Client Staking on Assets the Institution Already Holds in Custody
How a bank, broker or MiCA-authorised CASP adds staking to crypto custody it already operates - renting the validator operation, and building the part no vendor supplies: the per-customer reward record that a statement, a tax return and an audit are built from.
- Maturity
- Proven
- Model
- Native staking
- Proven stack
- Kiln · Figment · Blockdaemon · Sygnum
- Last verified
- August 2026
Reviewed by Andrei Yurkevich, Founding Member at Protofire
PostFinance's interval from crypto trading (21 Feb 2024) to ETH staking (16 Jan 2025) - the library's sequencing evidence.
At the verification date no MiCA-authorised EU retail bank was publicly documented running this pattern. The strongest retail references are Swiss banks supervised by FINMA, outside MiCA entirely.
01. The opportunity
An institution that already lets clients buy and hold crypto is sitting on idle proof-of-stake assets and a client base asking what those assets earn. Staking answers that without a new asset class, a new distribution channel or a new authorisation: the same custodied balance is delegated to validators, protocol rewards accrue against it, and the institution earns a disclosed commission on those rewards. The validator operation is rented from a staking provider. What cannot be rented is the record of which customer earned what, on which date, at what value, because that record is what a statement, a tax return and an audit are built from.
The sequencing evidence is unusually clear: PostFinance brought trading and custody live with Sygnum in February 2024 and added Ethereum staking about eleven months later, in January 2025. The timing is not arbitrary. Since ESMA's Q&A of 20 June 2024, the regulatory route is settled enough to plan against - staking-as-a-service sits inside MiCA as an activity ancillary to custody, rather than needing its own authorisation. And from 1 January 2026 the EU's DAC8 obligations took effect alongside the OECD Crypto-Asset Reporting Framework, so a reward stream that used to be an internal accounting matter is now reportable data with a filing date attached.
02. The regulatory position
03. Who's already done this
Ethereum staking in the PostFinance app and e-finance, minimum 0.1 ETH, twelve-week period before rewards are distributed, native staking directly on the network, roughly 2.5 million clients. The closest thing to a template for a retail bank, and the conservative shape: one asset, a minimum, and a disclosed waiting period.
Ethereum staking offered to clients, with an indicative annual rate published on its own terms page and no minimum withdrawal period at the time of publication. The broker-shaped variant, and a useful contrast to PostFinance on exit terms. The published rate is a provider figure that moves with the protocol and should not be quoted as current.
White-label ETH staking through Kiln Onchain. Kiln's case study of 24 January 2023 reports more than USD 65 million of ETH staked and 515 unique stakers in the first two months, implying an average position in the order of USD 126,000 - the only granular public unit economics for this pattern anywhere, and evidence the early adopters were large holders rather than mass retail. Provider-published figures from early 2023.
Institutional staking through Kiln across TON, ETH, DOT, ADA and BNB. The custodian-fronted variant, where the custodian rather than the end institution integrates the staking provider. Availability is provider-published; the launch date was not independently confirmed.
04. Does this fit you?
If you already run crypto trading and custody in your own channel, hold proof-of-stake assets for retail or wealth clients, and are roughly a year past that launch - yes, and the sequencing evidence says this is when institutions reach it.
Probably not if your custody is not yet live (start there), if your client balances are mostly stablecoin rather than proof-of-stake assets (a lending structure fits better), if your clients want to borrow against holdings rather than earn on them, or if you have promised same-day access to holdings - protocol unbonding periods and exit queues are not something integration work removes.
05. The stack, layer by layer
Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.
Custody, the client relationship and the reporting channel
The authorisation or a licensed partner's rail, custody of the assets to be staked, the client relationship with its onboarding and suitability process, and the app, statement and tax-reporting channel. BP-1 must already be live: this pattern has a hard prerequisite on crypto trading and custody being in production.
