How to Insure Large Crypto Holdings
- TheCryptoNicole
- 1 day ago
- 12 min read
Digital asset portfolios have grown to a size where loss is no longer a theoretical concern for many holders. A high net worth individual or family office with meaningful exposure to bitcoin, ether, or other digital assets faces a genuine question: what happens if a private key is compromised, a custodian is breached, or a smart contract is exploited. For most other asset classes, insurance answers that question. For crypto, the answer is more complicated.
This guide explains why conventional insurance policies generally exclude digital assets, what specialty coverage actually exists today, how underwriters evaluate risk, and what a family office or high net worth individual should do to put a coverage program in place. The crypto insurance market remains small relative to the assets it is meant to protect, and terms vary considerably by provider. Nothing in this article should be treated as a substitute for advice from a licensed insurance broker or attorney who can review a specific policy and jurisdiction.
Why Homeowners and Umbrella Policies Do Not Cover Crypto
Most standard homeowners and personal umbrella policies were written decades before cryptocurrency existed, and insurers have consistently declined to extend them to digital assets. There are two structural reasons for this.
First, standard homeowners policies typically require a "direct physical loss" to trigger coverage for stolen property, and courts have found that stolen cryptocurrency does not meet that standard because there is nothing physical to lose. In *Sedaghatpour v. Lemonade Insurance Company*, the Fourth Circuit Court of Appeals held that a homeowners policy did not cover the theft of $170,000 in cryptocurrency, reinforcing that "physical loss" language does not extend to a stolen private key or an unauthorized on-chain transfer (National Law Review).
Second, even where a homeowners policy does mention "money" or "currency," it typically caps that category at a low sub-limit, often $200 to $1,000, far below what any meaningful crypto holding would require (Maryland Insurance Administration). Personal umbrella policies generally follow the same exclusions, so they do not fill this gap either.
Anyone holding a large crypto position on the assumption that it falls under existing property or umbrella coverage is very likely uninsured. A digital asset security review is a useful first step to confirm what is and is not protected before assuming any coverage exists.
The Current State of the Specialty Crypto Insurance Market
A specialty market has developed over the past several years to address this gap, anchored heavily in the Lloyd's of London market. Lloyd's syndicates have become the primary institutional capacity behind most crypto insurance products sold today, working through coverholders and brokers who structure policies for custodians, exchanges, and, increasingly, direct holders (CII, Insurance Institute of London).
Several named providers illustrate the shape of the market as it stands today. Terms, limits, and availability change frequently, so figures below should be confirmed directly with a broker rather than relied on as current pricing.
Evertas describes itself as the only cryptoasset insurer selected by Lloyd's as a listed coverholder in its official marketplace, with capacity to insure individual cold storage wallets at limits reported in the hundreds of millions of dollars, underwritten through Lloyd's and other insurers such as Arch (Evertas).
Coincover offers consumer-facing and institutional products underwritten by Lloyd's syndicates including Atrium, TMK, and Markel, combining theft-prevention monitoring with an insurance component (Spark).
Marsh, the insurance broker, announced in March 2024 an $825 million capacity facility backed by Lloyd's syndicates specifically for cold storage and MPC-based custody, signaling how much market capacity is now built around segregated custody models (Spark).
Custodians such as BitGo and exchanges such as Bitstamp have separately reported large crime policies through Lloyd's and other carriers covering assets held online and offline.
These programs generally fall into several recognizable categories.
Crime and Theft Insurance for Custodians
This is the most established form of crypto insurance and covers a custodian's assets against theft resulting from hacking, employee dishonesty (fidelity coverage), and other criminal acts. It is typically purchased by the custodian or exchange itself, not the end client, and the client's assets are covered only to the extent they sit within the custodian's insured infrastructure and program limits.
Specie and Cold Storage Insurance
Specie insurance is a category historically used for physical valuables such as bullion and fine art, adapted for cryptographic private keys held in cold storage (offline, air-gapped devices or vaults). It insures against physical loss, destruction, or theft of the key material itself, often with per-wallet or per-vault limits.
Hot Wallet Coverage
Hot wallets, connected to the internet for operational liquidity, carry materially higher risk than cold storage and are priced and underwritten differently. Coverage focuses on unauthorized access, hacking, and system intrusion, and insurers typically cap the proportion of a custodian's total holdings that can sit in hot wallets under a given policy.
