
Crypto Business Insurance UK | Digital-Asset Broker
Why does a crypto business need specialist insurance treatment?
Crypto and digital-asset businesses occupy a strange position: they can carry enormous, concentrated value and serious institutional exposures, yet they remain one of the hardest sectors in the UK to insure. An exchange, custodian, trading firm or web3 startup faces a combination of risks almost no other business does — the theft of digital assets held in custody, directors exposed to a fast-tightening regulatory regime, smart-contract and technology failures, and the sheer volatility of the assets themselves. And with the FCA's new cryptoasset regime now finalised and approaching, the stakes for governance and compliance are rising sharply. Standard commercial and even conventional tech policies are simply not built for this.
This is the kind of genuinely difficult risk Miller & Partner exists to place. As a specialist broker for complex and emerging risks, we structure cover for crypto exchanges, custodians, trading firms, web3 startups and digital-asset businesses that generalist insurers won't quote — including firms told they're uninsurable. This guide explains why digital-asset custody crime is the exposure that defines the sector, how the new FCA regime changes your risk, why directors' and officers' cover is so critical, and how to present a crypto business so specialist underwriters engage. It sits in our technology cluster alongside our guides to AI liability insurance and SaaS business insurance.
How does The Insurability Framework™ apply to crypto firms?
Underwriter Intelligence
We know the specialist and Lloyd's markets with genuine appetite for digital-asset risk, and what shapes their terms — custody model, key management, regulatory status and governance. We present that evidence before the underwriter has to ask.
Difficult Risk Expertise
Crypto is a class most insurers decline outright. Our specialist scheme and Lloyd's access reaches the digital-asset underwriters — specie, D&O, tech and cyber — who will engage with a well-run, well-presented crypto business.
Risk Assessment
We audit the business the way a specie and D&O underwriter would: custody and private-key management, hot-versus-cold storage, governance and regulatory readiness, and smart-contract controls — the things that decide both terms and whether cover exists at all.
Claims Advocacy
A crypto claim — a custody hack, a regulatory action, a smart-contract failure — is high-value and technically complex. When it happens you deal with a named broker who understands digital-asset risk and the market, not a call centre.
Key facts at a glance
- Digital-asset custody crime is the defining exposure — theft of crypto through a hack or private-key compromise is the loss the whole sector is built to fear.
- The UK's new FCA cryptoasset regime was finalised on 30 June 2026 and is expected to come into force on 25 October 2027, with an authorisation window opening in autumn 2026.
- The regime brings custody rules (CASS 17), the Consumer Duty, operational resilience and the Senior Managers regime to crypto firms — sharpening directors' exposure.
- Crypto-custody (specie) policies wrestle with exclusions and sub-limits around private-key management, hot-versus-cold storage and reconciliation.
- Most generalist insurers refuse crypto outright — cover comes from a small number of specialist and Lloyd's markets.
- Directors' & officers' cover is critical — regulatory scrutiny and investor claims fall personally on senior managers.
- The volatility of digital assets makes valuation for cover a genuine challenge that must be addressed deliberately.
What must a crypto policy include that a standard policy won't?
Crypto businesses are often offered a standard commercial combined or tech policy, and it doesn't fit the risk — assuming an insurer will engage at all. A conventional policy assumes tangible property, familiar liability and a settled regulatory backdrop. It doesn't contemplate the theft of an intangible bearer asset from a digital wallet, the personal exposure of directors under a brand-new regime, smart-contract code that can fail irreversibly, or assets whose value can swing violently overnight. The gaps show up exactly where a crypto firm is most exposed: custody crime, D&O, technology liability and valuation. The comparison below shows where a standard policy falls short. Our cyber insurance page covers the cyber layer that sits alongside.
| Exposure | Standard commercial / tech policy | Specialist crypto programme |
|---|---|---|
| Crypto as a risk | Declined on sight by most insurers | Written by specialist digital-asset & Lloyd's markets |
| Digital-asset custody | Not covered — intangible bearer asset | Specie / crime cover for assets in custody |
| Private-key / hot-cold storage | Not contemplated | Cover reflecting key management & storage model |
| Directors & officers | Generic D&O, crypto often excluded | D&O geared to the FCA regime & investor claims |
| Smart-contract / tech | Standard tech assumptions | Technology liability for code & platform failure |
| Regulatory change | Ignores the new FCA regime | Structured around authorisation & conduct duties |
| Valuation & volatility | Fixed, tangible-asset assumptions | Cover addressing volatile digital-asset valuation |
Why is digital-asset custody crime the exposure that defines the sector?
