---
title: "Non-custodial payments: what they are and why they reduce risk for businesses"
seoTitle: "Non-custodial payments: what they are and why they matter"
description: "A non-custodial payment provider moves your money without holding it between payments. Who controls the funds, who carries the risk, and what to ask."
date: "2026-08-05"
category: "payments"
author: "BlindPay Team"
faq:
  - q: "What is a non-custodial payment?"
    a: "A payment where the provider moves and converts the money without holding a balance of it on your behalf. Funds stay in a bank account or wallet the business controls until the moment a payment executes, and if the payment cannot complete, they go back to where they started."
  - q: "What is the difference between custodial and non-custodial payments?"
    a: "Who holds the money between payments. A custodial provider keeps customer funds in its own accounts or wallets, so its solvency, controls, and record-keeping become the customer's risk. A non-custodial provider only touches funds for the transaction it is executing, so there is no standing balance exposed to the provider."
  - q: "Is BlindPay non-custodial?"
    a: "Yes, by design. With an external wallet, the customer controls the stablecoins, authorizes the exact amount of each payout, and BlindPay never takes custody beyond the single transaction it is asked to execute. If the receiving bank rejects or returns a payout, the stablecoins go back to the wallet that authorized it. BlindPay also offers managed wallets, in beta, for teams that choose to hold a balance with BlindPay between payments."
  - q: "Do non-custodial payments mean I have to manage private keys?"
    a: "Not necessarily. A business can use its existing custody setup, such as an institutional wallet provider, or run bank-to-bank flows through virtual accounts and payouts, where the stablecoins settle behind the scenes. Key management only becomes your job if you choose to hold the wallet yourself."
  - q: "What happens to my money if a non-custodial payment provider fails?"
    a: "Funds that were never sent to the provider are not affected, because they were never in its possession. The exposure is limited to payments in flight at that moment. With a custodial provider, every balance held on your behalf is exposed until the provider's accounts are reconciled and returned."
---

A non-custodial payment is one where the provider moves and converts your money without holding a balance of it on your behalf. Funds stay in a bank account or wallet you control until the moment a payment executes. If the payment can't complete, they go back where they started. A custodial provider, by contrast, keeps your money in its own accounts between payments, which quietly turns its balance sheet into your risk.

That risk isn't theoretical. When the banking-as-a-service middleware company Synapse filed for bankruptcy in April 2024, end users of the fintech apps built on it were owed about $265 million and lost access to it for months. The court-appointed trustee found the partner banks held about $180 million of that, and later put the shortfall at roughly $65 million to $95 million. Nobody had to steal anything. The records of who owned which dollars in the pooled accounts simply didn't reconcile.

For fintechs, PSPs, and payroll platforms that move customer money, where the funds sit between payments is a design decision with regulatory, audit, and balance-sheet consequences.

## What is the difference between custodial and non-custodial payments?

Three questions separate the two models.

- **Who holds the funds?** Custodial: the provider, in accounts or wallets it owns, often pooled across customers. Non-custodial: you, in an account or wallet you control, until a specific payment executes.
- **Who carries counterparty risk?** Custodial: you, on every dollar the provider holds for you. Non-custodial: only on the payment in flight at that moment.
- **What happens if the provider fails?** Custodial: balances freeze until an administrator works out who owns what. Non-custodial: funds you never sent are unaffected, because they were never in the provider's possession.

A useful way to picture it: a custodial provider works like a parking garage. Your car sits on their property between trips, and if the garage goes bust, getting it out is a legal process. A non-custodial provider works like a toll road. Your car is only on their road while it's moving, and it's yours the whole time.

## How do the two models compare?

| | Custodial | Non-custodial |
| --- | --- | --- |
| Fund control | Provider holds balances on your behalf | You hold funds until each payment executes |
| Failure handling | Funds stay in the provider's balance and are credited back there | Funds return to the originating account or wallet |
| Counterparty risk | Every balance held by the provider | Only the payment in flight |
| If the provider fails | Balances frozen pending reconciliation | Unsent funds unaffected |
| Reconciliation | Your ledger against the provider's internal ledger | Your ledger against bank statements and on-chain records |
| Typical use cases | Consumer wallets, stored-value apps, exchanges | B2B payouts, payroll, remittance, treasury |

Custody isn't wrong. It's a trade. Custodial balances make instant internal transfers and a simple "wallet" UX easy, and plenty of products need that. The point is to choose it deliberately, per use case, rather than inherit it from whichever provider you picked.

