Nigeria’s Securities and Exchange Commission wants crypto exchanges to keep most customer funds locked away from the internet. The regulator has proposed that digital asset custodians hold at least 80 percent of client assets in cold storage. Only a small slice would stay in hot wallets for daily withdrawals and transactions.
The proposal is part of a broader set of rules released on August 20. It targets exchanges, custodians, and other digital asset firms operating in Nigeria. Public comments on the draft close on September 3.
Cold storage means keeping crypto assets offline. This lowers the risk that hackers can reach customer funds through an internet-connected system. Companies like Trezor and Ledger make hardware wallets built for this kind of offline storage. Under the new rule, Nigerian custodians would need to shift most client holdings into similar setups.
SEE ALSO:Kenya Crypto Regulation: The Free Ride Just Ended
The SEC’s push follows a familiar pattern. When a crypto platform fails or gets hacked, customers often lose access to their money. Worse still, there is usually no clear timeline for recovery.
Nigerians have already lived through this. Patricia, a Nigerian crypto startup, suffered a breach in January 2022. The hack reportedly cost the company about two million dollars. Afterward, the platform froze withdrawals, and customers could not touch their assets for a long stretch.
Beyond cold storage, the draft rules also require firms to separate customer funds from company funds. This is not a new idea globally. It became a major talking point after the 2022 collapse of FTX in the United States. Regulators there alleged that the company quietly diverted customer funds to a trading affiliate. Celsius and Voyager also folded around the same time, leaving users stuck in long bankruptcy processes.
Nigeria’s SEC clearly wants to avoid a repeat of that story. Under the draft, custodians would need separate wallets for each client, or at least an equivalent ledger system that tracks who owns what. The rules would also bar them from lending, pledging, or using client crypto for their own trading, unless the client agrees and the SEC signs off.
The rules do not stop at custody. Firms would also face tighter reporting duties. They must report any major loss, cyber incident, or operational failure to the SEC within 24 hours. A full report must then follow within 48 hours. This mirrors a standard already used in Nigeria’s banking sector.
Capital requirements are rising too. Digital Asset Exchanges and Digital Asset Custodians would each need a minimum paid-up capital of two billion naira, or roughly 1.5 million dollars. Smaller categories of platforms would face lower thresholds, ranging from 200 million to 500 million naira. On top of that, firms would need a fidelity insurance bond covering at least 25 percent of their required capital.
Retail investors get a new safety net as well. The draft introduces a five-day cooling-off period for certain digital asset offerings. During that window, investors can withdraw and get a full refund.
Still, not everyone will find this shift easy. Several hardware wallet makers have historically shown little interest in African markets. Import duties and shaky last-mile delivery have kept adoption low. In fact, a Singapore-based hardware wallet company told TechCabal in December that it had sold about 15,000 wallets worldwide. Only around 200 of those sales came from Africa. Even so, a rule pushing 80 percent of assets into cold storage could change that math and pull more foreign wallet makers into the region.
Yet cold storage is not risk-free either. In June, hackers exploited a flaw in Coldcard, an offline wallet built by a Canadian company. They stole more than 1,700 Bitcoin, worth over 113 million dollars, according to research firm Galaxy Research. The incident is a reminder that offline does not always mean untouchable.
Ultimately, Nigeria is not acting alone on this front. Kenya has also moved to tighten its own digital asset rules this year, including new requirements around stablecoin reserves. Across the region, regulators seem to be converging on one goal. They want to make sure that when a crypto platform stumbles, customer money does not disappear with it.