Private Client · Wealth Structuring · International Tax
Digital Assets in Cyprus Trusts
Authority, custody, regulatory perimeter and reporting — a trustee's operating framework after MiCA, Article 20E and DAC8.
A thought-leadership paper by
Christos Malikkidis
Advocate, Cyprus Bar Association No. 6583 | Licensed Insolvency Practitioner
Christos Malikkidis & Co. LLC | SSPwealth | Limassol, Cyprus
September 2026 · Law stated as at 1 September 2026
Key Summary
The essential takeaways at a glance
- •Three 2026 regime changes now govern digital assets in Cyprus trusts: an 8% tax on crypto disposals (Article 20E, from 1 January), DAC8 reporting (retroactive to 1 January), and the close of the MiCA transitional period on 1 July.
- •Legal recognition of a digital asset as property only means it can be held on trust — the trustee must still confirm authority under the instrument, prudence, custody and regulatory permission.
- •Custody failure is the one irreversible risk: a lost private key destroys the asset. A 'licensed' custodian is not the same as a 'bankruptcy-remote' one — read the contract, not just the licence.
- •Article 20E imposes a flat 8% charge on crypto disposals, including crypto-to-crypto swaps and payments; losses offset only within the same tax year, with no carry-forward and no group relief.
- •DAC8 and CARF mean tax authorities will receive transactional data from the 2026 data year onward — the pre-2026 visibility gap has closed.
- •SSPwealth applies a ten-gate acceptance framework (authority, classification, provenance, custody, controls, perimeter, tax, reporting, succession, exit). Where the answers cannot be assembled, the correct outcome is refusal, not acceptance with reservations.
Important notice
This paper is a general commentary on Cyprus law and practice prepared for information purposes. It is not legal, tax, regulatory, accounting, fiduciary or investment advice, and it does not create a lawyer–client relationship. No reader should act, or refrain from acting, on the basis of anything in it without taking specific advice on their own facts.
Digital-asset law moves faster than any other area this practice touches. Positions described here reflect our understanding as at 1 September 2026 and should be re-verified at the point of any acquisition, custody appointment, transfer, conversion, distribution or filing decision. Where a matter has a foreign element — and in this field it almost always does — advice must also be taken in each relevant jurisdiction.
Contents
- 1.The question trustees can no longer defer
- 2.Authority: can this trust hold the asset at all?
- 3.Prudence: the standard of care in a volatile asset class
- 4.Custody and control: where most fiduciary failures actually occur
- 5.The regulatory perimeter after 1 July 2026
- 6.AML, sanctions and on-chain provenance
- 7.Tax: the Article 20E regime and what it means for trust structures
- 8.Reporting: DAC8, CARF and the end of practical invisibility
- 9.Succession, incapacity and the access problem
- 10.Insolvency, tracing and recovery
- 11.A ten-gate acceptance framework
- 12.How we work
1. The question trustees can no longer defer
For most of the last decade, a Cyprus trustee asked to hold bitcoin, ether or a tokenised instrument could reasonably answer with a version of “not yet”. The legal treatment was unsettled, no custodian would take the mandate on acceptable terms, the tax position rested on general principles applied by analogy, and the reporting perimeter did not reach the asset. Deferral was a defensible position because the alternative was to administer an asset class without a framework.
That answer expired in 2026. Three separate developments closed the gap in the space of six months:
- •Tax. Article 20E of the Income Tax Law (Law 118(I)/2002, as inserted by the Income Tax (Amending) (No. 4) Law of 2025) took effect on 1 January 2026, imposing a flat 8% charge on gains arising from the disposal of crypto-assets. For the first time crypto has its own dedicated article in Cyprus tax law rather than a treatment inferred case by case.
- •Reporting. Cyprus transposed DAC8 by a law that entered into force on 27 March 2026 with retroactive effect from 1 January 2026. Reporting crypto-asset service providers must have been collecting compliant due-diligence and transactional data from the start of the year, with the first exchange due by 30 June 2027.