Validator operation
Validator operation across the supported protocols, construction of delegate, claim and unstake instructions, and reward data at position level with an aggregate performance view. Not included by design: no custody, no client onboarding, no per-customer reward attribution against the institution's own ledger, no statement and no tax extract.
The reward record and the verification around it
Integration into custody and the core ledger with staked and spot balances reconciled; per-customer, per-epoch reward records valued at the date received, and the statement and reporting extracts drawn from them; independent verification of every constructed instruction before signing, plus the exposure limits that bound it; and the consent, disclosure and unbonding-expectation language with out-of-hours cover. The record is what cannot be rented.
06. Keep in mind
- The reward record is the part you build. Three providers have named production references at the validator and instruction-construction layer - Kiln, Figment and Blockdaemon - but none supplies per-customer reward attribution against an institution's own ledger, and no proven provider for that layer was identified at all. It is where most of the build cost and time will go, because there is nothing to buy.
- The staking provider authors the instructions you sign. A compromise there does not need custody access to cause a loss. In September 2025 roughly 192,600 SOL - about $41M - was drained from SwissBorg's Solana earn product through Kiln's interface, and SwissBorg reimbursed its customers from its own treasury. Independent verification of every instruction before signing, together with exposure limits, is treated here as essential.
- The liability sits with the institution by default. Staking is not a service MiCA lists, so there is nothing to apply for; ESMA's Q&A of 20 June 2024 brings it into scope as an activity ancillary to custody. MiCA Art. 75(8) leaves the institution liable for losses of client crypto-assets attributable to it, and ESMA reads that to cover losses arising from staking. Explicit per-customer consent to stake is required, because staking changes when the client can reach the asset.
- Reward events became reportable on 1 January 2026. DAC8 and the OECD Crypto-Asset Reporting Framework took effect in EU member states, with self-certification collected from 2026 and first reports to domestic tax authorities due in 2027.
Request the full blueprint
This is the short version. The full blueprint is a single document your counsel and board can read cold, and a third-party-risk function can lift wholesale. Leave your work email and your personal link arrives in your inbox.
- The regulatory position, stated article by article
- Proven options at each layer, with the vendors that hold up
- The risk table with a named owner for each risk
- The division of labour: what is rented, built, and operated
- The third-party-risk pack a DORA governance function can lift
- The delivery path, step by step, with the monitoring and incident model
FAQ
How is staking-as-a-service treated under MiCA?
Staking is not one of the crypto-asset services listed in MiCA Art. 3(1)(16), so there is no staking authorisation to apply for. ESMA Q&A 2067 of 20 June 2024 holds staking-as-a-service to be covered because the assets or the keys are held in custody, making it ancillary to custody, so a CASP offering it must comply with Arts. 59, 62 and 66-75. Art. 75(8) keeps the institution liable for attributable losses, explicit client consent is required, and Arts. 40 and 50 mean the pattern runs on proof-of-stake assets only.
Which institutions already offer retail staking on top of custody?
PostFinance, a systemically important Swiss bank supervised by FINMA, added Ethereum staking with Sygnum on 16 January 2025, with a minimum of 0.1 ETH, native staking on the network, and a twelve-week period before rewards are distributed, serving roughly 2.5 million clients. Swissquote, a FINMA-supervised Swiss bank and broker, offers Ethereum staking with an indicative published rate and no minimum withdrawal period. Both are the strongest retail references, and both sit outside MiCA under FINMA supervision.
What is the hard prerequisite for adding staking, and what does the institution build itself?
Adding staking presumes crypto trading and custody are already live, because the delegation has nothing to delegate otherwise. The institution owns the authorisation, custody, the client relationship and the reporting channel. It rents the validator operation across supported protocols from providers such as Kiln, Sygnum, Blockdaemon or Taurus. The part no vendor supplies, and the institution builds itself, is the per-customer, per-epoch reward record valued at the date received, the statement and tax extracts drawn from it, and independent verification of every constructed instruction before signing.
Already evaluating this for your institution?
When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.
Run this pattern in production, or tried to and stopped? .


