Get the hottest Fintech Hong Kong News once a month in your Inbox
Digital asset security used to be treated as a wallet problem. Protect the private key and the asset stays safe; lose it, and the asset is gone.
The logic still holds, but it no longer reflects what digital asset key management now demands of exchanges, custodians, banks and other platforms.
Banks are exploring digital asset services while custodians build platforms for institutional investors. Regulated assets are also starting to move onto digital rails, supported by blockchain infrastructure providers operating behind the scenes.
Daniel Toh,VP of Systems Engineering, APJ at Thales, said the shift has changed how organisations think about security.
Daniel Toh
“Private keys are not simply cryptographic credentials as they represent control over financial assets,” he said.
In an institutional digital asset environment, a private key can approve a customer withdrawal or move assets under custody. In tokenised markets, the same kind of authority may sit behind issuance or blockchain network operations.
Five years ago, Daniel noted, the industry’s focus sat largely on protecting cryptocurrency wallets.
Banks, custodians, asset managers and payment providers are now entering the market, and they expect controls closer to what they already run in traditional finance.
Daniel explained that the discussion has moved from “How do we secure keys?” to “How do we build governance, accountability and trust around digital asset operations?”
Hardware security modules, or HSMs, have taken on a broader operational role in response, appearing across exchanges, custody platforms and tokenisation infrastructure, where organisations need tighter control over who can use a key and under what conditions.
“The challenge is no longer just security. It’s implementing security without slowing down operations or creating friction for customers,” Daniel added.
Digital Asset Security Has Become a Financial Control Issue
Institutional platforms therefore must treat digital asset key management as part of their wider control environment.
Daniel observed that institutions want the same level of confidence in digital assets that they expect from traditional financial infrastructure. Key management, in turn, has to support more than storage. For many institutions, this mirrors the role HSMs have long played in protecting payment systems, PKI and other critical financial infrastructure.
A proper control framework should show who authorised a transaction and how the key remained protected. It should reduce insider risk without making multi-chain operations harder to run.
More mature businesses are also looking at the full transaction lifecycle. They want to know whether the system signs only authorised transactions and whether internal misuse can be caught early enough to stop it.
Evidence matters because organisations must be able to demonstrate what happened, who approved it and which controls were applied.
Exchanges Need Security That Keeps Up With Volume
Crypto exchanges clearly illustrate the problem because their role has expanded.
Many now operate more like financial institutions than trading venues, Daniel pointed out. They hold customer assets, serve institutional investors and run across multiple blockchain networks, often with staking services layered into the business.
Crypto exchange key management has moved closer to the centre of the operating model as a result.
“What we’re seeing is a move towards policy-driven security architectures where HSMs provide a hardware root of trust for transaction signing and key protection,” he explained.
Exchanges need to process high transaction volumes while keeping operational signing keys away from unnecessary exposure.
Controls that slow the business too much create their own problems, while speed without enough protection introduces obvious risk.
Daniel added that exchanges are tightening approval processes and automating parts of the workflow so transaction throughput does not come at the expense of security.
“The goal is to ensure that security scales with business growth rather than becoming a bottleneck,” he said.
What HSM Deployment Looks Like in Practice
Consider how an institutional digital asset platform handles a high-value transaction.
Before any signing takes place, the request may pass through risk analysis and policy checks. Approval checkpoints can then verify whether the transaction should proceed.
Once approved, the signing request is sent to the HSM, which performs the cryptographic operation inside a trusted hardware environment while keeping the private key within its secure boundary. The same architectural pattern is increasingly being adopted across custody platforms, tokenisation systems and blockchain infrastructure.
Custody Turns Key Management Into an Operating Model
Custody brings digital asset key management even closer to institutional finance.
Clients need assurance that assets cannot move without proper authority. Regulators and boards, meanwhile, expect evidence that the control model works beyond policy documents.
Daniel pointed out that custodians recognise that safeguarding digital assets means safeguarding trust.
