Crypto custody insurance usually protects a defined insured entity against specified loss events under stated custody and key-control conditions. It is not a blanket guarantee of every client balance. Buyers must verify the insured legal entity, covered wallets and keys, aggregate and per-event limits, exclusions, deductibles, claim process and how proceeds would reach clients.
Short Answer
Crypto custody insurance is a contract with defined insured parties, covered property, causes of loss, custody configurations, limits and exclusions. It should never be summarized as "all client assets are insured."
A headline limit can be meaningful, but only after the buyer confirms:
- the legal entity named in the custody agreement is insured
- the proposed wallet and key arrangement is covered
- the relevant loss event falls within the policy
- aggregate and per-event limits are understood
- exclusions, deductibles and claims procedures are acceptable
- the route from insurer payment to client recovery is documented
Insurance is one control in a custody program. It does not replace regulated status, asset segregation, secure key management, transaction governance, recovery testing or contractual rights.
What Custody Insurance May Cover
Public descriptions of institutional custody policies commonly refer to events such as theft or copying of private keys, dishonest acts by employees, or loss and destruction of keys. Coverage differs materially by policy and custody configuration.
BitGo, for example, publicly states that its policy applies to digital assets where its regulated custody entity maintains all keys. Its published insurance FAQ also distinguishes covered custody wallets from arrangements where the client or another party controls some keys. That illustrates why the architecture matters as much as the advertised amount.
| Question | Why it matters |
|---|---|
| Who is the insured? | The brand, custodian, affiliate and contracting entity may not be identical |
| Which wallets qualify? | Cold, hot, MPC, multisignature and delegated arrangements may receive different treatment |
| Which events are covered? | External theft, insider acts, key loss and operational errors are distinct risks |
| What is the limit? | Aggregate, per-event and sublimits determine the amount potentially available |
| Who shares the limit? | One policy may serve many customers and a portfolio of assets |
| What is excluded? | Client-controlled keys, protocol failures, fraud, war, sanctions or cyber events may be treated differently |
| Who pays the deductible? | The commercial effect changes if a customer bears deductibles or coinsurance |
| Who receives proceeds? | The claim and allocation process should connect policy payment to client recovery |
What It Usually Does Not Prove
The existence of insurance does not by itself prove that:
- every customer asset is covered at full value
- market, credit, protocol or smart-contract losses are covered
- an exchange or counterparty failure is covered
- a client's own compromised credentials are covered
- recovery will be immediate
- client assets are legally segregated or bankruptcy-remote
- every asset, chain, staking activity or DeFi interaction is within scope
Those questions require the custody agreement, policy evidence, legal analysis and operational diligence. Product marketing is not enough.
Custody Insurance Due-Diligence Checklist
Policy and entity scope
- Name every insured entity and compare the list with the proposed contracting entity.
- Confirm the policy period and renewal status.
- Identify the insurer or syndicate and obtain broker confirmation where appropriate.
- Determine whether coverage is first-party property, crime, cyber, errors and omissions or another form.
Wallet and key conditions
- Map which party controls every key share, device, credential and recovery path.
- Confirm whether cold, warm and hot wallets receive the same coverage.
- Ask how MPC, multisignature and sub-custody arrangements are treated.
- Verify whether staking, governance, bridging, DeFi or unsupported protocols change coverage.
Limits and exclusions
- Record aggregate, per-event and customer-specific limits or sublimits.
- Identify deductibles, coinsurance and self-insured portions.
- Review exclusions for employee conduct, social engineering, client error, protocol failure and sanctions.
- Model a loss larger than the available limit and document the residual exposure.
Claims and client recovery
- Ask who submits and controls a claim.
- Determine what evidence is required and how quickly an incident must be reported.
- Confirm how proceeds are allocated among affected customers.
- Review whether the customer has direct rights or relies on the custodian's obligations.
Compare Insurance With the Custody Agreement
Insurance evidence and the custody agreement should tell the same operational story. If the policy depends on the custodian holding every key, but the proposed solution gives the customer a key share, the headline coverage may not apply. If the contracting entity is in one jurisdiction while the insurance schedule names another, the buyer needs a written explanation.
Also test the incident process. Ask the custodian to walk through detection, account restriction, evidence preservation, notification, forensic work, claim submission, customer communication and restoration. A policy cannot compensate for an incident that the organization cannot identify or document.
A Better Custody Scorecard
| Area | Evidence |
|---|---|
| Legal model | Contracting entity, regulated status, asset ownership and segregation terms |
| Key architecture | Signing, quorum, recovery, privileged access and configuration ownership |
| Transaction governance | Roles, allowlists, limits, policy changes and emergency procedures |
| Operational resilience | Service levels, incident history, disaster recovery and tested continuity |
| Insurance | Current scope, limits, exclusions, deductibles and claim allocation |
| Exit | Asset withdrawal, record export, key or wallet migration and support obligations |
Insurance should influence the shortlist, but it should not dominate it. A well-insured design with weak withdrawal controls can still fail. A strong custody architecture with limited coverage leaves a different residual risk that may need separate mitigation.
Procurement Recommendation
Ask each finalist to describe three scenarios: external theft, insider misuse and loss caused by the customer's own compromised credentials. Require the vendor to identify which controls respond, whether insurance could apply and which losses remain with the customer. Put the answer into the risk register and contract negotiation.
Compare institutional crypto custody providers alongside security audit companies and compliance infrastructure providers. Verify every material claim directly with the provider and qualified advisers.
Primary and Authoritative Sources
- BitGo digital asset insurance
- BitGo insurance FAQs
- BitGo custody service agreement example
- NIST key management guidance
FAQ
Are all assets held by a crypto custodian insured?
Not necessarily. Coverage may depend on the contracting entity, wallet type, location, whether the custodian controls every key and the cause of loss. Verify the current policy and agreement.
Does custody insurance cover market losses?
Custody insurance generally addresses specified loss events, not price declines, poor investment performance or a stablecoin depeg. Exact policy terms control.
What is an aggregate insurance limit?
It is the maximum the insurer may pay across covered claims during the policy period. A large headline limit may be shared across many customers and wallets.
Does insurance replace custody controls?
No. Buyers still need key governance, transaction policy, segregation, recovery, access controls, monitoring, incident response and an enforceable custody agreement.
What evidence should a custodian provide?
Request a current certificate or broker confirmation, insured-entity and wallet scope, limits, exclusions, deductibles, claims procedure and explanation of how proceeds are allocated.
Are self-custody wallets covered?
Some specialist products may exist, but a custodian's policy may exclude wallets where a client or third party controls part of the key architecture. Confirm the exact configuration.
What is excess specie insurance?
It is additional coverage that may be arranged above a base custody policy, subject to separate underwriting, terms, exclusions and cost.
Where can institutions compare custodians?
FluidRWA's custody directory organizes institutional custodians and wallet providers for further diligence.
Compare custody providers beyond the headline
Review regulated entities, custody architecture, recovery, insurance scope and operational controls before shortlisting.