Frequently asked questions
Crypto custody and escrow, answered properly
Thirty-four questions that come up on first mandates — key control, insolvency, disputes, sanctions screening, supported assets, fees, access and data. Answered as we would answer them in writing to a client, without marketing hedging.
No question matches that search. Try a different term, or ask the custody desk.
General & service
01 – 05Escrow Chambers is a digital asset custody and on-chain escrow service. It takes control of cryptocurrency under a written mandate, holds it in a segregated vault with its own blockchain address, and releases it only when the conditions recorded in that mandate have been evidenced and approved by a required quorum of named signatories.
It is built for law firms, enforcement agencies, insolvency practitioners, arbitral institutions and corporate counsel rather than for retail trading. The functional comparison is a client account or stakeholder account, not a wallet app.
Professional and institutional clients: regulated law firms, enforcement and public bodies, insolvency practitioners, arbitral institutions, corporate legal and treasury teams, and their advisers.
Every instructing party is identified and verified before a vault is opened. For corporate parties, verification extends through the ownership chain to the individuals who ultimately control the entity.
None of those. Escrow Chambers does not take deposits, does not operate an order book or market, and is not a self-custody wallet you install on a device.
It is a custodian and escrow agent: it holds assets for others, under instruction, and moves them only under a defined approval process. There is no trading function, no yield product and no lending. That narrowness is the point — it removes the conflicts of interest that arise when the party holding your assets also profits from moving them.
Individuals are frequently parties to a mandate — as depositors, recipients or named signatories — but the mandate itself is opened by a professional instructing party such as a law firm, practitioner or agency.
That structure exists because escrow depends on someone owing professional duties in relation to the underlying transaction, and because it keeps identification, conflict checks and the relationship with the underlying agreement where they belong.
English and German. Mandate documentation, instructions, portal access, statements and audit exports are available in both, and the custody desk handles enquiries in both languages.
Where a matter requires documentation in a further language, certified translation can be arranged as an additional service and is recorded on the file.
Custody & security
06 – 11Nobody holds a complete private key, because one is never created. Signing keys are generated as independent shares using multi-party computation, each share held inside a separate hardware security module in a separate, access-controlled facility.
A transaction is signed by those shares co-operating mathematically, without any share revealing itself and without a whole key ever being assembled. There is therefore no file to steal, no device to seize and no individual who could be compelled to hand over control alone.
No. The signing infrastructure will not begin a signing ceremony until the client-side approval quorum for that vault has been satisfied and independently verified.
Escrow Chambers can stop a release — where a sanctions match, a court order or a breach of the mandate requires it — and can never cause one. Every route to moving value out of a vault passes through your named signatories.
Cold by default. The key shares required to sign rest offline and are only brought into a signing ceremony when an approved release requires it.
There is no permanently connected hot wallet holding client escrow balances. Hot-wallet compromise is the single most common cause of large custody losses in this sector, and an escrow service has no operational reason to accept that risk: escrow balances are not expected to move minute by minute.
Insurance arrangements, the perils covered and the applicable limits are confirmed in writing in the mandate documentation before a vault is opened, because cover differs by asset, jurisdiction and mandate type.
We deliberately do not describe insurance in general marketing language. “Fully insured” is a claim that means nothing without a scope, a limit and an insurer, so we give you the actual position for your mandate, in writing, on request.
The signatory is re-enrolled following an identity verification procedure carried out over a channel recorded at onboarding — never over the channel that made the request. That single rule defeats most account-takeover attempts.
Because quorums are configured with redundancy (2-of-3 rather than 2-of-2), the vault continues to operate normally while a signatory is re-enrolled. Assets never become unreachable because one person lost a phone.
Independent penetration testing and code review are carried out on a defined cycle and after material change, and the key management architecture is subject to separate review.
Current assurance reports, their scope and their date are provided to prospective clients during onboarding. We publish the practice rather than a badge, because a certification logo without a scope and a date tells a reader nothing useful.
