Crypto Insurance: What It Covers, What It Doesn't, and the Gaps Institutions Miss
Executive Summary
A custodian deck says “$500M insured” and a diligence box gets ticked. That box is the most over-read figure in the document. By mid-2026 a real insurance market exists for digital assets — Lloyd’s syndicates, Bermuda carriers, and reinsurers like Munich Re now write crime, specie, and bespoke crypto covers[1][2] — but “insured” tells you almost nothing about whether your assets are protected when they are actually lost. Four findings drive this assessment.
The Coverage Map
There is no such thing as a “crypto insurance policy.” There is a program — a tower of separate products, each adapted from a traditional line, each covering one slice of the risk surface[2]. Understanding what protection you actually hold means knowing which product responds to which peril, and — more importantly — where one product stops and the next has not started. Those seams are where claims die. Here is the map.
The two products that carry the asset risk
Crime / fidelity is the backbone. It is a first-party policy covering theft or loss of digital assets through crime — external acts like hacking, fraud, and robbery, and internal acts like employee dishonesty and embezzlement[3][4]. It protects assets in transit and on premises, and it can be endorsed to reach social-engineering scams and ransomware extortion. This is what an exchange or custodian buys to insure against a hot-wallet breach. One technical point decides whether it works at all: the policy’s definition of “money or securities” must be amended to include cryptocurrency. Leave the standard wording in place and an insurer can deny the claim by arguing crypto is not tangible property under a definition written for cash and bearer instruments[4][6].
Specie (vault) is its cold-storage counterpart. Specie is a specialty property cover that traditionally insured gold and fine art; for crypto it covers physical loss, damage, destruction, or theft of the media holding private keys — hardware wallets, paper keys, backup drives — inside a designated secure location[2]. If a fire destroys the vault or an insider smuggles out an encrypted drive, specie responds. The London market has offered $500M-plus limits on specie for crypto custodians[2]. But specie excludes hacking and cyber breaches entirely — it assumes the assets are offline[3]. That is the central seam in every custody program: crime covers the hot wallet, specie covers the cold vault, and the two rarely add up to your holdings or cover the same perils. A loss in the gap between them — say, a compromise during the warm-wallet signing step that moves assets from cold to hot — can fall outside both.
The products that cover costs and liability, not the coins
Cyber insurance covers the costs of a security incident, not the value of what was stolen. It pays for forensics, breach notification, data restoration, legal defense, and business interruption from network outages — but historically it did not reimburse stolen crypto, and many cyber policies carry explicit “digital asset” or “cryptocurrency” exclusions[4][6]. It is still essential: a hack triggers notification duties and forensic work that cyber covers even when the lost coins require a crime claim. Read the wording so that a “financial assets” exclusion does not quietly swallow your crypto exposure.
Technology Errors & Omissions (Tech E&O) / professional liability covers loss caused by a failure of technology or service, not crime. A smart-contract bug that locks up tokens, an internal systems failure that destroys keys, or a custodian mis-executing a client instruction lands here[12]. Slashing insurance — reimbursement for validator penalties on a proof-of-stake network — is usually structured as a Tech E&O subtype and is the cover most directly tied to the key-management architecture we assess in our custody key-management report (2026-002)[1]. Tech E&O is typically claims-made, so it only responds to claims reported during the policy period, and what counts as a covered “wrongful act” in a crypto context needs careful drafting.
Directors & Officers (D&O) protects the personal liability of executives — shareholder suits, regulatory investigations, governance-failure claims. In crypto it is in high demand and hard to obtain; underwriters price the sector as high-risk and a traditional firm’s existing D&O may exclude crypto activity unless endorsed[13]. Some carriers offer a stripped-down “skinny D&O” for private crypto companies to cut cost[12]. Kidnap, ransom & extortion (K&R) addresses the physical-coercion risk that follows people with access to large liquid crypto — there are documented cases of victims forced to transfer Bitcoin under duress[3]. K&R policies maintain strict confidentiality (disclosing that you hold one can void it) and should be drafted to allow a ransom paid in crypto if needed.
