If you stake, you've heard "not your keys, not your crypto." But when you delegate to a staking provider, who actually controls what? Most people can't answer that, and the industry is fine with the confusion. This is the technical reality.
Staking has become the default way to put idle crypto to work. Yet for something so widespread, the trust model underneath it stays poorly understood. When you stake through a provider, you're making an implicit bet about what that provider can and cannot do with your assets. Get that bet wrong and you learn the hard way, through frozen withdrawals, opaque fees, or worse.
This piece breaks down what "non-custodial" actually means at the protocol level, what a staking operator can and cannot touch, and how to evaluate any provider you're considering. No marketing, just the mechanics.
The custody spectrum
"Custodial vs non-custodial" gets treated as a binary. It isn't. There are three distinct models in production today, each with a different trust surface.
Custodial staking is what you get on most centralized exchanges. You send funds to the platform, they stake on your behalf, and they hold everything: your principal, your keys, your rewards. You hold an IOU. If the platform freezes withdrawals, gets hacked, or becomes insolvent, your assets are exposed. Convenient, but you've handed over control entirely.
Liquid staking (Lido, Rocket Pool, and similar) routes your funds through a smart contract. You deposit, and you receive a derivative token, stETH or rETH, representing your position. You keep a liquid, tradeable asset, but the trust shifts to the contract and its operator set: the code, its governance, and the node operators behind it.
Non-custodial delegation is the model where you retain control. You keep the key that governs your funds. The operator runs validator infrastructure on your behalf but is structurally incapable of moving your principal. They earn a fee for running reliable infrastructure, nothing more.
| Custodial (CEX) | Liquid staking | Non-custodial (Nodz) | |
|---|---|---|---|
| Who holds the principal | The platform | Smart contract | You |
| Slashing exposure | Borne by platform (opaque) | Socialized across the pool | Yours, tied to your operator |
| Withdrawal access | Platform can freeze | Via contract / secondary market | Always yours |
| Core trust assumption | Trust the company's solvency | Trust the code & operator set | Trust only the operator's uptime |
| Liquidity | Depends on platform terms | High (tradeable LST) | Bonded / unbonding period |
The distinction is not academic. It determines exactly what happens to your assets on the worst day.
What the numbers actually show
The market leans heavily toward the models where you give up control, and that concentration is now a recognized risk.
Roughly 34% of all ETH is staked today, representing approximately 41.4 million ETH, worth around $77 billion at current prices.
Lido currently accounts for approximately 9.41 million ETH, equivalent to around 22.7% of all staked ETH. Within the liquid-staking segment specifically, Lido holds a much larger 62.62% market share. Ethereum co-founder Vitalik Buterin has flagged staking concentration as a systemic risk.
Total value locked across liquid-staking protocols currently stands at approximately $34.83 billion across all supported blockchains. Ethereum-based liquid staking alone represents approximately $28.07 billion / 15.02 million ETH.

Total value locked across liquid staking protocols. Source: DefiLlama, accessed August 4, 2026.
The takeaway is simple: most staked capital today sits with providers that hold the keys, and the market is starting to treat that as a structural problem, not a convenience.
The key that actually matters
This is the part most explainers skip. In a proof-of-stake system, "your key" isn't one key. Staking separates two responsibilities, and the split is what the whole model rests on.
The validator (signing) key signs blocks and attestations. It has to be online and available to the network at all times, which means it lives on the operator's infrastructure. If this key is compromised, an attacker can sign malicious messages, but it cannot move funds.
The withdrawal key controls the actual assets. It authorizes unstaking and withdrawal. In a properly designed non-custodial setup, this key never touches the operator. It stays with you.
This separation is what makes non-custodial staking possible. The operator signs blocks in
your name to keep the validator active and earning, but has no path to your principal. On
Ethereum, this is enforced at the protocol level through withdrawal credentials: the
0x01 (and now 0x02) credential type points withdrawals to an address you control. The
operator can run the validator indefinitely and still never redirect a single wei of your
stake.

If a provider can unstake or withdraw your assets without you, they are not non-custodial. That is the test.
What can a failing or malicious operator actually do?
Being honest here builds more trust than any guarantee. Non-custodial does not mean risk-free. It means the type of risk is bounded and known. So let's be precise.
What an operator cannot do:
- Steal your principal. The withdrawal key isn't theirs.
- Withdraw or unstake without your authorization.
- Lock you out of your own funds indefinitely.
What an operator can do, and where real risk lives:
- Get slashed. If the operator double-signs (equivocates) or, on some chains, suffers severe downtime, the protocol penalizes the validator. That penalty comes out of your stake. A serious operator's entire job is engineering this risk toward zero.
- Cause liveness issues. If their infrastructure goes down, your validator stops attesting and stops earning until it recovers. You don't lose principal, but you lose yield.
- Capture or mismanage MEV. How an operator handles execution-layer rewards and MEV affects what actually reaches you.
This is the honest risk surface. The value of a good non-custodial operator is not "zero risk." It is minimizing the risks they can affect (slashing, downtime, MEV handling) while being structurally locked out of the one that would hurt most: your principal.
How Nodz is architected around this
At Nodz, the non-custodial model is not a feature we bolt on. It is the foundation. You retain your withdrawal credentials at all times. We run the validator infrastructure; we never hold the key that controls your funds.
On the infrastructure side, reliability is what minimizes the risks we can affect:
- Uptime / availability: 99.98%
- Slashing record: 0 slashing events since inception
- Networks supported: Solana, Starknet, Sui, Ethereum, Arbitrum
- TVL: $35M+
The result: institutional-grade infrastructure with a retail-simple guarantee. Your keys stay yours.
#engineering