Escrow mechanics
12 – 17Custody is holding an asset securely on someone else's behalf. Escrow is custody plus a condition: the custodian is instructed in advance that the asset may only be released once a defined event has occurred and been evidenced.
Every Escrow Chambers escrow is a custody arrangement. A custody mandate can also be opened without conditions, where a party simply needs assets held securely and accountably — for example while an estate is being administered or a restraint order is in force.
Yes. A mandate can provide for release to multiple destinations in fixed amounts or fixed proportions, and for staged distribution as milestones are satisfied.
This is used routinely for creditor distributions in insolvency, for settlement sums payable to several parties, and for transactions where a retention is released separately from the principal consideration.
The vault holds and nothing is released. Escrow Chambers does not adjudicate the underlying dispute — it has no standing to do so, and a custodian that decides such questions for itself is not a custodian.
The assets remain in escrow until the parties agree in the form the mandate requires, or until a court or tribunal with jurisdiction directs otherwise. Every submission, approval and rejection is available to both parties and to any tribunal, so the dispute is argued on a complete record.
Only by the same approval quorum required for a release, and the change is recorded in the audit log with the identity of everyone who approved it.
That rule exists so neither party can move the goalposts unilaterally once value is at risk. Conditions a party might reasonably need to vary later should therefore be drafted with that flexibility from the outset.
Yes. Escrowing a retention, a disputed portion, a warranty holdback or a first tranche is common, and the balance of the transaction can settle entirely outside the escrow.
The mandate defines exactly what the vault is responsible for and makes no assumption about the rest of the deal.
Well-drafted mandates include a long-stop: a date after which, absent satisfaction of the conditions, the assets are returned to the depositing party or dealt with in another specified way. We raise this at drafting stage precisely because it is the term parties most often forget.
Where no long-stop exists and the parties become unreachable or deadlocked, the assets remain in segregated custody and we will seek directions. The one thing a custodian must never do is decide the outcome for itself.
Legal, regulatory & compliance
18 – 24Beneficial ownership is determined by the underlying agreement and the applicable law, not by the custody arrangement. Escrow Chambers holds control of the assets, not beneficial title to them: it is a custodian, not a purchaser or a counterparty.
The mandate records who is beneficially entitled and in what circumstances that entitlement changes, and the audit record evidences continuity of control throughout the holding period.
Held assets are client assets, not balance-sheet assets. They sit in segregated on-chain addresses attributable to a specific matter and are never used for operational purposes, so they do not form part of the general estate available to creditors.
Recovery material is distributed across separate facilities under a documented procedure designed to let the entitled parties regain control independently of the continued operation of the business. The procedure is tested on a defined cycle, because an untested recovery plan is a hypothesis rather than a control.
Yes. Orders from a court of competent jurisdiction are actioned, and the affected parties are notified to the extent the order permits. Every step taken in response is logged, so the response itself is auditable.
Enforcement agencies can also open mandates directly to hold seized, restrained or forfeited digital assets, with access limited to named officers and a chain of custody documented from the moment of transfer into the vault.
Identification and verification of every party and named signatory; beneficial ownership verification for corporate parties; sanctions and politically exposed person screening at onboarding and continuously thereafter; blockchain analytics and provenance tracing on every inbound transaction; and ongoing monitoring of vault addresses against sanctions and illicit-finance datasets.
Mandates that cannot be satisfactorily verified are declined in writing, with reasons. That outcome is deliberately available to us: a custody service that accepts everything protects nobody.
Where the law requires a report, a report is made. Where the law restricts what we may tell you about it, we comply with that restriction. Nothing in a mandate overrides a legal obligation, and we would not sign one that purported to.
Everything done in response is logged, so the response remains auditable after the fact even where it could not be disclosed at the time.
Yes, as an additional service. We can produce a factual witness statement covering the custody record for a matter — what was held, when, on whose instruction and with what on-chain references — and can attend to speak to that record where required.
The underlying audit export is designed to be exhibited directly, so in many matters a statement is not needed at all.