The new, thin layer: parametric and on-chain covers
An emerging class pays on a defined trigger rather than proven loss. Stablecoin depeg cover pays if a coin trades below a threshold for a set period — Etherisc’s product pays if USDC sits below $0.95 for more than 24 hours[14], and the Geneva Association’s independent review documents Nexus Mutual’s version paying up to 90% of loss on a >10% depeg, with Nexus holding roughly two-thirds of all on-chain cover by end-2022[15][16]. The same trigger-based model extends to other perils — the Geneva review maps wallet, custodian, and smart-contract covers written by DeFi mutuals through bespoke on-chain contracts[15]. The appeal is speed: no loss adjustment, fast payout. The cost is basis risk — the fixed payout may be more or less than your actual loss — and a legal-recognition question, since some jurisdictions do not treat a parametric trigger as insurance at all[17]. The supervisory view is blunter: DeFi “insurers” sit outside solvency regulation and insurance guarantee funds entirely[15], and the EU authorities’ standing warning to crypto buyers — legal protection, if any, may be limited — applies with full force here[18]. Peer-reviewed insurability research adds the deeper caveat: these pools depend on subjective trigger expectations and decentralized governance in ways traditional reinsurance does not[19]. For a large institution these are a complement to indemnity cover, not a replacement, and the crypto-native pools carry their own counterparty and capacity limits.
The map, in one table
| Product | Peril it covers | Where the assets sit | What it does not cover |
|---|---|---|---|
| Crime / fidelity | Theft, hacking, insider fraud | Hot wallets, transit, on premises | Cold-vault physical loss; needs “money” defined to include crypto |
| Specie (vault) | Physical loss/damage/theft of key media | Cold storage, secure vault | Hacking and cyber breaches — explicitly excluded |
| Cyber | Incident response, BI, notification costs | N/A — covers costs, not coins | The value of stolen crypto (often expressly excluded) |
| Tech E&O / professional | Tech failure, smart-contract bug, slashing, mis-execution | N/A — covers liability/loss from error | Crime; claims-made timing gaps |
| D&O | Executive liability, regulatory defense | N/A | Crypto activity unless endorsed; fines often uninsurable |
| K&R | Coercion, extortion, ransom | Personnel with key access | Loss not involving duress/extortion |
| Parametric / on-chain | Depeg, slashing, hack trigger | Defined on-chain metric | Actual-loss matching (basis risk); legal recognition varies |
Most institutional programs are exactly this — a crime policy as the primary theft layer, specie stacked for cold storage, cyber for data and business interruption, D&O and E&O for management and professional exposure[2]. When we structured digital-asset coverage at scale, the failure mode was never the absence of a policy; it was the gap between two policies that each assumed the other had the loss covered. The next section is about those gaps — and the larger ones the tower cannot close at all.
The Coverage Gaps
The tower in the previous section looks comprehensive on a one-page summary. It is not. The gaps are not evenly distributed, and they are not all the insurer’s fault — several are structural limits of what insurance can do. Here is what most buyers get wrong: they negotiate hard on limit and premium, the two numbers on the quote, and barely read the exclusions and the basis-of-loss clause, where the claim is actually won or lost. Six gaps decide outcomes. They are not equal.
Tier 1 — the gaps that leave you uncovered when it matters most
1. Insolvency and default are not insurable. This is the single largest misconception in institutional crypto risk. Traditional insurance responds to perils — theft, damage, fraud — not to a custodian or counterparty mismanaging client funds into a hole. The FTX and Celsius failures were not insured events and could not have been: no peril was triggered, the money was simply gone[5]. Willis Towers Watson confirms the obvious — products to insure against the insolvency of staking, lending, or custody platforms are being explored, but the providers willing to write them are extremely limited, and the legal mechanics are ugly: if the custodian is bankrupt, a liability policy that would pay its clients can itself become an asset of the bankruptcy estate, contested before you ever recover[5]. What this means operationally: never let “our custodian is insured” stand in for “our assets survive our custodian’s failure.” The mitigation for default risk is legal structure — bankruptcy-remote segregation that keeps client assets out of the estate — not an insurance line item. We assess that structure in detail in our institutional custody report (2026-004); insurance is the wrong tool for that job and buying more of it does not make it the right one[11].
