Crypto custody for Belgian companies

Diagram comparing four crypto custody models and the approval trail each one leaves behind.

TL;DR

  • What it is: custody architecture is the arrangement that determines who holds the private keys to a company’s crypto assets and who can authorise a movement. Belgian companies choose in practice between a single-key wallet, an on-chain multisig, an MPC wallet, and custody with a licensed provider.
  • Why it is needed: a company has to be able to show which addresses it controls, who approved each outbound transaction, and that movements between its own wallets were never disposals. Some custody models produce that evidence automatically. Others produce none of it.
  • Why it matters: classification under draft and advisory CBN guidance, valuation at acquisition value under Belgian GAAP, AML documentation and the questions an auditor or a bank will ask all rest on records that the custody setup either creates or fails to create.
  • How Accryptax can help: we reconstruct on-chain activity, reconcile it across wallets, exchanges and protocols, and turn it into a documented trail that a Belgian accountant, auditor or tax inspector can follow back to the wallet, the block and the timestamp.

Most Belgian companies that hold crypto decide how to store it long before they decide how to account for it. In practice those are the same decision, and the order matters. A treasury setup chosen purely on security grounds can be perfectly sound and still leave the finance team with a year-end reconstruction problem that takes weeks to unpick.

Here is the version of that problem we see most often. A Belgian company holds part of its treasury in tokens. One director holds a hardware wallet. During the year, the company moves assets to a new wallet, pays a contractor, and swaps a position. At year-end the auditor asks a reasonable question about a single outbound transfer: who authorised it, and on what basis. The transaction itself proves that someone with the key signed it. It does not prove that the company decided anything. Nothing else exists.

What is custody architecture, and why is it an accounting question?

Custody architecture describes how private keys are generated, held and used to authorise transactions, and who is involved at each step. It covers three separable things: who can technically move assets, who is required to approve a movement before it happens, and where the record of that approval is kept.

The third element is the one finance teams inherit. A blockchain records that a valid signature was produced. It does not record why, by whom inside the organisation, or under what internal authority. Whether that context survives depends entirely on the architecture chosen. Some setups write the approval trail on-chain, where it is permanent and independently verifiable. Some keep it in a provider’s console, where it survives only as long as the subscription and the provider’s retention policy. Some do not create it at all.

That is why custody sits upstream of bookkeeping rather than beside it. The setup determines what evidence exists a year later, and evidence is what a Belgian accounting file is made of.

Which custody models do Belgian companies actually choose between?

Four models cover almost everything we encounter.

A single-key wallet is one hardware or software wallet controlled by one person, usually a founder or a director. It is cheap, fast and requires no coordination. It also concentrates the entire treasury behind one device and one individual.

An on-chain multisig is a wallet that only executes once a defined number of approved signers have confirmed. In the implementation most Belgian companies encounter, the individual approvals are signed off-chain and collected by a transaction service; the final execution is a single on-chain transaction that carries all the signatures with it. The set of signers who approved is therefore permanently recoverable from the chain. The record of who approved at what moment sits in that service rather than in a block.

An MPC wallet distributes the signing capability across shares held by separate parties or devices, using multi-party computation to produce a signature without the complete key ever existing anywhere. On-chain, the result looks like an ordinary single-signature transaction. The approval logic lives with the provider.

Third-party custody means a licensed provider holds the keys and the company holds a contractual claim. Movements inside the provider’s environment may never touch a public blockchain at all.

Each of these is a defensible choice. They are not interchangeable, and the differences that matter for accounting are not the differences that appear in a security comparison.

What does each model leave behind as evidence?

Model Who can move funds Approval trail Typical reconciliation burden
Single-key wallet One person None, unless documented off-chain by hand Low volume, but every authorisation must be evidenced separately
On-chain multisig Defined quorum of signers Signer set permanently recoverable from the execution transaction; approval timeline held by the transaction service Contract wallets are frequently mis-parsed by generic tools; internal transfers need decomposition
MPC wallet Defined approvers under provider policy In the provider’s logs only Clean on-chain data, dependent on export and retention
Third-party custody The provider, on instruction Provider statements No on-chain trail for internal movements; reliance on statement quality

Read that table as an evidence table rather than a security table. A single-key wallet is not automatically the weakest option in security terms if the key is well protected. It is close to the weakest in evidentiary terms, because nothing about the arrangement generates a record of corporate authorisation.

Multisig is the opposite case. It creates a durable, independently verifiable approval trail, and it creates parsing work, because a smart-contract wallet does not behave like an ordinary address. Transfers appear as internal calls rather than as simple sender-to-recipient movements, and tooling that assumes the simple case will read a treasury contract wrongly.