- •Regulation. The MiCA transitional period under Article 143(3) closed on 1 July 2026. Cyprus adopted the full eighteen-month window and CySEC set an internal filing cut-off of 27 February 2026. From 1 July, a Cyprus national CASP registration is no longer a basis on which to provide crypto-asset services, and a pending application does not extend the right to operate.
The practical consequence for fiduciaries is not that digital assets have become easier to hold. It is that the reasons for saying no have changed. “The law is unclear” is no longer available. What is available — and what a professional trustee should be prepared to rely on — is a properly reasoned refusal, a properly documented acceptance, or a properly structured alternative. All three require the same analytical work.
The central proposition
Legal recognition of a digital asset as property is the beginning of the trustee's analysis, not the end of it. Recognition tells you the asset can be held on trust. It tells you nothing about whether this trustee, under this instrument, with this custody arrangement, in this regulatory posture, may prudently hold it.
This paper works through that analysis in the order a trustee actually meets it: authority, prudence, custody, regulatory perimeter, financial crime, tax, reporting, the settlor's home jurisdiction, succession, and insolvency. It closes with a ten-gate framework we use on intake.
2. Authority: can this trust hold the asset at all?
The first question is not whether digital assets are good trust property. It is whether the trustee has power to hold them. A trustee who acquires an asset outside the powers conferred by the instrument commits a breach of trust regardless of how well the asset performs or how carefully it is custodied.
The Cyprus International Trust framework
The Cyprus International Trusts Law 69(I)/1992, substantially amended in 2012, gives trustees of a CIT the same investment powers as an absolute beneficial owner, subject to the terms of the instrument. That is a wide starting point and, on its face, wide enough to accommodate crypto-assets. The qualification matters more than the grant: the instrument may narrow it, and many older instruments do.
Trust deeds settled before roughly 2018 tend to define permitted investments by reference to categories drawn from a securities-and-property world — shares, debentures, units in collective investment schemes, immovable property, deposits with banks of a specified standing. A token that is not a security, not a unit, not a deposit and not immovable property may sit outside that list entirely. Where the deed uses an exhaustive list, the trustee has no power. Where it uses an inclusive formulation followed by a general sweep-up, the position is arguable — and “arguable” is a poor foundation for a multi-million-euro allocation.
Practical drafting response
- •For new instruments: an express digital-asset power, drafted by reference to the MiCA definition rather than to named tokens, so that it does not date. Name the asset class, the permitted custody models, and the trustee's power to appoint a licensed custodian and to delegate technical key management.
- •For existing instruments: a power-of-amendment review before any acquisition. Where the instrument cannot be amended, consider whether a deed of appointment, the exercise of an existing power to add investment powers, or an application to court under the CIT Law is the cleaner route.
- •Where the settlor is living and the structure is reserved-powers, confirm whether the investment direction sits with the settlor or a protector. A trustee executing a direction it had no power to accept is not protected by having been directed.
Property status and certainty of subject matter
Cyprus trust law operates on common-law principles within a legal system that is otherwise heavily influenced by civil-law codification. English authority recognising crypto-assets as a form of property is persuasive here but not binding, and the Cyprus courts have not yet had occasion to develop a substantial body of case law on the point. In practice the risk is not that a Cyprus court would decline to recognise a well-documented holding as trust property. It is that thin documentation makes the question harder than it needs to be.
Certainty of subject matter is the practical exposure. A trust of “the settlor's cryptocurrency” is not obviously certain. A trust of identified balances at identified addresses, evidenced by a deed of settlement recording the addresses, the transfer transaction hashes and the date and value of transfer, is. The discipline is no different from the discipline applied to a chattel or an unlisted shareholding — it is simply less familiar.
Documentation standard on settlement
- •Deed recording the specific assets settled, by token and quantity
- •Wallet or account addresses from which and to which the transfer was made
- •Transaction hashes evidencing the transfer on-chain
- •Valuation at the date of settlement, on a stated methodology and source
- •Confirmation of the settlor's title and source of the asset
- •Trustee minute recording acceptance and the basis on which it was accepted
Holding directly or through an underlying company
Most Cyprus structures that hold digital assets in practice hold them through an underlying company rather than at trustee level. The reasons are operational as much as legal: custodians and exchanges onboard corporate entities far more readily than trustees, the corporate layer provides a cleaner boundary between the trustee's own balance sheet and the asset, and it simplifies the tax analysis under Article 20E. The trade-off is an additional set of directors' duties, a corporate governance layer that must be operated rather than merely established, and an added substance question if the company is expected to be Cyprus tax resident.