2. The exclusions gut the cover exactly where crypto losses happen. Every policy carries exclusions, and crypto policies inherit the traditional ones while adding new carve-outs for risks insurers will not take[6]. Four of them matter disproportionately because they sit on top of the most common loss vectors:
- Social engineering / authorized transfer. Most crime policies exclude loss when an employee is tricked into voluntarily sending assets, because the transfer was authorized — even under false pretenses. This is the notorious gap, and it is also the most common way crypto actually leaves an institution, because so many hacks begin as phishing and crypto transfers are irreversible. It is coverable only by a specific social-engineering endorsement, usually sub-limited, often conditioned on call-back controls you must prove you maintained[6][4].
- Key-security negligence. Insurers sometimes add open-ended “failure to maintain security protocols” exclusions that let them deny a claim after the fact by pointing to any lapse — an unpatched server, a key briefly on an unsecured device. A vague negligence exclusion can swallow the entire point of insurance, which is to cover mistakes. Push to replace it with specific, testable warranties[6].
- State-backed cyberattacks. War and terrorism exclusions are standard, and the cyber market has been tightening the treatment of nation-state attacks. When a state-linked group — Lazarus is the recurring example — steals crypto, an insurer may try to classify it as cyber-war and decline. The line between “criminal hack from a certain country” and “act of war” is unsettled, and it sits directly over the largest exchange losses on record[4].
- Regulatory seizure and fines. Loss from government confiscation, asset freezes, or nationalization is excluded — it is legal authority, not theft. And regulatory fines for AML or securities breaches are almost always excluded under D&O and are uninsurable by law in many places; you may get defense costs, but you eat the penalty[6].
3. Capacity is the ceiling, and the limit is shared. The pool is shallow and has stayed shallow: brokers estimated roughly $3B of global crypto capacity — plus or minus a billion — in 2021[7]; Marsh McLennan put insured crypto at under 1% of a trillion-dollar market in 2022[8]; and by 2025, AM Best-linked commentary still counted only about 11% of crypto holders carrying any cover against a $3.31T asset base[20]. The largest dedicated custody facility on record, placed by Marsh in 2024, provides up to $825M[9] — and even that is a subscription tower assembled across many underwriters, each convinced separately, with capacity contracting sharply after any major loss event[2][5]. The certificate’s limit is an aggregate across all of the custodian’s clients, not your personal guarantee: measured against tens of billions under custody, the tower is a fraction of the book, and your recovery is a pro-rata claim on whatever remains.
Tier 2 — the gaps that produce disputes and surprises
4. Valuation and basis of loss is unsettled. When stolen crypto is reimbursed, at what price? The time of loss, the time of discovery, the time of claim settlement, and a 30-day average can differ by multiples in a volatile asset. Policies that do not pin the valuation basis precisely invite a dispute at exactly the moment you need certainty. Parametric covers trade this for basis risk: a depeg or slashing trigger pays a fixed sum that may not match your actual loss, and in a redemption you could conceivably collect even after recovering at full value — a mismatch regulators watch closely[17][14].