The governing law and the forum for disputes are stated expressly in the mandate and agreed before it is signed.
Where the escrow supports an underlying agreement, the mandate is normally aligned with that agreement's governing law, so the two instruments do not pull in different directions if the matter is ever litigated.
Assets, networks & fees
25 – 29Bitcoin (BTC); Ether and major ERC-20 assets including USDC, USDT, DAI and WBTC on Ethereum; USDC, USDT and MATIC on Polygon PoS; ETH and USDC on Arbitrum One; USDT on Tron; and SOL and USDC on Solana on request.
Support is deliberately conservative and limited to assets with deep liquidity, mature tooling and predictable settlement finality. An escrow that cannot be reliably released is not an escrow, so we would rather decline an asset than accept it with caveats.
Escrow Chambers does not operate as an exchange and does not take a spread on conversion.
Where a mandate requires conversion — for a distribution payable in fiat, for example — it is arranged with a regulated counterparty selected together with the instructing party, executed transparently, and recorded in the audit trail with the rate, the timestamp and the counterparty identified.
Network fees are passed through at cost and shown separately on every statement: as an estimate when a release is raised, and as an actual figure once the transaction confirms.
A release never quietly settles for less than the instructed amount because a fee was taken out of it without being specified. Where the mandate provides for fees to be borne by a particular party, that allocation is applied automatically.
Fees are agreed in the mandate before a vault is opened and are quoted as a fixed schedule rather than as a percentage of the value moved: a one-off mandate fee covering onboarding and vault creation, a periodic custody fee, a fixed fee per release plus the network fee at cost, and quoted charges for additional services.
We earn nothing from the assets themselves — no yield, no spread, no lending — so our commercial model gives us no preference about where the value ends up or how quickly it moves.
Non-fungible and less liquid tokens are assessed case by case. The three questions are whether the asset can be held securely, valued defensibly and released predictably.
Where any of those cannot be answered, we decline in writing rather than accept the mandate with caveats that would surface at the worst possible moment — typically at the point of distribution.
Access, accounts & data
30 – 34Access is issued during onboarding, not by self-registration. Once a mandate is accepted, each named user is enrolled individually with their own credentials and a hardware-backed second factor, and is granted only the role the mandate specifies.
There is no public sign-up, and shared logins are not permitted under any circumstances — an action that cannot be attributed to a person is not an audit record.
Yes, for every user without exception. Phishing-resistant, hardware-backed authentication is the standard.
Approval actions require fresh re-authentication rather than relying on an existing session, sessions expire on inactivity, and privileged actions are verified independently of login.
Yes, if the mandate provides for it. Viewing rights and approval rights are separate permissions.
A client, a counterparty, co-counsel or an auditor can therefore be given full visibility of balances, deposits, condition status and the audit trail without being given any authority to instruct or approve. Access can be scoped to a specific matter and a specific period, which is how auditor and expert access is usually granted.
The identification and verification material required to onboard parties and signatories, the contact and authentication data required to operate the vault, and the audit record of actions taken on the matter.
It is processed on a documented lawful basis, encrypted in transit and at rest, and retained for the period specified in the mandate — normally driven by the record-keeping obligations of the instructing party rather than by our preference. Retention, deletion and data subject rights are addressed in the mandate documentation rather than left to a default setting.
Email [email protected] with as much detail as you can safely provide. Reports from security researchers are welcome and are acknowledged; we ask that you do not test against live client vaults or attempt to access data that is not yours.
If you believe an instruction on a live matter may be fraudulent, contact the custody desk immediately — and do not use contact details supplied in the suspicious message itself.
A question we have not answered?
The custody desk answers substantive questions in writing before any commitment is made, including questions about matters we may ultimately decline. Write to [email protected] with the matter type, the assets involved and the outcome you need.
Ready to place a matter into custody?
Tell us the matter type, the assets involved and the release conditions you need. We will confirm in writing whether we can hold it, on what terms, and how long onboarding will take.