If one exposure defines crypto insurance, it is the theft of digital assets held in custody. Cryptoassets are bearer instruments: whoever controls the private keys controls the assets, and a successful hack, insider theft or key compromise can move enormous value irreversibly in moments, with no chargeback and often no recovery. This is why specie and crime cover for assets in custody is the flagship — and the hardest — cover in the sector, and why the whole industry orients its security around protecting keys.
Crypto-custody policies are technical and tightly drawn. They wrestle with exclusions and sub-limits around exactly the things that determine whether assets are safe: private-key management, the split between "hot" (online) and "cold" (offline) storage, multi-signature and reconciliation controls. Notably, these are the very categories the FCA's new custody rules (CASS 17) also focus on — regulator and underwriter have independently converged on the same risk taxonomy. For a firm, that means the security architecture is simultaneously your regulatory story and your insurance story: a robust, well-documented custody and key-management regime is the single strongest thing you can put in front of a specie underwriter, and increasingly in front of the FCA too.
From recent placement conversations
The reaction I hear most from crypto founders is weary frustration: they've built a genuinely well-governed business, and they still get "we don't cover crypto" from insurer after insurer. That's a reflection of where they've been asking, not of their risk. Digital-asset insurance is a specialist line — specie, D&O, technology and cyber underwriters, much of it at Lloyd's — and those markets will engage with a firm that can evidence its custody model and governance. The second thing that comes up constantly now is the new FCA regime: founders know it's coming but underestimate how much it sharpens their directors' personal exposure and reshapes what underwriters want to see.
The crypto businesses we place best treat their custody architecture and their governance as the pitch. A clear custody and private-key-management model, the hot-versus-cold split, multi-signature and reconciliation controls, a credible regulatory-readiness plan for the new regime, and sound smart-contract auditing — hand a specialist digital-asset underwriter that package and a risk most of the market refuses becomes one they'll structure properly. In this sector, the security and governance you can evidence are the whole conversation.
How does the new FCA cryptoasset regime change your risk?
The UK's regulatory treatment of crypto is changing fundamentally, and it reshapes the risk picture for every firm in the sector. Historically, crypto firms only had to register with the FCA for anti-money-laundering purposes. That has now changed: the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 brought cryptoassets within the FCA's remit, the FCA published its final rules and guidance on 30 June 2026, and the new regime is expected to come into force on 25 October 2027, with an authorisation application window opening in autumn 2026. Firms carrying on regulated cryptoasset activities — custody, trading, dealing, arranging, staking, stablecoin issuance — will need FCA authorisation, and those that miss the gateway may have to run off their UK business.
For insurance, the significance is that the regime imports the full weight of financial-services regulation: the Consumer Duty, operational-resilience requirements, client-asset custody rules (CASS 17), and the Senior Managers & Certification Regime (SM&CR). SM&CR in particular places personal accountability on named senior managers, which materially heightens directors' and officers' exposure. A firm that treats regulatory readiness and insurance as one exercise — evidencing governance, resilience and custody controls to both the FCA and its underwriters — is far better placed, both to secure authorisation and to secure cover on sensible terms. This is a defining moment for the sector, and the firms that prepare early will navigate it best.
Why is directors' & officers' cover so critical for a crypto firm?
Directors' and officers' cover is often the most important liability protection a crypto business carries, because the people running these firms are personally exposed on multiple fronts at once. Crypto companies are typically venture-backed and milestone-driven, operate in a sector under intense regulatory scrutiny, and — under the incoming regime and the SM&CR — will have named senior managers who are personally accountable for the firm's conduct. Investors who back a crypto firm may bring claims against directors if the business fails, if a hack destroys value, or if regulatory approval is delayed or refused; regulators may pursue senior managers directly.
