Custody at Settlement: Who Actually Holds the Keys Between Your Wallet and the Government’s
12 min read
Bitcoiners ask who holds the keys before they use an exchange, a lender, or a wallet service. They inspect withdrawal policy, signing arrangements, and counterparty risk before moving serious value.
Then a citizenship-by-investment invoice arrives and the same applicant sees a government logo, a licensed agent’s instructions, and a payment address. The custody question gets replaced by a simpler one: where do I send?
That is backwards.
Citizenship by Investment (CBI) is a legal route through which a sovereign state may grant citizenship after prescribed screening and a qualifying contribution or investment. The settlement leg may involve an applicant, advisor, licensed agent, settlement provider, bank, escrow arrangement, government account, or program wallet. The exact route depends on the program, asset, agreement, and current official instructions.
The applicant should name who controls funds at every step, what transfers control, what marks payment accepted, and what receipt discharges the obligation. If those answers are vague, settlement is not ready.
Custody Is A Sequence, Not A Label
Self-custody continues while the applicant controls the signing keys and can decide whether, when, and where the assets move. It ends when the applicant authorizes a transaction that transfers value to an address or account the applicant does not control.
That sounds obvious. The difficulty is that four different events are often collapsed into the word paid.
Authorized. The applicant or authorized signer approves the transaction.
Broadcast or submitted. The transaction enters the relevant network or payment system.
Confirmed or settled. The receiving system applies its confirmation policy and recognizes the value as received.
Commercially acknowledged. The recipient issues a receipt or updates the file to show that the applicant’s obligation has been satisfied.
Those events may occur seconds apart or much longer apart. They may also involve different risks. A transaction can be signed but not broadcast. It can be broadcast but unconfirmed. It can be confirmed on-chain but sent to the wrong destination. It can arrive at the intended destination while the recipient has not yet matched it to the correct applicant or invoice.
Custody is therefore one line in a larger settlement map. Authorization answers who can move the assets. Confirmation answers how the network treats the transfer. Reconciliation answers whether the recipient can connect it to the file. The receipt answers whether the legal or contractual payment obligation has been discharged.
The keys tell you who can move the value. The receipt tells you whether the file recognizes that movement as payment.
A well-run process defines all four before the applicant sends.
Map Every Handoff Before The Invoice
Start with the parties, not the technology.
Identify the applicant or paying entity. If a company, trust, family office, or relative will pay, confirm whether third-party funding is permitted and what beneficial-owner evidence is required. A technically valid transaction from an undisclosed payer can create a compliance problem even when the applicant ultimately supplied the money.
Identify the contractual payee. This may be the government, an authorized program account, a licensed agent, an escrow provider, or another party named in the official process. Do not infer the payee from a domain name or a prior invoice.
Identify each operational service. A payment processor may generate an address and monitor confirmation without taking custody. An exchange may control the sending keys while the applicant instructs a withdrawal. A bank may transmit fiat through correspondent institutions. An escrow provider may take legal and technical control subject to release conditions. These are materially different arrangements.
For each step, write five facts:
1. The sender and recipient. 2. The asset and network or fiat rail. 3. The wallet or account controller on each side. 4. The event that marks acceptance at that step. 5. The document or system record that proves completion.
If an intermediary holds funds, ask under what legal capacity, in whose name, under what release conditions, and which law. Do not use the word escrow unless an agreement defines the holder’s duties and release mechanism.
The joint FATF and OECD report on CBI and residency programs identifies intermediaries, multiple agencies, and professional enablers as important parts of the risk architecture. That does not mean an intermediary is improper. It means the file should make each intermediary’s role visible.
Verify The Instruction, Not Just The Address
An address can be valid and still be wrong for the payment.
The current invoice should identify the payee, applicant or file reference, amount, asset, network, receiving destination, validity window, confirmation policy or status terms, and any memo or reference required for reconciliation. If one of those fields is absent, obtain clarification through the agreed channel before sending.
Treat destination verification as a two-channel task for material payments. Compare the invoice with the authenticated client portal, known contact, signed instruction, or another pre-agreed method. Do not verify a changed address by replying only to the same email that announced the change. The Bitcoin developer guide’s payment-processing security guidance warns that payment requests need a secure delivery method because an attacker can replace the receiving address.
