Continental Postal Services of Hebland

Nigeria wants crypto firms to lock up 80% of customer assets offline

This is Follow the Money, our weekly series that unpacks the earnings, business, and scaling strategies of African fintechs, financial institutions, companies, and governments. A new edition drops every Monday.

When you buy cryptocurrencies such as Bitcoin or Ether on a local exchange, you are often trusting the platform with one simple task: to keep your funds safe. 

But what happens if the exchange is hacked, freezes withdrawals or suddenly shuts down? 

Nigeria’s Securities and Exchange Commission (SEC) wants cryptocurrency companies to have better answers. 

Under proposed rules released on August 20, crypto exchanges and other digital asset firms would have to separate customer funds from their own, strengthen how they safeguard cryptocurrencies, and report major losses, cyber incidents, and other material operational failures to the regulator.

The framework, which is open for public comment, brings a rule already familiar in the traditional banking sector to the digital asset industry: when something goes wrong, the regulator expects to know about it quickly. Like banks, crypto firms would have to notify their regulator of certain  incident reporting within 24 hours with further updates where necessary; the SEC’s proposal also requires digital asset firms to submit a detailed incident report within 48 hours. 

The SEC is also proposing higher financial requirements for digital asset businesses. Digital Asset Exchanges and Digital Asset Custodians (DACs) would each need minimum paid-up capital of ₦2 billion ($1.5 million) while Digital Asset Platform Operators (DAPOs), Digital Asset Offering Platforms (DAOPs), and Real-World Asset Tokenisation Platforms (RATOPs) would require ₦500 million ($371,600). Virtual Asset Service Providers would require ₦200 million ($149,000). 

The proposal also requires a current fidelity insurance bond covering at least 25% of the applicable minimum paid-up capital. 

The rules are aimed at strengthening investor protection and reducing the risk that customers lose access to their assets when a digital asset company fails. The stakes are high in a market where the collapse or failure of a platform can leave customers unable to access their money, with little clarity on when—or whether—they will be repaid. 

The proposal also gives retail investors a five-business-day cooling-off period for certain digital asset offerings. During that period, investors can withdraw their subscription and receive a full refund, subject to the conditions set out in the rules. The provision applies to subscriptions to digital asset offerings; it is not a blanket five-day withdrawal right for every cryptocurrency purchase on an exchange. 

Nigerians have already seen what can happen when a crypto company fails to protect customer assets. Patricia, a Nigerian crypto startup, suffered a breach in January 2022 that was reported to have cost the company about $2 million. The company later froze withdrawals, leaving customers unable to access their assets for extended periods. 

The SEC’s proposed fidelity insurance requirement is intended to provide another layer of protection against losses suffered by clients or investors as a result of operational failure, technology failure, cybersecurity breaches, custody failures, fraud, negligence, misconduct, misappropriation or unauthorised transactions. 

The protection would not extend to losses caused by market movements, price volatility or poor investment performance. 

Separating client money from company funds 

Globally, crypto platforms can hold assets belonging to many customers in the same wallet or account, a structure commonly known as an omnibus account. But those assets are still legally and operationally distinct from the platform’s own property.  

The 2022 wave of crypto failures in the United States showed the consequences when that separation breaks down. Firms including Celsius, Voyager, and FTX collapsed after taking on significant risks tied to lending, trading and related activities, leaving customers to navigate lengthy bankruptcy proceedings and uncertainty over the recovery of their assets. 

In FTX’s case, the US regulators alleged that customer funds were diverted to Alameda Research, its trading affiliate, and used for expenses and debts. The collapse prompted renewed scrutiny of customer-asset segregation and custody arrangements. 

In a post-FTX proposal, the Commodity Futures Trading Commission (CFTC) said customer and company funds should be kept separate, with daily reconciliations and records showing who owns the assets. In August 2026, the US SEC also proposed stronger custody requirements for investment advisers holding customer crypto assets. 

Nigeria’s SEC is proposing similar safeguards. Virtual Asset Service Providers (VASPs) would have to keep client assets separate from their own, while Digital Asset Custodians would have to legally segregate client assets from proprietary assets and those of affiliated entities. Custodians would also have to maintain separate wallets for each client, or equivalent internal ledgering systems that accurately attribute assets to individual clients. 

Custodians would also not be allowed to use client assets for proprietary trading, or lend, pledge, rehypothecate, or otherwise encumber them, unless the arrangement is disclosed, the client gives separate consent and the SEC permits it. They would also have to reconcile client assets, with discrepancies reported to the SEC within 24 hours. 

VASPs must keep customer funds separate from their own when users deposit naira or withdraw money from a crypto platform. Digital asset exchanges (DAXs) cannot use customer fiat to fund their own trading, operating expenses, lending, investments, or other obligations.

“Client fiat funds received or held in connection with on-ramp or off-ramp services shall be segregated from the [virtual asset service provider] VASP’s proprietary funds and handled in accordance with the client funds, trust account, safeguarding, and settlement requirements prescribed by the Commission,” the regulator said in the draft. 

Keeping client money and assets separate makes it easier to identify ownership and protect customers if a company becomes insolvent. 

The regulator is also setting consumer-protection rules for the emerging crypto-backed lending sector. Custodians would generally be prohibited from lending, pledging, or rehypothecating client crypto assets, unless the arrangement is disclosed, the client explicitly consents, and the SEC permits it. 

Digital Asset Exchanges (DAXs), meanwhile, would not be allowed to use client assets for their own benefit or for the benefit of affiliates or third parties. If an exchange wants to provide separate custody services, the proposed rules require the custody entity to be separately incorporated and registered or authorised as a Digital Asset Custodian.

