Safe vs Fireblocks vs Qualified Custody: Choosing a Crypto Custody Model
Where Safe, Fireblocks, and qualified custodians genuinely diverge in 2026, written by an official Safe partner that also wires MPC custody into client products.
Two things vary independently: the key-management technology (multisig, MPC, or HSM cold storage) and the legal arrangement (you self-custody, or a chartered qualified custodian holds the keys). Safe is self-custody multisig, fully on-chain and the standard for DAO and protocol treasuries. Fireblocks is MPC infrastructure that now also runs its own chartered qualified custodian, and suits high-volume institutional operations. Anchorage, Coinbase, and BitGo are qualified custodians, chartered entities that hold the keys, which run MPC or HSM internally. Many institutions run a hybrid.
Protofire is an official Safe partner (130+ Safes deployed, $2B+ secured across our deployments) and we integrate MPC custodians like Fireblocks into products; we are not affiliated with Fireblocks or any custodian, and we do not hold funds. Custody rules changed materially in 2025 to 2026 (see the regulatory note below), so the regulatory claims cite primary sources, and the guide names where self-custody is the wrong answer. See our other decision guides, including tokenizing regulated assets and stablecoin models.
At a glance
| 01Safe (multisig) | 02Fireblocks (MPC) | 03Qualified custodian | |
|---|---|---|---|
| Key technology | On-chain multisig | MPC threshold signing | MPC or HSM cold storage |
| Legal custody | Self-custody | Self-custody or via FBTC | Third-party chartered |
| Who holds the keys | You | You, or shared with the provider | The custodian |
| On-chain footprint | Smart-contract wallet | EOA-like single signature | Custodian-controlled |
| Transparency | Fully on-chain auditable | Off-chain, policy-based | Custodian attestations |
| DeFi composability | Native, highest | Broad | Limited |
| Best fit | DAO and protocol treasuries | High-volume institutional ops | Regulation or mandate-driven |
The three custody options
Safe (multisig)
- +Keys stay with you, fully self-custodied, no third party holds funds
- +On-chain and auditable: signer set, threshold, and history are public
- +Native DeFi integration, plus Safe Modules and Safe{Core} account-abstraction support
- −You own signer security and operations; a compromised signing UI can still be exploited (see the 2025 Bybit incident)
- −Uses ERC-1271 smart-contract signatures, which a few older contracts do not accept
- −Per-chain deployment, no single cross-chain identity out of the box
Safe is the smart-contract multisig standard for self-custody: signers approve transactions on-chain under a threshold you set, and Safe Modules add custom authorization such as spending limits, time-locks, and allowlists. Safe reports tens of billions in assets secured across millions of accounts, and Safe{Core} supports ERC-4337 account abstraction and passkeys. Because it is fully on-chain, anyone can audit the signer set, threshold, and every execution, and it integrates natively with DeFi. We are an official Safe partner, so this is the model we know most deeply, and it is the standard for DAO and protocol treasuries.
The trade-off is that it is shared control you operate, not a managed workflow, and on-chain transparency does not make it foolproof. The February 2025 Bybit hack, the largest crypto theft on record at roughly $1.5B, exploited a Safe multisig by compromising the signing front-end and deceiving signers into approving a malicious transaction; the contracts were fine, the humans were tricked. That is the concrete case for the discipline this model demands: a high signer threshold, transaction simulation, hardware signing, and defenses against blind-signing.
Fireblocks (MPC)
- +Threshold-signature (MPC-CMP) keys with proactive share refresh; no whole key ever exists
- +Policy engine (limits, allowlists, cooldowns) with fast, automated signing
- +Now runs its own NYDFS-chartered qualified custodian (Fireblocks Trust Company), plus the Fireblocks Network for settlement
- −The core platform is a managed vendor dependency
- −Off-chain, policy-based control is less transparent than an on-chain multisig
- −Its network and volume figures are self-reported; verify against current sources
Fireblocks is the most widely deployed MPC wallet infrastructure for institutions, with roughly $10T in cumulative secured transfers (about $6T in 2025 alone). MPC here is threshold signing (MPC-CMP, with proactive key-share refresh), not multisig: key shares are distributed so a whole key never exists in one place, and share distribution is configurable, in a self-custody setup the customer can hold all shares. A policy engine gates approvals off-chain before shares are released, and on-chain it produces one ordinary-looking signature, so lower gas, broad compatibility, and one workflow across chains.