Smart Contract and DeFi Coverage
Coverage for losses from bugs or exploits in smart contract code is a distinct and less mature line, discussed further below. Traditional custody crime policies generally exclude this exposure outright.
Directors and Officers Coverage for Crypto Businesses
For entities in the digital asset space, whether a fund, exchange, or infrastructure company, D&O coverage protects leadership against claims arising from business decisions and has become important for capital raising. Corgi launched a dedicated Digital Assets Coverage Endorsement for D&O in 2026 to address the gap left by standard policies, which typically carry blanket digital asset exclusions (PR Newswire). Reporting on the sector notes premium costs for exchange hack and custody coverage rose materially year over year through early 2025, reflecting tighter underwriting capacity and rising claims frequency (Founder Shield).
Self-Custody Versus Custodian-Held Assets: A Different Insurance Problem
This distinction is the single most important variable in how a large holder approaches coverage.
Custodian-held assets benefit from whatever institutional crime, specie, or crime-and-fidelity policy the custodian itself carries. A client's assets are covered only as a slice of the custodian's aggregate program, subject to the custodian's own limits, deductibles, and exclusions. A large holder should ask any custodian for the actual certificate of insurance, the aggregate versus per-client limit structure, and confirmation of what portion of assets held is in cold versus hot storage, since most policies cap hot wallet exposure. This is a natural area to compare against MPC vs multisig custody approaches, since custody architecture directly shapes what a custodian's insurer will underwrite.
Self-custodied assets are much harder to insure. With no institutional custodian standing behind the assets, an insurer has to evaluate the individual's or family office's own key management practices directly: how many signers are required, where key shares are geographically distributed, what hardware is used, and what operational procedures govern signing. Coverage exists here but is narrower, more expensive relative to sums insured, and more dependent on demonstrable security architecture, such as a properly implemented multisig wallet for family offices or an MPC-based signing scheme. Many self-custody policies explicitly exclude loss from the policyholder's own key mismanagement, covered further below.
Typical Policy Exclusions and Limitations
Every crypto insurance policy needs to be read carefully, since exclusions in this market are both more numerous and less standardized than in traditional lines. The following are recurring themes across the specialty market, though exact wording varies by carrier and must be confirmed on the specific policy.
Private key loss due to user error. If a private key or seed phrase is lost, misplaced, or given away by the holder rather than stolen through a network breach, most policies treat the resulting transaction as authorized and therefore uninsured. Insurers generally view this as analogous to voluntarily handing over the combination to a safe rather than the safe being broken into (Founder Shield).
War and nation-state exclusions. Standard war exclusion language, often reading close to "loss arising out of war, invasion, act of foreign enemy, hostilities, or warlike operations," has in some policies been extended to cover cyber operations attributable to nation-states. This matters in crypto because a large share of major thefts are attributed to state-linked actors. Industry analysis has noted that North Korea-linked actors were responsible for roughly $2 billion of the estimated $2.72 billion in total crypto theft in 2025, meaning a broadly worded war exclusion could in principle void coverage for a large share of real-world losses (CryptoNewsBytes).
Smart contract and protocol-level exploits. Standard custody crime and specie policies generally exclude losses arising from bugs, exploits, or governance failures at the smart contract or protocol level. This exposure sits in a separate, less mature market segment covered below.
Market volatility. Price declines are never an insurable event under any crypto policy. Coverage responds to theft, loss of custody, or a defined operational failure, not to the asset losing value.
Regulatory seizure and certain sanctions exposure. Some policies exclude losses arising from lawful government seizure or from transactions involving sanctioned addresses or jurisdictions.
Given this list, a large holder should assume that any single policy covers a narrower slice of total risk than the headline limit suggests, and should map exclusions against their specific custody architecture and threat model before treating a policy as comprehensive protection.
How Underwriters Assess Risk for Large Holdings
Underwriting a large crypto position is closer to underwriting a bank vault than a homeowner's jewelry. Insurers and brokers active in this market look at several factors before quoting terms.
