
Regulatory briefings / Covers: January 2025
DORA is in force: what crypto-asset service providers must now evidence
From January 17, 2025 the Digital Operational Resilience Act applies to crypto-asset service providers as financial entities.
Regulation arrived, losses concentrated, and banks moved to public networks. The common thread was accountability for operations.
Three things happened in 2025 that did not obviously belong together. Regulators finished writing rules. The largest theft in the industry's history was executed through a signing workflow. Banks began settling deposit tokens on public networks. The common thread is that each shifted the decisive question from technology to operations: who is accountable, how quickly, and what does the record show.
The Digital Operational Resilience Act became applicable to crypto-asset service providers as financial entities, with an ICT risk framework, incident reporting clocks that run on weekends, resilience testing and a register of ICT third parties. Covered in DORA is in force: what crypto-asset service providers must now evidence.
Approximately 1.5 billion dollars was taken from a single exchange through a compromised approval path rather than a contract flaw. Covered in The February 2025 exchange breach: lessons for signing operations.
The OCC reaffirmed that national banks may hold crypto-assets in custody, support certain stablecoin activity and operate nodes without prior non-objection, subject to safety and soundness; the FDIC followed with FIL-7-2025. Covered in OCC Interpretive Letter 1183: banks may act as nodes on distributed ledgers.
Federal stablecoin legislation created a licensing regime for permitted payment stablecoin issuers, and the House passed market structure legislation that continued in the Senate through 2026. Covered in The GENIUS Act is law and Market structure legislation: what digital asset operators should watch in the CLARITY Act. National transition periods under MiCA ran in parallel, examined in MiCA authorization for crypto-asset service providers.
A major US bank began settling a deposit token on a public Layer 2 network. Covered in Tokenized deposits move to public networks, and followed in 2026 by the consortium model discussed in Bank-led on-chain money and the operator question.
Approximately 3.4 billion dollars stolen across the year, concentrated in a few incidents, with a growing share from personal wallet compromise. Covered in 2025 digital asset losses: what the numbers say about operations. The practice notes that follow from it are Privileged actions on-chain and Node and RPC health as a security signal.
Named ownership. Every alert, escalation tier and privileged action has a person attached, not a queue. A published clock. Notification within ten minutes of detection, acknowledgement expected within fifteen, escalation continuing until someone accountable responds. Evidence by design. Timelines, change records, access logs and supplier assessments generated as the work happens, in the formats supervisors request, so that a request produces a file rather than a project.
Nothing in that list is specific to blockchain. That is the point. 2025 was the year digital assets stopped being a technology question for institutions and became an operations question, answered the way financial infrastructure has always answered it.

Related insights

Regulatory briefings / Covers: January 2025
From January 17, 2025 the Digital Operational Resilience Act applies to crypto-asset service providers as financial entities.

Operations notes / Covers: February 2025
The largest theft in the industry's history to date, approximately 1.5 billion dollars from a single exchange, was executed through the signing workflow, not a smart contract bug.

Perspectives / Covers: November 2025
In November 2025 a major US bank began settling a deposit token on a public Layer 2 network, signaling that public blockchains are now part of bank infrastructure.
Client Focus reviews the estate, the coverage required and the gaps, then sets out what changes.