A regulated financial institution holding cryptocurrency faces a structural problem: customer assets must be secure, auditable, and recoverable, yet the custodian itself becomes a high-value target. Traditional hardware security modules in data centers protect private keys, but they remain in the custodian’s control, creating legal liability, operational risk, and the infrastructure burden of managing backups and disaster recovery. Tangem offers an alternative framework. By embedding cryptographic operations into a physical card or ring that the customer retains, the custodian can offer institutional-grade security without ever holding or accessing private keys.
This arrangement changes the custody relationship fundamentally. Rather than storing assets on behalf of a customer—a model that requires licensing, bonding, and regulatory reporting—a platform can become a transaction facilitator and settlement layer while the customer maintains sole cryptographic control. The implication is significant: fintech platforms, broker-dealers, exchanges, and wealth managers can now offer non-custodial settlement without asking customers to manage their own hardware security or recovery procedures. Understanding how that shift works, and where the operational and security boundaries lie, is essential for institutions evaluating whether to build custody solutions on Tangem’s infrastructure.
Why non-custodial infrastructure appeals to regulated platforms
Custodial regulation is expensive and specific. A firm holding cryptocurrency on behalf of customers in most US jurisdictions must either become a qualified custodian under SEC rules, a bank, a money transmitter with state money-services licensing, or operate through a partner that holds those licenses. Each path involves capital requirements, audit obligations, insurance, regular compliance reports, and the operational cost of maintaining segregated accounts. The regulatory burden grows with the number of customers and the range of assets. A platform holding Bitcoin, Ethereum, Solana, and several hundred ERC-20 tokens must account for each separately and ensure that customer claims to specific holdings can be verified.
A non-custodial model inverts that cost structure. If customers retain cryptographic control through hardware stored in their possession, the platform avoids custodial licensing for the assets themselves. Instead, the platform manages the application layer: user accounts, transaction initiation, blockchain monitoring, fee handling, and settlement. The distinction matters operationally. The platform no longer needs to hold private keys, manage backup procedures, or carry insurance against theft or access compromise. Those responsibilities remain with the customer, supported by hardware that Tangem has designed to make key management easier and less error-prone than traditional seed phrase custody.
This arrangement also aligns incentives differently. A custodian traditionally earns fees partly because it manages risk on the customer’s behalf, making it a convenient but potentially expensive intermediary. A platform offering non-custodial settlement can compete on transaction costs and speed rather than on custody risk management. The customer pays less because the platform carries less liability. Simultaneously, the customer retains full cryptographic authority, making the relationship one of facilitation rather than entrusted guardianship. That clarity can reduce disputes over access, withdrawal restrictions, or asset recovery after account disputes or bankruptcy.
How Tangem’s architecture supports institutional settlement
Tangem’s core design principle is that private keys are generated, stored, and operated only within the secure chip embedded in the card or ring, never exported or accessible to the mobile application, the internet, or any connected device. When a customer initiates a transaction through the Tangem mobile app on Android or iOS, the following sequence occurs: the app constructs the transaction details, displays them for verification, and then uses NFC communication to send the unsigned transaction to the card. The secure chip performs the cryptographic signing operation internally and returns only the signed transaction to the app, which then broadcasts it to the blockchain.
That hardware isolation creates several institutional advantages. First, the platform cannot access or compromise the private key even if its servers are breached or its app is malicious. The customer’s cryptocurrency remains under control of the hardware device regardless of the platform’s security posture. Second, the physical device provides a second verification interface separate from the potentially compromised phone or computer. A customer must bring the card or ring near the NFC reader on their phone and confirm the transaction details on both the app and potentially through physical presence. This makes unauthorized transactions significantly harder to execute without the device’s physical presence.
Third, Tangem eliminates the dependency on seed phrases as a recovery mechanism. Instead of writing down 12 or 24 words and storing them in a safe deposit box or memorized location, users can create backup cards. These backup cards are generated through a multi-card threshold scheme: three backup cards created during wallet setup, for example, allow any two of them to recover the wallet if the primary card is lost. The scheme is cryptographically sound and eliminates the human error surface of copying down seed phrases incorrectly. Institutions can therefore offer a customer experience where backup is simple and recovery is procedural rather than dependent on the customer recalling a 24-word phrase.
Regulatory clarity around non-custodial settlement
The regulatory question is whether non-custodial infrastructure actually reduces custodial responsibility or merely relocates it. The answer depends on jurisdiction and how the arrangement is structured. In the United States, the SEC has clarified that an entity offering to hold cryptocurrency on behalf of customers is engaged in custodial activity and requires appropriate licensing. However, if a platform facilitates transactions and the customer maintains sole control of private keys through hardware in their possession, the platform may not be engaged in custodial activity at all. Instead, it is a service provider—similar to an exchange or broker that facilitates trading but does not hold settlement assets.