Custody architecture. Whether assets sit with a regulated qualified custodian, in self-custody, or in a hybrid arrangement fundamentally changes the risk profile and the products available. Custodians offering multisig, MPC, and audited cold storage give insurers concrete technical controls to underwrite against, rather than having to trust a single point of failure (Lockton).
Cold versus hot storage ratio. The proportion of assets kept offline versus in internet-connected wallets is one of the first questions any underwriter asks, and policies frequently cap the insurable hot wallet percentage or price it at a significantly higher rate.
Multisig and MPC usage. Distributed signing schemes requiring multiple independent approvals, ideally across separated geography and personnel, materially reduce the single point of compromise that most large thefts exploit. Insurers treat the presence of these controls, including address whitelisting and mandatory human review for large transfers, as core underwriting criteria.
Audit and incident history. Documented penetration testing, independent audits, and a clean or well-handled incident history factor into both eligibility and pricing. A prior breach does not automatically disqualify a holder, but it will shape terms and may require remediation evidence.
Governance and operational controls. For a family office, this extends to who can initiate a transaction, what dual-approval process exists, how key holders are vetted, and the disaster recovery plan if a key holder becomes unavailable or compromised.
A formal review of custody architecture and operational controls before approaching a broker tends to improve both eligibility and pricing.
The Claims Process: Why Crypto Claims Are Harder
Even with a policy in place, filing and settling a crypto insurance claim differs from a conventional claim in several ways.
Valuation timing. Policies are typically denominated and settled in fiat currency, but the underlying asset can move sharply between the date of loss and the date of settlement. Determining the reference price and timing for valuation is a recurring source of dispute.
Attribution and forensic evidence. Insurers generally require blockchain transaction logs, chain analysis reports, proof of wallet ownership, and a detailed incident response record showing how the loss occurred and what controls failed or held. Because wallet addresses are pseudonymous, establishing that a specific loss actually happened to the insured party requires more forensic work than a conventional theft claim.
Lack of standardized practice. Because the market is young, there is less settled precedent for how claims are adjudicated, which can lead to prolonged disputes over whether a loss falls inside or outside an exclusion, particularly around attributing an attack to an excluded cause such as a nation-state actor rather than a covered custody failure.
Family offices should plan for this by maintaining rigorous internal logging of custody operations, retaining forensic and legal counsel relationships in advance, and expecting a crypto claim to take longer and require more documentation than a comparable claim on a conventional asset.
Decentralized and Parametric Insurance Alternatives
Outside the traditional insurance market, a set of DeFi-native protocols has developed to offer coverage against smart contract risk directly on-chain. These are worth understanding, though they remain a materially less mature and lower-capacity alternative to regulated insurance.
Nexus Mutual is the largest and longest-running protocol in this category, operating as a member-owned mutual on Ethereum where participants stake tokens to underwrite risk and vote on claims. Since its 2019 launch it reports having protected several billion dollars in digital assets cumulatively, and it now offers both single-protocol smart contract cover and a bundled multi-protocol product (Gemini Cryptopedia; University of Mitosis).
Parametric models, designed to trigger automatic payouts when a predefined on-chain event occurs rather than going through manual claims assessment, have had a harder time gaining traction. Neptune Mutual, a parametric-model DeFi insurer, announced in 2024 that it was winding down operations, citing insufficient growth across the DeFi insurance sector as a whole (OpenCover).
For a family office or HNW holder, decentralized cover is best understood as a niche, supplementary layer for specific DeFi protocol exposure rather than a substitute for a licensed insurance policy on core holdings. Capacity is limited, the regulatory status of these products varies by jurisdiction, and claims are assessed by token-holder vote rather than a licensed claims process, which carries its own governance risk.
Practical Guidance for Family Offices and HNW Individuals
Approaching this market in an organized way materially improves both the availability and the terms of coverage.
Document custody architecture before approaching a broker. Insurers want to see, in writing, exactly how assets are held: custodian names and account structures, self-custody wallet architecture, multisig or MPC configuration, key holder identities and geographic distribution, and prior third-party audit reports.
Work with a specialty broker, not a generalist. Crypto insurance placement is a specialized skill, and the number of brokers with genuine relationships across the relevant Lloyd's syndicates and crypto-native carriers is still relatively small. A specialty broker will know current market appetite and how to structure a submission that avoids unnecessary exclusions.