Neither route is right in the abstract. The choice should follow from the custody model, the settlor's residence, the beneficiary profile and the expected transaction frequency — not from whichever is administratively easier to open.
3. Prudence: the standard of care in a volatile asset class
Authority answers whether the trustee may. Prudence answers whether the trustee should. The two are routinely conflated, and the conflation is where most trustee exposure in this area is generated.
The duty is not to avoid volatile assets. Trust law has never required that. The duty is to exercise the care and skill reasonably expected of a person conducting the affairs of another, and — for a professional trustee holding itself out as having particular expertise — to a correspondingly higher standard. What that means in practice is that the trustee must be able to show its reasoning, not defend its outcome.
Concentration and the diversification question
Digital-asset allocations in private structures are frequently extreme by the standards of any other asset class: it is not unusual to see a trust in which a single token represents the overwhelming majority of value. Sometimes this is unavoidable — the settlor's wealth was generated in that asset and the trust was established to hold it.
A trustee accepting a concentrated position should record, before acceptance: that the concentration was identified; that it was raised with the settlor; whether a rebalancing mandate was considered and, if declined, on whose instruction; whether the instrument contains an anti-diversification or retention clause and whether it is effective; and what the trustee's standing review obligation will be. A retention clause protects a trustee who has turned its mind to the position. It does not protect a trustee who has not looked.
Valuation policy
A trustee cannot report to beneficiaries, prepare accounts, calculate a distribution or compute an Article 20E gain without a valuation methodology fixed in advance. Ad hoc valuation is indefensible because it is unfalsifiable — a trustee that picks a price source after the event can always be said to have picked a convenient one.
| Element | What the policy must fix |
|---|---|
| Price source | Named venues or index provider, with a stated fallback where the primary source is unavailable or the market is halted |
| Timing | Valuation point (e.g. 23:59 UTC), applied consistently for accounts, distributions and tax computations |
| Illiquid assets | Treatment of tokens with no reliable market, locked or vesting positions, and staked balances subject to an unbonding period |
| Currency | Base currency and conversion source; whether EUR or the settlor's home currency governs |
| Review | Frequency of policy review and who approves a change |
Delegation
A trustee is not required to become a technologist. It is required to select, instruct and supervise those who are. Delegation of technical key management to a licensed custodian, of valuation to a specialist provider, or of on-chain analytics to a screening vendor is entirely proper — provided the trustee can show the selection process, the terms of the appointment, the scope of what was delegated, and evidence of ongoing supervision rather than a single onboarding file.
The distinction that matters: a trustee may delegate the operation of a control. It cannot delegate the judgment about whether the control is adequate.
The minute as the primary evidence
In a dispute, the trustee's file is the case. A minute that records only the decision is close to worthless. A minute that records the authority relied on, the alternatives considered, the risks identified, the advice taken, the person who decided and the date, and does so contemporaneously, is the difference between a defensible administration and an indefensible one.
What a digital-asset acceptance minute should show: authority under the instrument · asset classification and the basis for it · custody architecture selected and why · signing and approval controls · counterparty due diligence performed · source of wealth and sanctions position · valuation methodology adopted · tax and reporting analysis · concentration and beneficiary impact · exit and realisation route · date, decision-maker and advice relied on.
4. Custody and control: where most fiduciary failures actually occur
Every other section of this paper concerns risks that can be corrected. Custody failure is the one that cannot. A private key lost is an asset destroyed — there is no registrar to write to, no bank to indemnify the loss, and no court that can restore a balance to an address whose key no longer exists. This is the single respect in which digital assets are genuinely different from every other class of trust property, and it should drive the trustee's architecture.