An important 2026 correction to the old "Fireblocks is not a custodian" line: Fireblocks now operates its own NYDFS-chartered qualified custodian, Fireblocks Trust Company (used by Galaxy, FalconX, Bakkt, and others), so a regulated institution can get qualified custody from Fireblocks directly rather than only through third-party trusts. The ~2,400-organization Fireblocks Network adds direct settlement between counterparties. Peers in the MPC model include Copper, Cobo, Fordefi (DeFi-native), and Dfns. We integrate MPC custody into products as part of our custody work.
Qualified custodian
- +A chartered, regulated entity holds the keys (running MPC or HSM cold storage internally)
- +Compliance and insurance posture that some regulations and LP mandates require
- +Removes the key-management operational burden entirely
- −You give up direct control of the keys
- −Least composable with on-chain DeFi
- −Counterparty and default risk concentrated in one entity
A qualified custodian is a chartered entity that holds the keys under a regulated trust, running MPC or HSM cold storage behind the scenes: Anchorage (OCC national trust), Coinbase Custody (NYDFS-chartered, and approved in April 2026 for an OCC national trust charter), and BitGo Trust (South Dakota and New York trust, MiCA CASP license in Germany, insurance around $250M; BitGo went public on the NYSE in January 2026). "Qualified custodian" is a legal status layered on custody technology, not a technology itself.
Infrastructure providers such as Fireblocks, Copper, Cobo, Fordefi, Dfns, and Safe are not themselves qualified custodians unless paired with a chartered entity, though Fireblocks and some peers now operate or hold their own licenses. Custody insurance is also narrower than it sounds: it typically covers third-party theft and crime up to an aggregate limit shared across all clients, not market loss, protocol hacks, or client-authorized transactions, and it is available across models, not only qualified custodians.
Which should you use?
you are a DAO, protocol, or team that wants keys on-chain, auditable, and DeFi-native, and you can run disciplined signing operations.
you need policy-gated, fast, cross-chain signing and a settlement network, with the option of qualified custody from the same vendor.
an LP, a regulator, or internal policy requires a chartered custodian to hold the keys.
you split assets across self-custody and a custodian or MPC to balance speed against concentration risk.
Other options and context
- Exchange and prime-broker custody (Coinbase Prime, BitGo Prime): a prime broker custodies and services the assets and bundles trading, lending, and settlement on top; a fourth path alongside the three models above when you want custody packaged with execution rather than run separately.
- Embedded and consumer wallets (Privy, Turnkey, Web3Auth, Dynamic): a different problem, custody for your end users' wallets rather than your treasury, and closer to account-abstraction onboarding than to treasury custody.
- Regulatory currency: the US repealed SAB 121 (replaced by SAB 122 in January 2025), letting banks custody crypto, and the GENIUS Act (2025) created a federal stablecoin custody regime. In the EU, MiCA's CASP rules applied from December 2024, with legacy-VASP transition periods ending around mid-2026. Confirm the actual requirement with counsel before choosing a model.
FAQ
What is the difference between multisig and MPC custody?
Is Fireblocks a qualified custodian?
Which custody model does a DAO or protocol treasury use?
Do I actually need a qualified custodian?
Can I combine custody models?
Does Protofire hold our funds?
Reviewed by Luis Medeiros, Field CTO at Protofire. Last updated: July 2026.
We deploy and harden Safe multisig treasuries and wire MPC custodians into products, including the authority matrix, signing policy, transaction simulation, and monitoring around them.
Fireblocks and institutional custody integration →