On January 23, 2025, the SEC’s accounting staff announced in Staff Accounting Bulletin No. 122 that it was rescinding SAB 121’s guidance on safeguarding crypto assets. The public claim was about accounting. The disputed inference is broader: removing a liability from a bank’s ledger book also removed its responsibility for customer crypto lost in custody.
The record supports the accounting change, not the release from responsibility. SAB 122 expressly directs entities to assess potential safeguarding losses under existing accounting standards. It also preserves disclosure requirements concerning those obligations.
What did SAB 121 put on the books?
The SEC staff issued SAB 121 on March 31, 2022. Its central instruction addressed entities responsible for safeguarding crypto assets held for platform users, including maintaining the information needed to access those assets.
The staff identified technological, legal, and regulatory risks associated with that work. It instructed covered entities to recognize a safeguarding liability and a corresponding asset. Both were generally measured using the fair value of the crypto assets being safeguarded.
That requirement did not wait for a theft, a lost private key, or a customer lawsuit. It arose from the safeguarding obligation itself. The bulletin separately addressed adjustments to the corresponding asset for potential loss events.
This distinction matters. The balance-sheet liability was not a finding that the custodian had already lost customer property. Nor was it a judgment awarding customers damages. It was a prescribed accounting treatment for assets held for others and the risks attached to safeguarding them.
What exactly did SAB 122 rescind?
SAB 122 rescinded the interpretive guidance in Topic 5.FF of the Staff Accounting Bulletin Series. That was the section added by SAB 121. The rescission therefore removed the special recognition and measurement instructions, along with that section’s associated guidance.
The replacement did not say that custodians no longer had safeguarding obligations. Instead, it instructed an entity with such an obligation to determine whether to recognize a liability for the risk of loss under other accounting standards.
For U.S. generally accepted accounting principles, it identified Accounting Standards Codification Subtopic 450-20, Loss Contingencies. For international reporting, it identified IAS 37, Provisions, Contingent Liabilities and Contingent Assets.
SAB 122 directs retrospective application for annual periods beginning after December 15, 2024, and permits earlier application under specified filing conditions. It also calls for clear disclosure of the effects of the accounting change upon initial application. Removing the old entries was an accounting transition, not an instruction to disregard potential losses.
When must a loss still be recorded?
Under ASC 450-20, a loss contingency generally requires accrual when available information indicates that a liability was probably incurred by the financial-statement date and the loss can be reasonably estimated.
That is a different trigger from SAB 121’s safeguarding liability. The relevant question becomes whether the facts support recognizing a loss, rather than whether the entity holds customer crypto subject to the former guidance.
Failure to meet the accrual threshold does not necessarily end the accounting inquiry. ASC 450-20 generally requires disclosure when there is at least a reasonable possibility of loss. Those disclosures include the contingency’s nature and an estimate of the possible loss or range, or a statement that an estimate cannot be made.
SAB 122 thus replaced a crypto-specific balance-sheet treatment with an assessment under existing loss-contingency rules. A liability can disappear because the recognition model changed. That does not establish that every potential claim against the custodian disappeared with it.
Is the international treatment identical?
No. SAB 122 names a separate standard for entities applying international accounting standards. IAS 37 requires a provision when a past event creates a present legal or constructive obligation, an outflow of resources is probable, and the amount can be estimated reliably.
IAS 37 also distinguishes provisions from contingent liabilities. A contingent liability is generally disclosed unless the possibility of an outflow is remote.
Those requirements should not be compressed into the U.S. standard’s terminology. The two frameworks have their own recognition and measurement rules. SAB 122 directs the reporting entity to the applicable framework; it does not replace both with a declaration that custody creates no liability.
The bulletin also identifies IFRS 7, Financial Instruments: Disclosures, among the existing disclosure requirements entities should consider. That standard addresses the significance of financial instruments and the nature and extent of associated risks within its scope.
What must investors still be told?
SAB 122 explicitly says entities should consider existing requirements that allow investors to understand their obligation to safeguard crypto assets held for others. It identifies Items 101, 105, and 303 of Regulation S-K alongside the accounting standards.
These provisions do different jobs. Item 101 governs descriptions of the business. Item 105 requires discussion of material factors that make an investment speculative or risky. Item 303 governs management’s discussion and analysis of financial condition and operating results, including relevant known trends and uncertainties.
The SEC staff did not recreate SAB 121’s disclosure instructions word for word. It pointed entities back to requirements that already applied.
The consequence is narrower than either keeping or abolishing every previous disclosure. Material custody operations, risks, and financial effects remain subject to the applicable reporting requirements. A bank cannot treat the removal of the special safeguarding entry as permission to omit information otherwise required by those provisions.
What did bank supervisors require separately?
The accounting bulletin was not the source of national banks’ authority to provide crypto custody. In Interpretive Letter 1170, dated July 22, 2020, the Office of the Comptroller of the Currency concluded that national banks could provide cryptocurrency custody services.
The OCC addressed fiduciary and nonfiduciary custody. It required banks to conduct permissible activities consistently with applicable law and safe and sound banking practices. Its discussion included risk management, controls, and custody agreements.
Separate federal rules also govern fiduciary assets. Under 12 CFR 9.13, a national bank must keep assets held in a fiduciary capacity separate from its own assets. That requirement concerns fiduciary holdings, not every custody arrangement.
On March 7, 2025, the OCC issued Interpretive Letter 1183. It reaffirmed the permissibility of specified crypto activities and rescinded the prior supervisory nonobjection process established in Letter 1179. It nevertheless retained the requirement for safe and sound conduct consistent with applicable law. Removing an accounting instruction and removing a supervisory preclearance process were distinct actions.
Who decides whether a bank owes compensation?
SAB 122 does not adjudicate a customer’s claim. Whether a bank must compensate a customer for missing crypto depends on the custody agreement, applicable law, and the facts of the loss. The OCC’s custody guidance recognizes that the legal relationship and associated duties depend on how the service is structured.
The bulletin also describes the limits of its own authority. Staff accounting bulletins are not Commission rules or interpretations. They express staff interpretations and practices used in administering federal securities-law disclosure requirements.
That is why the word “liability” needs its context. Recognizing a liability in financial statements and establishing legal responsibility to a customer are different determinations. SAB 122 changed the former framework without purporting to settle the latter.
Did the repeal remove custodial liability?
No. SAB 122 removed SAB 121’s special safeguarding accounting, not banks’ responsibility for customer crypto. Its text expressly retains an assessment of potential losses and points to continuing disclosure requirements. The ledger changed. The rescission did not release custodians from their underlying obligations.



