Non-custodial payments: what they are and why they reduce risk for businesses

A non-custodial payment provider moves your money without holding it between payments. Who controls the funds, who carries the risk, and what to ask.

A non-custodial payment is one where the provider moves and converts your money without holding a balance of it on your behalf. Funds stay in a bank account or wallet you control until the moment a payment executes. If the payment can't complete, they go back where they started. A custodial provider, by contrast, keeps your money in its own accounts between payments, which quietly turns its balance sheet into your risk.

That risk isn't theoretical. When the banking-as-a-service middleware company Synapse filed for bankruptcy in April 2024, end users of the fintech apps built on it were owed about $265 million and lost access to it for months. The court-appointed trustee found the partner banks held about $180 million of that, and later put the shortfall at roughly $65 million to $95 million. Nobody had to steal anything. The records of who owned which dollars in the pooled accounts simply didn't reconcile.

For fintechs, PSPs, and payroll platforms that move customer money, where the funds sit between payments is a design decision with regulatory, audit, and balance-sheet consequences.

What is the difference between custodial and non-custodial payments?

Three questions separate the two models.

  • Who holds the funds? Custodial: the provider, in accounts or wallets it owns, often pooled across customers. Non-custodial: you, in an account or wallet you control, until a specific payment executes.
  • Who carries counterparty risk? Custodial: you, on every dollar the provider holds for you. Non-custodial: only on the payment in flight at that moment.
  • What happens if the provider fails? Custodial: balances freeze until an administrator works out who owns what. Non-custodial: funds you never sent are unaffected, because they were never in the provider's possession.

A useful way to picture it: a custodial provider works like a parking garage. Your car sits on their property between trips, and if the garage goes bust, getting it out is a legal process. A non-custodial provider works like a toll road. Your car is only on their road while it's moving, and it's yours the whole time.

How do the two models compare?

CustodialNon-custodial
Fund controlProvider holds balances on your behalfYou hold funds until each payment executes
Failure handlingFunds stay in the provider's balance and are credited back thereFunds return to the originating account or wallet
Counterparty riskEvery balance held by the providerOnly the payment in flight
If the provider failsBalances frozen pending reconciliationUnsent funds unaffected
ReconciliationYour ledger against the provider's internal ledgerYour ledger against bank statements and on-chain records
Typical use casesConsumer wallets, stored-value apps, exchangesB2B payouts, payroll, remittance, treasury

Custody isn't wrong. It's a trade. Custodial balances make instant internal transfers and a simple "wallet" UX easy, and plenty of products need that. The point is to choose it deliberately, per use case, rather than inherit it from whichever provider you picked.

How does BlindPay's non-custodial model work?

BlindPay is a non-custodial payment processor. In the docs' own words, it never takes custody of your stablecoins beyond the single transaction it is asked to execute (overview). Here's what that looks like in a payout from a customer-controlled wallet:

  1. Quote. You request a payout quote that locks the rate, fees, and the exact amount the recipient receives, for five minutes.
  2. Authorize. The wallet authorizes that exact amount and nothing more: an ERC-20 approve on Ethereum, Base, Polygon, or Arbitrum, a signed XDR on Stellar, or a token delegation on Solana.
  3. Execute. BlindPay collects the authorized stablecoins, converts them, and pays the recipient over a local rail such as Pix, SPEI, ACH, SEPA, or SWIFT (POBO/COBO).
  4. Return on failure. If the fiat transfer can't settle or the receiving bank returns it, the payout ends refunded and the stablecoins go back to the same wallet that authorized it.

One precise distinction worth knowing: a payout that ends failed, for example because a compliance check rejected it, does not refund automatically. It needs a follow-up with support (payouts). The automatic return covers what the bank rejects or sends back.

On the way in, a payin works the same way in reverse. A bank deposit is converted at the quoted rate and delivered straight to the destination wallet, rather than sitting in a provider balance. The full sequence is in how a stablecoin payment works.

BlindPay also offers managed wallets, in beta. Those are custodied by BlindPay, for teams that want a balance held between on-ramp and off-ramp without running their own wallet. It's an explicit choice made per customer, not the default.

Why does it matter for regulators and auditors?

Fintechs, PSPs, and payroll platforms moving customer money get asked the same questions by partner banks, auditors, and regulators: where are customer funds at any moment, in whose name, and can you prove it?

A non-custodial setup makes those answers shorter:

  • Fewer places money can sit. Each extra holding point is another ledger to reconcile and another entity whose failure affects your customers. Synapse is the cautionary example.
  • A public record for the stablecoin leg. Each on-chain transfer has a transaction hash that anyone can verify, with the amount, addresses, and timestamp. That's evidence your auditor can check without asking the provider.
  • Cleaner vendor due diligence. A partner bank reviewing your stack will ask what happens to customer funds if a vendor fails. "They were never held there" is the easiest answer to defend.

Regulation is moving the same direction. The US GENIUS Act, signed in July 2025, requires payment stablecoin issuers to hold one-for-one reserves and gives holders priority over those reserves if an issuer fails. That protects the token. It doesn't cover the provider in between, which is why the custody model of your payment provider still deserves its own review.

What should you ask a payments provider to check if it's really non-custodial?

"Non-custodial" appears on a lot of websites. These six questions tell you whether it describes the product:

  1. Between payments, where do my funds sit, and in whose name? The answer you want is "in your account or wallet," not "in a balance we hold for you."
  2. Who holds the private keys for the wallets my stablecoins sit in?
  3. When a payout is rejected or returned, where do the funds go, and does that happen automatically?
  4. Do you hold customer funds in pooled accounts beyond the payment in flight? If yes, for how long and under what records?
  5. If you went bankrupt tomorrow, would any of my funds be part of your estate?
  6. Can I see the on-chain record for every movement of my stablecoins?

A provider that answers all six in writing, with the same answers its docs give, is non-custodial. One that needs a follow-up call for question 1 probably isn't.

What to do next

Map where your customers' money actually sits today, hop by hop, from their bank account to the recipient's. Every hop where a third party holds a balance is a place to ask the questions above. Then read BlindPay's flow of funds in the docs and trace a test payout on a free development instance, where a payout quote for $777.00 is forced to end refunded, so you can watch the return land back in the wallet. The payout quickstart covers the setup.

This article is for general information only and is not legal, tax, or financial advice.

FAQ