---
title: "Custodial vs non-custodial off-ramps: who holds the money, and what happens if the provider fails"
seoTitle: "Custodial vs non-custodial off-ramps: the risk difference"
description: "A custodial off-ramp holds your stablecoins; a non-custodial one pulls them only at payout. What changes in insolvency, de-banking, and failed payouts."
date: "2026-09-26"
updated: "2026-09-26"
category: "payments"
author: "BlindPay Team"
faq:
  - q: "What is the difference between custodial and non-custodial off-ramps?"
    a: "A custodial off-ramp holds your stablecoins in a balance it controls until you pay out. A non-custodial off-ramp leaves them in your own wallet and pulls only the quoted amount at the moment a payout executes. The difference is who controls the funds while they wait."
  - q: "Is a non-custodial off-ramp safer?"
    a: "It removes one risk: the provider holding your balance when something goes wrong with the provider. It doesn't remove the others. During the payout itself the provider controls the funds in either model, and a payout can still be held for compliance review or fail at the bank. Non-custodial shrinks the window of exposure from weeks to the length of a payout."
  - q: "What happens to my stablecoins if a custodial off-ramp goes bankrupt?"
    a: "It depends on the legal structure of the account. In the Celsius bankruptcy, a US court ruled in January 2023 that assets in Earn accounts belonged to the company, which left those customers as unsecured creditors. Ask any custodial provider in writing how customer funds are held, in whose name, and whether its terms treat your balance as your property."
  - q: "Does BlindPay hold customer funds?"
    a: "For payouts from external wallets, no. The stablecoins stay in the customer's wallet until a payout executes, and the on-chain approval is scoped to the quoted amount. BlindPay also offers managed wallets, in beta, which BlindPay custodies on the customer's behalf for teams that don't want to sign transactions. A refunded payout returns the stablecoins to the wallet that funded it."
  - q: "What should I look for in a stablecoin off-ramp provider?"
    a: "Start with risk: where your funds sit between deposit and payout, how many banking partners pay out in each corridor, which licensed entity serves each one, and what happens to funds when a payout fails. Then check the commercial side: published pricing, fee splits in every quote, live quotes with expiry, and an OpenAPI spec with a sandbox that behaves like production."
---

A custodial off-ramp holds your stablecoins in a balance it controls until you pay out. A non-custodial off-ramp leaves them in your wallet and pulls only the quoted amount at the moment a payout executes. For most of the time, that's a small operational difference. It becomes the only difference that matters on the day the provider goes insolvent, loses its bank, or freezes withdrawals.

Every "which off-ramp" comparison lists speed, coverage, and fees. This one is about the other question: whose money is it while it waits?

## What does custody mean in an off-ramp?

Custody is control of the keys, or of the account, that holds the stablecoin between the moment you decide to pay and the moment fiat lands.

In a **custodial** model you deposit stablecoins with the provider first. They sit in the provider's wallets, credited to you on its internal ledger, and you pay out from that balance whenever you want. It's convenient. It's also a claim on the provider, not an asset in your hands.

In a **non-custodial** model the stablecoins stay in a wallet you control. When you want to pay out, you request a quote, authorize the provider to pull that exact amount, and the provider converts it and sends fiat. Before that call, the provider has nothing of yours.

## How does the money move in each model?

| | Non-custodial (BlindPay, external wallet) | Custodial balance |
| --- | --- | --- |
| Where funds sit before payout | Your wallet | The provider's wallets, on its ledger |
| Who can move them | Only you, until you authorize a payout | The provider |
| What you authorize | The quoted amount, per payout | Everything in the balance, once, at deposit |
| If the provider becomes insolvent | Your wallet balance is untouched | You may be a creditor of the estate |
| If the provider loses its bank | Stablecoins stay in your wallet; you can use another off-ramp | Balance can be stuck until banking returns |
| Pre-funding | None | The deposit is pre-funding |
| Convenience | An approval step per payout, unless you use a managed wallet | No signing per payout |

Neither model makes the provider's job disappear. During the payout itself, both hand the funds to the provider: it collects the stablecoin, converts it through a liquidity provider, and sends fiat from its own bank account. What non-custodial changes is how long that exposure lasts. Minutes per payout, instead of however long a balance sits.

## What happens if the provider becomes insolvent?

This isn't hypothetical. In the Celsius bankruptcy, a US bankruptcy court ruled in January 2023 that the crypto in customers' Earn accounts belonged to Celsius under its terms of use. Those customers became unsecured creditors in their own money. FTX's collapse in November 2022 showed the other failure: customer balances that were not where the ledger said they were.