Four models, four different risk profiles
| Model | Principal fiduciary exposure |
|---|---|
| Direct self-custody | Total loss on key loss or key compromise; concentration of knowledge in individuals; near-impossible to evidence adequate controls without purpose-built institutional infrastructure. Rarely appropriate for a professional trustee. |
| Institutional custody | Counterparty risk; contractual limitation of liability; whether client assets are legally segregated or merely operationally segregated; insurance scope and exclusions; jurisdiction of the custodian and of the assets. |
| Multisignature / MPC | Strong against single-point failure but only as strong as the signer set governance: who holds shares, what happens on death, resignation or incapacity, and whether the quorum can still be met under stress. |
| Exchange account | In most cases the trust holds a contractual claim against the platform, not a proprietary interest in identifiable assets. In an insolvency this distinction determines whether the trust is an owner or an unsecured creditor. |
Licensed is not the same as bankruptcy-remote
This is the most frequently missed point in custody due diligence, and it is worth stating plainly. A custodian holding an authorisation is supervised; that is a statement about conduct, capital and governance. Whether the trust's assets would be recoverable if the custodian failed is a separate question answered by the custody contract, the segregation mechanics actually operated, and the insolvency law of the custodian's jurisdiction. A trustee that reads the licence and not the contract has done half the diligence.
Contract terms that should be escalated
- •Any right for the custodian to rehypothecate, lend, pledge or otherwise use client assets, however framed
- •Pooling of client assets in omnibus wallets without per-client attribution in the custodian's books
- •Liability caps expressed as a multiple of fees rather than a proportion of assets under custody
- •Exclusion of liability for loss caused by third-party subcustodians, protocol failure or chain reorganisation
- •Unilateral rights to suspend withdrawals, amend supported assets, or change fee terms on short notice
- •Governing law and forum in a jurisdiction where enforcement against the custodian is impractical
Signing controls
The custody model determines where the keys sit. The signing policy determines who can move value, and it is the control most likely to be tested. A workable policy fixes, in advance and in writing: value thresholds and the approval level required at each; a dual-authorisation requirement above a stated threshold; a whitelisted-address regime with a mandatory cooling-off period before a new address becomes usable; an out-of-band verification step for any change to withdrawal instructions; and a documented procedure for emergency transfers that does not simply suspend the controls.
The test to apply:could one person, acting alone, move the whole of the trust fund? If the honest answer is yes, or “yes in an emergency”, the architecture is not adequate for a professional fiduciary regardless of how well that person is trusted.
5. The regulatory perimeter after 1 July 2026
MiCA — Regulation (EU) 2023/1114 — applied to crypto-asset service providers from 30 December 2024, with the stablecoin provisions having taken effect earlier. Article 143(3) allowed each member state to grandfather existing national-regime providers for up to eighteen months. Cyprus adopted the maximum period, so firms registered under the previous CySEC national framework could continue until 1 July 2026, provided they filed a complete MiCA authorisation application with CySEC by 27 February 2026.
Both dates have now passed. CySEC has been clear that a firm which failed to file was required to submit a wind-down plan, and that a pending application does not extend the transitional right to operate beyond 1 July. The national register, which was in substance an AML-focused registration rather than a prudential licence, has been decommissioned as a permanent alternative. From 1 July 2026, crypto-asset services can be provided from a Cyprus base only under a CySEC-issued MiCA authorisation — which, in exchange, carries an EU passport.
Why this matters to a trustee that is not a CASP
The perimeter risk for fiduciaries is not that they will be mistaken for an exchange. It is narrower and less obvious: custody and administration of crypto-assets on behalf of clients is itself a crypto-asset service under MiCA. A trust or corporate services provider that holds keys for multiple unconnected client structures, charges for doing so, and operates it as a service line is not obviously outside the definition merely because it calls itself a trustee.
The analysis turns on facts that are easy to state and uncomfortable to answer honestly:
- •Is the activity carried on for third parties, or for structures of which the provider is itself the fiduciary?
- •Is it remunerated as a discrete service, or subsumed within a fiduciary fee?
- •Is it held out to the market as a service offering?
- •How many unconnected structures does it cover, and is it operated at scale with dedicated infrastructure?
- •Does the provider exercise independent discretion over the assets, or execute instructions?
