The HKMA updated its expected standards for banks and their subsidiaries that hold digital assets for clients, covering crypto, tokenised securities and other tokenised assets. The guidance sets out governance, segregation, key management, cold wallet controls, monitoring and staking requirements. It asks banks to apply extra caution to permissionless tokens on public permissionless networks.
Why it matters: The HKMA's custody guidance now names public permissionless chains as a distinct, higher risk, which will shape how banks price and structure custody on them.
For Ethereum: Banks must treat permissionless tokens on public permissionless networks as higher risk, and the guidance says permissioned tokens may allow recovery of lost assets.
The guidance applies to authorised institutions and subsidiaries of locally incorporated authorised institutions that custody digital assets on behalf of clients. It covers crypto assets, tokenised securities and other tokenised assets, and excludes the bank’s own holdings.
The main requirements:
A risk assessment and board oversight before launch (para 1).
Client assets segregated from the bank’s own, including on-chain wallet addresses (para 6).
No lending, pledging or encumbering client assets without explicit client consent (para 7).
A risk-based approach that depends on the type of network: private permissioned, public permissioned or public permissionless (para 9).
For crypto assets, hardware security modules for keys, whitelisted withdrawal addresses from cold wallets and systematic verification of each transaction (paras 10 to 11).
Monitoring of the custody system and its dependencies, including blockchain protocols and cryptographic libraries (para 24).
Staking from custody remains governed by the HKMA’s April 2025 guidance, read together with the SFC’s terms for platforms that stake (para 26).
Implications
The update brings tokenised securities and other tokenised assets inside the same custody standard as crypto, which matters as Hong Kong banks take custody of tokenised funds and bonds. Banks can apply lighter controls to lower-risk tokenised assets, but the default for crypto assets is the full set.
For Ethereum
Paragraph 9 says permissionless tokens on a public permissionless network may face heightened cybersecurity risk, and that lost assets may be hard to recover. It contrasts this with permissioned tokens that have access controls in the smart contract. Paragraph 11 makes the full set of key and wallet controls the norm for crypto assets such as ether, and allows a risk-based approach for other digital assets, except that banks should “exercise extra caution” before relaxing controls for permissionless tokens on public permissionless networks. For a tokenised bond or fund issued on Ethereum, a permissioned token with issuer controls is the easier path to lighter custody treatment. That nudges tokenisers towards permissioned token standards on Ethereum, not away from Ethereum.
Elsewhere in Asia
Singapore’s prudential consultation makes a similar distinction for capital: tokens on permissionless chains can get the lower capital treatment only if the issuer can freeze or correct transactions and whitelist holders.
What to watch
Whether Hong Kong banks offer custody of tokens on public chains beyond bitcoin and ether, and the staking terms the HKMA and SFC align on.