settlematic
Guides·11 min read·By Keshav Sharma

Custodial vs. Non-Custodial Crypto Payment Processors, Explained Simply

Custodial processors hold your funds; non-custodial ones never can. See what the Celsius rulings, 2025 hack data, and MiCA/FCA rules mean for merchants.

Do this next

Compare custody models

  1. Custodial processors hold keys and convert.
  2. Non-custodial settlement binds addresses to your wallet.
  3. Use the table below for the attribute-level split.

A custodial crypto payment processor takes possession of customer payments in a pooled balance and settles to you on a schedule, usually for 0.5-2% of volume. A non-custodial processor routes each payment directly to an address you control and only watches the chain. The difference decides who can freeze, delay, or lose your money.

TL;DR

A custodial crypto payment processor receives your customers' money into wallets it controls, then pays you out on its own schedule — you are its creditor until it does. A non-custodial processor never controls the funds; payments settle directly to wallets whose keys only you hold. The difference is invisible on a good day and decisive on a bad one.

Settlematic sweep destinations settings with destination addresses configured across EVM, Bitcoin, Solana, and Tron chain families

The clearest proof of that isn't a whitepaper. It's a bankruptcy court ruling, and we'll get to it in a moment.

The one question that separates the two models

Forget the marketing language for a second. Every crypto payment provider on the market answers to a single question:

If this company disappeared tomorrow — hacked, frozen, insolvent, or served with a court order — could my customers' in-flight payments disappear with it?

If yes, it's custodial. If no, it's non-custodial. Everything else is implementation detail.

Custody, in regulatory terms

Custody, in regulatory terms, is not about who says they own the funds. It's about who holds the private keys. Under Article 3(1)(17) of MiCAR, custody means the safekeeping of crypto-assets or the means of access to them — private cryptographic keys — or the exercise of control over those assets on a client's behalf. The UK takes the same view: safeguarding covers custody on behalf of another person, including control of the means of access such as private cryptographic keys.

Keys equal custody. That's the whole test.

What a custodial processor actually does with your money

Providers like BitPay, CoinGate, and Coinbase Commerce operate on a broadly similar shape:

  • You generate an invoice or checkout session.
  • Your customer sends crypto to an address the processor controls.
  • The processor confirms the payment and credits your account balance.
  • On its own schedule — daily, weekly, T+1, T+3 — it sends you fiat or crypto.

Between steps 3 and 4, your money is on the processor's balance sheet. That gap is called float, and during it you're an unsecured creditor of a private company. You have a claim, not an asset.

For most merchants, most of the time, this is completely fine and quite convenient. The processor handles fiat conversion, chargeback-style dispute handling, tax reporting, and bank settlement. That's real value. The question is what you're paying for it in tail risk.

What a non-custodial processor does instead

A non-custodial processor watches the blockchain instead of holding the money.

  • You configure settlement destinations — wallets you control.
  • The processor derives a unique deposit address bound to your destination at issuance.
  • Your customer pays that address.
  • The processor detects the confirmation on-chain, reconciles it to the invoice, fires webhooks, and updates your ledger.

Funds never enter a pooled processor wallet. There's no payout queue because there's no payout — the money was already yours the moment it confirmed on-chain.

The critical design detail is address binding. A per-payment address is not automatically non-custodial; plenty of custodial processors issue unique addresses too, and even with unique addresses, deposit keys stay with the processor. What makes it non-custodial is that the destination is cryptographically fixed when the address is created and cannot be redirected afterward — not by the processor, not by a compromised dashboard, not by a rogue employee.

The Celsius ruling: the same platform, two outcomes

Here's the case study that makes this concrete, and it's the strongest available evidence that custody structure decides outcomes.

Celsius froze withdrawals in June 2022 and entered bankruptcy. Customers had money on the same platform, under the same brand, with the same login. But they were in two different products:

  • Earn accounts — customers deposited assets and received interest.
  • Custody accounts — customers' assets were held on their behalf.

