian.
- Your own vault. Your bitcoin sits in a segregated vault in your name, never pooled with anyone else's, and you can verify it on-chain at any time.
- Recovery without Onramp. If Onramp becomes unresponsive, CoinCover and BitGo Trust execute recovery together. What Happens to Your Bitcoin if Onramp Goes Away? covers the process.
Separately, Onramp maintains custody insurance through Canopius, a Lloyd's of London syndicate: up to $50M in aggregate coverage across our custody operations. Onramp pays the premium.
Consumer-Grade and Institutional-Grade, Side by Side
| Hardware wallet (consumer-grade) | Single institution (institutional-grade) | Multi-Institution Custody | |
|---|---|---|---|
| How it is set up | Seed generated on one device, under your control | Key material generated in a controlled ceremony | Key material generated in a controlled ceremony at each of three institutions, offline |
| Who can move the bitcoin | Whoever has the device and PIN, or the seed | Several employees acting together, at one firm | Two of three independent institutions acting together |
| Backups | Seed phrase copies you make and store | Engineered, at one firm | Engineered, at each institution |
| Outside review | None | Auditors and, for qualified custodians, regulators | SOC 2 Type I report; BitGo Trust is a qualified custodian |
| What one failure can do | A lost or exposed seed can lose it | A breach, insider, or insolvency at that firm can reach it | A breach, failure, or bad actor at one institution cannot move it |
| Your upkeep | Ongoing, for as long as you hold | None | No hardware wallets, seed phrases, backups, or PINs to manage |
| Speed to move | Minutes | Varies by firm | Typically 24 to 48 hours |
Where Self-Custody Remains the Right Answer
If you value sole control above everything else, run your setup carefully, and have an inheritance plan your family could follow, self-custody is a sound choice. Many holders keep both: an amount in a wallet they manage and the rest in Multi-Institution Custody. Moving From Self-Custody to Multi-Institution Custody covers how to keep a self-custody amount alongside a vault.
For a fuller comparison of every model, with costs and who each fits, see Bitcoin Custody for $500K to $10M.
Explaining the Difference to Someone on the Fence
When a friend says their hardware wallet is secure, they are usually right about the device. Three questions move the conversation from the product to the operation around it:
- How was it set up, and who saw it happen? With a hardware wallet, on one device, by you. With institutional custody, in a controlled ceremony under documented procedures.
- What has to go wrong for the bitcoin to be lost or taken? With one device and one seed, one thing. With a single institution, one firm. With a 2-of-3 quorum of independent institutions, at least two.
- Who could recover it if you could not? Could Your Family Recover Your Bitcoin Without You? is a practical way to test the answer.
FAQ
Is a hardware wallet secure enough for a large amount of bitcoin?
The device can be very secure. The open question is the operation around it: how the key was created, how the backup is stored, how vendor incidents are handled, and what happens if you cannot act. For large amounts, many holders weigh that ongoing job as heavily as the device itself.
What does "institutional-grade" security mean?
Keys created offline in controlled ceremonies, no single employee able to reach them, engineered backups, independent audits, and withdrawals verified by people trained to spot fraud. It describes a set of controls around the key, not a better device.
Is an exchange the same as institutional-grade custody?
An exchange may run institutional-grade controls, but every key sits at one firm, so that firm is a single point of failure. Multi-institution custody requires two of three independent institutions to move bitcoin, so no one of them can lose it, move it, or use it.
Is Onramp a custodian?
No. Onramp is a custody solution. BitGo Trust is the qualified custodian. In Multi-Institution Custody, Onramp, BitGo Trust, and CoinCover each secure a key offline, never on a consumer device, in a 2-of-3 multisig. You never hold a key yourself.
Can the institutions move my bitcoin without me?
Nothing moves without your permission. It takes two of three institutions to move your bitcoin, and every withdrawal requires a liveness check and video calls with both Onramp and BitGo Trust.
Is Onramp's custody independently examined?
Yes. Onramp has been issued a SOC 2 Type I report: an independent CPA firm examined the design of the controls behind Multi-Institution Custody. A Type II examination is underway.
Can I use a hardware wallet and Multi-Institution Custody together?
Yes. Many holders keep an amount in a wallet they manage directly and the rest in a Multi-Institution Custody vault. You can withdraw from your vault to your own wallet, typically within 24 to 48 hours.