Legal structure and operating risk

Which layer has an addressee and which does not — and why a 3-of-5 multisig says nothing yet about key management.

This lesson has had no expert review. It was written for this platform and against the evidence it cites; nobody has gone through it independently.

Learning objectives

  • You can separate the three layers of an institutional on-chain position and assign each its addressee.
  • You can name what a multisig threshold leaves unstated.
  • You can separate technology risk from market risk even when both materialize on the same day.

Check your prior knowledge

Answer these for yourself before reading on. Wherever you hesitate is where this lesson pays off.

Core concept

Fact

Three layers, two addressees

An institutional on-chain position has three layers: the vehicle holding it (a legal person with articles, governing bodies and supervision), the service providers in between (custodian, signing hardware, RPC and indexing providers — each under contract), and the protocol itself. The first two layers have addressees: someone carries an obligation. The third usually has none. Conflating the layers means looking for contractual duties where there is no contracting party.

Risk

A threshold is not yet key management

“3-of-5” describes a condition in the contract, nothing more. What stays open: where do the five keys physically sit? Do they all come from one hardware vendor? Are two holders in the same room? How is a key revoked when a holder leaves the organization, and how long does that take? Those questions decide whether the threshold holds when it matters — the contract answers none of them.

Uncertainty

Outsourced means relocated, not removed

Between the decision and the chain sit providers that rarely appear in the risk register: the RPC endpoint used for reads and sends, the indexer the reporting is built on, the signing hardware. A service contract typically governs availability, not correctness: an endpoint serving stale data is available. Whether that case is covered has to be checked in the contract — it cannot be assumed.

Interpretation

Two causes, one day

When a position loses money on a day the indexer was also down, two causes are in play and they belong apart: the market loss would have happened regardless; the outage cost the ability to see it in time. Only separating them leads to a usable action — one calls for a different position size, the other for a second data path.

Definitions

Vehicle
The legal person that holds a position and to which the supervisory obligations attach.
Threshold signature in the glossary
A rule under which a transaction becomes valid only with a minimum number of signatures.
RPC endpoint in the glossary
The interface through which an application reads a chain and sends transactions to it.

Model

  1. Vehicle — legal person, governing bodies, supervision: addressee present

  2. Service providers — custody, signing, data: addressee by contract

  3. Protocol — mechanism plus governance: usually no addressee

  4. Consequence: claims stop at the second layer

Where an obligation has an addressee — The boundary between layers two and three is where an operations manual has to stop saying “the provider”.

Formulas

What an m-of-n threshold states

able_to_act if reachable_keys >= m ; externally_controlled if controlled_keys >= m
m
Number of signatures the contract requires
n
Total number of keys issued
reachable_keys
Keys whose holders can actually sign in time
controlled_keys
Keys that could be controlled by the same party

Limit: The formula counts keys, not their independence. If all n keys come from one vendor, sit in one building or rest with one provider, the effective number of independent holders can be far below n — while the threshold stays formally unchanged.

Worked example

A threshold that carries less than it appears to

Threshold
3 of 5
Hardware
all five devices from one vendor, same firmware version
Locations
three holders at the same site
Revocation process
documented, last rehearsed 14 months ago

Formally m = 3, n = 5. Measured against independent failure sources: one firmware defect touches all five devices at once, one site outage touches three holders at once — exactly the threshold.

The threshold is effective against a single dishonest holder and ineffective against a common vendor defect.

Reading: The number “3 of 5” is correct and still misleading as long as the independence of the five is not documented alongside it. The action follows directly: a second vendor, a second site, a rehearsed revocation — not a higher threshold.

Retrieval

An institution documents “3-of-5 multisig” as its custody control. What is missing from that documentation?
A provider's indexer serves stale balances for a day while remaining reachable throughout. Is the service contract breached?

Exercise on real data

Read the guiding questions and mark which of them a service contract can answer and which only the protocol itself can.

Dimension 3: technology →

Application

Write the custody-control line for an operations manual so an auditor can follow it without a follow-up question.

Related case studies

Institutional reading

Bank
In which risk register does an RPC provider outage sit today?
Insurance
Would a key loss caused by a vendor defect be a covered event or an excluded one?
Advisory
Which of these items would you commit to a client in writing?

Key takeaways