5. The same program books differently across markets — and capacity lives in two places. The bulk of large-tower capacity sits in Lloyd’s of London and Bermuda; the US domestic market is thin and most US risk is exported to London via surplus lines[2]. MiCA changes the demand side in Europe by making custodians liable for client-asset loss under Article 75, which is pushing European carriers and brokers toward MiCA-specific liability products[21][11]. The supply side is hardening in parallel: EIOPA has advised the European Commission to apply a one-to-one capital charge to any crypto asset an EU (re)insurer holds on its own balance sheet — a clear signal of how European prudential supervisors price the asset class, even as MiCA pushes custody-liability demand toward the same carriers[22]. The consequence for a global institution: coverage, wording, and even the availability of a given cover vary by booking entity and domicile, and a program placed for your London entity may not map cleanly onto your Singapore or Frankfurt operations. The travel-rule and sanctions-screening obligations that sit underneath all of this are themselves a moving target under FATF Recommendation 16[23].
Tier 3 — real, but bounded
6. DeFi and parametric covers are immature, not absent. Smart-contract exploit cover exists — Munich Re writes a Smart Contract Risk product, and DeFi mutuals like Nexus Mutual cover risks commercial insurers will not — but capacity is thin, limits are low, premiums are high for lack of loss data, and known-vulnerability exclusions are standard[1][16]. For a large institution these are a supplement for a specific niche, not a foundation, and the crypto-native pools introduce their own counterparty and token-dependency risk. This is a genuine gap, but a bounded one: it affects a defined slice of DeFi exposure, and the mitigation — code audits, conservative protocol selection, modest reliance — is executable.
The weighting, in one table
| # | Gap | Tier | Why it bites | Can insurance close it? |
|---|---|---|---|---|
| 1 | Insolvency / default not insurable | 1 | Largest losses (FTX, Celsius) are credit risk, not a peril | No — needs legal structure, not a policy |
| 2 | Exclusions over common loss vectors | 1 | Authorized-transfer fraud, key negligence, state-backed hacks carved out | Partially — only via bought-back endorsements |
| 3 | Capacity ceiling / shared aggregate | 1 | Broker-estimated ~$3B pool vs. trillions at risk; limit split across all clients | No — structural market limit |
| 4 | Valuation / basis of loss | 2 | Which price, which date; parametric basis risk | Partially — pin the wording precisely |
| 5 | Cross-market / jurisdiction divergence | 2 | Capacity and wording vary by domicile and booking entity | Partially — place per entity |
| 6 | DeFi / parametric immaturity | 3 | Thin capacity, high price, known-vuln exclusions | Largely — bounded, supplement only |
Negotiate the table in order, top row first. A generous limit and a competitive premium do not compensate for an un-bought-back social-engineering exclusion or a custody arrangement that fails the bankruptcy-remoteness test. The gray zone here is real: as of mid-2026 the market has no settled answer for insolvency cover, no consensus on state-backed-attack wording, and no depth of capacity against a systemic event. Buy what the market offers, close the exclusion gaps you can, and treat the rest as a risk you manage with structure and diversification — because the insurer will not.
The Buyer’s Playbook
The gaps in the previous section are not reasons to skip insurance. They are reasons to buy it deliberately, verify it against the wording, and never let it stand alone. This is the playbook — for the team placing the cover and the board overseeing them.
Procurement: read the wording, not the certificate
A certificate of insurance is a marketing artifact. It states a limit and a carrier; it tells you nothing about whether your loss is covered[10]. Demand the full policy wording for every layer in the tower, and put three questions to it:
- Which perils, hot versus cold? Confirm crime covers your hot-wallet and transit exposure and that the “money/securities” definition has been amended to include crypto — without that endorsement the whole crime layer is contestable[4]. Confirm specie covers your cold storage and understand that it stops at the cyber boundary[3]. Map the seam between them against your own warm-wallet signing flow.
- What do the exclusions carve out? Find the social-engineering exclusion and buy it back, because authorized-transfer fraud is your most probable loss[6]. Replace any open-ended “failure to maintain security” exclusion with specific warranties you can actually meet. Get clarity on state-backed-attack treatment in writing. Confirm D&O at least covers regulatory defense costs.