The court ruled that assets in interest-bearing Earn accounts became property of the bankruptcy estate, because Celsius's Terms of Use transferred ownership to the company; those holders became general unsecured creditors. Custody-account holders were treated as retaining their own crypto through the case's later proceedings and plan.

The recovery gap that followed:

Account typeLegal statusRecovery
Custody accountsAssets remained the customer's100% — $425 million distributed as of January 2026
Earn accountsUnsecured creditor claimBetween 15% and 72% depending on creditor class

Same company. Same collapse. The only variable was the legal and technical structure of who held the asset. More than 600,000 creditors filed claims totalling over $4.7 billion, against an estate that recovered roughly $2 billion.

It's worth being fair here: the more famous custodial failure ended far better than anyone predicted. FTX has distributed $10.3 billion to date, bringing repayment to 96.6% of FTX.com customer claims and 100% for FTX.US customers, with around 98% of creditors set to receive 119% of their allowed claim as valued in November 2022.

But read the fine print on that recovery. The strong outcome is attributed to asset appreciation, litigation settlements, and rising crypto prices — and claims were valued using November 2022 prices, a model some creditors argue undervalues them badly against current market rates. A merchant who was owed a $50,000 settlement in November 2022 got made whole in nominal 2022 dollars — after three and a half years of litigation.

That's the realistic custodial downside. Not necessarily zero. But locked up, litigated, and valued at the worst possible moment.

The 2025–26 threat data: risk is concentrating in centralised services

If custodial risk were shrinking, this would be an academic debate. It isn't.

Chainalysis recorded US$3.4 billion stolen from January through early December 2025, with the Bybit attack on 21 February 2025 accounting for nearly US$1.5 billion in a single day — the largest digital-asset heist ever attributed. The top three hacks accounted for 69% of all losses, and the ratio between the largest hack and the median incident crossed 1,000x for the first time.

The directional finding matters more than the headline number:

Individual wallet compromises surged to 158,000 incidents, but total value stolen from individuals actually declined from $1.5 billion to $713 million. The threat is increasingly concentrated in centralized services. Exchanges and custodians, despite institutional security teams, remain vulnerable to sophisticated attacks on private key infrastructure and signing processes.

Individual attacks are getting more frequent and less lucrative. Attacks on pooled custodians are getting rarer and vastly more lucrative. That's exactly what you'd predict from an attacker optimising for return: pooled funds are a bigger prize than your funds.

And this isn't opportunistic crime any more. DPRK-linked hackers alone stole $2 billion in 2025, in what was their most destructive year yet in both value stolen and sophistication of intrusion and laundering tactics.

Non-custodial architecture doesn't make you unhackable. It makes you a small target instead of part of a large one.

What regulators in your market now require

Regulation has broadly settled the definitional question in the last eighteen months, and it settled it around control of keys — which has direct consequences for how each model is treated.

European Union (including Cyprus, Ireland, Malta, Germany)

Under MiCA, crypto-asset service providers must be authorised to provide crypto-asset services in the EU, with the EU-wide transition period ending on 1 July 2026. After that date, any entity providing crypto-asset services to EU clients without a MiCA licence must cease offering those services. Cyprus firms fall under this via CySEC as national competent authority.

Custody is a licensed activity carrying real capital: €125,000 in own funds for custody and exchange services, versus €50,000 for advisory. Custodial providers must segregate client assets from company funds and reconcile daily, use secure cold storage and multi-signature key management, and maintain clear custody agreements. They also carry ongoing obligations including assigning each client an individual register of positions and reporting on deposited assets at least quarterly.

United Kingdom

The UK finalised its position this summer. The Cryptoassets Regulations bring a broad range of cryptoasset activities within the FCA's regulatory perimeter from 25 October 2027, with FCA applications scheduled from 30 September 2026 to 28 February 2027. On 30 June 2026 the FCA published policy statement PS26/10 confirming final rules for UK-issued qualifying stablecoins.