Layer coverage rather than relying on a single policy. Given the exclusions common to this market, most sophisticated holders combine custodian-level crime insurance for assets held with a qualified custodian, a separate specie or self-custody policy for assets held directly, and D&O or E&O coverage if holdings sit inside an operating entity or fund. No single policy today is likely to cover the full range of realistic loss scenarios.
Reassess coverage as holdings and architecture change. Pricing and capacity shift as the market matures, and a change in custody structure directly affects underwriting, so coverage should be reviewed at least annually rather than treated as a set-and-forget purchase.
Get an independent security review before seeking coverage. Underwriters respond favorably to documented controls. A structured digital asset security review ahead of a submission can identify gaps that would otherwise mean higher premiums, lower limits, or additional exclusions.
This is best treated as a multi-step process involving both a security assessment and a licensed broker relationship, rather than a single purchase decision. To work through custody architecture and coverage strategy together, schedule a consultation with our team.
Conclusion
Insurance for crypto holdings has moved from a niche experiment to a functioning, if still limited, specialty market, anchored largely in the Lloyd's of London syndicate structure and a small number of crypto-native underwriters and coverholders. Coverage exists for custody-related theft, cold storage loss, and, in the case of institutional entities, D&O exposure. It does not exist, in any meaningful way, for the categories most holders assume are covered by default: homeowners policies, general umbrella coverage, private key mismanagement, or losses tied to war or nation-state attribution.
For a family office or high net worth individual with a large position, the practical path forward is to separate custody strategy from insurance strategy and address both deliberately. That means understanding exactly what a custodian's existing insurance program actually covers, hardening self-custody arrangements with multisig or MPC controls that make coverage obtainable in the first place, and working with a broker who can place layered coverage across the gaps that any single policy will leave. Terms in this market change quickly, so every figure and provider named in this article should be confirmed directly with a licensed broker before any coverage decision is made.
Frequently Asked Questions
Does my regular homeowners insurance cover stolen cryptocurrency? No. Standard homeowners policies typically require a direct physical loss to trigger coverage, and courts, including the Fourth Circuit in *Sedaghatpour v. Lemonade Insurance Company*, have found that stolen crypto does not meet that standard. Even where a policy references money or currency, sub-limits are typically capped at $200 to $1,000, far below any meaningful holding.
What is the difference between crime insurance and specie insurance for crypto? Crime insurance generally covers theft resulting from hacking, unauthorized access, or employee dishonesty, and is typically purchased by custodians and exchanges. Specie insurance is adapted from coverage historically used for physical valuables and applies to private key material held in cold, offline storage, often with per-wallet or per-vault limits.
Can I insure crypto that I hold myself instead of through an exchange or custodian? Yes, but self-custody coverage is narrower, harder to obtain, and typically more expensive relative to the sum insured than custodian-based coverage. Underwriters will scrutinize your specific key management setup, including whether you use multisig or MPC, before quoting terms, and most policies exclude losses caused by your own key mismanagement.
Will insurance cover losses from a DeFi smart contract hack? Traditional custody crime and specie policies generally exclude smart contract exploits outright. Coverage for this exposure exists mainly through decentralized protocols such as Nexus Mutual, which remain smaller in capacity and operate through a member-vote claims process rather than a licensed insurer's claims department.
Why do some crypto policies exclude nation-state attacks? Most policies carry a standard war exclusion that has, in some cases, been extended to cyber operations attributed to a foreign state. This matters because a large share of major crypto thefts, including a significant portion of 2025's total losses, has been attributed to state-linked actors, meaning a broadly worded exclusion could deny coverage for some of the largest and most common loss scenarios in the market.
How much does crypto insurance typically cost? Pricing varies by custody architecture, asset type, cold-to-hot storage ratio, and claims history, and has trended upward, with reporting noting year-over-year premium increases in the exchange-hack and custody coverage segment as underwriting capacity has tightened. Because pricing is quoted per submission, current rates should be obtained directly from a specialty broker.
What documentation do I need before approaching an insurance broker? Expect to provide a detailed description of your custody architecture, including custodian account structures or self-custody wallet configuration, multisig or MPC setup and key holder distribution, any prior security audits or penetration test reports, incident history, and internal governance policies around transaction approval.

Comments