Skip to main content
znobia

Digital-asset Crime / Specie / Custody / Staking

Custodial loss, hot-wallet compromise, smart-contract logic failure, validator slashing — five distinct perils with different binders.

Cover for the operational base of digital-asset operations is not a single binder. It is a class taxonomy in which each peril responds under its own Insuring Clause, its own exclusions, and — in some structures — its own carrier. The most common buyer error is to assume that “crypto cover” placed against one peril will respond to another. It does not.

Perils

How cover responds — peril by peril.

01

Hot-wallet compromise

Insuring clause ·Cover responds to the unrecoverable loss of cryptographic key material from a Listed Wallet by reason of one of the Insured Events enumerated in the binder — unauthorised external actor, internal collusion, certain forms of social engineering, specified malware classes.

Exclusions ·Cover excludes loss arising from a smart-contract logic flaw in any contract not enumerated on a separate Listed Contract Schedule, where one is in force.

02

Cold-storage compromise

Insuring clause ·Cover responds to physical loss, mysterious disappearance, or unauthorised access to Specie cold-storage media — hardware wallets, paper backups, HSM-protected key material in named cold facilities — per Specie-class wording.

Exclusions ·Cover excludes any peril originating from a hot path, key material on internet-connected systems, or contract-logic events.

03

Smart-contract logic failure

Insuring clause ·Cover responds (where placed) to unrecoverable loss of digital assets from a Listed Contract caused by a logic defect in the Listed Contract or its dependencies, subject to disclosure of the audit history and the Listed Contract Schedule. This is its own binder, frequently placed on a separate Cyber-class structure.

Exclusions ·Cover excludes loss caused by key compromise (which belongs on the hot-wallet wording), market-value fluctuation, and any economic-attack vectors expressly excluded on the wording.

04

Validator slashing

Insuring clause ·Cover responds (where placed) to defined slashing events against staked digital assets where the staking activity is conducted from a Listed Validator under documented operational controls. We read each placement against the specific protocol’s slashing conditions before binding.

Exclusions ·Wording remains immature relative to hot-wallet and Specie cover; exclusions vary materially by carrier and by protocol, and are read line-by-line at submission.

05

Insider fraud / internal collusion

Insuring clause ·Cover responds to dishonest acts of named employees and, on certain wordings, contractors with documented system access. Frequently sits at the Crime / Specie boundary and may dovetail with cyber.

Exclusions ·Insider events that begin with credential theft from a non-employee may fall outside the Crime wording and require a separate cyber response.

Fig 01

Custody perils · taxonomy

Custody perils — taxonomy diagramFive distinct custody perils arranged as a hand-drawn risk taxonomy: hot-wallet compromise, cold-storage compromise, smart-contract logic failure, validator slashing, and insider fraud. An oxblood cross-reference between the hot-wallet and cold-storage nodes marks the smart-contract logic gap — the binder boundary buyers most commonly misread, since neither the hot-wallet nor the cold-storage wording responds to a contract-logic event.01Hot walletKey compromise02Cold storeSpecie / facility03Smart contractListed-contract schedule04SlashingProtocol-defined05InsiderCrime / fidelity
Five perils. Five binders. The oxblood cross-reference between the hot-wallet and cold-storage nodes marks the smart-contract logic gap — the binder boundary buyers most commonly misread, since neither wording responds to a pure contract-logic event.

Underwriting

What an underwriter will ask.

  1. 01

    Custody architecture. HSM grade and FIPS level. Signing-quorum policy. Wallet enumeration (hot, warm, cold). Hot/cold split as a percentage of assets under custody. MPC versus multi-sig posture and the threshold structure.

  2. 02

    Operational controls. Segregation of duties between key-holders. Audit-log retention policy. Key-rotation cadence and the trigger events that force rotation. Privileged-access workflow.

  3. 03

    Incident history. Past losses, near-misses, and root-cause logs over the prior 36 months. Any reported losses to current or prior carriers.

  4. 04

    Audit posture. SOC 2 Type II date and scope. ISO 27001 certification scope. Penetration-test cadence and last report date. Bug-bounty programme structure.

  5. 05

    Sanctions and KYC controls. Counterparty screening provider and refresh cadence. Jurisdiction filter list. OFAC and UK sanctions posture. Travel-rule compliance posture.

  6. 06

    Recovery posture. Incident-response retainer (named provider). Forensic-accounting retainer. Disaster-recovery RTO and RPO. Tabletop-exercise cadence.

Use the RFI form to indicate your operating posture — same business day response from a named broker.

Carrier panel

Carrier panel — published on authorisation.

Panel slot 01

Published on authorisation.

Panel slot 02

Published on authorisation.

Panel slot 03

Published on authorisation.

Panel slot 04

Published on authorisation.

Panel slot 05

Published on authorisation.

Panel slot 06

Published on authorisation.

Editorial reference · public-press third-party reporting

We are in the coverholder application process at Lloyd’s. The syndicates publicly known to write digital-asset Crime, Specie, and Cyber cover in 2026 — based on public press, broker reporting, and the carriers’ own disclosures — include Atrium Syndicate 609 (hot-wallet cover with dynamic limits, supporting the Coincover programme), Mosaic and Chaucer (digital-asset Cyber, anchoring the Native “Risk Collective”), and Canopius Syndicate 4444 (digital-asset Custody at Lloyd’s London and Lloyd’s Asia, with Qubit as the first APAC coverholder). This is third-party reference based on public reporting, not a representation of any existing carrier relationship.

Process

From enquiry to instruction-to-bind.

  1. 01

    Enquiry

    RFI form or direct email to a named broker. Same-business-day acknowledgement; named broker assigned within one business day.

  2. 02

    Pre-qualification

    Six-question Q-pack run jointly. Initial appetite read from the market. Typically 5-10 business days.

  3. 03

    Submission

    Underwriting submission drafted by znobia; reviewed with the client; sent to the target market. Typically 5-15 business days.

  4. 04

    Quote

    Markets respond with indicative terms. We summarise quotes against the original risk and the buyer’s stated priorities — limit, retention, exclusions.

  5. 05

    Bind

    Client issues an instruction-to-bind. Binder issued by the carrier. Typically a further 5-10 business days post-quote.

  6. 06

    Servicing

    Endorsements, mid-term changes, claims notifications, renewal. Each handled by the same named broker as on placement.

Typical timeline: 4-12 weeks. Expedited paths available for renewal.

Related primers

Recent intelligence on this class.

znobia acts as an insurance intermediary. We do not underwrite risk. Cover, where available, is placed with authorised carriers and is subject to underwriter approval, policy terms, exclusions and conditions. Nothing on this site is investment, tax, legal or financial advice. Cover described on this page is illustrative. Availability, terms, limits, retentions, and pricing are determined by the underwriter and are subject to underwriter approval, policy terms, exclusions, and conditions. Past availability does not indicate future availability, pricing, or capacity. Digital assets are volatile and may be subject to total loss. Insurance, where placed, is limited to specified perils and does not protect against market-value fluctuation.