Nigeria SEC Proposes 80% Cold Storage Requirement for Customer Crypto Assets
Nigeria’s Securities and Exchange Commission has proposed a major overhaul of how crypto companies protect customer funds, including a requirement that digital-asset custodians keep at least 80% of client assets in cold or offline storage.
The requirement is part of the SEC’s broader Proposed Rules on Digital and Virtual Assets Operations, Custody and Markets, published on August 20, 2026. The draft covers issuance, tokenisation, trading, custody, transfers, settlement, investment services and other virtual-asset activities in Nigeria.
The rules are not yet final.
The SEC opened them for public comment, meaning the framework could still change before becoming binding.
But if adopted substantially as written, the proposal would impose some of the clearest custody standards yet on Nigeria’s growing crypto industry.
At Least 80% of Customer Crypto Would Have to Stay Offline
The most eye-catching requirement is the proposed cold-storage threshold.
Under the draft, Digital Asset Custodians would be expected to hold at least 80% of client digital or virtual assets in cold storage, unless the SEC specifies another percentage.
The remaining portion could stay in hot or warm wallets where necessary for operational purposes such as withdrawals, settlement and transaction processing. Reporting on the proposed framework also notes that those online wallets would be subject to monitoring, reconciliation and access controls. (Technology Times)
That effectively means the majority of customer crypto would need to be stored in systems that are not continuously connected to the internet.
What Is Cold Storage?
Cold storage refers to keeping the private keys controlling crypto assets offline.
A conventional exchange wallet connected to the internet is often described as a hot wallet.
Hot wallets are useful because they make withdrawals and transactions faster.
But because they are online, they can also be more exposed to cyberattacks.
Cold-storage systems are designed to reduce that attack surface by keeping critical signing keys disconnected from everyday internet-connected infrastructure.
For a large crypto custodian, this does not necessarily mean simply placing funds on a consumer hardware wallet.
Institutional cold-storage systems can involve:
- multiple authorised signers,
- specialised key-management systems,
- offline signing environments,
- physical security,
- access controls,
- and recovery procedures.
Nigeria’s draft goes beyond simply requiring offline storage and also proposes stronger controls around how private keys are generated, stored and used. (Technology Times)
Why 80%?
Crypto exchanges need some assets available online.
If every coin were stored entirely offline, processing routine withdrawals would become much slower and more operationally difficult.
But keeping too much crypto online increases the amount potentially exposed if a hot wallet is compromised.
The 80% proposal attempts to balance those two needs.
Most customer assets would remain in comparatively protected offline storage, while a smaller operational reserve could remain accessible for day-to-day activity.
The exact balance can matter enormously for a large exchange.
If a platform holds the equivalent of $100 million in customer crypto, an 80% threshold would mean at least $80 million would normally need to remain in cold storage.
Only the remainder would be available across hot or warm wallet infrastructure, subject to the SEC’s operational requirements.
Customer Assets Would Also Have to Be Segregated
The proposal is not only about where crypto is stored.
It also strengthens the principle that customer assets should remain separate from the company’s own assets.
That matters because one of the biggest risks in crypto has historically been platforms treating customer deposits as though they were part of the company’s own balance sheet.
When that happens, customer funds can become exposed to:
- company trading losses,
- creditors,
- poor treasury management,
- or misuse by insiders.
Nigeria’s regulatory direction is increasingly toward treating custody as a distinct responsibility rather than allowing exchanges to freely mix client assets with corporate funds.
The SEC’s existing regulatory framework already recognises Digital Asset Custodians as a specific regulated category, and the latest proposal considerably expands the controls expected of them. (SEC Nigeria rules and regulations)
Firms Could Face Restrictions on Using Customer Crypto
The proposed framework would also restrict custodians from freely lending, pledging or otherwise using customer crypto for their own purposes.
According to reporting on the draft, customer assets generally could not be pledged, lent or used for proprietary activity without appropriate customer consent and regulatory approval. (Tech Orijin)
That addresses another major risk exposed by previous crypto failures.
A customer may believe their Bitcoin is simply sitting in custody.
But if a platform has secretly lent it out or pledged it as collateral elsewhere, the customer’s risk is very different.
Strong segregation and rehypothecation rules are designed to make that distinction clearer.
Security Incidents Could Have to Be Reported Within 24 Hours
Nigeria’s proposal also introduces tighter incident-reporting requirements.
Digital-asset firms would be expected to notify the SEC of major cybersecurity incidents, operational failures or losses within 24 hours, with more detailed reporting following shortly afterward. (Tech Orijin)
That matters because crypto hacks can develop extremely quickly.
If private keys are compromised, attackers can move assets across multiple wallets and blockchains within minutes.
Regulators therefore need rapid notification if they are going to:
- assess customer exposure,
- coordinate with other agencies,
- monitor market impact,
- and determine whether a platform can continue operating safely.
The proposal moves crypto firms closer to the type of incident-reporting expectations already common in traditional financial institutions.
Key Management Would Become a Major Compliance Requirement
Cold storage is only useful if the keys controlling those assets are properly protected.
A poorly designed offline system can still fail.
For that reason, the proposed rules also emphasise cryptographic key management.
Reporting on the draft says custodians would need controls including:
- segregation of duties,
- multi-party authorisation,
- restricted key access,
- recovery arrangements,
- and multi-signature or equivalent safeguards for material transactions.
The objective is to prevent a single employee, compromised account or technical failure from being able to move significant customer assets alone.
That is a critical issue in crypto custody.
Unlike a bank transfer, an incorrectly signed blockchain transaction may be practically irreversible.
The Rules Would Apply Beyond Companies Physically Based in Nigeria
The SEC says the rules would apply not only to companies physically operating in Nigeria but also to businesses that provide services to Nigerian residents or target Nigerian investors through digital channels.
The draft explicitly covers people or firms that:
operate in Nigeria,
provide services to Nigerian residents,
or target the Nigerian market directly or indirectly.
That could make the rules relevant to international crypto platforms even if their headquarters are outside Nigeria.
This is potentially one of the most significant parts of the proposal.
Nigeria is effectively saying that serving Nigerian crypto customers may itself create regulatory obligations.
The Rules Are Still Proposed
The most important caveat remains that the framework is not yet final.
The SEC published the rules for consultation on August 20 and invited comments within two weeks of publication.
That means industry participants can still raise concerns about:
- the 80% threshold,
- capital requirements,
- technical custody requirements,
- reporting timelines,
- or other parts of the framework.
The final rules could therefore differ from the proposal.
Until the SEC formally adopts them, crypto firms should not be described as already being legally required to hold 80% of customer assets offline.