None of these is individually decisive. Taken together they describe a spectrum, and a provider drifting up it should take advice before it arrives rather than after. The safer architecture for most fiduciary businesses is to place technical custody with an authorised third-party custodian and to retain the trustee role squarely on the fiduciary side of the line.
The separate Cyprus fiduciary licence
This sits alongside, and does not displace, the requirement for an administrative service provider to be licensed under the Law Regulating Companies Providing Administrative Services and Related Matters (Law 196(I)/2012), or to be covered by the Cyprus Bar Association or ICPAC regime. Holding one authorisation is not evidence of compliance with the other. A trustee should be able to state which authorisation covers which activity, and identify any activity covered by neither.
Perimeter discipline. Trust law confers powers. It does not confer regulatory permissions. A power in the instrument to hold, stake, lend or convert digital assets authorises the trustee as against the beneficiaries. It does not authorise the trustee as against CySEC. These are two separate permissions and both are required.
6. AML, sanctions and on-chain provenance
Cyprus fiduciaries are obliged persons under the Prevention and Suppression of Money Laundering and Terrorist Financing Law 188(I)/2007, as amended, and the obligations do not change because the asset is a token. What changes is the evidence available and the evidence expected.
Source of wealth where the wealth is on-chain
Conventional source-of-wealth work rests on documents produced by regulated intermediaries: bank statements, audited accounts, sale agreements, tax returns. A settlor whose wealth was generated by early acquisition, mining, protocol participation or trading on venues that have since ceased to operate may be able to produce very little of that, and may be entirely honest.
The evidential response is to combine what the settlor can produce with what the chain can prove:
- •Signed message proving control of the originating address, executed at a specified time and retained on file
- •Chain-analytics report tracing the funds back through prior hops, with a documented risk rating for each counterparty cluster identified
- •Contemporaneous corroboration of the acquisition narrative — exchange records where they survive, tax filings, correspondence, transaction records at the relevant dates
- •Explanation of any gap in the chain of custody, recorded rather than left implicit, together with the trustee's assessment of it
The trustee should not treat an exchange's onboarding of the client as a substitute for its own file. The exchange verified identity for its own purposes; it did not verify source of wealth for the trustee's.
Sanctions
Sanctions screening in this asset class is address-level as well as name-level. An asset that is entirely clean on a name screen may have passed through a designated address or a mixer, and the exposure attaches to the asset. Screening must therefore be performed at intake, at each material transfer, and on a periodic basis for held positions — because a counterparty that was clean at intake may be designated afterwards, and the trust will still be holding assets that touched it.
The Travel Rule
Regulation (EU) 2023/1113 applies originator and beneficiary information requirements to transfers of crypto-assets, in parallel with MiCA. In practice this means a trustee moving assets to or from a European CASP will be asked to provide structured information about the trust, and should decide in advance how the structure is described, who is named, and what is disclosed about the beneficiaries. Confidentiality expectations set at settlement should be revisited in that light — a settlor who was promised discretion in 2019 should be told what the position is now.
7. Tax: the Article 20E regime and what it means for trust structures
Cyprus enacted the most significant reform of its tax system in over twenty years in December 2025, published in the Official Gazette on 31 December 2025 and effective in most respects from 1 January 2026. For digital assets, the reform inserted a new Article 20E into the Income Tax Law.
The charge
| Feature | Position under Article 20E |
|---|---|
| Rate | Flat 8% on gains arising from the disposal of crypto-assets |
| Persons in scope | Any person — individuals and legal persons alike, on the ordinary territorial basis (worldwide for Cyprus tax residents; Cyprus-source or PE-attributable for non-residents) |
| Definition of crypto-asset | Aligned with Article 3(1)(5) of MiCA, giving a single definition across the tax and regulatory regimes |
| Disposal | Sale, gift or donation, exchange of one crypto-asset for another, and use of crypto-assets as a means of payment |
| Mining | Excluded from Article 20E; receipts from mining fall under general income tax principles |
| Staking, airdrops, forks | Outside Article 20E on receipt and taxed under general rules; a later disposal of the asset received falls within the 8% charge |
| Losses | Offset against crypto disposal gains in the same tax year only — no carry-forward and no group relief |
| Effective from | Tax years beginning on or after 1 January 2026; no grandfathering of pre-existing holdings |
What this changes for a trust
Crypto-to-crypto is a taxable event
This is the provision most likely to catch an unprepared administration. A trust that rebalances between tokens, routes through a stablecoin, or pays a service provider in crypto has made a disposal each time. A structure operating any volume of on-chain activity requires transaction-level records with an established cost-base convention from the first transaction, not reconstructed at year end. Reconstruction after the fact is expensive, frequently impossible, and produces a position the trustee cannot stand behind.