Read the asset and network separately. USDT exists on multiple networks. An address format that looks familiar does not prove that the recipient supports the token contract, chain, or network version being sent. Lightning invoices are not reusable on-chain addresses. A bank account instruction has its own currency, beneficiary, reference, and correspondent details.
Check the amount after fees. With Bitcoin, the network fee is separate from the output amount. With some token networks, the sending wallet needs the network’s native asset for fees. With exchange withdrawals, the platform may deduct a withdrawal fee or send in a batch. The receiving amount must satisfy the invoice, not merely the amount entered on the first screen.
Use a test transaction only when the recipient’s procedure permits it. A small unscheduled payment can create a partial-payment exception, reuse an invoice incorrectly, or fail to test the actual high-value path. If a test is authorized, document how it will be matched and whether a fresh destination will be issued for the balance.
Confirmation Is A Risk Policy
Bitcoin does not contain a universal field that says a payment is finally irreversible for every commercial purpose. It gives the recipient increasing confidence as blocks are added after the transaction.
The Bitcoin developer guide explains that broadcasting does not ensure receipt, that an unconfirmed transaction requires risk analysis, and that each additional block adds a confirmation. Its verifying-payment section uses six confirmations as a common high-value benchmark while explicitly describing that number as somewhat arbitrary. The correct threshold is the recipient’s disclosed policy for that payment, not a number copied from a generic article.
Ask whether the invoice marks paid when the transaction enters the mempool, receives one confirmation, reaches a higher threshold, or is manually reviewed. Ask what happens if the fee is too low, the transaction is replaced, the wrong amount arrives, or a chain disruption delays confidence.
Lightning uses a different acceptance model. A successful payment produces settlement evidence from the Lightning implementation, while a failed or expired invoice does not become valid merely because the payer attempted it. The payer should preserve the invoice, payment hash, wallet record, and receipt without publishing sensitive preimage or routing information unnecessarily.
USDT confirmation depends on the network and the recipient’s policy, but token settlement also carries issuer control that native Bitcoin does not. Tether’s legal terms state that Tether Token transactions are not reversible and that Tether may freeze tokens or bar transactions under specified legal and risk conditions. That makes two statements true at once: the payer may not be able to reverse an erroneous transfer, while the issuer retains technical controls over the token. Do not market USDT as equivalent to permissionless Bitcoin custody.
For bank transfers, the payer’s debit notice is not the recipient’s final receipt. Obtain the recipient’s acknowledgement, not only the sending bank’s confirmation.
Distinguish Processing From Custody
A service can observe, match, and report a payment without controlling the receiving keys. That is processing without custody.
BTCPay Server’s official documentation describes its model as non-custodial: it can derive a fresh receiving address from an extended public key and monitor payment without requiring the merchant’s private key. Payment goes directly to the merchant’s wallet. This architecture reduces one intermediary-custody layer, but it does not remove every operational risk.
The server or invoice interface can still be compromised. A malicious configuration can display the wrong destination. The merchant can lose its own keys. The payer can choose the wrong network or amount. A receiving wallet can be controlled by an organization whose internal signing policy is unknown to the payer. Non-custodial software answers who holds keys at the processor layer. It does not answer every governance question around the recipient.
With an exchange withdrawal, the exchange controls the keys until it signs and broadcasts. Review, allowlists, batching, and restrictions can affect timing. Clicking withdraw does not equal broadcast.
An escrow arrangement adds a custody step when the holder controls funds subject to agreed conditions. Obtain the agreement, identify the holder, understand release and refund terms, and address price movement while assets are held.
The point is not to demand a zero-intermediary route in every case. The point is to identify the route that actually exists and decide whether its controls match the value at risk.
What Bitsettle Does In The Stack
BitSettle is the Bitcoin and USDT settlement rail used across the Bitcitizen ecosystem. Its public architecture states that native Bitcoin, Lightning, and supported USDT payments settle to a wallet controlled by the recipient, with BitSettle watching and confirming rather than holding a provider balance. It is built on BTCPay Server.
