A custodian advertises a round number, say $120 million of insurance. A chief financial officer may read that as cover attached to their own firm's holdings. Usually it is not: it is the limit of a policy the custodian has bought for itself, and it stands behind every customer whose assets sit under the same arrangement.
Our piece on who actually holds institutional crypto noted in passing that cold-storage cover is aggregated and that exclusions can reach the custodian's own negligence. This piece opens up the mechanics: what the policies behind the marketing pay for, what they leave out, why hot and cold storage are placed differently, and how an advertised limit relates to what any one customer could recover.
Crime and specie: two markets doing different jobs
Digital-asset cover is assembled from two older lines of business. Lockton describes crypto insurance as falling "within the remit of either the crime/fidelity market or the specialist (or 'specie') market". The specie market historically insured fine art, bullion and jewellery, and has since extended to crypto held in cold storage (Lockton, 23 May 2023).
Aon's 2021 paper on crypto capacity explains the specie logic. The coins never leave the blockchain, so what an insurer really covers is access: "It's like cash in a vault; the risk is being unable to retrieve its contents. Insurers cover the keys to the vault." Specie insurers, the paper says, "cover physical loss or physical damage caused by natural named perils, deliberate and dishonest acts, and third-party physical theft."
Hot and cold storage are treated as different risks. Online keys are, in Aon's words, "far more exposed to third party cyber-hacks and wider employee collusion", so hot-wallet cover costs more. Clients "tend to start with a crime policy, given its broader application", and once capacity in the crime market runs out they turn to the specie market for offline assets, where larger limits come at a more competitive rate.
Crypto.com's custody programme shows the split in practice. Trade press reported in February 2026 that Crypto.com Custody Trust Company carries $120 million of cover, developed with Aon and backed by underwriters at Lloyd's: $100 million for assets in cold storage, against physical loss, damage or theft, and $20 million for crime and third-party theft (Beinsure, 1 February 2026). The larger slice sits in cold storage, where Aon says larger limits are available.
What the policies pay for, and what they leave out
Neither product promises that a customer gets its assets back whatever happens, and the exclusions can matter more than the headline limit. Relm Insurance, which is regulated by the Bermuda Monetary Authority, lists among the exclusions found in custody cover "loss of funds due to the custodian's own negligence or failure to follow mandated security procedures, as well as broader exclusions like blockchain-wide failures". A policy with that wording still responds to an outside theft carried out despite sound controls. It does not stand behind the custodian's own lapses.
Retail account protection shows the same pattern at a smaller scale. Bloomberg reported in March 2026 that Coinbase introduced its account protection programme in 2021 with a $1 million cap, and that the original terms excluded losses from "a security vulnerability" in a customer's own computer and from phishing that handed a third party access. The revised programme offers $1,000, $10,000 or $250,000 of cover by monthly subscription, and applies only to an outbound transfer "cryptographically signed exclusively by Coinbase". One customer who lost nearly $100,000 in bitcoin had a claim denied because required security settings had not been switched on (Insurance Journal, via Bloomberg, 30 March 2026). None of this makes the product improper. It makes it a conditional promise rather than an indemnity against every loss, and the two are easily confused when both are marketed as insurance.
An aggregate limit is not a per-customer limit
The larger gap is arithmetic rather than wording. Aon describes cold-storage cover as written on an aggregated basis, so that "any one insured is capped at the market capacity, and once the limit is eroded for one client, it is gone." Read from the customer's side, a single limit bought by the custodian stands behind the whole book at once, and a claim that uses it up leaves nothing for the next loss under that policy.
Scale sharpens the point. In the same paper Aon put available capacity at approximately $700 million, noted that most custodians store "tens of billions of dollars worth of digital assets", and described a cold-storage facility led by the Lloyd's syndicate Canopius offering limits of up to $625 million for any one client. In March 2024 Marsh launched a facility offering digital-asset custodians up to $825 million of cover against natural disasters, third-party theft and internal collusion by employees, for offline storage and for multi-party computation (MPC) set-ups, supported by Lloyd's syndicates and London-market insurers (Reinsurance News, 26 March 2024).