That distinction is not automatic or universally clear, which is why institutions building on Tangem’s infrastructure typically engage regulatory counsel to confirm the specific arrangement. If a platform offers to replace a customer’s lost Tangem card, for example, that might be characterized as custodial recovery. If the platform instead walks the customer through a recovery process using backup cards held by the customer, the platform may have a cleaner non-custodial position. Similarly, if the platform holds any operational authority over which transactions are approved or settles them on behalf of customers, custodial licensing may still apply. The key variable is whether the customer or the platform controls the final cryptographic decision.
Several jurisdictions outside the US have taken more explicit positions. Switzerland’s FINMA and Singapore’s MAS have both acknowledged that platforms offering non-custodial infrastructure can operate with lighter regulatory oversight than custodians, provided the arrangement genuinely reserves cryptographic control to the end user. This regulatory clarity has driven institutional adoption. Platforms can now confidently build settlement services on Tangem cards without the licensing and capital burdens of traditional custodians, while marketing that the customer controls their own assets.
Integration patterns for fintech platforms and brokers
A regulated broker or fintech platform integrating Tangem typically follows a specific workflow. During account onboarding, the customer receives or purchases a Tangem card. The card arrives with no keys loaded. The customer opens the Tangem mobile app, creates a wallet on the card, and generates backup cards. The platform’s own application then connects to the Tangem wallet through standard blockchain wallet protocols such as WalletConnect or similar integrations, allowing the platform to suggest transactions but requiring the customer to confirm them by bringing the card within NFC range of their phone.
The platform handles the business logic: order entry, price discovery, fee calculation, and blockchain broadcasting. When a customer wants to buy Bitcoin or trade an ERC-20 token, the platform app prepares the transaction, displays the amount and destination to the customer, and then relies on Tangem’s hardware wallet to sign it. This separation of concerns is important. The platform sees the transaction but cannot execute it without the customer’s card present and the app’s signing interface accessible. A rogue employee at the platform cannot drain accounts. A breach of the platform’s database cannot yield private keys. A phishing attack on the customer is significantly harder because private keys never appear in app memory or on the network.
For enterprise and institutional customers, some platforms offer additional features. Whitelisting of destination addresses, transaction limits, and multi-approval workflows can be implemented at the platform level, complementing Tangem’s hardware security. A wealth manager might require a junior advisor to initiate a transaction and a senior partner to confirm it through their own Tangem card before settlement. The platform enforces the policy; the cards enforce the cryptography. This layering allows institutions to build compliance controls without centralizing custody.
Operational durability and customer experience trade-offs
Tangem’s design includes water and dust resistance, with no batteries, cables, or screens required. This durability reduces operational friction. A customer does not need to charge the card, replace batteries, or manage connectors. The card remains functional for years and requires no maintenance. However, the trade-off is that the customer’s phone becomes the only interface for checking balances, initiating transactions, and viewing transaction history. If the customer loses their phone or the phone is stolen, they cannot transact until they recover or replace the phone. The card itself remains secure because it holds no information that identifies the customer or displays any data; the card is only useful in combination with the app.
This dependency on a single application introduces an operational risk that institutions must consider. If Tangem’s mobile app becomes unavailable on the app store, or if a customer’s phone is too old to run a current version, accessing assets becomes difficult. The card itself is not compromised, but the interface to transact is broken. Some institutions mitigate this by running their own Tangem-compatible app or by ensuring alternative signing interfaces are available. The the official Tangem Wallet site provides documentation for developers building these integrations, but the operational dependency remains real.
Customer experience around transaction confirmation also requires attention. NFC communication between the card and phone is fast but not instantaneous. A transaction that might take one second to sign on a traditional desktop requires the customer to bring the card near their phone and wait for NFC handshake. For retail customers, this is often acceptable and even preferable because it forces deliberate action. For institutional traders executing multiple transactions per day, the friction may be unacceptable. Institutions can address this by issuing multiple Tangem cards or rings to power users, or by designing workflows where the Tangem card is used only for sensitive operations while routine transactions flow through other mechanisms.
Security assumptions that remain customer responsibility
Tangem’s hardware wallet architecture significantly reduces the threat surface compared to seed phrase management or centralized custodians, but security is not absolute. The customer’s phone remains a potential vulnerability. If the phone is compromised with malware, the app could be replaced with a phishing version that shows false transaction details. The customer could be tricked into confirming a transfer to an attacker’s address. The hardware card would correctly sign the transaction, but the underlying instruction would be fraudulent. This is why additional verification layers—such as a platform displaying the transaction destination in a separate interface, or a customer reading the destination address aloud to a colleague—remain important.
Physical loss of the card or ring is also a real scenario. Tangem’s design means the lost device cannot be used without the app and without knowledge of the wallet’s PIN. However, if a customer loses a card before creating backup cards, or if all copies of backup cards are also lost, the associated cryptocurrency is unrecoverable. This is actually more durable than a lost seed phrase, because the customer cannot make a mistake in recovery: if the hardware is gone and backups are not available, recovery is impossible by design. Institutions must therefore ensure that customers understand the importance of creating and securely storing backup cards as part of onboarding.
