I manage treasury questions every day, and when it comes to holding corporate bitcoin and ether, I've learned that protection and liquidity don't have to be opposing goals. You can build a treasury control framework that keeps assets secure from theft, human error, or regulatory surprises — while still allowing your business to access funds when it needs them. Below I share the practical controls I implement or recommend for CFOs who want to safeguard their crypto holdings without unnecessarily locking up liquidity.

Define your risk appetite and operational model

The first thing I do is decide what the organisation can tolerate. Is the goal to hold strategic reserves, or to manage operational cashflows and payroll? That answer drives everything: custody choices, transaction limits, and how much of your position sits in "active" wallets versus cold storage. My advice: document this clearly in a treasury policy with sign-off from the board.

Layered custody strategy: hot, warm, cold

I rarely trust a single wallet for all purposes. Instead, I adopt a layered approach:

  • Cold storage: Long-term reserves, hardware wallets or dedicated custodian vaults (e.g., Coinbase Custody, Fireblocks, BitGo). These keys are offline and used only for occasional rebalancing.
  • Warm/custodial MPC: Mid-level liquidity for larger, less frequent business needs. Multi-party computation (MPC) solutions from vendors like Fireblocks or Copper give security similar to multisig with faster recovery and easier operational workflows.
  • Hot wallets: Day-to-day operational flows, tightly limited by transaction and balance caps, monitored 24/7.
  • Separating these buckets reduces blast radius: a compromised hot wallet doesn't drain strategic reserves.

    Multisig, MPC and access controls

    I insist on threshold cryptography for any wallet that holds meaningful amounts. There are two mainstream designs that I use:

  • Multisignature (multisig): Solutions like Gnosis Safe on Ethereum provide distributed signing across multiple key-holders. I map signers to roles (CFO, Head of Ops, Legal, external custodian) and set approval thresholds appropriate to transaction size.
  • MPC / custodial threshold signing: Providers like Fireblocks, Fireblocks Cross-Chain, Copper, and BitGo offer MPC-based signing which reduces single-key risk and allows more flexible recovery.
  • In practice, I combine custodial MPC for operational needs with a multisig cold vault for strategic reserves. This hybrid gives fast execution while retaining human oversight and auditability.

    Policy-driven approvals and segregation of duties

    A technical control without process is brittle. My treasury policy codifies:

  • Transaction approval thresholds: e.g., up to $50k can be executed by Treasury Ops; $50k–$1M requires CFO + Head of Legal; >$1M requires CFO + CEO + external custodian sign-off.
  • Segregation of duties: The person executing a transaction cannot be the one authorising it. Key generation, signing, and reconciliation are separated.
  • Dual controls for withdrawal destinations: New destination addresses require multi-step approvals and a waiting period.
  • These policies should be enforced by wallet configuration, not just paperwork. Use systems that support role-based approvals and write workflows into your treasury software.

    Transaction safety mechanisms

    To avoid catastrophic mistakes or fraud I implement several on-chain and off-chain controls:

  • Address whitelisting: Only allow outgoing transfers to pre-approved addresses for specified counterparties; new addresses go through a validation challenge.
  • Time locks and cooling-off periods: For large transfers, require a timer (e.g., 24–72 hours) between approval and execution to allow cancellation on detection of compromise.
  • Tx limits and velocity controls: Daily, weekly, and per-transaction caps enforced at the wallet/service level.
  • Batching and gas control: Use batched transactions for routine payouts to reduce fees and exposure; set safe gas settings and transaction nonces to prevent replacement attacks.
  • Key ceremonies, custody hygiene and recovery

    Key generation and recovery must be planned like a bank vault opening. I insist on:

  • Documented key ceremonies: Who attends, where it happens, how seeds/keys are handled, and how backups are stored (hardware-secured, geographically separated).
  • Air-gapped seed storage: For hardware wallets: metal seed backups in secure, insured storage. For multisig, use separate custodians or keyholders.
  • Recovery playbook: A tested plan to recover keys or rotate signing parties, including engagement with vendor support and legal counsel.
  • Accounting, valuation and reporting

    Crypto requires tight, auditable records. I maintain:

  • Real-time dashboard: Aggregated balances, positions (BTC/ETH), cost basis, and unrealised P&L across providers (Fireblocks, Coinbase, Kraken, etc.).
  • Reconciliation: Daily on-chain reconciliation that matches exchange/custodian records to on-chain addresses. I use automated tools (e.g., Bitwave, CoinLedger) but keep manual spot-checks.
  • Accounting policy: Clear treatment for impairments, revaluation, and revenue recognition aligned with local GAAP/IFRS and disclosed to auditors.
  • Insurance, legal and regulatory alignment

    Insurance is not a substitute for good controls but is part of a layered defence:

  • Custodian insurance: Prefer custodians offering explicit cold-storage insurance for client assets.
  • Corporate insurance extensions: Explore crime, cyber and custody insurance for the company’s exposures.
  • Regulatory compliance: Ensure KYC/AML for counterparties, review licensing needs for custody or asset management, and maintain legal opinions for treasury activities.
  • Smart contract risk management (for Ether and tokens)

    Holding ETH often means interacting with smart contracts (staking, bridging, DeFi). I treat these as third-party risk:

  • Limit on protocol exposure: Cap how much we allocate to any single protocol and set maximum duration.
  • Audits and bug bounties: Only use audited contracts and consider insured wrap products when available.
  • Bridge risk controls: Avoid trust-minimized bridges without additional safeguards; prefer reputable bridges and monitor bridge TVL and governance risks.
  • Operational playbooks and continuous monitoring

    Execution is where policies meet reality. I enforce:

  • 24/7 monitoring: Alerts for large outgoing transactions, anomalous sign-in attempts, or sudden balance changes.
  • Periodic drills: Key compromise simulations and recovery drills at least annually.
  • Vendor due diligence: Regular assessments of custodians, wallet providers, and auditors; contractually enforce SLAs, audit rights, and data access.
  • ControlPurposeTypical Tools
    Multisig / MPCMitigate single-key compromiseGnosis Safe, Fireblocks, BitGo
    Layered custodySeparate liquidity vs reservesCold wallets, custodians, hot wallets
    Whitelisting & time locksPrevent fraud & mistakesGnosis Safe modules, custodian workflows
    Reconciliation & dashboardsAuditable books & quick detectionCoinLedger, Bitwave, in-house dashboards
    Insurance & legalTransfer residual riskCustodian policies, market insurers

    Finally, liquidity preservation is a matter of process as much as tech. I avoid sweeping everything into cold storage. Instead, I maintain a predictable operational float, automated top-ups, and pre-authorised credit lines or stablecoin liquidity arrangements for settlement needs. That way, the business never stalls because of overzealous security, and the treasury remains nimble.

    If you'd like, I can share a simple template for transaction approval thresholds, a sample key ceremony checklist, or a vendor comparison I use when evaluating custodians. Managing crypto at scale is a continuous effort, but with clear policies, layered custody, and disciplined operational controls, CFOs can protect corporate bitcoin and ether while keeping liquidity available for the company to grow.