An advertised figure therefore leaves three questions open: whether the limit is per customer or aggregate across the book; what share of assets under custody it represents; and whether any of it has already been eroded by an earlier claim.
Capacity, and how it is placed
Much of the dedicated capacity has been placed in London. Aon wrote that demand for cover "completely surpassed what the London market could provide", and Marsh's facility is backed by Lloyd's and London-market insurers. Aon's $700 million estimate is now five years old; Marsh's facility is a more recent data point, not a measure of the whole market.
What the placement process rewards is set out plainly. Aon calls collusion "the most pressing exposure for cold storage within the specie market", and says a major element of the contract is "a detailed roadmap of the client's operational procedures". Custodians are asked, for example, for the minimum number of individuals needed to generate a fraudulent transaction. A custodian that cannot answer that has a problem larger than its insurance.
Directors and officers cover
A digital-asset firm's directors and officers carry a separate exposure, and brokers say standard forms fit poorly. Lamda Broking says a standard technology-company D&O policy is "usually not" enough for a crypto exchange, citing exposures such as custody of assets, crypto regulation and token sales, and recommends negotiating specialised language. It lists recurring exclusions: regulatory fines and penalties, which it says "are usually excluded by law from insurance"; the value of lost assets, since "D&O won't pay the value of those lost assets", which is a matter for crime or custody cover; and claims brought by one insured against another.
Fullsteam, writing in May 2022, described a virtual currency exclusion aimed at the valuation of the currency and its effect on the business, and said that as of June 2022 it could not be removed from any D&O policy for a blockchain business, because insurers could not reliably quantify exposure to volatility and manipulation. That view is four years old and terms may have moved; the durable point is that D&O in this sector is negotiated clause by clause.
What regulators have said about marketing it
Regulators have addressed crypto marketing in general more than insurance claims in particular. The UK Financial Conduct Authority's statement on common issues with cryptoasset promotions, first published on 25 October 2023 and last updated on 6 February 2026, names three: claims about safety, security or ease of use made without highlighting the risks; risk warnings that are hard to read; and inadequate information on the risks of the specific product promoted. It is not written about insurance, but a headline insurance figure is a claim about safety.
In the United States the relevant move went the other way. On 15 February 2023 the SEC proposed replacing the Advisers Act custody rule with a safeguarding rule that would have extended it to all client assets, crypto included, kept with qualified custodians. It was never adopted: the SEC withdrew it on 12 June 2025 along with thirteen other pending proposals. New York's Department of Financial Services issued guidance on 30 September 2025 requiring BitLicensees and limited purpose trust companies that custody virtual currency to disclose in writing the general terms of their custody arrangements, including sub-custody; it deals with segregation and customer property interests and does not mention insurance. None of the regulatory material we reviewed sets rules for how a custodian may describe its insurance limits.
What stays outside these policies
Smart-contract exploits are not the risk a crime or specie policy is written against, which is the theft or destruction of keys a custodian holds. Our threat model for institutional DeFi covers the Euler, Nomad and Beanstalk exploits, with losses from about $77 million to about $197 million. A separate market has grown in that gap. Nexus Mutual describes itself as "a decentralized insurance alternative" operating as a discretionary mutual whose members assess claims, and Bloomberg reported that it had paid more than $18 million of claims since its 2019 launch, for incidents from smart-contract hacks to the FTX collapse. It is a different instrument from a regulated insurance contract, and should be assessed as one.
Across the sources above, the gaps are consistent: price and valuation risk; losses traced to a customer's own security set-up rather than the custodian's; blockchain-wide failures; and, in the wordings Relm describes, the custodian's own negligence or failure to follow its security procedures. None of that makes the cover worthless. Crime and specie policies move a real, specific risk, theft and collusion against a custodian that follows its own controls, onto an underwriter with the capital to bear it. They are narrower than the marketing suggests, and the capacity behind them is counted in hundreds of millions of dollars.
This is not tax, legal, accounting or investment advice; what a particular policy pays in a particular loss depends on its wording and the facts. For the wider work of assessing a manager, from custody agreements to valuation, see our piece on operational due diligence for digital-asset managers.