What a staking ETF demands of the infrastructure underneath
The bar for institutional staking infrastructure is no longer a matter of opinion. It is written into a prospectus.
On 28 July 2026, Morgan Stanley Investment Management listed two staking products on NYSE Arca: the Morgan Stanley Ethereum Trust (MSSE) and the Morgan Stanley Solana Trust (MSOL). Both carry a 0.14% expense ratio and both integrate staking from launch. The listing got the coverage. The filing terms are the part worth reading if you run validators for a living, because they describe, in numbers, what an issuer will and will not accept from an operator.
Four numbers that set the specification
The expense ratio is 0.14%. Custodians and staking providers deduct a service fee equal to 5% of gross staking rewards, which leaves roughly 95% reaching shareholders, and Morgan Stanley retains none of it itself. MSSE intends to stake between 50% and 80% of the ether it holds under normal conditions. MSOL can stake up to 100% of its SOL.
Read those together and you have a specification rather than a press release. The entire cost of running validators for a regulated, exchange-listed product has to fit inside 5% of gross rewards. The staking ratio is a band the operator has to hold, not a target it can drift away from. And the difference between the two products tells you the band is chain-specific, set by how quickly capital can be moved back out.
A staking ratio is an operational instruction
The 50% to 80% band is the part operators tend to underestimate.
An exchange-traded product has to meet redemptions, which means it cannot have everything staked. The unstaked portion is not idle capital, it is the liquidity buffer that makes the redemption promise work. Ethereum exits are queued at the protocol level and take as long as the queue takes, which is outside anyone's control on the day. So the operator's job is not simply to stake what it is handed. It is to activate and exit validators on the issuer's schedule, hold the ratio inside the band while flows move in both directions, and have a documented process for partial exits under a redemption event nobody scheduled.
Solana stake deactivation resolves at an epoch boundary rather than through an open-ended queue, which is why a Solana product can carry a higher staking ratio than an Ethereum one. The infrastructure consequence is the same in both cases. Capacity planning is driven by the issuer's flow rather than the operator's convenience, and activation headroom has to already exist rather than being provisioned on request.
Custody and signing are two different jobs
The asset sits with regulated custodians. The staking provider runs the validators and never holds the asset.
That separation is the structural fact underneath the whole product, and it narrows what the operator is being hired to do. Key generation, signing, availability, and reporting. The operator has to hold validator keys in a way that survives an audit, sign attestations without any single person being able to produce a malicious one alone, and prove both of those on request. Threshold signing stopped being a talking point and became a procurement question for exactly this reason.
It also means the operator's failure modes show up in someone else's accounts. A missed attestation becomes a line in a report an auditor reads.
The 5% envelope prices your architecture
This is where hardware economics stop being a matter of preference.
Everything the operator does has to fit inside that 5% service fee on gross rewards: redundancy, monitoring, on-call cover, key management, reporting, and whatever mechanism covers a slashing event. On hyperscaler pricing, a fully redundant validator fleet with the data depth needed for reporting spends a real share of that envelope on instance hours and egress before anyone has looked at an alert. We have written the validator hosting cost comparison up in detail, and the shape of it is that rented capacity turns a fixed fee into a variable cost that rises with the product's success.
Owned hardware changes the shape rather than removing the cost. Capital goes in up front. What follows is a run cost you can hold roughly flat while assets under management grow, which is the only version of this that survives a 0.14% expense ratio being competed downward.
Reporting has to survive a daily NAV
Rewards accrue per validator, per day. A product publishing a daily net asset value needs that accrual attributable at the same granularity, reconcilable against on-chain data, and delivered on a schedule that does not slip because someone was away.
Most operator dashboards are not built for this. They are built for the operator, to answer whether anything is broken, and they answer it well. An issuer's accounting team is asking a different question: what did this specific validator earn on this specific date, and can you show the working. Those are different systems, and the second one is usually what is missing when an operator fails diligence for reasons it cannot quite explain afterwards.
The real change is being named
Morgan Stanley named its staking provider publicly at launch. That is the shift, and it matters more than the flows.
For most of the past few years the operator sat behind the product. Delegation was a commercial arrangement between two private parties and the end investor never learned who was running the validator. A disclosed operator inside a listed product is a different relationship. Diligence becomes documentary: slashing history across the full operating record, uptime evidence with a stated measurement method, the legal entity and jurisdiction that holds the hardware, key management architecture, incident history, audited financials, and certification status. It is the same movement, seen from the other end, as institutions choosing to run validators themselves rather than buy a yield product.
An operator that cannot produce those in a form a bank's risk function will accept is not in the running, and its published yield never enters the conversation. That is a harder filter than any rewards table, and it will thin the field faster than fee compression does.
What to have ready
If you want to be on the other side of one of these mandates, the artifacts matter more than the pitch. Uptime evidence with the measurement method stated. Slashing history for the full operating record rather than a recent window. The named legal entity, and the jurisdiction where the hardware physically sits. Key management architecture, written down. Independent fault domains that are genuinely independent, not three logical zones sharing one control plane. Per-validator, per-day reward accrual you can hand to an accountant. A slashing cover mechanism with the claim process described. Current audit and certification status. Our longer piece on evaluating managed staking and oracle operators covers how buyers weigh these against each other.
None of it is exotic. Most of it is simply written down, which is the part operators skip.
The question worth sitting with: if an issuer published your name in a prospectus next quarter, which of those eight would you have to go and build first?
About LinkPool. We run staking and oracle infrastructure for Web3 protocols and institutional operators on owned hardware across three availability zones in Manchester. Completing ISO 27001 and SOC 2. AAA Staking Rewards rating across Operations, On-Chain, Security, and Maintenance. Zero slashing across our operating history. Contact: [email protected].
Frequently asked questions
What does a staking ETF or ETP issuer require from an infrastructure provider?
A disclosed operating record rather than a yield quote. In practice that means slashing history across the full operating record, uptime evidence with a stated measurement method, the legal entity and jurisdiction holding the hardware, key management architecture that survives audit, per-validator reward reporting suitable for a daily NAV, a slashing cover mechanism with a described claim process, and current audit and certification status. The infrastructure also has to hold a staking ratio the issuer sets, not one the operator prefers.
Why do staking ETPs not stake 100% of their assets?
Because the product has to meet redemptions and exits are not instant. Ethereum exits are queued at the protocol level, so an issuer keeps an unstaked buffer to fund redemptions without waiting on that queue. Morgan Stanley's Ethereum trust intends to stake 50% to 80% of its ether under normal conditions. Solana stake deactivation resolves at an epoch boundary instead, which is why its Solana trust can stake up to 100%.
How much of the staking reward reaches the investor?
In the Morgan Stanley products, roughly 95%. The prospectus provides for custodians and staking providers to deduct a service fee equal to 5% of gross rewards, and Morgan Stanley retains none of the remainder. That 5% is the operational envelope. Everything the operator spends on redundancy, monitoring, reporting and slashing cover has to fit inside it.
Does the staking provider hold the assets?
No. In this structure the asset stays with regulated custodians and the staking provider runs validators without taking custody. The operator's scope is key generation and signing, availability, and reporting. That separation is what makes the operator's uptime and reporting quality the thing being diligenced, rather than its balance sheet.