
Institutional
Should Institutions Trust One Vendor or Four? The Case for Specialized Crypto Infrastructure
FTX and Bybit both failed because one entity or one signing pathway held every function at once. Separating custody, staking, prime brokerage, and issuance into independently audited entities keeps a single failure from spreading.
SEP 16, 2026
Last updated SEP 16, 2026 · V1
TL;DR
- FTX misused roughly $8B–$10B in customer funds; Bybit lost roughly $1.5B. After those events, the practice of unbundling, meaning using separate vendors for separate needs gained traction as a risk control.
- Combining services in how a client uses them (one login, one dashboard) presents lower operational risk; however combining them inside one legal entity or one balance sheet does not. That’s why the market is consolidating and unbundling at the same time.
- The specialized model separates custodian, staking provider, prime broker, and ETP issuer into separately regulated and audited entities.
- Four vendors potentially create more attack surface but a smaller blast radius, and the integration points can be contractually and technically bounded.
- The decision comes down to blast-radius thinking: for each counterparty what could go wrong if that vendor has a bad week.
- Diligencing four vendors is more work, but that work is auditable. Bundled simplicity hides the boundaries you cannot inspect.
Specialized crypto infrastructure: what is “unbundling”
Unbundling means using independent and audited entities, with financial intermediaries being separately regulated for functions that a full-stack model would place inside one: custody, trading, market-making, settlement, and issuance. Bundling puts all those functions onto a single vendor.
A custodian, a prime broker, and an ETP issuer operate as separately regulated entities, while the staking provider operates as a non-custodial technology platform, with each being independently audited.
| Type | What is shared | Example | Risk character |
| Convenience bundling | One login, one integration, one dashboard | Unified UX across independent providers | Low, functions stay separate underneath |
| Risk bundling | One balance sheet, one key, one legal entity | All failure modes held together | High, one failure reaches everything |
Convenience bundling is fine. One interface over independent, segregated providers costs nothing structurally.
Risk bundling is the concern. When one balance sheet, one signing pathway, or one legal entity holds every failure mode, a single event cascades.
Lesson One, FTX: when custody, trading, and market-making share one balance sheet
The failure at FTX was structural, and the structure is what institutions should study.
FTX acted as custodian and exchange at once. Through its affiliate Alameda Research, FTX also acted as proprietary trader and market-maker.
Customer assets were commingled across entities. According to prosecutors and bankruptcy filings, roughly $8B to $10B in customer deposits were misused, and Alameda borrowed from customer funds routinely.
The contagion mechanism was direct. When Alameda grew insolvent after the FTT token collapsed in November 2022, a customer run followed. Vertically integrated conflicts of interest meant there was no firewall between the functions.
John J. Ray III, who oversaw the Enron liquidation, said he had never seen such a complete failure of corporate controls, and FTX had no board and no proper accounting department.
The generalizable lesson concerns structure. When functions that should be adversarial or independent operate inside one entity, there is no firewall. Segregation is a structural property enforced by legal separation between entities. FTX terms only imitated segregation.
Regulated frameworks exist to force real separation, for example: MiFID II segregation rules and CFTC commingling prohibitions
Lesson Two, Bybit: when one trusted pathway controls everything
The Bybit heist didn’t break any encryption or signing keys, which makes the case interesting.
On February 21, 2025, attackers stole roughly $1.5B, more than 401,000 ETH and related assets. It remains the largest crypto theft on record. Investigators attributed it to North Korea’s Lazarus Group.
The mechanism targeted the tooling around the keys. Attackers compromised a Safe{Wallet} developer’s machine and injected malicious JavaScript into the signing interface at app.safe.global.
The malicious code activated only for Bybit. Ordinary users of the interface saw nothing unusual, while Bybit’s signers approved a routine cold-to-warm transfer as it appeared on screen.
The actual transaction altered the wallet’s contract logic and ownership. The displayed transaction and the signed transaction were different.
The multisig worked exactly as designed, the threshold was met, and multiple humans signed, but the interface was compromised.
Signers trust that the screen shows what they’re actually signing. When it doesn’t, every counterparty can approve a fraudulent transaction without knowing.
As a result, one dependency shared across an entire signing flow turned into a single point of failure even when no cryptography was broken. Attackers target the humans and tooling around the keys.
The case for specialized crypto infrastructure
When the custodian, staking provider, prime broker, and ETP issuer are four separate entities, a failure at one does not reach the other three. Each is independently audited, and regulated where applicable, so the blast radius stays local in a bad-case scenario.
Each specialist becomes independently diligence-able. That produces four advantages:
- Separate audits. Each entity carries its own attestations and control reviews.
- Separate regulatory oversight. Different regulators watch different functions.
- Separate insurance. Coverage attaches to specific, bounded functions.
- Separate legal entities. One insolvency does not consume the others.