A third area is NFC relay attacks. Theoretical research has shown that NFC communication can be intercepted and relayed over distance under specialized conditions. This would allow an attacker to make it appear that the card is signing a transaction it is not actually seeing. Tangem has implemented defenses against this, but the risk is not zero. A hardware wallet review for institutional use should therefore include an assessment of these residual risks and a determination of whether compensating controls at the platform level are necessary.
Competitive positioning in institutional custody
The institutional custody market includes traditional custodians such as Fidelity Crypto, Kingdom Trust, and Coinbase Custody, which hold private keys on behalf of customers and charge fees for that service. It also includes emerging platforms offering non-custodial settlement, some built on Tangem and others on alternative hardware or software architectures. Tangem’s advantage is that it offers an established, durable hardware form factor with institutional adoption. Its disadvantages are that it requires the customer to maintain a physical device and that recovery processes are less flexible than cloud-based backup systems.
For institutions evaluating whether to build on a non-custodial wallet architecture using Tangem, the decision often comes down to the target customer profile and regulatory jurisdiction. If the institution serves customers who value absolute cryptographic control and are willing to manage a physical card, Tangem is a strong foundation. If the institution needs to serve customers who demand cloud backup, phone-only operation, or minimal friction, other solutions may be more appropriate. The regulatory environment also matters: in jurisdictions where non-custodial platforms have clear exemptions from custodial licensing, building on Tangem becomes more economically attractive.
The long-term competitive question is whether Tangem’s advantage persists as other hardware wallets improve and as software-based non-custodial solutions mature. Tangem’s NFC form factor is distinctive, but it is not insurmountable. Competitors could launch similar cards or rings. What Tangem has built that is harder to replicate is a comprehensive ecosystem: a secure chip design, mobile apps for Android and iOS, institutional partnerships, regulatory alignment in multiple jurisdictions, and a track record of durability in the field. These factors explain why several emerging fintech platforms, particularly in Europe and Asia-Pacific, have chosen to build custody solutions on Tangem’s infrastructure rather than developing alternative hardware.
Future institutional adoption and infrastructure maturation
The near-term evolution of Tangem-based platforms will likely include more sophisticated integration patterns. Multi-signature wallets where institutional customers can issue multiple Tangem cards to different signers, requiring multiple cards to approve high-value transactions, are already technically feasible and likely to become more common. Institutional wallet services that embed Tangem card issuance into their onboarding, manage backup card distribution through secure channels, and provide customer support for card replacement or recovery are moving from niche offerings to mainstream institutional products.
A second trend is the expansion of decentralized finance integration. As platforms build more sophisticated DeFi transaction capabilities—such as complex swap routing, liquidity pool participation, or governance voting—the challenge of signing these transactions through a physical card increases. Solutions include batch signing, where multiple transactions are approved in a single card interaction, or app-level abstraction where the platform translates a complex instruction into a simple payment that the card can understand. Both approaches trade simplicity of signing for complexity elsewhere in the process.
Finally, the regulatory environment will continue to clarify. As more jurisdictions explicitly recognize non-custodial platforms as distinct from custodians, the cost advantage of building on Tangem’s architecture will compound. Fintech platforms will be able to offer cryptocurrency settlement without the licensing and capital burden of traditional custody, using Tangem’s hardware as a foundation for customer control and institutional compliance. The customer experience will improve as Tangem’s ecosystem matures: better recovery tools, faster NFC interaction, improved phone app experiences, and tighter integration with decentralized applications.
Frequently asked questions
Does building on Tangem’s infrastructure eliminate custodial licensing requirements?
Not automatically. A platform offering non-custodial settlement through Tangem may still require money transmitter licensing or other financial services licenses depending on jurisdiction and the specific services offered. However, if the platform genuinely reserves cryptographic control to the customer and does not hold assets on behalf of customers, custodial licensing for the cryptocurrency itself may not apply. Institutions should engage regulatory counsel to confirm the specific arrangement.
What happens if a customer loses their Tangem card before creating backup cards?
The cryptocurrency associated with that card becomes unrecoverable if no backup cards were created. This is by design: Tangem uses threshold backup, where multiple backup cards can collectively recover a wallet. If the primary card and all backups are lost, recovery is not possible. Institutions must ensure customers understand this during onboarding and provide clear procedures for backup card creation and secure storage.
Can a platform using Tangem prevent customers from accessing their cryptocurrency?
No. The platform cannot access or freeze the customer’s private keys because the keys remain in the Tangem hardware. The platform can prevent transaction broadcasting through its own application, but a customer with the Tangem card and access to an alternative wallet app or blockchain interface can transact independently. This is an advantage for non-custodial settlement but means platforms cannot enforce redemption restrictions or hold customer assets as collateral.

