I manage treasury questions every day, and when it comes to holding corporate bitcoin and ether, I've learned that protection and liquidity don't have to be opposing goals. You can build a treasury control framework that keeps assets secure from theft, human error, or regulatory surprises — while still allowing your business to access funds when it needs them. Below I share the practical controls I implement or recommend for CFOs who want to safeguard their crypto holdings without unnecessarily locking up liquidity.
Define your risk appetite and operational model
The first thing I do is decide what the organisation can tolerate. Is the goal to hold strategic reserves, or to manage operational cashflows and payroll? That answer drives everything: custody choices, transaction limits, and how much of your position sits in "active" wallets versus cold storage. My advice: document this clearly in a treasury policy with sign-off from the board.
Layered custody strategy: hot, warm, cold
I rarely trust a single wallet for all purposes. Instead, I adopt a layered approach:
Cold storage: Long-term reserves, hardware wallets or dedicated custodian vaults (e.g., Coinbase Custody, Fireblocks, BitGo). These keys are offline and used only for occasional rebalancing.Warm/custodial MPC: Mid-level liquidity for larger, less frequent business needs. Multi-party computation (MPC) solutions from vendors like Fireblocks or Copper give security similar to multisig with faster recovery and easier operational workflows.Hot wallets: Day-to-day operational flows, tightly limited by transaction and balance caps, monitored 24/7.Separating these buckets reduces blast radius: a compromised hot wallet doesn't drain strategic reserves.
Multisig, MPC and access controls
I insist on threshold cryptography for any wallet that holds meaningful amounts. There are two mainstream designs that I use:
Multisignature (multisig): Solutions like Gnosis Safe on Ethereum provide distributed signing across multiple key-holders. I map signers to roles (CFO, Head of Ops, Legal, external custodian) and set approval thresholds appropriate to transaction size.MPC / custodial threshold signing: Providers like Fireblocks, Fireblocks Cross-Chain, Copper, and BitGo offer MPC-based signing which reduces single-key risk and allows more flexible recovery.In practice, I combine custodial MPC for operational needs with a multisig cold vault for strategic reserves. This hybrid gives fast execution while retaining human oversight and auditability.
Policy-driven approvals and segregation of duties
A technical control without process is brittle. My treasury policy codifies:
Transaction approval thresholds: e.g., up to $50k can be executed by Treasury Ops; $50k–$1M requires CFO + Head of Legal; >$1M requires CFO + CEO + external custodian sign-off.Segregation of duties: The person executing a transaction cannot be the one authorising it. Key generation, signing, and reconciliation are separated.Dual controls for withdrawal destinations: New destination addresses require multi-step approvals and a waiting period.These policies should be enforced by wallet configuration, not just paperwork. Use systems that support role-based approvals and write workflows into your treasury software.
Transaction safety mechanisms
To avoid catastrophic mistakes or fraud I implement several on-chain and off-chain controls:
Address whitelisting: Only allow outgoing transfers to pre-approved addresses for specified counterparties; new addresses go through a validation challenge.Time locks and cooling-off periods: For large transfers, require a timer (e.g., 24–72 hours) between approval and execution to allow cancellation on detection of compromise.Tx limits and velocity controls: Daily, weekly, and per-transaction caps enforced at the wallet/service level.Batching and gas control: Use batched transactions for routine payouts to reduce fees and exposure; set safe gas settings and transaction nonces to prevent replacement attacks.Key ceremonies, custody hygiene and recovery
Key generation and recovery must be planned like a bank vault opening. I insist on:
Documented key ceremonies: Who attends, where it happens, how seeds/keys are handled, and how backups are stored (hardware-secured, geographically separated).Air-gapped seed storage: For hardware wallets: metal seed backups in secure, insured storage. For multisig, use separate custodians or keyholders.Recovery playbook: A tested plan to recover keys or rotate signing parties, including engagement with vendor support and legal counsel.Accounting, valuation and reporting
Crypto requires tight, auditable records. I maintain:
Real-time dashboard: Aggregated balances, positions (BTC/ETH), cost basis, and unrealised P&L across providers (Fireblocks, Coinbase, Kraken, etc.).Reconciliation: Daily on-chain reconciliation that matches exchange/custodian records to on-chain addresses. I use automated tools (e.g., Bitwave, CoinLedger) but keep manual spot-checks.Accounting policy: Clear treatment for impairments, revaluation, and revenue recognition aligned with local GAAP/IFRS and disclosed to auditors.Insurance, legal and regulatory alignment
Insurance is not a substitute for good controls but is part of a layered defence:
Custodian insurance: Prefer custodians offering explicit cold-storage insurance for client assets.Corporate insurance extensions: Explore crime, cyber and custody insurance for the company’s exposures.Regulatory compliance: Ensure KYC/AML for counterparties, review licensing needs for custody or asset management, and maintain legal opinions for treasury activities.Smart contract risk management (for Ether and tokens)
Holding ETH often means interacting with smart contracts (staking, bridging, DeFi). I treat these as third-party risk:
Limit on protocol exposure: Cap how much we allocate to any single protocol and set maximum duration.Audits and bug bounties: Only use audited contracts and consider insured wrap products when available.Bridge risk controls: Avoid trust-minimized bridges without additional safeguards; prefer reputable bridges and monitor bridge TVL and governance risks.Operational playbooks and continuous monitoring
Execution is where policies meet reality. I enforce:
24/7 monitoring: Alerts for large outgoing transactions, anomalous sign-in attempts, or sudden balance changes.Periodic drills: Key compromise simulations and recovery drills at least annually.Vendor due diligence: Regular assessments of custodians, wallet providers, and auditors; contractually enforce SLAs, audit rights, and data access. | Control | Purpose | Typical Tools |
| Multisig / MPC | Mitigate single-key compromise | Gnosis Safe, Fireblocks, BitGo |
| Layered custody | Separate liquidity vs reserves | Cold wallets, custodians, hot wallets |
| Whitelisting & time locks | Prevent fraud & mistakes | Gnosis Safe modules, custodian workflows |
| Reconciliation & dashboards | Auditable books & quick detection | CoinLedger, Bitwave, in-house dashboards |
| Insurance & legal | Transfer residual risk | Custodian policies, market insurers |
Finally, liquidity preservation is a matter of process as much as tech. I avoid sweeping everything into cold storage. Instead, I maintain a predictable operational float, automated top-ups, and pre-authorised credit lines or stablecoin liquidity arrangements for settlement needs. That way, the business never stalls because of overzealous security, and the treasury remains nimble.
If you'd like, I can share a simple template for transaction approval thresholds, a sample key ceremony checklist, or a vendor comparison I use when evaluating custodians. Managing crypto at scale is a continuous effort, but with clear policies, layered custody, and disciplined operational controls, CFOs can protect corporate bitcoin and ether while keeping liquidity available for the company to grow.