Layered control frameworks have become the backbone of digital asset custody security. Segregation of duties and dual control reduce the risk of one person moving client assets, while audit trails show how each decision was made.
“The emphasis is on ensuring that no single individual, application or system can independently control client assets,” he said.
HSMs sit inside that model as a trusted cryptographic foundation. They protect private keys throughout their lifecycle and allow custodians to sign transactions without exposing those keys outside the secure environment.
Many custody platforms integrate HSMs into wider operational workflows, linking cryptographic controls with approval processes and audit evidence.
“In many institutional custody architectures, the HSM serves as the root of trust upon which the entire operational model is built,” Daniel observed.
In practice, institutions need more than documented procedures. They need operational controls that demonstrate how assets remain protected while transactions are being authorised and executed.
Tokenisation Raises the Stakes for Digital Asset Key Management
Tokenisation broadens the conversation beyond cryptocurrency, and tokenisation security is becoming part of that conversation in ways crypto-only platforms rarely had to consider.
Daniel called it one of the most significant developments in digital assets because it brings real-world financial assets onto digital infrastructure.
Tokenised financial instruments raise different questions than a crypto wallet does, especially when real-world ownership rights are involved.
When a private key authorises the issuance of tokenised securities or the transfer of regulated digital assets, compromised credentials can have direct financial and legal consequences.
“We’re no longer just protecting cryptocurrency holdings. We’re protecting ownership rights, issuance authority and asset lifecycle controls,” Daniel added.
Compromised or misused keys can affect how an asset is issued, administered or transferred. Smart contract governance adds another layer, especially when administration keys influence how the platform operates over time.
Daniel pointed out that tokenisation forces organisations to look beyond wallet protection, especially when issuer keys and smart contract governance sit inside regulated workflows.
“Key management should not be viewed as a technology project, but it should be viewed as financial infrastructure,” he explained.
Because these controls become increasingly difficult to retrofit, decisions made early will shape how confidently an organisation can scale tokenisation as adoption grows.
Infrastructure Providers Join the Trust Layer
Blockchain infrastructure providers have a different role from exchanges and custodians, but their cryptographic operations are becoming equally important.
Daniel noted that these providers increasingly see themselves as part of the trust layer supporting digital asset markets.
Infrastructure providers are responsible for cryptographic operations that support network integrity and service availability, particularly in validator and staking environments.
Failures here don’t always look like a failed withdrawal or a custody breach.
They may affect network participation and the reliability of services institutional customers depend on.
Many providers are adopting HSM-based architectures to protect validator and signing keys, since those customers expect standards close to what they already see in traditional finance, Daniel added.
Providers may sit behind the scenes, but their controls still influence how much confidence banks and other institutional customers place in the services built on top.
Key Management as a Business Enabler
The wider shift, Daniel observed, is that organisations are starting to view secure key management as more than a security investment.
“They increasingly see it as a business enabler. One that helps them build trust, satisfy regulators, onboard institutional customers and scale digital asset services with confidence,” he said.
The value varies by use case.
An exchange may need to process large transaction volumes without exposing operational keys. A custodian must prevent any single person or system from gaining sole control of client assets. Tokenisation platforms need to protect the authority behind issuance and asset administration.
HSMs sit beneath those operations to keep cryptographic authority within a controlled hardware environment while the wider platform applies the required approvals and policies. Rather than acting as standalone security devices, HSMs become part of an end-to-end control framework that combines cryptographic protection with business policies, approval workflows and audit evidence.
As digital assets become part of financial infrastructure, digital asset key management is turning into a question of control rather than a back-office security line item.
“The conversation around digital assets has evolved, from protecting private keys, to building trusted operational models that can support institutional finance at scale,” Daniel noted.
“The question today is ‘How do we use HSMs to build secure, scalable and trusted digital asset operations?’ That is where we are seeing the strongest adoption and the greatest business value.”
Featured image: Edited by Fintech News Hong Kong based on an image by freepik via Magnific.