Banking Risk

Digital Assets and Crypto Risk for Traditional Investment Firms

By Jonas (Yonas) Mohamed Osman Abdelghafour · August 2026

Executive introduction

Crypto and tokenised assets are increasingly connected with traditional finance through custody, exchange-traded products, tokenised funds, stablecoins and institutional trading infrastructure. For European firms, 2026 is also a significant regulatory transition year because the MiCA grandfathering period for eligible crypto-asset service providers ended across the EU on 1 July 2026.

Traditional investment firms therefore need a risk framework that distinguishes several very different exposures: volatile crypto-assets, regulated tokenised financial instruments, stablecoins, custody arrangements and third-party crypto service providers.

Key takeaways

Market and liquidity risk

Crypto-assets can exhibit high volatility, fragmented liquidity and continuous 24-hour trading. Correlations can change rapidly during stress, and price gaps can occur across venues.

Risk limits should therefore consider realised and implied volatility, venue concentration, order-book depth, weekend liquidity, stablecoin settlement dependence and the possibility that market access differs by jurisdiction.

Custody risk

Custody of digital assets introduces risks around private keys, wallet architecture, cyber security, transaction authorisation and recovery. Traditional segregation concepts remain important, but operational implementation is different.

Firms should understand whether assets are held on-chain, with a qualified custodian, through an omnibus structure or through an exchange account, and what legal claim the client has if the provider fails.

Counterparty and venue risk

Crypto trading often depends on exchanges, brokers, custodians and stablecoin issuers. Concentration can be high. Counterparty due diligence should therefore assess financial strength, regulatory status, segregation, settlement, cyber controls and withdrawal capability.

Risk limits should reflect the possibility that an exchange can become unavailable during the exact period in which the firm wants to reduce exposure.

Stablecoin risk

Stablecoins aim to maintain a stable value but can face reserve, liquidity, governance and redemption risks. BIS analysis in 2026 continues to highlight potential macro-financial consequences if stablecoins become widely used substitutes for deposits or money-market instruments.

Investment firms should therefore avoid treating stablecoin balances as equivalent to insured bank cash without analysing the specific issuer and reserve structure.

Tokenisation

ESMA’s 2026 risk monitoring describes tokenisation as gaining momentum while adoption remains limited. Tokenisation can improve settlement and programmability, but it can also add smart-contract, interoperability, technology-provider and legal-ownership risks.

The risk of a tokenised bond remains fundamentally linked to the issuer and cash flows of the bond. DLT changes the infrastructure, not the underlying credit economics.

MiCA transition in 2026

ESMA stated that the EU-wide transitional period under MiCA expired on 1 July 2026. Firms providing crypto-asset services without the required authorisation after the applicable transition must cease unauthorised services.

Traditional investment firms should therefore verify the regulatory status of crypto service providers and distinguish crypto-assets under MiCA from tokenised instruments that qualify as financial instruments under other EU legislation.

Practical example

An asset manager uses a regulated custodian for Bitcoin exposure but holds settlement balances in a stablecoin on a trading venue. The portfolio market risk appears limited because positions are hedged. A venue outage prevents withdrawal while the stablecoin temporarily trades below par.

The loss arises not from the directional Bitcoin position but from settlement, counterparty and stablecoin liquidity. This illustrates why digital-asset risk cannot be reduced to price volatility.

What risk leaders should do now

  1. Classify digital exposures by legal and economic structure.
  2. Separate market risk from custody and counterparty risk.
  3. Set venue and custodian concentration limits.
  4. Assess stablecoin issuer and reserve risk explicitly.
  5. Verify MiCA or other applicable regulatory status of service providers.
  6. Stress withdrawal restrictions, exchange outages and de-pegging.
  7. Maintain key-management and incident-response controls for direct custody.
  8. Treat tokenisation technology as an additional infrastructure layer, not a replacement for credit analysis.

Frequently asked questions

MiCA provides a regulatory framework for crypto-assets and crypto-asset service providers in the EU, but it does not remove market, operational or counterparty risk. Traditional risk-management controls remain necessary.

Tokenised securities and crypto-assets are not necessarily the same. A token can represent a conventional financial instrument, in which case the applicable regulatory classification may differ from a crypto-asset governed primarily by MiCA.

Conclusion

Digital assets should be brought inside the ordinary enterprise-risk architecture rather than treated as a completely separate universe. Market, credit, liquidity and operational principles still apply, but the infrastructure creates new failure modes.

The strongest approach decomposes the exposure into underlying asset risk, venue risk, custody risk, settlement risk, technology risk and regulatory status. That makes digital-asset risk manageable without pretending that every token represents the same economic problem.

About the author

Jonas (Yonas) Mohamed Osman Abdelghafour writes about financial risk management, quantitative modelling, actuarial science, banking risk, insurance risk, capital modelling, model validation, climate risk and geopolitical risk. His work focuses on translating complex quantitative and regulatory risk issues into practical frameworks for financial institutions. Author profile.