Diligencing four vendors is more operationally complex than diligencing one. However, that complexity is auditable. You can inspect each boundary, contract, and the underlying dependencies.
Bundled simplicity hides the elements you cannot verify. Complexity you can audit beats simplicity you cannot check.
A specialized staking provider fits this model directly. Everstake is a non-custodial validator that has operated 130+ networks to date, and its infrastructure stays separate from custody and trading at all times.
Assets remain with the client’s chosen custodian. The staking function is isolated and independently reviewable so has no exposure to the problems of neighbors.
That’s why specialized institutional custodians continue to proliferate, and regulated banks are entering as single-function custodians.
The counterarguments
Objection 1: More vendors means more attack surface. More integration seams create more places for Bybit-style supply-chain compromise. But attack surface and blast radius are different measures. Specialization trades a larger surface for a smaller blast radius. The seams can be contractually and technically bounded, monitored, and constrained.
Objection 2: The market is consolidating. Ripple spent roughly $4B across 2023 to 2025 acquiring Hidden Road, GTreasury, and Rail, and now spans custody, prime brokerage, treasury, and settlement.
The consolidation extends across banks too. Citi plans native Bitcoin custody before the end of 2026 under its Custody+ platform, and BNY Mellon, State Street, and Standard Chartered are moving similarly.
A bank offering integrated access under segregated, regulated, bankruptcy-remote custody differs from FTX-style risk bundling. The core difference is that Citi pitches traditional and crypto assets within one reporting framework, while custody stays legally segregated underneath. Integration at the UX layer differs from commingling at the entity/vendor layer.
Even the consolidators keep functions legally separate. Ripple still relies on a third-party vendor for compliance tooling, and BNY Mellon serves as reserve custodian for RLUSD.
Objection 3: Coordination risk. Moving assets across four counterparties introduces settlement, timing, and operational risk, and connectivity concerns.
Off-exchange settlement, clear legal segregation, and coordination tooling address timing and counterparty exposure. Infrastructure answers the coordination objection.
The answer to coordination overhead is better coordination. Specialization is the right default for high-value, fiduciary-bound institutional holdings where blast-radius containment outweighs coordination overhead.
A decision framework: one vendor or four?
These are evaluative criteria, and each institution weighs them against its own mandate and risk appetite.
| Question | What to look for | Why it applies |
| What functions reside inside one legal entity? | Custody, trading, and issuance separated | Concentration is the FTX failure mode |
| Are client assets segregated and bankruptcy-remote? | Legal segregation backed by structure | Determines recovery if a vendor fails |
| Is each applicable function separately regulated, and is every entity independently audited? | Distinct oversight and attestations | Enables independent diligence |
| What is the shared-dependency map? | Signing tooling, key custody, balance sheet | Shared tooling is the Bybit failure mode |
| What is the blast radius of a bad week? | Downstream effects of one failure | The central containment test |
Run each counterparty through blast-radius thinking. For every vendor, ask what fails downstream if that vendor has a bad week.
Please note, it is not legal, tax, or fiduciary advice.
Conclusion
Unbundling is the market pricing in lessons learned the expensive way. FTX proved the danger of one balance sheet, and Bybit proved the danger of one trusted pathway.
The market is doing two things at once: consolidating at the convenience layer while separating at the risk layer. The reconciling idea is the distinction between vertical integration under segregated custody and commingling under one entity. Complexity you can audit beats simplicity you cannot verify.
FAQ
What is unbundling in crypto infrastructure?
Unbundling is the practice of using separate entities for custody, staking, prime brokerage, and issuance (with financial intermediaries being separately regulated). This is the model Everstake operates within as a standalone, audited, non-custodial staking provider.
Why did FTX collapse?
FTX commingled customer funds with its affiliate Alameda Research, and roughly $8B to $10B in deposits were misused. FTX had no real segregation, no board, and no auditable controls.
How did the Bybit hack happen?
Attackers compromised a Safe{Wallet} developer’s machine and spoofed the signing interface used by Bybit. Around $1.5B and more than 401,000 ETH were stolen on February 21, 2025, attributed to Lazarus Group.
Does using several providers reduce risk compared to using one crypto custodian?
Using four independent, segregated providers contains the radius of any single failure, which suits high-value institutional holdings. Everstake supports this model by keeping staking separate from custody, so a client’s custodian relationship stays independent.
What is the difference between vertical integration and risk bundling?
Vertical integration can keep functions in separate, segregated, regulated entities under one brand. Risk bundling places all failure modes on one balance sheet, one key, or one entity, which is the pattern FTX demonstrated.
Does specialization increase or decrease attack surface?
Specialization can increase attack surface while decreasing blast radius, since more seams exist but each is bounded. A single failure no longer reaches every function, which is the containment goal Everstake and other specialists support.
Share with your network