An institution can hold clear legal title to Bitcoin and still not know who is able to move it. Once Bitcoin stops sitting in storage and starts backing a loan or an onchain position, the question that decides risk becomes who can move it, and whether that can be verified or checked.
Ownership tells an institution who holds the asset. It says nothing about who can move the coins, which is what determines risk once Bitcoin is put to work.
This article turns that question into a checklist. It is the same custody due diligence an institution runs on any counterparty, applied to an asset where whoever holds the keys can move the funds.
Key takeaways
- Legal ownership and operational control are separate questions, and control is the one that decides risk.
- Control runs from the institution through custody and the signing setup, out to every party that can act on the asset.
- How Bitcoin is held and signed for governs what happens under stress, so segregation, rehypothecation, key management, and recovery all need scrutiny.
- A position that cannot be verified onchain or recovered without a counterparty's cooperation is not fully controlled.
Mapping the Bitcoin control chain
Start with a map. Trace the asset from the institution through custody and the signing architecture to wherever it is deployed. At each stage a different party may hold authority, and the job is to make that authority explicit rather than assumed.
For each stage in the chain, four questions apply:
- Who holds authority at this stage, and is that party named and accountable?
- What actions can that party take, and are those actions bounded or open-ended?
- Under which conditions can they act, and are those conditions written down and enforced?
- Can the institution verify what happened, or does it rely on a report from the party being reviewed?
Where any of these has no clear answer, risk concentrates. The map matters most at the joints, where one party hands authority to the next and responsibility is easiest to lose.
Why custody does not equal control
A qualified custodian can hold the underlying Bitcoin securely and still leave open who can authorise a deployment or trigger a liquidation once the asset is put to work. A position that touches a lender, a protocol, an administrator, or a technology provider introduces authority that lives outside the custodian relationship, often with no visibility back to the custodian. Institutional Bitcoin control has to be assessed across the whole chain, not read off a single agreement.
Follow the keys: signing authority and key management
Signing architecture is where control actually lives, so a serious review describes it in operational terms. Who holds the shares of signing authority? Bitcoin key management is the difference between a structure that can be moved unilaterally and one that requires agreement.
Another four questions frame the signing review:
- Who possesses signing authority, and is it split across parties or concentrated in one?
- Is authority unilateral or conditional, meaning can a party sign freely or only when defined conditions are met?
- Can any single party move the Bitcoin independently, without the cooperation of the institution?
- What is the recovery mechanism if a signer becomes unavailable or compromised?
A structure where one external party can sign alone is a very different proposition from one where the institution is a required participant in every movement. That difference rarely appears in a custody label, which is why the signing review is worth doing on its own.
The signing model, more than any label on the account, tells a risk team who is really in control.
Follow the Bitcoin: onchain collateral verification
Bitcoin settles on a public ledger, so an institution does not have to take every balance on trust. Onchain visibility supports independent checks on how much Bitcoin backs a position and whether collateral is where the paperwork says it is, turning a reported position into one the institution can confirm for itself.
The strength of that check depends on structure. When holdings map to identifiable onchain outputs, a reviewer can inspect balances and confirm collateral status directly, rather than waiting for a periodic statement. Inside a pooled structure that clarity is harder to reach, because the ledger shows the provider's aggregate position, not the institution's slice.
Follow the failure scenarios
A framework earns its value under stress. Run the central question through the situations that actually cause losses, because naming them in advance is what makes the answer actionable.
The question never changes: who controls the Bitcoin then, and can the institution recover its position?
Six scenarios cover most of the ground:
- Custodian failure, where the party holding the Bitcoin becomes insolvent or unavailable.
- Borrower default, where a counterparty in a financing arrangement fails to meet its obligations.
- Lender failure, where the party on the other side of that arrangement collapses.
- Technology failure, where a protocol or signing system stops behaving as expected.
- Governance failure, where the process meant to authorise decisions breaks down or is captured.
- Market stress, where rapid movement forces liquidations and tests every mechanism at once.
Structures that answer these cleanly share a property. Control and recovery are defined in advance, not dependent on any single party choosing to cooperate at the worst moment.
The six-category framework

The whole review comes down to six categories, each with a plain question to answer. Together they give a risk team one checklist for any institutional Bitcoin arrangement.
Used consistently, it lets an institution compare very different providers on the same terms. A category that cannot be answered is itself a finding.
Mapping the framework to Verifiable Bitcoin Accounts
Once the framework is in place, it becomes a lens for specific infrastructure, including Threshold's own. Verifiable Bitcoin Accounts were built around the same categories a risk team would use, so the mapping is direct.
A Verifiable Bitcoin Account runs from the custody setup an institution already operates, with the Bitcoin fully segregated and attributable.
The institution sends a single Bitcoin transaction to create its reserved output, the anchor UTXO, and authorizes the reservation from an Ethereum account in its existing custody stack. Nothing else about the setup changes. (see the full technical diagram here)
- Custody: The Bitcoin stays within the institution's existing custody arrangement, in its own segregated UTXO(s), and custody does not transfer when capital is deployed. Only tBTC moves. Compatible with qualified custodians such as Anchorage and Fireblocks Trust, as well as MPC and self-custody setups.
- Control: The reservation's terms are written into Bitcoin Script on the anchor UTXO, so authority is bounded by code rather than a promise.
- Verification: Every condition can be audited by inspecting that script on the anchor UTXO.
- Recovery: The release path is predefined and enforced by Bitcoin consensus, not counterparty cooperation. Governance can run through two independent layers: the onchain spending conditions and an optional legal claim on the Bitcoin.
The assets are never pooled. tBTC is minted against the reservation to an Ethereum address the owner names, and on redemption in kind the tBTC is burned and the reservation on those same UTXOs is released. Institutional adoption of Bitcoin in onchain markets scales on independent verification, not assurance. Anyone can verify the reservation by running a Bitcoin node, and the tBTC mint and ownership record by reading Ethereum.
The verification rests on tBTC, the tokenized Bitcoin Threshold has operated for six years. tBTC uses threshold cryptography and a rotating operator set rather than a single named custodian, and its peg is verifiable onchain, which lets balances and movements be confirmed by inspection instead of by trust.
Here is a short video on how threshold cryptography works, to get a gist on how BTC is bridged to tBTC.
Frequently asked questions
Is legal ownership of Bitcoin the same as control? No. Legal ownership establishes title, while control depends on who holds the keys and the authority to sign, and those can rest with different parties once Bitcoin is deployed.
How do you evaluate institutional Bitcoin custody? Trace the control chain from the institution through custody and the signing setup, then confirm each of the six framework categories in turn. A category that cannot be answered marks where the risk sits.
What is rehypothecation of Bitcoin? Rehypothecation is when a provider reuses client Bitcoin for its own purposes. It changes the risk an institution carries even when legal ownership on paper appears unchanged, which is why a review should confirm whether and how it can occur.
What does asset segregation mean for institutional Bitcoin? Segregation means client Bitcoin is held in a way that can be attributed to that client alone, rather than pooled with other clients in a shared wallet. It shapes what an institution can verify onchain and what it can recover if a provider fails.
How can an institution independently verify its Bitcoin position? When holdings map to identifiable onchain outputs, a reviewer can inspect balances and confirm collateral status directly on the Bitcoin blockchain. Structures built on verifiable UTXOs support this proof, while pooled structures make it harder to reach.
Check other Bitcoin Markets available onchain

.png)

.png)