Canada Introduces New Crypto Custody Rules to Protect Investors After QuadrigaCX Collapse

TheNewsCryptoPublished on 2026-02-04Last updated on 2026-02-04

Abstract

Following the QuadrigaCX collapse in 2019, which resulted in the loss of $123 million in customer funds, Canada’s Investment Regulatory Organization (CIRO) has introduced new crypto custody rules for exchanges. The regulations aim to protect investors by enforcing stronger custody arrangements, improved internal controls, and clear separation of client assets from company funds. The framework adopts a risk-based approach, requiring higher-risk firms to meet stricter standards while allowing flexibility for lower-risk platforms. CIRO will actively update the rules as new threats emerge and has the authority to investigate misconduct and impose penalties. The move reflects Canada’s protective regulatory stance, bringing crypto custody under existing securities laws.

The Canadian Investment Regulatory Organization (CIRO) has announced that Canada has introduced new crypto custody rules for the exchanges to reduce the risk of investor losses and prevent failures, as the QuadrigaCX collapse happened in 2019.

This move immediately takes effect after the direct response to the past crypto failure, like the QuadrigaCX collapse. QuadrigaCX was one of the canada’s largest crypto exchanges. After its CEO died, it has missed about $123 million of customer funds. Investigations later found that this was caused by its poor controls, weak governance, and serious custody failures.

What CIRO’S new crypto rules do

CIRO’S Digital Asset Custody Framework used a risk-based approach, which sets clear standards for protecting investors from hacking, fraud, weak controls, and poor governance. The firms which higher risk activities should meet the stronger custody standards, and the lower-risk firms get more flexibility but still need the protections.

After the new rules, crypto platforms in Canada should use stronger custody arrangements and improve the internal controls and oversight with clear separation of customer assets from the company funds. CIRO says many platforms are already following a similar structure, and any transitions to the new rules will be handled case by case without disrupting the firms suddenly.

Canada’s approach towards crypto custody

CIRO says that it will actively monitor the new risk, and the regulators will update the new rules if they seem to have any new custody threats and repeated problems across the firms. This shows that the framework still needs to be fixed and will evolve as per the crypto market changes.

Canada has taken a protective approach towards crypto regulations and is bringing crypto custody platforms under the existing securities laws. CIRO has the authority to investigate the misconduct, impose fines, and suspend the firms, which shows a strong focus on the custody and increased attention on stablecoins.

Highlighted Crypto News:

Ethereum Eyes Frame Transactions as Hegota Headliner

TagsCanadaCryptocurrency

Related Questions

QWhat event prompted Canada to introduce new crypto custody rules?

AThe collapse of QuadrigaCX in 2019, which resulted in the loss of approximately $123 million in customer funds due to poor controls, weak governance, and custody failures.

QWhich organization announced Canada's new crypto custody rules?

AThe Canadian Investment Regulatory Organization (CIRO) announced the new crypto custody rules.

QWhat is the main approach of CIRO's Digital Asset Custody Framework?

AIt uses a risk-based approach, setting clear standards for protecting investors from hacking, fraud, weak controls, and poor governance, with higher-risk firms facing stronger custody requirements.

QHow do the new rules require crypto platforms to handle customer assets?

APlatforms must use stronger custody arrangements with clear separation of customer assets from company funds and improve internal controls and oversight.

QWhat regulatory powers does CIRO have under the new framework?

ACIRO has the authority to investigate misconduct, impose fines, and suspend firms, showing a strong focus on custody and increased attention on stablecoins.

