Glossary / Regulation & tax
Safeguarding of client assets
Also known as Safekeeping of clients' crypto-assets and funds, Client asset segregation.
- What is Safeguarding of client assets?
- Safeguarding of client assets is the MiCA obligation on a crypto-asset service provider to hold your coins and cash apart from its own, so its creditors cannot reach them.
Article 70 of Regulation (EU) 2023/1114 bars any use of client crypto-assets for the provider's own account and protects ownership rights in insolvency. Client cash other than e-money tokens must sit with a credit institution or central bank by the end of the business day after it arrives. Whether your exchange balance survives the exchange failing depends on which legal entity holds it.
How it works
Safeguarding of client assets sits in Article 70 of Regulation (EU) 2023/1114, in the block of conduct obligations that binds every authorised crypto-asset service provider whatever service it sells. The article splits into two halves that behave differently.
For crypto-assets, paragraph 1 obliges any provider holding client coins or the means of access to them (private keys included) to make adequate arrangements that protect client ownership rights, "especially in the event of the crypto-asset service provider's insolvency", and to prevent the use of those coins for the firm's own account. There is no permitted borrowing window, no discretion to lend the float out overnight, and no exception for a firm that intends to put the coins back.
For cash, paragraphs 2 and 3 are more mechanical. Client funds that are not e-money tokens have to be placed with a credit institution or a central bank by the end of the business day following the day they were received, in an account separately identifiable from any account holding the firm's own money. That deadline is the sharpest line in the article: client deposits cannot linger in the operating account. Paragraph 5 switches paragraphs 2 and 3 off for providers that are already electronic money institutions, payment institutions or credit institutions, because those firms safeguard cash under their own regime instead.
Firms offering custody carry a longer list under Article 75. Client holdings must be segregated from the firm's own holdings, held separately on the distributed ledger, and legally segregated from the firm's estate so that its creditors "have no recourse to crypto-assets held in custody", with operational segregation on top. A custodian is liable for losses attributable to it, capped at the market value of the lost crypto-asset at the time the loss occurred. Clients get a statement of position at least once every three months, and a summary of the custody policy on request.
Enforcement is not decorative. Article 111(1)(d) lists infringements of Articles 65 to 83, covering both Article 70 and Article 75, and Article 111(3) requires member states to arm their authorities with fines against a legal person of at least EUR 5,000,000 or 5% of total annual turnover. Article 111(4) adds a temporary ban on the responsible directors managing any crypto-asset service provider.
Why this matters when you buy bitcoin
Safeguarding of client assets is the reason two entries under one brand name can offer you materially different protection on the identical coin. The site's 63 exchange records describe operators, but the contract you sign is with a legal entity inside that operator, and the entity is chosen by your country of residence. That is what the phrase "regulated exchange" hides: regulated where, and by whom.
Across the 231 country guides, most jurisdictions have no equivalent of Article 70. Without an authorisation regime, the only thing standing between your balance and a liquidator is a sentence the operator wrote and can rewrite. The 32 crypto-licence guides mark where a supervisor has published rules a firm can be fined for breaking, and the EU MiCA states are where the segregation obligation has teeth.
The 41 wallet reviews are the other side of this. A non-custodial wallet has no client assets to safeguard, because you were never a client with respect to the keys. Safeguarding matters only for as long as somebody else holds your bitcoin, which argues for keeping an exchange balance no larger than what you are actively trading.
Bitstamp Europe and Bitstamp USA hold the same coin under different rules
Bitstamp publishes a separate set of terms for each legal entity it trades through, and each safeguarding clause is written to the law binding that entity, not the brand above it. The split runs along entities, not documents: two of those texts belong to one entity, Bitstamp UK Limited, the second being the version for reaching it through the Robinhood platform, and their custody sections match down to the lettered sub-paragraphs. Europe S.A. and USA Inc. are where the answer changes.
The Bitstamp Europe S.A. terms open the custody section with "Bitstamp as a licensed crypto-assets service provider safeguards all Crypto-Assets you hold in your Account in accordance with Applicable Law", then spell out what that means in practice. Your coins are held in an omnibus wallet in Bitstamp's name alongside other clients' coins, and "may from time to time be held in the wallet together with Bitstamp's Crypto-Assets (for example where they reflect fees payable to us)". The estate protection is stated plainly: crypto-assets in custody are "legally segregated from our estate in the interest of our Clients in accordance with MICAR", so creditors have no claim on them even in insolvency. So is the residual risk: in the event of a shortfall you may incur a loss, shared pro rata with other affected clients as Bitstamp determines. Cash gets the parallel treatment, held with banking providers on a pooled and commingled basis but segregated from Bitstamp's own funds, and in insolvency "Currency in your Account is not part of the mass of Bitstamp's assets". A summary of the custody policy is available on request, which is Article 75(3) showing through the contract.
The Bitstamp USA Inc. terms carry a clause headed "Customer Assets Not Segregated from other Customer Assets", which says Bitstamp "shall have no obligation to segregate by blockchain address Digital Assets owned by you from Digital Assets owned by other customers" and that balances may be commingled at one or more addresses. Title stays with you and Bitstamp may not grant a security interest in your assets or hypothecate them. What is missing is the estate sentence: no MiCA legal segregation, because MiCA does not reach a US entity. Same brand, same bitcoin, different answer to the question that matters when a firm fails.
Safeguarding of client assets vs Own funds requirement
Safeguarding of client assets and the own funds requirement protect completely different money, and one word in the regulation runs them together. Article 67 is titled "Prudential requirements" but calls the thing it demands "prudential safeguards", an amount the firm must hold at all times equal to at least the higher of the Annex IV permanent minimum capital for its service type and one quarter of the preceding year's fixed overheads. Article 70, in the same chapter of obligations on every provider, asks instead for arrangements that "safeguard the ownership rights of clients". Same word, two different jobs.
Own funds are the firm's own capital, sized to absorb the firm's own losses before those losses reach anyone else. Client assets under Article 70 were never the firm's, and no amount of capital makes spending them acceptable. A well capitalised firm can still have lent out your coins, and a thinly capitalised one can have every client coin exactly where it belongs. Reading a capital figure as evidence that your balance is safe is a category error.
Safeguarding of client assets vs Proof of reserves
Safeguarding of client assets is an obligation with a named supervisor and a fine attached; proof of reserves is a voluntary attestation an operator commissions and can stop commissioning. An attestation shows that coins existed at a moment in time. It is silent on the legal question of whose estate those coins fall into when the company stops trading, which is the question Article 75(7) answers by requiring legal segregation from the provider's estate.
They also fail differently. A proof-of-reserves snapshot can be true and useless if liabilities were understated or the assets were borrowed for the day. A breached segregation obligation leaves the firm liable, its directors bannable, and the client with a claim outside the insolvency queue. Treat an attestation as a hygiene signal and the licence behind the entity as the protection.