The loss rules are unforgiving
Same-year offset only, with no carry-forward and no group relief, means realisation timing carries real cost. A trust that realises a large gain in one year and a large loss in the next pays 8% on the gain and receives nothing for the loss. Where a structure holds multiple positions with different embedded results, the sequencing of disposals within the tax year is a decision to be taken deliberately and minuted, not left to operational convenience.
Identify the taxable person before the first transaction
Whether the charge falls on the trustee, on an underlying Cyprus company, or on a beneficiary on distribution depends on the structure, the residence of each party and the terms of the trust. This has to be resolved at the design stage. It determines the holding architecture, the residence and substance requirements of any underlying company, and the shape of the record-keeping obligation. Resolving it after the assets are in place usually means restructuring, and restructuring a crypto position is itself a series of disposals.
Staking and yield need separate treatment
A structure that stakes will have two distinct streams: the reward on receipt, under general income tax rules, and the gain on eventual disposal, at 8%. These require separate tracking, separate valuation at different dates, and a cost-base convention for rewards. Where the staking is conducted through a third-party provider, the trustee should confirm at the outset that the provider's reporting is granular enough to support the position — many are not.
The record-keeping point, put bluntly. The 8% rate is attractive. It is only available to a structure that can compute the gain. Cost base per acquisition lot, disposal proceeds, date and time, valuation source and applicable expenses — captured contemporaneously. A trustee that cannot produce this has an exposure, not a rate.
8. Reporting: DAC8, CARF and the end of practical invisibility
Council Directive (EU) 2023/2226 — DAC8 — extends automatic exchange of information to crypto-asset transactions, transposing the OECD Crypto-Asset Reporting Framework into EU law and borrowing MiCA's definitions. Member states were required to transpose by 31 December 2025 and to apply the provisions from 1 January 2026.
Cyprus transposed late. The implementing law entered into force on 27 March 2026 with retroactive effect from 1 January 2026, which produces a specific and awkward consequence: an obligation to have collected compliant data during a period before the domestic law existed. Reporting crypto-asset service providers with a Cyprus nexus that onboarded users between 1 January and 27 March 2026 without CARF-standard self-certification and transaction capture have a data gap to remediate. The first reporting deadline is 30 June 2027, which is closer than it appears once the remediation work is scoped.
The consequence for trust structures
A trust or its underlying company that transacts through a reporting CASP is a reportable user. The CASP is obliged to identify the entity, obtain self-certification, identify controlling persons — which will ordinarily capture the settlor, the trustee, the protector and beneficiaries with a sufficient interest — and report transactional data to the Cyprus Tax Department for onward exchange. DAC8 also goes further than CARF in one respect worth flagging: where a reportable user fails to provide requested information after reminders, the provider must prevent that user from transacting.
This sits on top of, rather than replacing, the trust's existing CRS position and the beneficial ownership register. The three regimes overlap imperfectly. A trustee should be able to state, for each regime, which entity reports, who is identified, to which authority, and on what cycle. Inconsistency between what a trust reports under CRS and what a CASP reports about the same trust under DAC8 is precisely the kind of discrepancy an exchange of information regime is designed to surface.
Planning assumption. From the 2026 data year onward, the working assumption for any digital-asset structure should be that tax authorities in every jurisdiction connected to the structure will receive transactional data about it. Advice built on the visibility gap that existed before 2026 is advice that has already expired. Advice built on correct characterisation and correct reporting has not.