Several Nigerian and Africa-serving crypto companies, including Busha, Bitmonie, and Blockchain.com, have entered the crypto-backed lending market. If the SEC’s proposal is adopted as drafted, exchanges that want to continue offering custody, lending, or related services may need to obtain the relevant registration or restructure those activities through a separately authorised entity. 

A Nigerian virtual asset company operating across multiple categories could therefore face multiple registration requirements, fees, and minimum-capital thresholds, depending on the functions it performs. 

Keeping crypto assets and their keys secure

Digital asset custodians would have to keep at least 80% of customer assets in cold storage, leaving only what is needed for withdrawals, settlements, and transactions in online wallets. 

Cold storage systems are designed to keep crypto stored offline, reducing the risk of hackers accessing customer assets. Such examples include crypto hardware wallets which are a popular cold storage method; companies such as Trezor and Ledger manufacture physical wallets for storing crypto. 

Several Nigerian cryptocurrency exchanges operate custodial wallets and storage systems, which allow them to store customer assets themselves, rather than non-custodial wallets, which users control. Requiring custodians—which can also include exchanges—to keep 80% of customer assets in cold storage could increase demand for hardware wallets and other offline storage systems from foreign manufacturers. 

A man using a crypto app on their phone. Image Source: AdobeStock.

Yet, several hardware wallet companies do not heavily prioritise African markets, including Nigeria, due to customs duties and the loss of control over last-mile delivery. 

In December 2025, Singapore-based hardware wallet manufacturer Cypherock told TechCabal that it had sold about 15,000 wallets globally, but only about 200 in Africa.

However, the proposed rules could change that. The SEC’s logic is to keep customer assets in offline locations to make them easier to retrieve when needed, such as when the regulator or other authorities need to freeze them during an investigation. 

But hardware wallets have shown they are not hack-proof. 

In June, hackers exploited a vulnerability in Coldcard, an offline hardware wallet built by Canadian company Coinkite, stealing about 1,779 Bitcoins worth over $113 million, according to US-based research firm Galaxy Research. 

With possibly stronger demand for cold storage, however, hot storage wallet providers who primarily serve Nigerian cryptocurrency exchanges may be caught in this regulatory provision, limiting business and adoption. If custodians must keep 80% of customer assets offline, online wallet technology providers could see less demand for their services.

Technical service providers, including wallet infrastructure companies, would fall under the digital asset custody rules if they directly hold customers’ private keys. The regulator also wants multiple people or signatories involved in accessing customers’ assets, so no single person can control them, as well as records that can be audited at all times, whether they use custodial or non-custodial wallets. 

Stablecoins face new local requirements

Stablecoin issuers, foreign-based or local, would also have to keep enough assets in reserve to cover what they owe holders—retail users and businesses.

Naira-backed stablecoins would need reserves equal to 100% of their outstanding liabilities, in cash or cash equivalents. Foreign-currency stablecoins would need reserves worth at least 120% of what they owe, held in the same currency or equivalent cash instruments. 

A USD-backed stablecoin serving the Nigerian market, such as USDT and USDC, can be held in USD instruments, but would require a higher redemption limit.

A trader using the Kraken crypto app on their phone. Image Source: Kraken.

The SEC also wants stablecoin reserves to be kept separate from customer funds. While foreign issuers would not need to hold those reserves in Nigeria, they must still hire a local representative, show proof that they’re regulated abroad, and regularly disclose their reserves.

Kenya took a different approach with its gazetted rules, requiring stablecoin issuers to keep 30% of their reserves with local banks and the rest in local instruments. 

On August 25, Tether opened roles for expansion leads in Nigeria and Côte d’Ivoire, underscoring the El Salvador-based issuer’s immediate focus.

Commodity-backed stablecoins, such as gold-backed tokens like Tether’s XAUt, would need to hold 100% backing, while crypto-backed stablecoins would need to hold at least $150 worth of approved liquid crypto assets for every $100 of stablecoins issued, keeping that level of backing at all times.

The rule would also prevent connected companies from controlling different parts of the same stablecoin business in a way that creates conflicts of interest. 

If Company A owns Company B and Company B issues a stablecoin, Company A cannot promote that stablecoin on its platform without meeting the SEC’s restrictions and safeguards. 

The regulator is also tightening who can issue and list digital assets in Nigeria. Like Kenya, Nigeria has also proposed that foreign-issued stablecoins, such as USDT or USDC, must be approved by the SEC before cryptocurrency exchanges can list them on their platforms.

“A foreign-issued stablecoin shall not be listed, admitted for trading, custodied, settled, promoted, or otherwise used by a DAX [digital asset exchange] or other regulated platform in Nigeria unless recognised or authorised by the Commission,” the regulator said.

If more African countries adopt this rule, foreign stablecoin issuers like Tether and Circle must soon set up local entities in different countries to comply with specific local rules, or otherwise be selective about the countries they prioritise, forcing them to price risk. 

At scale, it could lead to a scenario where USDT and USDC, popular US dollar-backed stablecoins, would no longer be accessible in certain African markets, as regulators fight to uphold monetary sovereignty.

True scale demands moving beyond surface-level integrations to robust execution. We’ve filtered the noise out of Moonshot 2026, optimising the conference strictly for high-calibre connections between startup founders, global financial operators, enterprise leaders and individuals rewiring Africa’s technical frameworks. Get 20% off Early Bird tickets for a limited time.


Crédito: Link de origem

Leave A Reply

Your email address will not be published.