Related Reads

a16z: From Companies to DAOs, DUNA May Become the Next Generation Organizational Form

This article, "From Companies to DAOs: How DUNA Could Become the Next Organizational Form," traces the 500-year evolution of business collaboration. It begins with medieval structures like the *commenda* and Florentine *compagnia*, which exposed partners to personal risk. The modern corporation, exemplified by the Dutch East India Company (VOC), was a revolutionary leap, enabling large-scale, capital-intensive ventures by offering limited liability and reducing coordination costs. However, corporations introduced new challenges like principal-agent problems and bureaucratic overhead. The piece argues that software and internet-native protocols are now reducing these traditional overheads. Decentralized Autonomous Organizations (DAOs) emerged as a new model for coordination without centralized management. Yet, DAOs face a significant legal vacuum: they lack legal recognition, leaving members exposed to unlimited personal liability, and their tokens are vulnerable to being classified as securities under unclear regulations (e.g., the Howey Test). This has forced projects into suboptimal workarounds like offshore foundations. The article identifies the Decentralized Unincorporated Nonprofit Association (DUNA) as a potential solution. Recently legalized in states like Wyoming, the DUNA provides a legal wrapper for decentralized networks. It grants key protections—legal personality, limited liability, and perpetual existence—to a group without imposing a traditional hierarchical management structure. This allows token-holder communities to govern, hold assets, and contract as a single legal entity, aligning with their decentralized nature. While DUNA doesn't solve all governance challenges or magically resolve securities law questions, it represents a crucial step. It fills the legal recognition gap, offering a native legal form for internet-scale, decentralized collaboration and extending the separation of personal risk from organizational venture into a new domain.

marsbit1m ago

a16z: From Companies to DAOs, DUNA May Become the Next Generation Organizational Form

marsbit1m ago

2026 Mid-Year Report On-Chain RWA: Tokenized Stock Market Cap Doubles in a Year, But 90% of Rights Are Hollow Shells

The 2026 Mid-Year Report on On-Chain RWA highlights a significant growth in tokenized stock market capitalization, which nearly doubled from $951 million in March to $1.89 billion by July. However, the report reveals a fundamental contradiction in this "layer 2.5" ecosystem: products with the strongest legal foundation (like regulated U.S. infrastructure) lack liquidity and distribution, while freely tradable offshored wrapper products often lack substantive ownership rights. The increase is driven largely by a few products (SECZ, FGRS, STRCx) and platforms (Ondo, xStocks, Securitize collectively hold over 85% share). While distributed value across networks like Ethereum, Solana, and BNB Chain has grown, the market remains fragmented. Products referencing the same underlying asset (e.g., Apple stock) are distinct legal liabilities with different intermediaries and jurisdictional rules, offering varying degrees of legal claim. The report cautions that headline numbers are misleading, as they reflect changes in distributed token value—driven by issuance, conversions, and price movements—not pure investor inflows. True "canonical shares" with legal ownership, wide wallet distribution, institutional liquidity, and independent on-chain price discovery do not yet exist at scale. Tokenized treasuries show stronger product-market fit, and ETFs may be easier to scale than single stocks. The core takeaway is a trade-off: legal certainty versus liquidity and composability.

marsbit50m ago

2026 Mid-Year Report On-Chain RWA: Tokenized Stock Market Cap Doubles in a Year, But 90% of Rights Are Hollow Shells

marsbit50m ago

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

The Coldcard hardware wallet has been compromised, with hackers stealing approximately 594.5 Bitcoin (~$40 million) from 500 addresses in just 25 minutes. The root cause was a critical software bug, undetected for five years, which disabled the device's secure chip for generating true random numbers. This led to the creation of private keys based on predictable data like the processor's serial number, drastically reducing cryptographic security. The attackers exploited this offline by brute-forcing possible seed phrases, finding active addresses on the public ledger, and signing transactions. Initially, Coinkite (Coldcard's maker) claimed only older models were at risk but later admitted all devices running the compromised firmware were vulnerable. CEO Rodolphe Novak (NVK) apologized but ruled out financial compensation for affected users. To secure funds, owners must urgently update their firmware to specific safe versions, generate a completely new seed phrase on the updated device, and transfer all assets to new addresses created with that new seed. While a BIP-39 passphrase can help, it does not replace this migration process. Other Coinkite products like TAPSIGNER were not affected. This incident underscores that even specialized hardware requires rigorous, independent code audits, especially for cryptographic functions. It parallels past failures, like a 2006 OpenSSL bug in Debian, and raises questions about whether automated code analysis can ever fully replace human scrutiny in critical security areas.

cryptonews.ru3h ago

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

cryptonews.ru3h ago

Trading

Spot
活动图片