BitGo and HashKey are broadening their institutional staking tie-up into a wider Asia-Pacific framework covering trading flows, fund custody and real-world-asset tokenization, although the four workstreams are at different stages of implementation. The most developed piece is staking: HashKey Cloud will act as a validator partner on BitGo’s platform, initially supporting Ethereum and Solana for eligible institutional clients. The structure keeps assets inside BitGo’s custody framework while HashKey Cloud supplies validator infrastructure, separating key controls from network consensus operations. Institutions still face staking risks such as slashing, lockups and reward variability, and the firms have not published fees, minimum positions or launch markets.
Custody for HashKey Capital and associated funds is conditional on onboarding and separate agreements. BitGo operates through regulated entities including a U.S. trust bank and licensed businesses in Singapore, Europe and the Middle East, while HashKey Capital holds Hong Kong licenses for securities dealing, advisory and asset management. Trading and tokenization remain broad frameworks without venue, settlement, issuer, blockchain or amount disclosures. BitGo Head of APAC Sales Abel Seow said institutions want custody, staking, trading and tokenization across an asset’s lifecycle, while HashKey OnChain business-group chief Leo Li said the combination gives institutions a route through those functions.
Separately, Bitget Wallet COO Alvin Kan called for clearer transaction permissions and recovery controls following Bitget Exchange’s reported $387.5 million breach. He said shared signing and administrative systems can expose many users to one security failure, with custody risk ultimately about “blast radius.” Bitget Wallet said its separate self-custodial service was not affected by the exchange incident. Kan argued wallets should explain spending limits, one-time versus recurring approvals, how to revoke permissions, and what recovery authority exists if a device or backup is lost.
The exchange said attackers obtained high-level internal credentials through a third-party security product vulnerability, allowing fraudulent withdrawal instructions to bypass controls. The Sept. 24 incident affected portions of its hot and warm wallet infrastructure, while cold wallets remained secure and private keys were not leaked. Bitget revised its loss estimate from $351.6 million to $387.5 million, said user balances were unaffected, and said its User Protection Fund would cover the loss, with Mandiant and SlowMist assisting the investigation. Bitcoin withdrawals reopened at 08:00 UTC on Sept. 28. BlockSec later found attackers converted assets that issuers could freeze, moved value cross-chain into Bitcoin and sent some BTC into CoinJoin transactions.
Regulators are also focusing on custody controls. ESMA’s crypto custodian resilience review will assess governance, key management, transaction controls, smart-contract risks and third-party dependencies from the second half of 2026 into 2027. The SEC’s proposed custody framework for investment advisers and regulated funds, described by Commissioner Hester Peirce, would require advisers to assess whether no permitted custodian is available and repeat that assessment quarterly. The proposal remains open for public comment.