A payments provider isn't a lending platform, and most custodial off-ramps don't lend out balances. But the legal question is the same. When a custodian fails, what you get back depends on how the balance was held: segregated or pooled, in your name or the provider's, and what the terms of service say about ownership. Stablecoin laws focus mostly on issuers and their reserves. An intermediary holding your tokens is a separate question.

A non-custodial payout sidesteps it. Funds that never left your wallet aren't part of anyone else's estate.

## What happens if the provider loses its bank?

Off-ramps need banks to send fiat, and banks drop fintech and crypto clients faster than most people expect. In March 2023, Silvergate announced its wind-down and Signature Bank was closed within days of each other, and a long list of crypto companies lost their US dollar rails over a single weekend.

For a **custodial** customer, a de-banked provider means a balance you can see and can't use until the provider finds a new bank. For a **non-custodial** customer, it means one off-ramp stopped working. The stablecoins are still in your wallet, and you can route the next payout through another provider the same day.

That's why banking-partner concentration belongs on every due-diligence list, custodial or not.

## What does non-custodial not protect you from?

Be honest about the limits.

- **Compliance holds.** A payout that is being reviewed is in the provider's hands. On BlindPay, a hold can last up to 30 days before it's approved or fails.
- **Failed payouts.** A refunded payout returns the stablecoins to the funding wallet right away. A failed one doesn't refund automatically and needs support. [Are stablecoin payments reversible](/resources/more/are-stablecoin-payments-reversible) explains why the on-chain leg is final once it confirms.
- **Rail and liquidity partners.** Someone still converts the stablecoin and someone still sends the bank transfer. A non-custodial model doesn't change how many partners sit behind each corridor.
- **Your own key management.** If your wallet is compromised, a non-custodial provider can't help. Custody moves to you, along with the responsibility.

## What 8 questions should you ask an off-ramp provider about risk?

1. **Where do my funds sit between deposit and payout?** A good answer names the wallet and who controls it, for every product. "In your wallet until you execute" and "in our omnibus wallet, credited to your ledger" are both honest answers. Vague ones aren't.
2. **If you custody funds, in whose name, and are they segregated?** Ask for the terms of service clause that governs ownership, not a sales summary.
3. **What happens to my balance if you become insolvent?** A good answer references a legal structure, not a promise.
4. **How many banking partners pay out in each of my corridors?** One bank per corridor is a single point of failure. Ask what happened the last time a partner changed.
5. **Which licensed entity serves each corridor?** Check it against a published [licenses page](/licenses), and see [what is a VASP](/resources/more/what-is-a-vasp) for what the licenses mean.
6. **What happens to funds when a payout fails, and how fast?** The answer should distinguish a refund of the stablecoin from a failure that needs manual work, and give timings for each.
7. **Do you require pre-funded balances?** Pre-funding is custody by another name. [What no pre-funding means](/resources/more/no-pre-funding-stablecoin-payouts) covers the models.
8. **Can I leave without moving a balance?** If your funds already live in your own wallet, switching providers is an integration project, not a withdrawal.

These sit on top of the commercial checks: corridor coverage, live quotes, settlement speed, and API quality, covered in [how to choose an on/off ramp provider](/resources/more/how-to-choose-on-off-ramp-provider) and [how to choose a stablecoin API](/resources/more/how-to-choose-a-stablecoin-api). Compliance depth is its own topic: [the travel rule for off-ramps](/resources/more/travel-rule-stablecoin-off-ramps) and [off-ramp limits](/resources/more/stablecoin-off-ramp-limits).

## How does BlindPay handle custody?

BlindPay supports both models and says which one each product uses.

- **External wallets (non-custodial).** The stablecoins stay in the customer's wallet until a payout executes. The customer authorizes only the quoted amount: an ERC-20 approve on EVM chains, a signed transaction on Stellar, or a token delegation on Solana. See [payouts](/docs/payouts).
- **Managed wallets (custodial, beta).** BlindPay custodies the balance on the customer's behalf, so there's no client-side signing. Useful for teams that don't want to run key management.
- **Offramp wallets.** Deposit addresses that BlindPay creates and manages, which convert each deposit to fiat as it lands; see [what is an off-ramp wallet](/resources/more/what-is-an-off-ramp-wallet).

A refunded payout returns the stablecoins to the wallet that funded it, and nothing has to be parked in advance for an external-wallet payout. For wires, BlindPay sends SWIFT payments on behalf of the customer (POBO/COBO), with UETR tracking and MT103 confirmations, from the same API.

Pick the model per flow, not per company. Put payouts you control on an external wallet, and use managed or offramp wallets only where the convenience is worth the custody. Then run the eight questions above against every provider on your shortlist, including us.

*This article is for general information only and is not legal or financial advice.*