For 21 CBI fees, the general payment framing is clear: BTC, Lightning, and USDT are our payment rails through BitSettle at the Bitcoin-native price. Stripe is the card or Link rail at the standard price. Credit cards and bank transfers are also accepted as needed. USDC and other non-USDT stablecoins are not offered as payment options.
USDT availability is subject to payer eligibility, the supported network, and current Tether terms. Tether’s 26 February 2026 terms classify U.S. Persons, Canadian Persons, Singaporean Persons, specified sanctioned persons, and residents or officials of listed prohibited jurisdictions as Prohibited Persons, subject to stated exceptions. An applicant within those definitions must use another permitted rail and obtain advice before attempting a USDT payment.
That describes 21 CBI’s fee settlement. It does not establish that every government accepts every rail or that every contribution moves through BitSettle. The El Salvador program overview and stablecoin settlement guide are reference points, not a basis for comparing programs. Government payments follow current instructions issued after compliance clearance.
For any BitSettle invoice, verify the live amount, asset, network, destination, and expiry. The recipient’s wallet controls the keys after value lands. The payer controls whether to send until authorization. BitSettle supplies the invoice and confirmation layer between those points; it does not need to take custody merely to observe the payment.
When a service provider later makes a statutory payment, that onward payment is a second transaction, custody event, and receipt. Do not describe the first transfer as direct to government unless it is.
Build The Settlement Receipt Pack
The final record should be boring.
Preserve the approved payment instruction and invoice. Keep the version actually used, including the issue time, expiry, destination, asset, network, amount, and applicant reference. If an instruction changed, preserve the superseded version and the authenticated correction.
Preserve authorization evidence appropriate to the payer. For a personal wallet, keep the wallet record. For a company or multisignature treasury, include internal approval, required authority, signer policy, or transaction proposal.
Preserve the transaction identifier, relevant addresses, token contract for USDT, amount, fee, timestamp, settlement status, and confirmation state at acceptance. Export a stable copy because explorer interfaces change.
Preserve the commercial receipt. It should identify the amount, asset, file, recipient, date, and whether the obligation is satisfied. Keep any onward remittance separate.
Reconcile the payment with the already-approved source-of-funds schedule. A clean invoice does not reset provenance. If the paying wallet differs from the wallet approved during diligence, stop and update the file before sending. If the exchange, desk, or bridge route changed, document the change.
Record exceptions immediately. An underpayment, duplicate send, wrong memo, delayed confirmation, or returned bank wire needs a dated note, supporting records, resolution, and named decision-maker.
Ask These Questions Before You Send
Who is the legal payee, and who controls the receiving wallet or account?
Does any processor, exchange, agent, escrow provider, or bank take custody? If so, when and under what agreement?
What exact event transfers control away from the applicant?
Which asset, network, destination, amount, memo, and validity window govern?
What confirmation policy marks the transaction accepted?
Which receipt proves that the correct obligation has been discharged?
What happens after an underpayment, wrong-chain transfer, delayed confirmation, refusal, withdrawal, or program pause?
Has the paying wallet and transaction route already cleared source-of-funds review?
If the file team cannot answer those questions in writing, pause. A payment of this size should not depend on oral shorthand or an address pasted into a chat.
A paid Sovereignty Strategy Session gives you one hour with Adam Juchniewicz, CEO, to map the custody and settlement handoffs before a contribution or fee moves. It is $475 through BitSettle or $500 through Stripe, and the amount paid credits toward professional fees if you retain 21 CBI within 90 days. Book through advisory; there is no obligation to proceed.
Verify the payee. Map the handoff. Keep the Receipt.
This article is general information, not legal, tax, immigration, financial, custody, or compliance advice. Payment routes, recipient accounts, confirmation policies, escrow terms, refund rights, and program rules vary and can change. Use only current authenticated instructions supplied after compliance clearance. Confirm material transfers with the licensed parties handling the file and obtain qualified legal and tax advice for your circumstances.

Adam Juchniewicz, CEO
US Air Force veteran. Bitcoiner since 2020.
