Digital Asset Custody: Who Owns the Lock | Elacity
Sophisticated custody now splits the private key across many machines, and every share still answers to the operator. Splitting a key is not the same as owning the lock.
Digital Asset Custody Split the Key. The Operator Still Owns the Lock.
You can now hold a tokenized Treasury, a tokenized fund share, or a tokenized bond and never once touch the key that moves it. The apparatus of digital asset custody around that token has grown genuinely sophisticated. Almost none of that sophistication is pointed at you.
On September 1, 2026, Ripple and SettleMint announced a partnership to give financial institutions across Asia Pacific one connected system for issuing, custodying, and servicing digital assets. SettleMint's chief executive framed the moment cleanly: capital markets are moving fully on-chain, and that shift only works when custody and lifecycle management run as one system rather than two.
This is where the whole market is going. The value of tokenized real-world assets on-chain now runs into the tens of billions of dollars. The largest of them, BlackRock's BUIDL fund, lives on a public chain while its actual Treasuries and books sit with BNY Mellon. The asset is legible to everyone. The control over it is not.
Digital Asset Custody Learned to Split the Key
The easy criticism of custody is that one company holds one key, so one company can lose everything at once. That criticism is out of date. Ripple Custody splits a private key into encrypted shares using multi-party computation, so no single person and no single machine ever holds the whole secret. This is real security engineering, and it closes the most obvious hole.
So the honest question is no longer whether the key is split. It is who the shares answer to.
Splitting a Key Is Not Sharing Control
In institutional custody, the shares are held by the custodian and its own infrastructure, and the key reassembles when the operator's governance rules allow it: approval workflows, policy engines, compliance checks the operator writes and the operator can rewrite. You, the person the token belongs to, hold no share and set none of those rules. The split exists to protect the custodian's balance sheet from insider theft. It does not hand you the gate.
We have already watched the version of this that fails in the open. When FTX collapsed in November 2022, customer assets sat on the platform, but the platform held the keys and decided who could withdraw. Multi-party computation would not have stopped that, because the people who ran the box were the problem. The lesson was never to split the key across more machines the same company controls. It was that when someone else owns the lock, your access is a promise, revocable the instant their interests stop matching yours.
Where the Lock Should Sit
Elacity starts the custody question from the opposite end. Not: how does the operator protect its holdings. Instead: how does the owner's right decide when the key opens.
In Elacity's model the key that unlocks what you own is split across an owned quorum of independent machines, a two-of-three threshold, and Elacity holds no share of it either. Before any machine releases its piece, it re-checks your rights on-chain. The gate answers to the rights recorded against your name, not to a policy console inside one company.
The key is used, never owned. The secret exists in the clear only for a fraction of a second, inside a sealed sandbox, welded to the single transaction it authorizes, and then it is wiped. No app, no platform, and no attacker ever holds it. The asset stays encrypted everywhere except that one sealed moment of use.
Be precise about what that buys, because the honest edges matter. This is trust-minimised, not trustless. A quorum that colluded could in principle reconstruct a key, and that possibility is designed in rather than hidden. Today that quorum is an owned, operator-run set; permissionless, staked node markets are still being built. The claim is not that trust disappears. It is that the gate is welded to your on-chain rights instead of a company's discretion, and that no single machine can open it alone.
The difference sounds subtle and is not. Institutional multi-party custody and an owned rights quorum can both say the same words, that no single party holds the key. Only one of them binds that key to your entitlement rather than to the custodian's operating policy. The sentence is identical. The theory of power underneath it is opposite.
Custody Is an Ownership Question in Disguise
The tokenization wave has settled the easy half of the problem. A public ledger can record that a fund share, a bond, or a Treasury is yours, and ownership recorded on-chain is real progress. But recording who owns an asset and controlling when that asset moves are two different jobs, and custody is where the second one actually lives.
If the entity that reassembles the key can be compelled by a court, breached by an attacker, or can simply change its terms, then the record of your ownership sits downstream of someone else's decision. That is the gap institutional custody, however well engineered, does not close, because it was never built to close it. It was built to keep the operator safe. We walk through the mechanics of custody that no single device gets to keep in our explainer on who actually holds the keys, part of our work across DeFi and market strategy.
What to Watch Next
The next phase of tokenization will not be won by whoever issues the most assets. It will be won by whoever makes the gate answer to the owner. When a custody model is announced, ask one question of it: does the key open on your rights, or on the operator's rules. Splitting a key is not sharing control. Owning the lock is.
Follow Elacity on X for how the ownership layer of the digital economy is being built.