- What limit applies to your assets? Establish that the headline number is an aggregate shared across all of the custodian’s clients, then estimate your recoverable share after the aggregate is consumed and the deductible is met[10]. A $500M tower behind tens of billions in assets under custody is not $500M of protection for you.
Build the tower with a specialist, per booking entity
Only a handful of global brokers run dedicated digital-asset desks — Aon, Marsh, WTW, Howden, and a few boutiques — and they hold the relationships with the few underwriters who write crypto[3]. Treat broker selection like hiring a professional-services firm: ask how many crypto programs they have placed, with which carriers, and whether they have handled a crypto claim — claims advocacy in novel coverage matters more than placement. Because capacity lives mainly in Lloyd’s and Bermuda and wording diverges by domicile, place and review the program per booking entity, not once for the group[2][21]. A cover that responds for your London entity may not exist, or may read differently, for your Singapore or Frankfurt operation — and under MiCA Article 75 the liability picture for your EU entity is its own analysis[11].
Earn the pricing credits before you negotiate the price
Crypto insurance is rated on controls, and the data pack you bring to underwriting moves the rate materially. Hot-wallet percentage is among the largest rating factors: a hot-heavy risk quotes at a multiple of a mostly-cold book. That tracks the market’s structure — crime cover for hot wallets has always been the scarcer, costlier layer, while cold-storage specie is where the largest limits sit[2]. Insurers credit demonstrable controls: a SOC 1 / SOC 2 report, documented key-ceremony and quorum procedures, withdrawal-funding discipline, and the key-management architecture itself — MPC, multisig, HSM — which determines whether crime and Tech E&O respond and which we assess in our key-management report (2026-002). Bring the evidence, not the brochure. The discipline that earns the insurance credit is the same discipline that prevents the loss; underwriting is just the external audit that prices it.
Govern it as one layer, not the answer
Three things belong on the board’s agenda, not just the treasury team’s:
- Control mapping. Maintain an explicit map from each material risk to the policy that covers it — and flag every risk that no policy covers, so the gap is a decision, not an accident. Insolvency, market depeg, and regulatory fines belong in the “uninsured by design” column.
- The structural backstop. For the largest exposures — custodian default and client-asset loss — the protection is legal structure, not insurance: bankruptcy-remote segregation that keeps assets out of the estate, assessed against the standards in MiCA, NYDFS guidance, and the MAS framework. We cover that diligence in full in our institutional custody report (2026-004)[11]. Insurance is the backstop for theft and error inside a sound structure, never a substitute for the structure.
- Skin in the game as a signal. A captive can both add a layer and signal commitment — Gemini’s “Nakamoto” captive, built with Marsh, gave the market evidence the firm was serious about its own risk and reportedly made commercial layers easier to place[24]. For a large institution a captive or alternative risk-transfer vehicle is worth evaluating where commercial capacity is thin, but it is a sophistication play, not a starting point.
The verification checklist
Before signing off that a custodian or your own program is “insured,” confirm:
- Full policy wording obtained for every layer — not a certificate.
- Crime “money/securities” definition amended to include digital assets.
- Hot/cold perils mapped with the seam between crime and specie understood.
- Social-engineering exclusion bought back; no open-ended negligence exclusion.
- State-backed-attack and regulatory-seizure treatment confirmed in writing.
- Per-client recoverable share estimated against assets under custody, net of deductible.
- Program placed and reviewed per booking entity.
- Uninsured-by-design risks (insolvency, depeg, fines) logged and accepted by the board.
- Legal segregation opinion in place — the structural backstop insurance cannot replace.
Board members should be asking one question in every digital-asset insurance review: if our worst loss happened tomorrow, which clause pays, and how much reaches our clients after everyone else has claimed? If the team cannot answer from the wording in the room, the program has not been bought — it has been ticked.
Report Overview
Published Date
12 Jun 2026
Reading Time
24 mins
Downloads
0
About Author
Yirifi Admin
Published reports
6
Related Reports
No related reports found.