What a Business Crypto Wallet Does Differently
Why a company cannot use a personal wallet, what controls a business wallet adds, and what each control is actually preventing.
What this covers
A personal crypto wallet has one rule: whoever has the key can move the money. For one person looking after their own savings, that is fine. For a company it is a problem. Reading this next to a corporate crypto wallet turns the general points into specific ones.
The problem stated plainly
If one employee can move company funds on their own, then one compromised laptop, one convincing phone call, or one unhappy departure can empty the account.
Every feature of a business wallet exists to remove that single point of failure.
Control one: more than one person has to agree
Payments are created by one person and approved by another. The person who creates cannot approve their own.
This sounds obvious and it is the control most often weakened, usually because the team is small and it is inconvenient. If there are only two people, both should be able to approve and neither should be able to approve their own. It is more annoying and it is the entire point.
Control two: money can only go to approved addresses
Withdrawals go to a list of addresses registered in advance. Adding a new one requires approval and a waiting period, usually a day.
The waiting period is the part that matters and the part people switch off. It turns a successful break-in from an instant loss into an alert with time to react. Almost every large company crypto theft involved someone adding an address and using it within minutes. Businesses face the same thing from the other side, which is what a provider serving funds and family offices is for.
Control three: limits
Caps per transaction, per day, per person. Small routine payments go through easily. Large ones need the full approval chain.
This keeps the controls from being irritating in ordinary use, which is what keeps them switched on.
Control four: a record of everything
Who did what, when, from where. Including attempts that failed or were rejected.
The rejected attempts are the useful part. A run of rejected withdrawals is the clearest early sign that someone’s account has been taken over, and a log that only records successes will not show it.
Control five: reports that reconcile
Balances at the end of each month, every movement with its value in ordinary money at the time, fees listed separately, in a format your accounting system can read.
If the wallet cannot produce this, someone is building it by hand every month.
Doing it yourself or using a provider
A company can run its own multi-signature arrangement, where several keys are needed to move funds. Several do it well.
What it needs is people who understand the process, a recovery procedure that has actually been tested rather than written down, keys kept in different places, and a plan for when a key holder leaves.
That is ongoing work and it does not stop. The alternative is a provider that enforces the rules in software, where the work is theirs and your risk is that you chose the wrong provider.
Neither is automatically right. The question is which risk your company is better placed to manage, and for most smaller companies it is the second one. The thing that only matters when something goes wrong is whether the list of countries covered exists, and it is worth checking before it does.