Beneficiary communication
There is a client-relationship dimension to this that is easily overlooked. Settlors who established structures when crypto activity was in practice unreported may have expectations that no longer hold, and may not have connected the general noise about crypto regulation to their own arrangements. The conversation is better initiated by the trustee, in a controlled way, than prompted by a notice from a revenue authority.
9. Succession, incapacity and the access problem
A trust exists to survive the people involved in it. Digital assets are the first significant class of trust property where the death, incapacity or departure of a single individual can destroy the asset outright rather than merely complicate its administration. The planning response has to be built at the outset; it cannot be retrofitted after the event that triggers the need for it.
The problem, precisely stated
Access to a digital asset is knowledge of, or the ability to reconstitute, a cryptographic key. Knowledge held by one person dies with that person. Knowledge written down in an accessible place is a security exposure. Knowledge distributed among several people is a governance problem. Every solution is a trade-off between the risk of loss and the risk of theft, and a trustee's architecture is a statement about where it has chosen to sit on that spectrum — which is a decision that should be minuted as such.
Design principles
- •No single point of failure, including the trustee. The question is not only what happens if the settlor dies, but what happens if the individual at the trustee who operates the arrangement resigns, is dismissed or becomes incapacitated on the same day.
- •Keys never go in the letter of wishes. A letter of wishes circulates. Where a sealed instruction is used, it should identify the location and the access procedure rather than containing the material itself, and its integrity should be verifiable.
- •Test the recovery procedure. An untested recovery procedure is a hypothesis. It should be exercised on a documented schedule, on a de minimis balance, with the result recorded. A trustee that has never tested recovery cannot say the control exists.
- •Plan for the custodian failing, not only for people failing. Where an institutional custodian holds the keys, the succession question includes what happens if that custodian ceases business, loses authorisation or is acquired. The exit route should be identified before the appointment, not during the crisis.
- •Onboard beneficiaries before distribution, not at it. Distributing a digital asset to a beneficiary who has no custody arrangement and no understanding of key management converts a well-administered trust asset into a likely loss the day after it leaves the structure. A trustee's duty does not extend past distribution, but its reputation does.
The question to ask at every review. If the two people who currently understand how this works were both unavailable tomorrow, could a successor trustee — working only from the trust file — identify the assets, establish control, and realise them? If not, the arrangement is not yet administrable.
10. Insolvency, tracing and recovery
The insolvency lens is the most useful stress test available to a trustee, because it strips away everything except the question of what the trust actually owns. It is also the lens through which the difference between the four custody models becomes concrete rather than theoretical.
Proprietary interest or contractual claim
Where assets are held at an address the trust controls, or by a custodian under an arrangement that genuinely segregates client assets and confers a proprietary interest, the trust is an owner. Where assets sit as a balance on an exchange, the trust in most cases holds a contractual claim against the platform. On the platform's failure the first is recoverable and the second ranks with unsecured creditors. The history of exchange failures in this sector is, in essence, a history of account holders discovering which of the two they held.
The determination turns on the custody documentation, the mechanics of segregation as actually operated rather than as described in marketing material, and the insolvency law governing the custodian. It is a question to be answered in the due diligence file before assets are transferred, and revisited when the custodian's terms change.
Tracing
Digital assets are unusual in that the transaction record is public and permanent, which makes tracing technically feasible to a degree unavailable for cash. The constraints are legal rather than evidential: mixers and privacy protocols can break the practical chain, cross-chain bridges complicate the analysis, and identifying the person behind an address ordinarily requires an order against an intermediary.
Cyprus courts have shown willingness to grant interim relief in support of asset recovery, and the practical route in a fraud or misappropriation case typically combines a freezing order, disclosure orders against identifiable intermediaries, and coordination with the custodians or exchanges holding the relevant accounts. Speed is decisive: assets move in minutes, and the value of an order declines sharply with every hour between the discovery and the application.
The trustee's own insolvency
A point that is easy to overlook. Trust assets are not available to the trustee's creditors, but that principle is only useful if the assets can be identified as trust assets. A trustee that has commingled client digital assets in a single wallet without per-client attribution in its own books has created exactly the evidential problem the principle is meant to avoid. Segregation must be operated and recorded at the level of each trust, not merely asserted.
