Tokenized stocks may be onchain, but the SEC still wants the keys

cointelegraphPublished on 2025-12-18Last updated on 2025-12-18

Abstract

The US Securities and Exchange Commission (SEC) has issued guidance allowing broker-dealers to custody tokenized stocks and bonds under existing customer protection rules, specifically Rule 15c3-3. This means tokenized securities will be treated under traditional frameworks rather than as a new asset class. Broker-dealers must maintain exclusive control over private keys, ensuring that only authorized parties can move the assets. They are also required to prepare for risks like 51% attacks, hard forks, and legal restrictions. The guidance emphasizes that tokenized securities must behave like traditional securities, regardless of blockchain technology. Meanwhile, platforms like Nasdaq and Securitize are advancing plans for compliant onchain trading of tokenized equities.

The US Securities and Exchange Commission’s Trading and Markets Division on Wednesday laid out how broker-dealers can custody tokenized stocks and bonds under existing customer protection rules, signaling that blockchain-based crypto asset securities will be slotted into traditional securities safeguards rather than treated as a new category.

The division said it would not object to broker-dealers deeming themselves in possession of crypto asset securities under existing customer protection rules, as long as they meet a set of operational, security and governance conditions. This applies only to crypto securities, including tokenized stocks or bonds.

While the statement is not a rule, it provides clarity on how US regulators expect tokenized securities to fit within traditional market safeguards.

The guidance suggests that tokenized securities are not treated as a new asset class with unique rules. Instead, they are being placed into existing broker-dealer frameworks, even if they settle within blockchain networks.

Source: US SEC

TradFi on a blockchain: Tokenized securities’ custody rules

At the core of the statement is Rule 15c3-3, the regulator’s consumer protection rule. This requires broker-dealers to maintain control or physical possession of fully paid customer securities.

The division said that crypto asset securities recorded in blockchains may satisfy the “physical possession” requirements under certain circumstances. This means broker-dealers must retain exclusive control over the private keys used to access and transfer the assets.

Despite being on a blockchain, customers and third parties, including affiliates, should not have the ability to move the security without the authorization of the broker.

The statement draws a clear boundary between tokenized securities and crypto-native self-custody models. It prioritizes customer protection over crypto’s permissionless ethos.

Broker-dealers are expected to prepare for scenarios like 51% attacks, hard forks, airdrops and other disruptions. They must also maintain plans that account for seizure, freezing or transfer restrictions under lawful orders.

The guidance reinforces that, regardless of the technologies used to issue or settle tokenized stocks or bonds, they are expected to behave like securities first.

Trading tokenized securities inside regulated market rails

In a separate statement issued the same day, SEC Commissioner Hester Peirce highlighted the trading-side challenges that remain for crypto asset securities.

Peirce raised questions focusing on national securities exchanges and alternative trading systems that facilitate trading crypto asset securities, including pairs where one asset is a security and the other is not.

The questions reflect growing pressure to settle blockchain-based assets with market-structure rules originally designed for traditional equities.

Peirce’s request raises whether existing frameworks and related disclosures and reporting requirements impose costs that outweigh their benefits when applied to crypto trading platforms.

Related: US Fed pulls guidance blocking its banks from engaging with crypto

Platforms jumping into tokenized equities

The statements come as crypto platforms and trading institutions have increasingly begun to tokenize securities.

On Nov. 30, Nasdaq's head of digital assets strategy, Matt Savarese, said the exchange plans to move fast on tokenized stocks. He said the exchange plans to work with the SEC as quickly as possible to make the feature available in the trading platform.

On Tuesday, Securitize, which focuses on tokenizing securities, announced that it plans to launch compliant, onchain trading for tokenized stocks. The company said that it will be presented in a swap-style interface familiar to decentralized finance (DeFi) users.

On Thursday, crypto exchange Coinbase launched a stock trading feature as part of its push to become an “everything exchange.”

Magazine: Koreans ‘pump’ alts after Upbit hack, China BTC mining surge: Asia Express


Related Reads

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru3h ago

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru3h ago

Trading

Spot
活动图片