I manage treasury decisions every day with an eye for both protection and flexibility. When a company holds meaningful amounts of bitcoin or ether, the CFO must balance the need to secure assets against operational demands for liquidity. Below I outline precise, actionable controls I recommend implementing to protect corporate crypto holdings without unnecessarily blocking liquidity. These are grounded in real-world practices, industry tools, and regulatory realities—intended to be practical for firms ranging from startups to publicly listed companies.
Governance and policy foundations
Start by formalizing crypto treasury policy. A clear, written policy is the foundation for every downstream control.
Define scope and custodial model: Specify which assets are approved (BTC, ETH, stablecoins), what percentage of liquidity can be held in crypto, and whether custody will be self-custody, institutional custody (e.g., Coinbase Custody, BitGo, Fireblocks), or a hybrid model.Segregation of duties: Create roles for approval, execution, reconciliation, and audit. The person authorizing a transfer should not be the one executing it.Approval matrix: Establish monetary and situational thresholds. Example: transfers above $250k require CFO + COO sign-off; above $2M requires board sign-off.Risk appetite and limits: Set concentration limits per exchange/counterparty, percentage of treasury in staking/DeFi, and maximum open exposure to smart-contract risk.Custody and key management
Custody choices dramatically affect security and liquidity. The right control depends on your risk tolerance and operational needs.
Prefer institutional custody for material balances: Providers like Fireblocks, BitGo, and Coinbase Custody offer MPC/multisig and insured solutions while maintaining good API-driven liquidity.Multisignature arrangements: If self-custody, use multisig wallets (e.g., Gnosis Safe for Ethereum). Implement n-of-m with geographically and organizationally separated signers—e.g., 3-of-5 where signers include CFO, CTO, Head of Legal, external custodian, and an independent director.Hardware security: Hardware wallets such as Ledger or HSMs in combination with a multisig design add layers. Keep hardware keys in separate physical secure locations (bank safe deposit boxes, secure data centers).Key lifecycle management: Maintain a documented process for key generation, backup (sharded backups with Shamir Secret Sharing if appropriate), rotation, and secure decommissioning. Test recovery annually with dry runs.Transaction controls and approvals
Design controls that prevent rogue transfers but allow efficient operations.
Pre-signed vaults and time locks: Use transaction time-lock windows for large outflows (e.g., a 24–72 hour time lock for transfers > $500k) to allow cancellation if suspicious.Dual approvals for outgoing transfers: Require at least two independent approvers for non-routine transfers. One can be an automated treasury system and the other a human signer.Whitelist addresses: Maintain a managed whitelist of authorized counterparties and hot wallet addresses. Require approvals for any new address addition by the board or delegated committee.Liquidity management without blocking access
Protecting assets shouldn’t mean locking them up forever. Use layered liquidity strategies.
Hot vs. warm vs. cold wallet architecture: Keep minimal hot wallet balances for day-to-day operations (payroll, merchant processing), a warm wallet for routine larger flows, and cold storage for long-term reserves.Automated replenishment rules: Configure thresholds where warm wallets automatically top up from cold storage subject to pre-approved limits and time locks.Use institutional liquidity providers: Maintain relationships with several custodial exchanges and OTC desks to execute large trades with minimal market impact—examples include Cumberland, Genesis, or Coinbase Prime.Settlement and settlement guarantees: For fiat off-ramps, test settlement windows and keep correspondent banking relationships up-to-date to avoid fiat liquidity churns.Counterparty and market risk controls
Diversify counterparties and limit exposure.
Counterparty concentration limits: Cap exposure to any single exchange/custodian (e.g., no more than 25% of total crypto holdings).Credit and due diligence: Perform KYC, financial health reviews, and operational audits of custodians and OTC partners. Review legal protections and segregation of client assets.Use limit orders and VWAP strategies: When converting crypto to fiat, use execution strategies (VWAP, TWAP) and algos to reduce market impact.Staking, DeFi, and yield strategies—controls to enable yield without undue risk
Yield can be attractive but requires explicit guardrails.
Approval for yield strategies: Any staking or DeFi activity above a small operational threshold should require a formal approval process and a documented security review.Smart-contract risk limits: Limit exposure per protocol (e.g., max $X or max % of treasury). Use audited protocols and track insurance coverage where available.Trusted intermediaries: Consider institutional staking providers (e.g., Lido, Kraken, Coinbase) that offer SLAs, and ensure you understand custodian custody when delegated staking is used.Monitoring, reconciliation, and reporting automation
Visibility is critical for both security and compliance.
Real-time monitoring: Implement continuous monitoring tools (e.g., Chainalysis, Elliptic, Arkham) to detect suspicious flows, address tagging, and blacklisting.Automated reconciliations: Reconcile on-chain balances with custodial reports daily. Use tools or internal scripts that check addresses, transactions, and balances against ledger entries.Accounting and valuations: Standardize valuation methodology (e.g., mark-to-market method and cut-off times). Ensure accounting systems support crypto entries and impairment rules per IFRS/GAAP guidance.Regulatory reporting: Keep AML/KYC/CDD records and be prepared for tax reporting. Coordinate with legal and external counsel for cross-jurisdictional holdings.Incident response and insurance
Prepare for breaches and losses with a tested plan and financial mitigants.
Incident response playbook: Create a documented, rehearsed incident response plan covering theft, loss of keys, counterparty failure, and smart-contract exploits. Define escalation paths and external contacts (forensic firms, law enforcement, counsel).Insurance coverage: Explore crime and custody insurance through providers like Lloyd’s syndicates or specialized policy brokers. Understand exclusions (social engineering, unauthorised transacting) and limits.Recovery drills: Run periodic tabletop exercises and recovery tests (e.g., multisig signer swaps, private key recoveries) with independent observers.Internal controls, audits, and third-party assurance
Independent verification builds confidence with stakeholders.
Internal audit cadence: Schedule internal audits for custody, reconciliations, and policy compliance at least semi-annually.External attestations: Obtain SOC 2 or audit reports from custodians, and consider third-party penetration testing for treasury systems. Engage external auditors to verify holdings for financial reporting periods.Board oversight and transparency: Provide the board with periodic reports that include current holdings, counterparty exposure, and summary of material transactions and incidents.Practical checklist for implementation
| Governance | Written crypto treasury policy, approval matrix |
| Custody | Institutional custody or multisig + HSM, key rotation plan |
| Transaction | Whitelist, dual approvals, time-locks |
| Liquidity | Hot/warm/cold tiers, automated replenishment, OTC relationships |
| Monitoring | On-chain analytics, automated reconciliations, alerts |
| Risk | Counterparty limits, smart-contract exposure caps |
| Incident | Response playbook, insurance, recovery drills |
These controls deliver both protection and operational liquidity by combining sound governance, modern custody practices, automated monitoring, and thoughtful counterparty diversification. In practice I recommend starting with a short, implementable policy, deploying a multi-tier custody model, and integrating continuous monitoring. Over time expand into more sophisticated yield strategies or DeFi only after stress-testing your recovery and legal frameworks. With the right mix, CFOs can hold BTC and ETH as strategic assets while preserving the ability to deploy capital when opportunities or obligations arise.