MPC and smart-contract wallets: which key arrangements are custody?
Is an MPC wallet provider a custodian? It depends on what the provider’s key share, signer or contract can do alone. FinCEN asks whether it has total independent control over value. MiCA asks whether it safekeeps or controls a means of access. VARA asks whether the firm safekeeps assets for another on verified instructions, with keys held or controlled as the marker. FIU-IND asks whether it administers an instrument enabling control. None of the four names MPC, account abstraction or hardware signers, so each verdict applies a general test.
Five key arrangements at a glance
| Key arrangement | US: FinCEN control test | EU: MiCA means of access | UAE (Dubai): VARA custody rules | India: FIU-IND function test |
|---|---|---|---|---|
| MPC or threshold signatures, provider holds one share below the signing threshold | Points away from money transmission if the share cannot complete a transaction alone (FIN-2019-G001 s.4.2.2). Flips if the provider hosts, books the value or stands between owner and payment system. | Exposed. A share kept on behalf of clients can be read as a means of access the provider safekeeps or controls (Art 3(1)(17)); no ESMA text settles whether a share alone qualifies. | Exposed if the share is read as part of the private keys: Custody Services is safekeeping for another on verified instructions (Regulations, Schedule 1), and client assets count as held or controlled where the firm holds or controls the private keys or seed phrase (Compliance and Risk Management Rulebook Rule V.A.2(d)). | Exposed. Safekeeping or administration of instruments enabling control over VDAs for another is notified activity (iv) (para 1.2.2), wherever the provider sits (para 1.4). |
| MPC with every share on client devices, provider supplies software and coordination only | Strongest position. A developer or seller may be exempt from BSA obligations for creating or selling the application (s.1.1). Flips if the provider uses it to accept and transmit value. | Strongest position. Hardware or software providers of non-custodial wallets should not fall within MiCA (recital 83). Flips if the provider keeps a backup or recovery share for clients. | The Rule V.A.2(d) marker points away on these facts, but Dubai Law No. (4) of 2022 Art 16(a)(6) separately lists services related to virtual asset wallets. | Activity (iv) points away on these facts. Check activity (iii), transfer of VDAs, if the provider relays transactions. |
| ERC-4337 smart-contract account with a provider-run bundler, paymaster or session-key signer | A DApp developer is not a money transmitter for merely creating it; using or deploying it to accept and transmit value is money transmission (ss.4.4, 5.2.2). A provider signer that can move value alone points to independent control. | Recital 22 keeps services provided in a fully decentralised manner without any intermediary outside MiCA. A provider-held signer can be read as a means of access; moving client assets between addresses is transfer service (j) (Art 3(1)(16)). | A provider-held signer points to the Rule V.A.2(d) marker. Moving assets from one entity or wallet to another is VA Transfer and Settlement Services (Regulations, Schedule 1). | Automating a function in a smart contract does not relieve the controlling parties (para 7.1.2). Activities (iii) and (iv) are both in view. |
| Hardware-signer SaaS or co-signing API, provider operates the signing hardware | Holding the only key and signing on instruction is the hosted wallet pattern: total independent control (s.4.2.1). As a co-signer only, s.4.2.2 applies. | Holding a client’s key in provider-run hardware reads as safekeeping a means of access (Art 3(1)(17)). A device or software the client alone operates is recital 83 territory. | Safekeeping and acting only on verified instructions is the Schedule 1 definition of Custody Services. | Holding the signing key for another in the course of business is activity (iv); registration is a mandatory prerequisite (para 2.1). |
| Multi-signature wallet, provider holds one of several keys | Covered on a live page: where the legal line sits for non-custodial and multi-sig wallets. | |||
Sources: FinCEN FIN-2019-G001 and the FIU-IND guidelines dated 8 January 2026, as at 18 September 2026; Regulation (EU) 2023/1114, the VARA rulebooks and Dubai Law No. (4) of 2022, as at 19 September 2026. Each cell is Infinilex’s application of the cited provision to a generic architecture, not a regulator’s statement about it.