11. A ten-gate acceptance framework
The framework below is the sequence we apply on intake. Each gate is a stop: a negative answer is resolved, or the asset is not accepted. The value of a gated process is that it produces a file which shows, in order, what was asked and what the answer was — which is what a court, a regulator, an auditor or a professional indemnity insurer will want to see.
| Gate | Question to be answered and evidenced |
|---|---|
| 1. Authority | Does the instrument empower the trustee to hold this asset? If unclear, is it amended, or is the acquisition declined? |
| 2. Classification | What is the asset for trust, regulatory, tax, AML and insolvency purposes? These may differ, and each must be answered separately. |
| 3. Provenance | Is source of wealth established to the standard the file must meet, including on-chain analysis and address-level sanctions screening? |
| 4. Custody | Which model, which provider, on what contractual terms, with what segregation and what recovery route? Contract reviewed, not merely the licence. |
| 5. Controls | Signing thresholds, dual authorisation, whitelisting and cooling-off, out-of-band verification, documented emergency procedure. |
| 6. Perimeter | Does anything the trustee proposes to do require a MiCA authorisation or another licence it does not hold? |
| 7. Tax | Who is the taxable person, on what events, at what rate, and can the cost base be evidenced from the first transaction? |
| 8. Reporting | Which regimes apply — DAC8, CRS, beneficial ownership, home-jurisdiction reporting — who reports, and is the position consistent across all of them? |
| 9. Succession | Could a successor trustee take control from the file alone? Has recovery been tested and the test recorded? |
| 10. Exit | How is this position realised, over what period, at what expected cost, and what happens if the primary venue is unavailable? |
A trustee that can answer these ten questions in writing, before acceptance, has met the standard. A trustee that cannot has taken on an asset it is not yet in a position to administer — which is a different problem from having taken on a risky asset, and a much harder one to defend.
The default position. Where the answers cannot be assembled, the correct outcome is refusal or quarantine, not acceptance with reservations. A trustee is never criticised for declining to accept an asset it could not administer properly. It is invariably criticised for accepting one it could not.
12. How we work
SSPwealth is the private client and wealth structuring practice of Christos Malikkidis & Co. LLC, a Cyprus law firm based in Limassol. We act for internationally mobile families, founders and their advisers on the design, implementation and ongoing governance of Cyprus and cross-border structures.
What we do in this area
- •Structuring and review. Cyprus International Trusts and underlying holding structures for families with digital-asset wealth, including review and amendment of existing instruments whose investment powers predate the asset class.
- •Trustee governance. Digital-asset policies, acceptance protocols, custody due diligence, signing and approval frameworks, valuation policies and minute templates for professional trustees and private trust companies.
- •Regulatory perimeter advice. Whether a proposed activity requires MiCA authorisation or falls within an existing Cyprus fiduciary licence, and how to structure the activity so the question does not arise.
- •Tax and reporting. Article 20E analysis, identification of the taxable person, cost-base and record-keeping frameworks, and DAC8, CARF and CRS positioning across the structure.
- •Cross-border coordination.Instructing and coordinating counsel in the settlor's home jurisdiction so that both sides of the structure are advised on the same facts.
- •Contentious and recovery work. Interim relief, tracing and recovery where digital assets have been misappropriated or a counterparty has failed, drawing on insolvency practice as well as litigation.
Why families work with us
We are a boutique practice, which means the person who designs the structure is the person who runs it. Our work is concentrated in private client, wealth structuring, corporate governance and international tax. We hold the whole picture rather than a slice of it, and we say when something should not be done.
Holding digital assets in a Cyprus structure?
Schedule a confidential consultation with Christos Malikkidis to review authority, custody, the regulatory perimeter, and your Article 20E and DAC8 position.
Schedule a ConsultationThis paper is general commentary and not legal, tax or regulatory advice. Law stated as at 1 September 2026. Positions in this area change rapidly and should be re-verified at the point of any decision. © Christos Malikkidis & Co. LLC 2026. All rights reserved.