Custody Insurance refers to a policy underwritten by a traditional commercial insurer or a specialized crypto insurance carrier, covering losses suffered by a third-party custodian (an exchange, a professional custody service provider) from specific events like external theft, hacking, or insider collusion and fraud. When an incident occurs, the insurer pays out according to the policy's terms. This is an entirely different mechanism from the insurance fund already covered on this site: an Insurance Fund is an internal reserve an exchange builds up in advance using its own capital (typically a portion of trading fees), and whether and how much gets paid out depends on the exchange's own decision and that fund's actual balance at the time. Custody insurance, by contrast, is a commercial policy the exchange or custodian purchases from an external insurer, with payout determined by terms written in black and white in the policy — theoretically independent of the custodian's own financial condition.
These two mechanisms frequently get conflated by users, partly because most platforms rarely draw a strict distinction in their marketing language between "we have an insurance fund" and "we carry a commercial policy" — but for a user, understanding exactly which mechanism actually covers their assets directly affects how much compensation they can realistically expect, and how quickly, if a platform runs into trouble.
The fundamental reason Custody Insurance exists is that crypto assets, unlike traditional bank deposits, aren't covered by institutional protections like FDIC deposit insurance — once a custodian is hit by a hack or internal fraud, users are entirely exposed to the risk of whether the custodian itself is even capable of compensating them. Commercial insurers underwriting this risk essentially spreads it, through premiums, from a single custodian out across the broader capital markets, giving the custodian the capacity to fulfill its compensation obligation to users even after a major loss event, rather than collapsing outright from a single incident.
But this market remains at an early stage of development: according to GlobalData's 2024 consumer survey, only roughly 11% of crypto holders globally actually have some form of insurance coverage, meaning close to 90% of holders are entirely exposed with no insurance whatsoever. The same survey also found a substantial share of the uninsured expressing clear willingness to purchase coverage, indicating real market demand — but the supply side (the number of insurers willing to underwrite this risk, and their underwriting capacity) remains noticeably insufficient. This is exactly why, even when some exchanges claim to carry commercial insurance, the actual policy's coverage scope and payout cap often fall far short of the total scale of user assets held on the platform.
In practice, Custody Insurance can be roughly divided into several types depending on scope and target: one type focuses specifically on the custody service itself, covering asset losses a custodian suffers from external theft or internal collusion. Another, broader type is digital asset crime insurance, which can extend to a wider range of criminal categories like employee fraud and social engineering. A third type focuses on a specific storage form, such as a policy specifically covering loss or damage to cold-storage assets. Coverage scope and exclusions vary substantially between policies; most explicitly exclude losses from market price fluctuation itself, user-side operational error (like sending to the wrong address), Private Key loss, and asset seizure by regulators — meaning custody insurance was never designed as an all-encompassing safeguard covering every possible loss scenario.
Premium levels are typically calculated as a percentage of the value of covered assets. Industry data shows that institutional-grade Cold Storage policies backed by robust security measures generally run roughly 1% to 2.5% of covered asset value annually; coverage for DeFi protocols (underwritten through decentralized insurance protocols like Nexus Mutual, for instance) can even run below 1% if the protocol itself has a solid audit track record and relatively low risk. Conversely, as several major hacking incidents pushed up overall risk assessments in early 2025, premiums for exchange hack coverage rose roughly 35% year over year — reflecting how the insurance market's pricing for this class of risk adjusts dynamically alongside the industry's actual loss events.
For an everyday user, seeing an exchange or platform claim that "assets are protected by Custody Insurance" — the most practical approach isn't to take it at face value, but to check several specific details further. First, what is this policy's payout cap, and how does that actually compare to the platform's total user asset scale? Most policies' payout caps fall far short of the platform's actual total user asset value, meaning that in the event of a large-scale loss incident, the insurance payout very likely won't be enough to make every affected user fully whole. Second, what's the specific scope of events this policy actually covers — does it cover the risk scenarios you're most worried about (a hack, internal fraud), or only a narrower, more specific set of circumstances? Third, and most easily overlooked: does this policy protect "the platform's assets" or "the assets in your individual account"? Most policies actually cover losses at the platform's overall operational level, and whether — and how — any payout gets distributed to individual users often still depends on the platform's own mechanism and willingness, rather than the policy automatically and directly compensating each affected user.
The more fundamental thing to understand: custody insurance is one line of defense that reduces risk, but it was never the only line of defense, and it doesn't guarantee you'll get back everything you had. Like proof of reserves, multisig, Cold Storage, and the other mechanisms repeatedly discussed on this site, each defends against a specific class of risk — no single mechanism covers every scenario. Layering multiple defenses together, rather than relying on any one protection mechanism alone, is the relatively practical approach to managing risk.
The February 2025 Bybit incident, in which over $1.5 billion in assets was stolen, clearly illustrated the current gap in the custody insurance market: even though the total crypto market has reached a scale of trillions of dollars, an analysis from law firm Spark pointed out that the incident highlighted a clear gap between the scale of custodied assets and the actual scope of coverage — most exchanges, even when carrying commercial policies, have payout caps that fall far short of the platform's actual total user asset value. Bybit's ability to close its funding gap and restore normal withdrawals within an extremely short window relied primarily on bridge loans from institutional partners and its own capital, not a custody insurance payout. This case is often cited in the industry to illustrate that "being insured" and "actually being fully covered when a loss occurs" are two things frequently conflated, but in practice carry a substantial gap between them.