Why the rulebooks are silent on MPC and account abstraction
FinCEN’s guidance of 9 May 2019 says its treatment of wallet intermediaries “is not technology-dependent” and rests on four criteria, the fourth being total independent control over the value. MiCA speaks of the means of access, VARA’s Custody Services Rulebook (version dated 19 May 2025, effective 19 June 2025) of keys, seeds and multi-signature approaches, and FIU-IND of instruments enabling control. A key share, a session key and a guardian right are named nowhere, so the question is whether each behaves like the thing the text does name. The four tests are set out in full in non-custodial wallets and custody licensing.
MPC and threshold signatures: where the share sits
In a threshold scheme no complete private key exists in one place; a set number of shares must cooperate to sign. Where every share lives on client devices and the provider only ships coordinating software, the provider resembles the developer FinCEN says may be exempt for creating or selling an application, and the non-custodial wallet provider MiCA’s recital 83 keeps out of scope.
Where the provider keeps a share, the US and the other three regimes part company. On FinCEN’s second-authorisation-key reasoning, a provider that cannot move value alone lacks total independent control. The MiCA, VARA and FIU-IND tests ask instead whether a means of access, a key or an instrument enabling control is held for someone else, and a share that takes part in every signature can be read that way.
MiCA Article 75(9) permits a custody CASP to use other providers of that service only where they are authorised CASPs, and ESMA’s statement of 23 June 2026 reminds CASPs not to delegate custody to unauthorised entities. A CASP building on a share-holding vendor therefore needs its own documented view.
Smart-contract accounts: bundlers, paymasters and session keys
Under ERC-4337 users hold smart-contract accounts with their own verification logic. A bundler packages UserOperations into a transaction to the singleton EntryPoint contract, and a paymaster is a helper contract that agrees to pay for the transaction instead of the sender (ERC-4337, as at 19 September 2026).
MiCA’s recital 22 covers services performed or controlled directly or indirectly, including where part is decentralised. Recital 93 excludes validators, nodes and miners from the transfer service; it does not mention bundlers or relayers, so a provider should not assume the exclusion reaches it.
Three provider roles deserve a written analysis: a session key the provider holds, a guardian right that can replace the owner’s signer, and an upgrade right over the account’s logic. Each can reach the assets without the client, depending on how it is scoped.
Hardware-signer SaaS and co-signing APIs
A signing service that runs the hardware, holds the key and signs when an API call arrives is the arrangement the custody definitions describe most directly: FinCEN’s hosted wallet and VARA’s Custody Services definition both fit, as row four of Schedule A shows.
The position improves where the client operates the device, or where the provider co-signs but cannot complete a transaction. The operating controls for a signer service are in the self-custody compliance controls checklist.
Five facts that flip the verdict
- Can the provider complete a transaction alone? One share plus another it controls counts. This is FinCEN’s total independent control criterion (ss.4.2.1, 4.2.2) and VARA’s held-or-controlled marker (Rule V.A.2).
- Can the provider recover, rotate or re-share keys without the client? A recovery path it can run by itself reads as a means of access under MiCA Article 3(1)(17).
- Is the value booked in the provider’s accounts, or does the client reach the chain only through the provider? FinCEN treats either fact as money transmission regardless of the label (s.4.2.2).
- Does a provider-run paymaster, bundler or relayer handle client value, or only gas? Accepting and transmitting value engages FinCEN’s section 4.4, MiCA’s transfer service and VARA’s transfer and settlement activity.
- Does an affiliate or special purpose vehicle the provider controls hold keys? VARA counts assets held by a controlled legal entity (Rule V.A.2(c)).
If the answer is custody: what follows, and who signs
EU. Custody and administration is crypto-asset service (a), and Article 59 bars providing it in the Union unless the provider is authorised as a CASP under Article 63 or is a financial entity permitted under Article 60; the Article 143(3) transitional period ended on 1 July 2026. Article 75 then sets register, statement, segregation and liability duties, set side by side in crypto custodian licence terms compared. On MiCA authorisation, Infinilex quarterbacks, EU local counsel files.
Dubai. Custody is a standalone activity licence. The Custody Services Rulebook requires a separate legal entity from group members carrying on other VA activities (Rule III.B.5), with a limited exception for VA Transfer and Settlement Services (Rule III.B.6), statements at least monthly (Rule III.D.4) and an audit trail kept for at least eight years (Rule III.D.5). The Dubai entity that will hold the licence signs and files the application as applicant; Infinilex coordinates through the VARA licensing service; fees and capital are on the VARA cost, capital and timeline page. For the ADGM and DIFC regimes see ADGM and DIFC crypto licensing.
