Skip to content
Decision guide // updated July 2026

Safe vs Fireblocks vs Qualified Custody: Choosing a Crypto Custody Model

Where Safe, Fireblocks, and qualified custodians genuinely diverge in 2026, written by an official Safe partner that also wires MPC custody into client products.

TL;DR

Two things vary independently: the key-management technology (multisig, MPC, or HSM cold storage) and the legal arrangement (you self-custody, or a chartered qualified custodian holds the keys). Safe is self-custody multisig, fully on-chain and the standard for DAO and protocol treasuries. Fireblocks is MPC infrastructure that now also runs its own chartered qualified custodian, and suits high-volume institutional operations. Anchorage, Coinbase, and BitGo are qualified custodians, chartered entities that hold the keys, which run MPC or HSM internally. Many institutions run a hybrid.

Protofire is an official Safe partner (130+ Safes deployed, $2B+ secured across our deployments) and we integrate MPC custodians like Fireblocks into products; we are not affiliated with Fireblocks or any custodian, and we do not hold funds. Custody rules changed materially in 2025 to 2026 (see the regulatory note below), so the regulatory claims cite primary sources, and the guide names where self-custody is the wrong answer. See our other decision guides, including tokenizing regulated assets and stablecoin models.

Scorecard

At a glance

01Safe (multisig)02Fireblocks (MPC)03Qualified custodian
Key technologyOn-chain multisigMPC threshold signingMPC or HSM cold storage
Legal custodySelf-custodySelf-custody or via FBTCThird-party chartered
Who holds the keysYouYou, or shared with the providerThe custodian
On-chain footprintSmart-contract walletEOA-like single signatureCustodian-controlled
TransparencyFully on-chain auditableOff-chain, policy-basedCustodian attestations
DeFi composabilityNative, highestBroadLimited
Best fitDAO and protocol treasuriesHigh-volume institutional opsRegulation or mandate-driven
In detail

The three custody options

01

Safe (multisig)

Self-custody smart-account multisig
Strengths
  • +Keys stay with you, fully self-custodied, no third party holds funds
  • +On-chain and auditable: signer set, threshold, and history are public
  • +Native DeFi integration, plus Safe Modules and Safe{Core} account-abstraction support
Trade-offs
  • You own signer security and operations; a compromised signing UI can still be exploited (see the 2025 Bybit incident)
  • Uses ERC-1271 smart-contract signatures, which a few older contracts do not accept
  • Per-chain deployment, no single cross-chain identity out of the box

Safe is the smart-contract multisig standard for self-custody: signers approve transactions on-chain under a threshold you set, and Safe Modules add custom authorization such as spending limits, time-locks, and allowlists. Safe reports tens of billions in assets secured across millions of accounts, and Safe{Core} supports ERC-4337 account abstraction and passkeys. Because it is fully on-chain, anyone can audit the signer set, threshold, and every execution, and it integrates natively with DeFi. We are an official Safe partner, so this is the model we know most deeply, and it is the standard for DAO and protocol treasuries.

The trade-off is that it is shared control you operate, not a managed workflow, and on-chain transparency does not make it foolproof. The February 2025 Bybit hack, the largest crypto theft on record at roughly $1.5B, exploited a Safe multisig by compromising the signing front-end and deceiving signers into approving a malicious transaction; the contracts were fine, the humans were tricked. That is the concrete case for the discipline this model demands: a high signer threshold, transaction simulation, hardware signing, and defenses against blind-signing.

02

Fireblocks (MPC)

MPC infrastructure, now with its own qualified custody
Strengths
  • +Threshold-signature (MPC-CMP) keys with proactive share refresh; no whole key ever exists
  • +Policy engine (limits, allowlists, cooldowns) with fast, automated signing
  • +Now runs its own NYDFS-chartered qualified custodian (Fireblocks Trust Company), plus the Fireblocks Network for settlement
Trade-offs
  • The core platform is a managed vendor dependency
  • Off-chain, policy-based control is less transparent than an on-chain multisig
  • Its network and volume figures are self-reported; verify against current sources

Fireblocks is the most widely deployed MPC wallet infrastructure for institutions, with roughly $10T in cumulative secured transfers (about $6T in 2025 alone). MPC here is threshold signing (MPC-CMP, with proactive key-share refresh), not multisig: key shares are distributed so a whole key never exists in one place, and share distribution is configurable, in a self-custody setup the customer can hold all shares. A policy engine gates approvals off-chain before shares are released, and on-chain it produces one ordinary-looking signature, so lower gas, broad compatibility, and one workflow across chains.

An important 2026 correction to the old "Fireblocks is not a custodian" line: Fireblocks now operates its own NYDFS-chartered qualified custodian, Fireblocks Trust Company (used by Galaxy, FalconX, Bakkt, and others), so a regulated institution can get qualified custody from Fireblocks directly rather than only through third-party trusts. The ~2,400-organization Fireblocks Network adds direct settlement between counterparties. Peers in the MPC model include Copper, Cobo, Fordefi (DeFi-native), and Dfns. We integrate MPC custody into products as part of our custody work.

03

Qualified custodian

A chartered third party holds the keys
Strengths
  • +A chartered, regulated entity holds the keys (running MPC or HSM cold storage internally)
  • +Compliance and insurance posture that some regulations and LP mandates require
  • +Removes the key-management operational burden entirely
Trade-offs
  • You give up direct control of the keys
  • Least composable with on-chain DeFi
  • Counterparty and default risk concentrated in one entity

A qualified custodian is a chartered entity that holds the keys under a regulated trust, running MPC or HSM cold storage behind the scenes: Anchorage (OCC national trust), Coinbase Custody (NYDFS-chartered, and approved in April 2026 for an OCC national trust charter), and BitGo Trust (South Dakota and New York trust, MiCA CASP license in Germany, insurance around $250M; BitGo went public on the NYSE in January 2026). "Qualified custodian" is a legal status layered on custody technology, not a technology itself.