D&O cover responds to these personal exposures — defence costs and liability arising from claims against directors and officers in their management of the company. In crypto it needs to be structured with the sector's specific risks in mind: regulatory investigation and enforcement, investor and shareholder claims, and the governance failures that a hack or collapse can expose. Given how many high-profile crypto failures have ended in claims against the individuals at the top, D&O is not a box-ticking cover here — it is core protection for the people steering a firm through a volatile market and a tightening regulatory regime, and it belongs in the programme from an early stage.
What are the technology, smart-contract and cyber risks?
Beneath the custody and regulatory exposures sits a layer of pure technology risk, because a crypto business is, at bottom, a software business handling value. Smart contracts — self-executing code that moves assets automatically — can contain bugs or vulnerabilities that, once deployed, may be exploited or may fail irreversibly, causing direct financial loss to the firm or its clients. Platform errors, failed transactions, and the operational-resilience failures the FCA now scrutinises all sit alongside this. These are professional and technology exposures that a standard policy neither contemplates nor covers.
A properly structured programme therefore includes technology and professional liability for code, platform and service failures, and cyber cover for the hacking, data-breach and system-compromise risks that overlap heavily with custody crime. Given that a single smart-contract exploit or platform breach can affect many users simultaneously and irreversibly, robust code auditing, penetration testing and operational-resilience controls are both good practice and central to insurability. A crypto firm that can evidence rigorous technology governance — audited contracts, tested systems, resilient operations — is protecting its clients and presenting a far stronger risk to the specialist market.
What insurance does a crypto or digital-asset business need?
A crypto programme is a genuine stack of specialist covers, and they must be structured together to fit a business that is part custodian, part software firm and part regulated financial-services entity. The core structure looks like this:
Digital-asset custody (specie / crime)
The flagship cover: specie and crime protection for cryptoassets held in custody against theft, hacking and key compromise — tightly drawn around your storage and key-management model.
Directors' & officers' liability
D&O geared to regulatory scrutiny, investor claims and SM&CR senior-manager accountability under the new FCA regime.
Technology & professional liability
Professional and technology indemnity for smart-contract, platform and service failures, plus errors in advice or execution.
Cyber
Cyber cover for hacking, data breach, system compromise and business interruption — overlapping closely with custody crime.
Commercial & management covers
Employers' and public liability for staff and premises, plus business interruption and the general covers any growing company needs.
Cover checker: what does your crypto business need?
Select the profile closest to your operation. Tags show what's legally required, essential, or worth considering. Every crypto business should be built individually — this checker maps the starting point. Our guide to directors' & officers' cover covers the governance core.
- CRITICALCustody crime / specie for client assets on the platform.
- CRITICALD&O for regulatory & SM&CR exposure.
- ESSENTIALCyber & technology liability.
- LEGALEmployers' liability for staff.
- RECOMMENDEDRegulatory readiness for the new regime.
- CRITICALSpecie / crime cover — custody is your whole business.
- CRITICALPrivate-key & hot-cold controls reflected in cover.
- ESSENTIALCASS 17 readiness for the new custody rules.
- ESSENTIALD&O & cyber.
- LEGALEmployers' liability.
- CRITICALTechnology / smart-contract liability for code failure.
- CRITICALD&O for a VC-backed, pre-revenue venture.
- ESSENTIALCyber & IP cover.
- LEGALEmployers' liability once you employ.
- CONSIDERPerimeter question — are you in FCA scope?
- CRITICALCrime & custody for assets you hold or trade.
- ESSENTIALProfessional / tech liability for execution errors.
- CRITICALD&O for regulatory & market-abuse exposure.
- LEGALEmployers' liability (£10m).
- CONSIDERValuation basis for volatile positions.
- CRITICALD&O & regulatory — issuers face heavy scrutiny.
- CRITICALBacking-asset custody & crime cover.
- ESSENTIALCASS 16 / redemption readiness.
- ESSENTIALTechnology & cyber.
- LEGALEmployers' liability.
- CRITICALCrime & cyber for a payments-handling business.
- ESSENTIALProfessional / tech liability.
- CRITICALD&O for FCA & payments regulation.