India. A provider carrying on a notified activity must register with FIU-IND; non-registration is treated as a violation of the PMLA and may invite action under section 13(2). The reporting entity files on FINGate; the legal sign-off on the FIU-IND registration track sits with an Indian advocate, company secretary or chartered accountant.
US. On 15 September 2026 the Senate vote to invoke cloture on the motion to proceed to H.R.3633, the Digital Asset Market Clarity Act, failed, short of the 60 votes required. Nothing in it is enacted, FinCEN guidance FIN-2019-G001 remains the operative federal money-transmission position, and the SEC’s investment-contract analysis stands. This piece covers federal law only. Any US registration or reliance opinion is signed by Infinilex counsel admitted in the US; Infinilex counsel qualified in India and for the relevant UAE regulator sign those legs, and for the EU leg Infinilex scopes the work, builds the fact record and briefs the EU local counsel who sign, named to the client before they act.
Frequently asked questions
Is an MPC wallet provider a custodian?
It depends on what the provider's key share can do without the client. None of FinCEN, MiCA, VARA or FIU-IND names MPC, so each regime's general test applies. If the provider holds one share that cannot complete a transaction alone, section 4.2.2 of FinCEN's FIN-2019-G001 points away from money transmission. MiCA, VARA and FIU-IND instead ask whether a means of access, a key or an instrument enabling control is held for another, so a provider-held share is exposed there even where it clears the US test.
Does an MPC wallet provider need a custody licence in Dubai or the EU?
Only if what it does meets the custody definition, which turns on the key-share design. MiCA Article 3(1)(17) asks whether the provider safekeeps or controls the means of access to crypto-assets on behalf of clients; recital 83 keeps hardware or software providers of non-custodial wallets outside the Regulation. VARA defines Custody Services as safekeeping virtual assets for another on verified instructions, and treats client assets as held or controlled where the firm holds or controls the private keys or seed phrase. A provider that keeps no share has the stronger position.
How is a smart contract wallet using account abstraction regulated for custody?
None of FinCEN's 2019 guidance, MiCA, VARA's rulebooks or FIU-IND's guidelines names ERC-4337 accounts, so each regime's general test applies to whoever runs the surrounding services. FinCEN says the developer of a decentralised application is not a money transmitter for creating it, but becomes one by deploying it to accept and transmit value. MiCA's recital 22 keeps services provided in a fully decentralised manner without any intermediary outside the Regulation. FIU-IND says a smart contract does not relieve the controlling parties. A provider-held session key, guardian or upgrade right is the fact to examine first.
How is a hardware signer SaaS or co-signing API classified for custody?
By who can make the device sign. Where the provider operates the signing hardware, holds the only key and signs when the client instructs, the pattern matches FinCEN's hosted wallet: total independent control, even though the host is contractually obliged to act only on the owner's instructions. It also matches VARA's definition of Custody Services. Where the provider sells hardware or software that the client alone operates, MiCA's recital 83 and FinCEN's section 1.1 point the other way.
Is a threshold signature wallet provider a money transmitter in the US?
FinCEN's 2019 guidance does not name threshold signatures; its closest reasoning is section 4.2.2 on multiple-signature wallet providers. Applying that reasoning, a provider points away from money transmission if it restricts its role to creating unhosted wallets that need its additional authorisation and it cannot move value alone. The provider becomes a money transmitter if it also hosts the wallet, records the value as an entry in its own accounts, stands between the owner and the payment system, or keeps total independent control, whatever it calls itself. This is the federal position only, as at 18 September 2026.
Need a written view on your key architecture?
Bring the signing flow: who holds each share or signer, who can recover it, and what any relayer touches. On a free discovery call we map those facts against all four tests.
Further reading
Self-custody meets institutional control: where the legal line actually sits · Self-custody compliance controls checklist · Crypto licence requirements by country · Crypto custodian licence terms compared · The crypto travel rule in India, the UAE, the EU and the US · Crypto AML programme
This article is general information, not legal advice on your architecture, and reaches no conclusion on any product or vendor. Regulator positions are as at 18 and 19 September 2026, and the page is re-verified quarterly. Have the structure reviewed on your own facts before you rely on it.