Skip to content
All articles

Where Are Your Keys? A Technical Breakdown of Non-Custodial Staking

08-04-2026

Where Are Your Keys? A Technical Breakdown of Non-Custodial Staking

If you stake, you've heard "not your keys, not your crypto." But when you delegate to a staking provider, who actually controls what? Most people can't answer that, and the industry is fine with the confusion. This is the technical reality.

Staking has become the default way to put idle crypto to work. Yet for something so widespread, the trust model underneath it stays poorly understood. When you stake through a provider, you're making an implicit bet about what that provider can and cannot do with your assets. Get that bet wrong and you learn the hard way, through frozen withdrawals, opaque fees, or worse.

This piece breaks down what "non-custodial" actually means at the protocol level, what a staking operator can and cannot touch, and how to evaluate any provider you're considering. No marketing, just the mechanics.

The custody spectrum

"Custodial vs non-custodial" gets treated as a binary. It isn't. There are three distinct models in production today, each with a different trust surface.

Custodial staking is what you get on most centralized exchanges. You send funds to the platform, they stake on your behalf, and they hold everything: your principal, your keys, your rewards. You hold an IOU. If the platform freezes withdrawals, gets hacked, or becomes insolvent, your assets are exposed. Convenient, but you've handed over control entirely.

Liquid staking (Lido, Rocket Pool, and similar) routes your funds through a smart contract. You deposit, and you receive a derivative token, stETH or rETH, representing your position. You keep a liquid, tradeable asset, but the trust shifts to the contract and its operator set: the code, its governance, and the node operators behind it.

Non-custodial delegation is the model where you retain control. You keep the key that governs your funds. The operator runs validator infrastructure on your behalf but is structurally incapable of moving your principal. They earn a fee for running reliable infrastructure, nothing more.

Custodial (CEX)Liquid stakingNon-custodial (Nodz)
Who holds the principalThe platformSmart contractYou
Slashing exposureBorne by platform (opaque)Socialized across the poolYours, tied to your operator
Withdrawal accessPlatform can freezeVia contract / secondary marketAlways yours
Core trust assumptionTrust the company's solvencyTrust the code & operator setTrust only the operator's uptime
LiquidityDepends on platform termsHigh (tradeable LST)Bonded / unbonding period

The distinction is not academic. It determines exactly what happens to your assets on the worst day.

What the numbers actually show

The market leans heavily toward the models where you give up control, and that concentration is now a recognized risk.

Roughly 34% of all ETH is staked today, representing approximately 41.4 million ETH, worth around $77 billion at current prices.

Lido currently accounts for approximately 9.41 million ETH, equivalent to around 22.7% of all staked ETH. Within the liquid-staking segment specifically, Lido holds a much larger 62.62% market share. Ethereum co-founder Vitalik Buterin has flagged staking concentration as a systemic risk.

Total value locked across liquid-staking protocols currently stands at approximately $34.83 billion across all supported blockchains. Ethereum-based liquid staking alone represents approximately $28.07 billion / 15.02 million ETH.

Liquid staking total value locked and protocol rankings on DefiLlama

Total value locked across liquid staking protocols. Source: DefiLlama, accessed August 4, 2026.

The takeaway is simple: most staked capital today sits with providers that hold the keys, and the market is starting to treat that as a structural problem, not a convenience.

The key that actually matters

This is the part most explainers skip. In a proof-of-stake system, "your key" isn't one key. Staking separates two responsibilities, and the split is what the whole model rests on.

The validator (signing) key signs blocks and attestations. It has to be online and available to the network at all times, which means it lives on the operator's infrastructure. If this key is compromised, an attacker can sign malicious messages, but it cannot move funds.

The withdrawal key controls the actual assets. It authorizes unstaking and withdrawal. In a properly designed non-custodial setup, this key never touches the operator. It stays with you.

This separation is what makes non-custodial staking possible. The operator signs blocks in your name to keep the validator active and earning, but has no path to your principal. On Ethereum, this is enforced at the protocol level through withdrawal credentials: the 0x01 (and now 0x02) credential type points withdrawals to an address you control. The operator can run the validator indefinitely and still never redirect a single wei of your stake.

The validator key sits on operator infrastructure while the withdrawal key stays with the user

If a provider can unstake or withdraw your assets without you, they are not non-custodial. That is the test.

What can a failing or malicious operator actually do?

Being honest here builds more trust than any guarantee. Non-custodial does not mean risk-free. It means the type of risk is bounded and known. So let's be precise.

What an operator cannot do:

  • Steal your principal. The withdrawal key isn't theirs.
  • Withdraw or unstake without your authorization.
  • Lock you out of your own funds indefinitely.

What an operator can do, and where real risk lives:

  • Get slashed. If the operator double-signs (equivocates) or, on some chains, suffers severe downtime, the protocol penalizes the validator. That penalty comes out of your stake. A serious operator's entire job is engineering this risk toward zero.
  • Cause liveness issues. If their infrastructure goes down, your validator stops attesting and stops earning until it recovers. You don't lose principal, but you lose yield.
  • Capture or mismanage MEV. How an operator handles execution-layer rewards and MEV affects what actually reaches you.

This is the honest risk surface. The value of a good non-custodial operator is not "zero risk." It is minimizing the risks they can affect (slashing, downtime, MEV handling) while being structurally locked out of the one that would hurt most: your principal.

How Nodz is architected around this

At Nodz, the non-custodial model is not a feature we bolt on. It is the foundation. You retain your withdrawal credentials at all times. We run the validator infrastructure; we never hold the key that controls your funds.

On the infrastructure side, reliability is what minimizes the risks we can affect:

  • Uptime / availability: 99.98%
  • Slashing record: 0 slashing events since inception
  • Networks supported: Solana, Starknet, Sui, Ethereum, Arbitrum
  • TVL: $35M+

The result: institutional-grade infrastructure with a retail-simple guarantee. Your keys stay yours.

#engineering