Infrastructure providers such as Fireblocks, Copper, Cobo, Fordefi, Dfns, and Safe are not themselves qualified custodians unless paired with a chartered entity, though Fireblocks and some peers now operate or hold their own licenses. Custody insurance is also narrower than it sounds: it typically covers third-party theft and crime up to an aggregate limit shared across all clients, not market loss, protocol hacks, or client-authorized transactions, and it is available across models, not only qualified custodians.

Verdict

Which should you use?

If your priority is
Full self-custody and on-chain transparency

you are a DAO, protocol, or team that wants keys on-chain, auditable, and DeFi-native, and you can run disciplined signing operations.

Safe
If your priority is
Institutional operations at volume, with policy controls

you need policy-gated, fast, cross-chain signing and a settlement network, with the option of qualified custody from the same vendor.

Fireblocks (MPC)
If your priority is
A regulation or mandate requires a qualified custodian

an LP, a regulator, or internal policy requires a chartered custodian to hold the keys.

Qualified custodian
If your priority is
Operational speed with a control floor

you split assets across self-custody and a custodian or MPC to balance speed against concentration risk.

Hybrid
Also consider

Other options and context

  • Exchange and prime-broker custody (Coinbase Prime, BitGo Prime): a prime broker custodies and services the assets and bundles trading, lending, and settlement on top; a fourth path alongside the three models above when you want custody packaged with execution rather than run separately.
  • Embedded and consumer wallets (Privy, Turnkey, Web3Auth, Dynamic): a different problem, custody for your end users' wallets rather than your treasury, and closer to account-abstraction onboarding than to treasury custody.
  • Regulatory currency: the US repealed SAB 121 (replaced by SAB 122 in January 2025), letting banks custody crypto, and the GENIUS Act (2025) created a federal stablecoin custody regime. In the EU, MiCA's CASP rules applied from December 2024, with legacy-VASP transition periods ending around mid-2026. Confirm the actual requirement with counsel before choosing a model.

FAQ

What is the difference between multisig and MPC custody?
A multisig (Safe) is an on-chain smart-contract wallet: several signers each hold a key, and a transaction executes when a threshold approve, all visible on-chain. MPC custody (Fireblocks and peers) splits one key into shares held off-chain and signs collaboratively, so a whole key never exists in one place; on-chain it produces one ordinary signature. Multisig is transparent, DeFi-native, and self-operated; MPC is off-chain, policy-engine-driven, cheaper in gas, consistent across chains, and a managed platform. Neither is strictly better: it depends on whether you value on-chain transparency and composability or institutional workflow controls and signing speed.
Is Fireblocks a qualified custodian?
As of 2026, it can be. Fireblocks began as MPC wallet infrastructure, not a custodian, but it now operates its own NYDFS-chartered qualified custodian, Fireblocks Trust Company, so a regulated institution can obtain qualified custody from Fireblocks directly. Other chartered qualified custodians include Anchorage (OCC), Coinbase Custody, and BitGo Trust. The distinction still matters: the base MPC platform on its own is infrastructure, and qualified custody is the separate, chartered service layered on top.
Which custody model does a DAO or protocol treasury use?
Self-custody multisig, almost always Safe, because it keeps keys with the community, is auditable on-chain, and integrates natively with DeFi. What makes it safe in practice is operational discipline: a signer threshold high enough that no two compromised or colluding signers can move funds, hardware signing and transaction simulation, and defenses against the blind-signing and compromised-UI attack that caused the 2025 Bybit theft. We deploy and harden exactly this setup as an official Safe partner.
Do I actually need a qualified custodian?
Only if a regulation, an LP mandate, or internal policy specifically requires one. A qualified custodian is a chartered entity that holds the keys, which some regulated funds must use, but it is the least composable and most hands-off model. If you are not under that obligation, self-custody (Safe) or MPC (Fireblocks and peers) usually gives more control and composability. Confirm the real requirement with counsel first, because a qualified custodian is sometimes assumed rather than actually mandated.
Can I combine custody models?
Yes, and many institutions do. A common hybrid keeps operational, DeFi-facing assets in self-custody (Safe) or MPC for speed and composability, while holding reserves with a qualified custodian to satisfy a mandate and reduce concentration risk. The models are not mutually exclusive; the design question is which assets sit where, and what controls and reporting connect them. We build these hybrid setups and the treasury operations around them.
Does Protofire hold our funds?
No. We are the engineering partner, not a custodian. As an official Safe partner we deploy and harden self-custody multisig infrastructure, and we integrate MPC custodians like Fireblocks into products, but the assets stay with you or with your chosen custodian, under an authority matrix you control. We build and operate the integration and treasury workflows around your custody, and never take custody of your funds ourselves.

Reviewed by Luis Medeiros, Field CTO at Protofire. Last updated: July 2026.

Build it

We deploy and harden Safe multisig treasuries and wire MPC custodians into products, including the authority matrix, signing policy, transaction simulation, and monitoring around them.

Fireblocks and institutional custody integration

Book a call with Alejandro Losa

Deciding on a custody model, or integrating one into your product? Talk to us about the right setup for your treasury.

Protofire 2026. All rights reserved

Message us on Telegram