MPC sits between the two. The on-chain data is the cleanest of the four, because a threshold signature is indistinguishable from an ordinary one. That cleanliness is also the catch: the fact that finance and a director both approved a transfer exists nowhere except in the provider’s records. If the company changes provider, or the retention window closes, the assets remain and the evidence does not.

What do the 2026 incidents actually show?

The industry data has moved in a direction that makes this an operational question rather than an academic one. In the first half of 2026, security firm CertiK counted over $444 million lost across 33 wallet compromise incidents, making it the most financially damaging attack category of the period. At more than $13 million per event that is by far the highest average loss of any attack type in its data: more than twice that of phishing and roughly eighteen times that of code vulnerabilities. The pattern is a small number of highly targeted attacks aimed at key management rather than at code.

The reference case remains the Bybit theft of February 2025. Blockchain analytics firm Elliptic put the loss at around $1.46 billion and judged it, hedged as a probability rather than a certainty, the largest single theft ever recorded in any domain; other counts place it between $1.4 and $1.5 billion. What makes it instructive for a treasury design discussion is not the size. It is that the exchange’s approval process functioned exactly as designed. Malware manipulated what the signers were shown, and they approved a transaction that was not the one they believed they were authorising. A multi-party approval process produced a complete and verifiable trail of an authorisation that nobody intended to give.

Chainalysis, in its 2026 Crypto Crime Report, describes the same shift from the other direction. Losses at centralised services keep growing because attackers go after the way keys are held and transactions are signed, and a recurring method is to persuade legitimate signers to authorise something other than what they believe is in front of them. Compromises of personal wallets follow a parallel line, rising from 7.3% of all stolen value in 2022 to 44% in 2024 before falling back to roughly a fifth in 2025. Institutional resources and professional security teams have not made this category go away.

Two conclusions follow for a company treasury. The first is that an approval trail is worth what the approvers could actually verify at the moment they signed, which makes independent verification of transaction details a control in its own right rather than a technical detail. The second is that key management is now the principal exposure, which is precisely the layer that also determines what a company can later prove.

Why does proving control matter under Belgian rules?

Belgian accounting law does not yet offer a complete settled regime for crypto assets. The CBN issued a draft advice in 2019 and a formal advice in 2021 that deals specifically with crypto used as a means of payment. Between them they point to three possible balance-sheet classifications depending on the intention behind the holding: investments, inventory, or other receivables. None of the three can be applied without documented evidence of what the company holds, since when, and why.

Belgian GAAP compounds this. It is a historical-cost framework built on the prudence principle. Assets are carried at acquisition value, write-downs are mandatory when realisation value at year-end falls below acquisition value, and for the categories crypto assets fall into, an increase in value cannot be recognised before it is realised. Applying that to a token position requires per-lot acquisition data that survives every move the assets have made. A custody migration that a crypto subledger reads as a series of disposals will manufacture gains that never occurred, and those gains flow into the corporate tax base at the standard rate under corporate income tax rules, currently 25%, or 20% on the first €100,000 of profit for qualifying SMEs. There is no exemption threshold for companies.

Then there is the ownership question, which is where single-key setups create the most exposure. When a director holds the only key to a wallet in his own name, on his own device, with no record separating company assets from personal ones, the company has an assertion rather than a demonstration. That is a weak position in front of an auditor, a weaker one in front of a bank, and a poor starting point if the tax administration takes a different view of who actually holds the assets.

The same evidence set does duty in an AML context. Belgian accountants are obliged entities, and identifying who controls a wallet, where the assets came from and who the counterparties were is not optional file-building. Custody arrangements that obscure control make an engagement harder to accept, not easier to run.

One boundary is worth stating plainly. A company that self-custodies its own treasury is not providing a service to anyone and is not, on that basis alone, carrying on a regulated activity. Holding crypto assets on behalf of third parties is a different matter and falls within the scope supervised by the FSMA. Projects that hold user funds should take that distinction seriously before choosing a wallet.

Where does custody quietly break the books?

Five failure modes account for most of the damage we see, and none of them looks like a security incident.

Migration read as disposal. Moving a treasury from one architecture to another produces a burst of transfers between addresses the company controls. Unless every one of those addresses is labelled as own before the data is processed, the result is a set of fictional realisations and a distorted tax base. This is by some distance the most expensive error on the list.