## How does BlindPay's non-custodial model work?

BlindPay is a non-custodial payment processor. In the docs' own words, it never takes custody of your stablecoins beyond the single transaction it is asked to execute ([overview](/docs/overview)). Here's what that looks like in a payout from a customer-controlled wallet:

1. **Quote.** You request a payout quote that locks the rate, fees, and the exact amount the recipient receives, for five minutes.
2. **Authorize.** The wallet authorizes that exact amount and nothing more: an ERC-20 `approve` on Ethereum, Base, Polygon, or Arbitrum, a signed XDR on Stellar, or a token delegation on Solana.
3. **Execute.** BlindPay collects the authorized stablecoins, converts them, and pays the recipient over a local rail such as Pix, SPEI, ACH, SEPA, or SWIFT (POBO/COBO).
4. **Return on failure.** If the fiat transfer can't settle or the receiving bank returns it, the payout ends `refunded` and the stablecoins go back to the same wallet that authorized it.

One precise distinction worth knowing: a payout that ends `failed`, for example because a compliance check rejected it, does not refund automatically. It needs a follow-up with support ([payouts](/docs/payouts)). The automatic return covers what the bank rejects or sends back.

On the way in, a payin works the same way in reverse. A bank deposit is converted at the quoted rate and delivered straight to the destination wallet, rather than sitting in a provider balance. The full sequence is in [how a stablecoin payment works](/resources/more/how-a-stablecoin-payment-works).

BlindPay also offers **managed wallets**, in beta. Those are custodied by BlindPay, for teams that want a balance held between on-ramp and off-ramp without running their own wallet. It's an explicit choice made per customer, not the default.

## Why does it matter for regulators and auditors?

Fintechs, PSPs, and payroll platforms moving customer money get asked the same questions by partner banks, auditors, and regulators: where are customer funds at any moment, in whose name, and can you prove it?

A non-custodial setup makes those answers shorter:

- **Fewer places money can sit.** Each extra holding point is another ledger to reconcile and another entity whose failure affects your customers. Synapse is the cautionary example.
- **A public record for the stablecoin leg.** Each on-chain transfer has a transaction hash that anyone can verify, with the amount, addresses, and timestamp. That's evidence your auditor can check without asking the provider.
- **Cleaner vendor due diligence.** A partner bank reviewing your stack will ask what happens to customer funds if a vendor fails. "They were never held there" is the easiest answer to defend.

Regulation is moving the same direction. The US GENIUS Act, signed in July 2025, requires payment stablecoin issuers to hold one-for-one reserves and gives holders priority over those reserves if an issuer fails. That protects the token. It doesn't cover the provider in between, which is why the custody model of your payment provider still deserves its own review.

## What should you ask a payments provider to check if it's really non-custodial?

"Non-custodial" appears on a lot of websites. These six questions tell you whether it describes the product:

1. **Between payments, where do my funds sit, and in whose name?** The answer you want is "in your account or wallet," not "in a balance we hold for you."
2. **Who holds the private keys for the wallets my stablecoins sit in?**
3. **When a payout is rejected or returned, where do the funds go, and does that happen automatically?**
4. **Do you hold customer funds in pooled accounts beyond the payment in flight?** If yes, for how long and under what records?
5. **If you went bankrupt tomorrow, would any of my funds be part of your estate?**
6. **Can I see the on-chain record for every movement of my stablecoins?**

A provider that answers all six in writing, with the same answers its docs give, is non-custodial. One that needs a follow-up call for question 1 probably isn't.

## What to do next

Map where your customers' money actually sits today, hop by hop, from their bank account to the recipient's. Every hop where a third party holds a balance is a place to ask the questions above. Then read BlindPay's [flow of funds in the docs](/docs/overview) and trace a test payout on a free development instance, where a payout quote for $777.00 is forced to end `refunded`, so you can watch the return land back in the wallet. The [payout quickstart](/docs/quickstart-payout) covers the setup.

*This article is for general information only and is not legal, tax, or financial advice.*