Notably, the FCA has been asked directly how custody and safeguarding requirements will apply to self-custody, non-custodial technology providers, and firms holding cryptoassets on behalf of clients — an open question worth watching if you operate in the UK. On safeguarding, the FCA is adopting a technology-agnostic approach to private key management and clarifying the scope of control-based application. Control remains the test.

United States

The GENIUS Act created a federal stablecoin framework and removes compliant payment stablecoins from the federal definitions of "security" and "commodity," putting banking regulators in charge instead of the SEC and CFTC. Critically for self-custody, the Act carves out any transaction by means of a software or hardware wallet that facilitates an individual's own custody of digital assets.

Legal analysts note the flip side for intermediaries: wallet providers and payment platforms that connect to these systems may face scrutiny if they indirectly touch customer assets or transaction flows. "Indirectly touch" is doing a lot of work in that sentence — and it's precisely the exposure a non-custodial design avoids.

Australia

Australia passed the Corporations Amendment (Digital Assets Framework) Bill 2025 on 1 April 2026, requiring crypto exchanges and custody providers to obtain an Australian Financial Services Licence (AFSL). The rationale, per practitioners, rests on the long-standing regulatory principle that custody creates fiduciary responsibilities irrespective of the technological medium. The compliance gap is stark: of roughly 400 crypto platforms registered in Australia, only 10 per cent are registered with ASIC.

The pattern across all four jurisdictions is identical. Custody triggers licensing, capital requirements, segregation duties, and fiduciary obligations. Not holding keys doesn't exempt a provider from all regulation — AML, Travel Rule, and consumer protection still apply — but it removes the single heaviest category of obligation, and with it the counterparty risk that obligation exists to manage.

Side-by-side comparison

DimensionCustodial processorNon-custodial processor
Who holds keys during paymentProcessorYou (bound at address issuance)
Payout timingProcessor's schedule (T+1 to T+7)On-chain confirmation; no payout step
Float / reserve heldYesNone
If processor is hackedYour in-flight funds are in the poolYour funds were never in a pool
If processor is insolventUnsecured creditor claim (Celsius Earn)Funds already in your wallet
Fiat conversion & bank settlementUsually built inUsually you arrange separately
Chargeback-style dispute handlingOften offeredNot available — on-chain is final
Key management burdenProcessor's problemYour problem
Typical regulatory posture (EU)Licensed custody CASP, €125k capitalLighter; still AML/Travel Rule scope
Account freeze riskProcessor can freeze your balanceNo balance to freeze

Where custodial genuinely wins

Balanced assessment matters more than a sales pitch, so here's the honest case for the other side. Choose custodial if:

  • You need automatic fiat conversion and bank deposits. Custodial processors are far better at the crypto-to-fiat-to-bank-account leg. Non-custodial usually leaves you to handle off-ramping.
  • You have no internal key management capability. Non-custodial moves the security burden onto you. If nobody at your company can responsibly manage a wallet, a seed phrase, or a multisig policy, you have simply relocated the risk — not reduced it. Chainalysis reported $30 million stolen in H1 2026 through physical coercion attacks, with 25–30% of losses involving intimidation of family members or acquaintances — self-custody has its own threat model.
  • You want dispute mediation. On-chain payments are final. There is no reversal mechanism. If your business model needs refund arbitration, a custodial intermediary provides it.
  • Your volumes are tiny. If you process £2,000 a month, counterparty risk is a rounding error and convenience should win.

Non-custodial makes most sense when settlement amounts are large enough that float genuinely matters, when you already run crypto treasury operations, when you bill internationally and payout delays hurt cash flow, or when you're in a jurisdiction where you'd rather not inherit a third party's regulatory exposure.

