Swan Trinity: Three Keys, Zero Accountability — The New Custody Math
CoinCube
The data is unambiguous. After the August Coldcard hardware wallet compromise, Swan's Sovereign advisory service grew from a niche product to 1,300–1,400 clients. That is the measurable signal. The unmeasurable one is more consequential: Swan CEO Cory Klippsten used that window to announce Trinity — a custody product where the customer holds zero keys and three institutions each hold one. The pitch is simple: eliminate the single point of failure by distributing trust across three independent firms. The math is not simple. The math is the problem.
Silence in the logs is louder than the crash. And the logs here are empty. No whitepaper. No audit plan. No third-party disclosure. No governance protocol. What exists is a podcast announcement and a Q4 target date. The product was revealed on Unchained before any formal release. The idea is credited to BitGo CEO Mike Belshe. The third key holder is unnamed. This is not a product launch. This is a narrative test.
Swan Trinity is not a technology innovation. It is a trust redistribution mechanism. The underlying cryptography — 2-of-3 multisig, key splitting — has been production-tested for years. Casa and Unchained Capital built collaborative custody models on exactly this foundation. The difference is structural: in collaborative custody, the user holds two keys and the company holds one. In Trinity, the user holds nothing. Swan holds one key. BitGo holds one key. An unnamed third institution — possibly UK-based — holds the third.
This inversion matters. It moves the security assumption from "the user is competent and at least one institution is honest" to "at least two institutions never collude." That is a stronger assumption. It is also an unverified one.
The product has not launched. Klippsten announced it on the Unchained podcast before any formal release. Target date is Q4. No technical whitepaper exists. No audit plan has been disclosed. The third key holder's identity is unknown. The governance protocol between the three institutions is undisclosed. The recovery procedure if one institution declares bankruptcy is undefined.
The market context matters. The Coldcard incident — a hardware wallet supply-chain compromise — shook the self-custody community. It validated a narrative that institutional custody alternatives are necessary. Klippsten is explicitly positioning Trinity as the answer to both self-custody failures (Coldcard) and historical custodial failures (Mt. Gox, Celsius). That is a convenient binary. It is also a false one.
Swan's existing infrastructure is relevant. The company already works with BitGo Trust, Bakkt, and Equity Trust — three regulated custodians. Swan Vault offers collaborative custody. Swan Sovereign offers advisory services for self-custody. Trinity is the logical endpoint of this product spectrum: the complete surrender of user key control. Klippsten has described a five-step custody range, and Trinity sits at the extreme end — the "trust-minimized" position where the user bears zero security responsibility.
Let me be precise about what is being proposed.
The security model rests on a single assumption: three independent institutions will not collude. Two of three colluding institutions control the full balance. That is not a theoretical risk. That is the arithmetic of 2-of-3 multisig. The threshold for theft is not "one institution goes rogue" — it is "two institutions coordinate." The psychological barrier to that is lower than the industry narrative suggests.
I have audited enough smart contracts to know that trust assumptions are the first thing to fail. In 2018, I spent six weeks manually auditing a Solidity codebase and found a reentrancy vulnerability that could have drained $2.5 million. The code was the problem. The marketing deck said otherwise. The same principle applies here: the governance structure is the code, and it has not been published.
The third key holder is the critical unknown. The entire security architecture depends on this entity's technical competence, financial stability, and operational independence. None of that can be verified. Klippsten says they are "evaluating partners." That is not a security model. That is a placeholder.
There is also a legal coordination problem. If the third party is a UK company, Trinity spans two legal jurisdictions. Bankruptcy isolation across US and UK courts is not automatic. Asset recovery in a cross-border insolvency scenario is legally complex. The product's promise — "your bitcoin is safe even if one institution fails" — requires a legal framework that has not been disclosed.
The cost structure is another unexamined variable. Three institutions each need to be compensated. That means three custody fees. The pricing model has not been announced, but the economics of multi-institutional custody are inherently more expensive than single-custodian alternatives. For institutional clients, this might be acceptable. For the high-net-worth individuals Swan appears to target, it is a material consideration.
The "no customer keys" positioning is a double-edged sword. It lowers the barrier to entry for users who do not want to manage hardware wallets. But it also eliminates the user's ability to verify their own assets independently. The verification mechanism — whether it is zero-knowledge proofs, audit reports, or something else — has not been specified.
Let me also address the competitive landscape. Fireblocks uses MPC — multiparty computation — which is cryptographically more sophisticated than simple multisig. BitGo itself offers traditional institutional custody with insurance coverage. Coinbase Custody has regulatory approval and brand trust. Trinity's differentiation is the "three independent institutions" structure. But that structure is replicable. BitGo could partner with two other custodians and offer the same product tomorrow. The moat is not technical. It is relational — and relationships can be duplicated.
The governance gap is the most concerning element. Three institutions need a binding agreement that covers: dispute resolution, key recovery procedures, bankruptcy protocols, audit rights, and collusion penalties. None of this has been disclosed. In traditional finance, this would be a 200-page legal document reviewed by multiple counsel. In crypto, it is a podcast announcement.
The collusion vector deserves more scrutiny. Klippsten claims "you won't have two institutions colluding to steal your coins." That is a narrative statement, not a mechanism. Business dependencies between Swan and BitGo already exist — they have partnered since 2023. Shared legal counsel, data-sharing agreements, joint marketing initiatives — these are the soft collusion vectors that do not require a formal conspiracy. They emerge from operational proximity.
The regulatory picture is also incomplete. Custody products are not securities — the Howey test does not apply to storage services. But state money transmission laws and trust regulations do apply. BitGo Trust is a South Dakota-chartered trust company. Swan works with regulated entities. The compliance framework exists. But cross-border coordination between US and UK regulators adds complexity that has not been addressed.
The bulls have a point. The demand is real. The Coldcard incident exposed genuine vulnerabilities in self-custody. Hardware wallets are not immune to supply-chain attacks. The 1.5 million BTC loss figure Klippsten cites may be unverified, but the direction is correct: self-custody failures are not rare.
The timing is also right. Institutional adoption of bitcoin requires custody solutions that traditional finance can understand. Multi-institutional key splitting maps more cleanly onto traditional custody frameworks than collaborative custody does. A family office or pension fund is more likely to accept "three independent custodians" than "you hold two keys."
And the Swan-BitGo relationship provides a foundation. They have worked together since 2023. BitGo Trust already serves as Swan's custodian. The operational framework exists. That is not nothing.
The product also fills a genuine vacuum. Between "you manage your own keys" (self-custody) and "one company holds everything" (traditional custody), there was no middle ground for users who want institutional security without single-custodian risk. Trinity occupies that space. The positioning is smart. The execution is unproven.
The floor is an illusion; the floor is a trap. In custody, the floor is the trust assumption. Trinity's floor is "two institutions won't collude." That is a better floor than "one institution won't fail." But it is still a floor. And floors can collapse.
The question is not whether Trinity will launch. It is whether the trust model survives contact with reality. Three institutions is better than one — mathematically. But the math only works if the institutions are actually independent. Business dependencies, shared legal counsel, cross-institutional data agreements — these are the soft collusion vectors that no marketing deck will disclose.
Wait for the third key holder. Read the governance protocol. Verify the recovery procedure. Precision is the only currency that never inflates.