It is also not always a planned event. In July 2026 Coinkite, the manufacturer of the COLDCARD hardware wallet, disclosed that a build error had let a software random number generator supply the randomness for seed generation instead of the intended hardware source, narrowing the search space for seeds created on affected firmware. Its technical write-up is candid about both cause and remedy: installing the fix corrects new seeds but leaves existing ones exactly as they were, so unless a narrow entropy exception applies, the holder has to generate a fresh seed on the updated device and move the funds to the new wallet. For a company, a security advisory of that kind arrives as an instruction to generate a new wallet and transfer everything to it. That is a mass internal transfer, initiated under time pressure, with no disposal behind it. Whether it lands in the books as such depends entirely on whether the address register was being maintained beforehand.

Gas paid by the wrong party. With a multisig, the signer who submits the execution transaction pays the network fee from their own address while the assets move from the company wallet. When a director executes from a personal address, the fee sits outside the company and the transaction sits inside it. The same split arises with sponsored transactions and on chains where the fee payer is a separate role from the signer. Small amounts, persistent reconciliation noise, and an avoidable discussion about whose wallet is whose.

Contract wallets parsed as ordinary addresses. A multisig treasury moves value through a contract call rather than a plain transfer, so the assets travel as internal calls while the transaction itself originates from whichever signer submitted it. Generic tooling either double-counts the movement, drops it, or attributes it to the wrong address.

Provider logs that do not outlive the provider. Approval policies, signer changes and the identity of each approver are what turn an MPC wallet from a technical arrangement into an internal control. If those records cannot be exported in a durable format, the control is unevidenced from the moment the relationship ends.

Omnibus custody with no statement discipline. Where a provider holds assets in pooled wallets, internal movements never appear on-chain. The provider’s statements become the primary accounting record, which makes their completeness and granularity a due diligence item rather than an afterthought.

What should a company require from any custody setup?

Whatever architecture is chosen, six requirements are worth fixing in writing before the first transaction rather than after the first audit.

  1. A maintained register of every address the company controls, with the date control began and the date it ended. This is the single control that prevents internal transfers from being read as sales.
  2. A durable record of who authorised each outbound movement, held somewhere that survives a change of provider, a change of signer and a change of finance lead.
  3. Exportable transaction history in a machine-readable format, tested once while the relationship is still healthy rather than during the exit.
  4. A documented approval policy that matches the actual configuration. A policy requiring two approvals is worth nothing if the wallet is technically configured to accept one.
  5. A written procedure for signer departure and key loss, covering what happens when a director leaves, a device fails, or an approver becomes unavailable.
  6. Separation between corporate and personal assets at the address level, with no wallet used for both.

The fifth point deserves more attention than it usually gets. Any arrangement in which one identifiable person can move the entire treasury alone is a single point of failure, and the failure does not have to be an attack. A director who leaves on bad terms, a device that dies, an illness, a lost passphrase: each produces the same outcome as a theft on the balance sheet, with the added complication that the assets are still visibly there and simply cannot be reached. An auditor will ask how that scenario is handled long before anyone asks about the wallet brand.

When is a simple setup good enough?

Often. A company that accepts occasional crypto payments and converts them promptly does not need a threshold-signature treasury and an approval matrix. A single well-protected hardware wallet, a documented procedure for who may use it, a maintained address register and a habit of never mixing personal and corporate assets will carry that company perfectly well.

The threshold is not a portfolio value. It is the point at which any of the following becomes true: more than one person needs to be able to move funds, the treasury is material to the balance sheet, assets are held rather than converted, the company operates across several chains or protocols, or an external auditor is involved. At that point the informal arrangement stops being proportionate, and the cost of formalising it is far lower before a migration than after one.

From wallet configuration to a defensible file

The uncomfortable part of custody design is that the failures are silent. A weak setup does not announce itself. It surfaces months later as a reconciliation that does not close, a classification that cannot be supported, or an auditor’s question that has no answer beyond a transaction hash.

A custody model does not only decide who can move the money. It decides what you will still be able to prove a year later.

At Accryptax we work at the point where these two worlds meet. We reconstruct on-chain activity across wallets, exchanges and protocols, identify which addresses belong to the company, separate internal transfers from real disposals, and document the result so that it holds up in an audit file. Where a treasury setup is already in place we assess what it produces and what it fails to produce. Where one is still being chosen, we would rather be in the room before the keys are generated than after the first migration.

If you are holding digital assets through a Belgian company and you are not certain what your current setup would be able to demonstrate, book a free 30-minute consult and we will walk through it with you.

This article is general information about Belgian accounting, tax and reporting practice. It is not individual advice and does not take account of your specific situation. Nothing in it is a recommendation of any product, provider or transaction.

Leave a Reply

Your email address will not be published. Required fields are marked *