How to tell what your current processor actually is

Marketing pages are unreliable here — "non-custodial" gets applied loosely. Five questions that produce a definitive answer:

  • "Can you produce the private key for the address my customer paid?" If they can, they're custodial. This is the only question that really matters.
  • "Is there a settings screen where I change my payout address?" If yes, then a compromise of your dashboard — or theirs — can redirect money in flight. Genuinely bound addresses can't be redirected after issuance.
  • "What is your payout schedule?" The existence of a schedule proves the existence of float. Non-custodial has no schedule because there's no intermediary step.
  • "Do you hold a reserve, rolling balance, or minimum payout threshold?" All three are custody by another name.
  • "If you filed for bankruptcy today, would my in-flight payments be estate property?" Ask for the answer in writing, and check it against the terms of service — Celsius Earn holders discovered their ownership status in the Terms of Use, after the fact.

The market context

This decision is arriving on more desks because the volumes are no longer marginal. A McKinsey and Artemis Analytics study published in February 2026 stripped out trading flows, internal fund movements, and automated protocol activity, leaving $390 billion in actual stablecoin payments for 2025 — more than double 2024. B2B transactions accounted for $226 billion of that, nearly 60 percent of the total, growing 733 percent year over year. The January 2026 PayPal/National Cryptocurrency Association survey found 39% of U.S. merchants already accept cryptocurrency at checkout, with 75% planning to accept stablecoin and crypto payments within 24 months.

Most of those merchants will pick a processor without ever asking who holds the keys. That's the whole reason this article exists.

The bottom line

Custodial processors trade counterparty risk for convenience. Non-custodial processors trade convenience for control. Neither is universally correct.

But the Celsius outcome is the fact to keep in mind while you choose. Same platform, same collapse, two structures — 100% versus 15–72%. Nobody in an Earn account chose that risk deliberately. They just never asked who owned the asset, and found out from a bankruptcy judge.

Ask the question before you need the answer.

Settlematic operates a true non-custodial model: every invoice and checkout address is cryptographically bound to a destination you control at issuance, across Ethereum, Polygon, BSC, Solana, Tron, and Bitcoin. See how settlement works, Collect for invoicing, Gateway for checkout, and our security architecture.

Sources: Chainalysis 2026 Crypto Crime Report · McKinsey & Artemis Analytics, February 2026 · FCA PS26/10 and CP25/14 · Regulation (EU) 2023/1114 (MiCA) · Corporations Amendment (Digital Assets Framework) Bill 2025 (AU) · GENIUS Act, S.1582 · FTX Recovery Trust distributions · Celsius bankruptcy proceedings · PayPal/NCA merchant survey, January 2026

Frequently asked questions

Is a non-custodial payment processor unregulated?
No. It typically avoids custody licensing — a licensed activity under MiCA with authorisation, prudential safeguards, and safekeeping of client assets among its core obligations — but AML, KYC/KYB, Travel Rule, sanctions screening, and consumer protection rules still apply. Lighter obligations, not none.
Does a unique deposit address per invoice mean non-custodial?
No, and this is the most common misunderstanding. Custodial processors issue unique addresses too; the keys still sit with them. Non-custodial requires that the destination is cryptographically bound at issuance and cannot be changed afterward.
What happens if I lose access to my settlement wallet?
Nobody can recover it for you. This is the genuine trade-off — you're exchanging counterparty risk for key management responsibility. Use multisig or institutional custody for the destination wallet if a single seed phrase makes you nervous. That is a legitimate reason to prefer custodial.
Can a non-custodial processor freeze my account?
It can suspend your ability to create new invoices. It cannot freeze funds already settled, because it never held them.
Do I still need KYB with a non-custodial processor?
Usually yes, especially at scale or in regulated corridors. Merchant onboarding, Travel Rule, and sanctions obligations attach to the payment service, not just to custody.
Is non-custodial cheaper?
Often, because there's no float to fund and no payout infrastructure to run — but compare all-in. A May 2026 Paybis survey of over 1,000 business decision-makers found a third expected stablecoin fees around 3%, when the real end-to-end figure generally sits below 1% including network, provider, on/off-ramp fees, and FX spread. Model your own corridor rather than trusting a headline rate.

Continue reading

Start invoicing and accepting crypto payments

Collect and Gateway on one non-custodial platform - funds always sweep to wallets you control.