Segregated crypto in a custodian bankruptcy still needs a key that works
In December 2021 a customer asked Prime Trust, a Nevada trust company that then held assets for a good part of the US crypto industry, for a large ether withdrawal. The omnibus wallets on its custody platform could not cover it. The staff who went looking found that customer deposits had been landing for eleven months in a multi-signature cold wallet the company had built in 2018 and believed it had retired, and that nobody at the company could sign from it. The Delaware bankruptcy court’s account of it, written in July 2025, spends one clause on the cause: Prime “did not have access to the 98f Wallet”, 98f being the last three characters of its address. In the months that followed the company bought replacement ether with commingled customer fiat to pay withdrawals. The 23,778 ETH one customer sent there was still in the wallet in May 2025.
The ledger was right and so was the chain. The assets were, in the words that will matter below, actually present.
Switzerland wrote the rule for this situation before Prime Trust broke. Art. 242a of the debt enforcement and bankruptcy act, added by the DLT Act and in force since August 2021, gives a client a claim to have crypto assets handed out of a custodian’s bankruptcy estate, provided the custodian undertook to hold them ready for the client at all times and they are attributed to the client individually or to a pool with a visible share. Art. 16 of the Banking Act says the same for banks. It is the sentence in the custody terms that lets a Swiss custodian call itself bankruptcy-remote.
I read the Federal Council’s message on the bill, the document that tells a Swiss court what parliament meant, to find out what the claim is a claim to. The answer is on page 62, in the paragraph where the government answers consultation respondents who worried the right would be hard to enforce:
Artikel 242a E-SchKG begründet lediglich einen Anspruch gegen die Konkursmasse für den Fall, dass die betreffenden Vermögenswerte tatsächlich vorhanden sind und darüber verfügt werden kann.
The article founds a claim against the estate only for the case that the assets are actually present and can be disposed of. Thirty pages earlier the same document explains when a crypto asset is in the estate at all: when the client has no access of their own and the bankrupt holds every key needed to dispose of it directly. Where the administrator cannot dispose of it, the message says plainly, handing it over is not possible, and it points to the neighbouring provision on access to data, under which a key might be demanded as data.
So the statute has three written conditions, and the message spells out a fourth that the text carries only in its opening words about power of disposal. The estate has to be able to sign. Segregation is a right to be paid out of a wallet the administrator can open.
The fourth condition
A Swiss custodian can show the first three today. The undertaking is in the contract. The attribution is in a register, which the message allows to be the custodian’s own database rather than the ledger. The balances are on-chain for anyone to check. All of it is paper, and all of it was true of Prime Trust on the morning of the withdrawal request.
The fourth condition is a fact about keys, and for most institutions it is a fact about a vendor. Wallet infrastructure now runs on multi-party computation platforms, where the key is never assembled and exists as shares split between the institution and the platform, plus a customer-held backup encrypted to a recovery key someone keeps, plus a recovery tool the vendor publishes. I have read one. Whether an administrator standing in what is left of the institution can run that tool, with the vendor’s systems switched off and the person who kept the recovery key gone, is the only fact Art. 242a turns on. It is a fact about a backup that was cut on one day and a workspace that kept creating keys after.
Where the institution holds only some of the shares, I read the message as saying the asset may not fall into the estate at all, because the estate lacks enough keys to act alone. The administrator then has to get hold of it before anyone can claim it out again. The passage was written about a client and a custodian sharing keys, not a custodian and its vendor, and no court has applied it either way. The administrator’s first question is the same in both readings. Can this institution sign without the vendor.
FINMA has been near this once. Its staking guidance from December 2023 devotes a section to whether tokens locked in a validator are “held ready at all times”, notes that no bankruptcy court has ruled, and calls the law uncertain. That is the same question, asked about a much smaller obstacle. An unbonding period delays a withdrawal by days. A backup nobody has restored delays it forever, and the guidance assumes throughout that control over the withdrawal keys is a fact rather than a claim.
The circular
FINMA Circular 2023/1 on operational risks and resilience has applied to banks since January 2024. It expects backup and recovery processes that are regularly tested and validated, an inventory of critical functions with a tolerance for their disruption, and exercises under severe but plausible scenarios, including ones that run for months and remove basic resources. The two-year transition ran out this January.
Read next to Art. 242a, that is the recoverability test the bankruptcy law silently assumes. Read the way bank IT reads it, it is a database restore. I have not seen a custody policy in which “recovery test” means reconstructing signing capability from the customer-held backup with the vendor unreachable. The mapping from the circular’s expectations to what a crypto custodian would actually have to show is eleven lines long, and I have not seen it in any policy either.
A Swiss bank is not a Nevada trust company, goes the objection. It has an auditor, a regulator, a reconciliation that runs every night, and it did not leave a cold wallet in a drawer. All true, and all of it checks the first three conditions. Prime Trust had an auditor too. Its register said the ether was there, and the ether was there. What was gone was the signature, and nothing in a reconciliation touches signatures. The register and the chain agree with each other right up to the moment someone tries to move something.
Which leaves a Swiss client holding a right parliament wrote down in 2020, against an estate whose ability to honour it nobody measured while the institution was still alive. The statute gives you a claim. Only a key gives you a signature.