- LEGALEmployers' liability (£10m).
- CONSIDERFintech structure — see tech cover.
Why do so many insurers refuse crypto businesses?
It's worth understanding why crypto is so hard to insure, because it explains how to overcome it. Part of the reason is genuine: the risks are real, large and, in custody crime, potentially catastrophic and unrecoverable. But a large part is reputational and unfamiliarity-driven — many generalist insurers simply decline anything with "crypto" attached, regardless of how well-governed the firm is, because they don't understand the risk and don't want the association. The result is that a well-run, well-capitalised digital-asset business can be turned away by the mainstream market as reflexively as a poorly-run one.
The consequence is that crypto is a specialist placement, not a mainstream one. Cover is written by a comparatively small number of specie, D&O, technology and cyber underwriters — much of the capacity sitting at Lloyd's — who understand digital-asset risk and will engage with a firm that presents it properly. A comparison site or a generalist broker will rarely reach them. This is precisely the gap a specialist broker fills: knowing which markets have appetite, and presenting the custody model, governance and regulatory readiness in the way those underwriters need to see. Being refused by the mainstream market is the norm for crypto — and it is not the end of the conversation.
Why is valuing digital assets for cover so difficult?
A final distinctive challenge is valuation. Cryptoassets are famously volatile — the value of assets held in custody, or of a firm's own positions, can swing dramatically in hours, which makes setting and maintaining an appropriate sum insured genuinely difficult. Insure to a figure set months ago and a loss at a market peak could leave a serious gap; the exposure a custody policy needs to cover is a moving target in a way it simply isn't for tangible property. This is compounded by the technical question of how a loss of a bearer digital asset is valued and settled at all.
The answer is to treat valuation as an active part of the programme rather than a set-and-forget number: understand how the policy values and settles a digital-asset loss, keep sums insured under review against the assets actually held, and be clear on the basis of settlement in advance. The same discipline that protects against underinsurance in any sector applies here, but with volatility turning an occasional review into an ongoing one. A firm that can show it manages this deliberately is both better protected and a more credible risk to a specie underwriter.
Red-flag checklist: would an underwriter worry about your firm?
Tap each statement that is currently true of your business. These are the things that make a digital-asset underwriter cautious — the more that light up, the harder your placement becomes. The first two are, on their own, potentially decisive.
Risk assessor: how will an underwriter score your crypto business?
What regulations apply to crypto businesses?
The UK's regulatory treatment of crypto is being rebuilt, and each strand shapes both compliance and how the risk is underwritten.
The new FCA cryptoasset regime
The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 bring cryptoassets within the FCA's remit. The FCA published its final rules on 30 June 2026, with the regime expected in force on 25 October 2027 and an authorisation window opening in autumn 2026.
Regulated activities & authorisation
Custody, trading, dealing, arranging, staking and stablecoin issuance become regulated activities requiring FCA authorisation. Firms that do not apply through the gateway may need to run off their UK business.
Client-asset custody & conduct rules
New custody rules (CASS 17), stablecoin backing rules (CASS 16), the Consumer Duty, operational-resilience requirements and market-abuse rules all apply — much of it mapping onto the risks a specie and cyber underwriter already prices.
Senior Managers & anti-money-laundering
The Senior Managers & Certification Regime places personal accountability on named individuals, and the existing money-laundering registration obligations continue — both central to a firm's governance and D&O exposure.
What drives the cost of crypto business insurance?
There is no meaningful "average premium" for a crypto business — a pre-revenue web3 startup and an established custodian holding hundreds of millions in assets are entirely different risks. What every firm can do is understand the rating factors and work the ones within its control:
| Rating factor | Why it moves your premium | Mitigation |
|---|---|---|
| Custody model | Custody crime is the defining loss | Documented model; cold-storage majority |
| Private-key management | Key compromise is catastrophic | Multi-signature, segregation, reconciliation |
| Assets under custody | Sums insured drive specie pricing | Right-sized limits; sub-limits understood |
| Governance & D&O | Regulatory & investor exposure | Strong board, controls, D&O in place |
| Regulatory readiness | The new regime reshapes the risk | Authorisation plan; conduct & resilience controls |
| Smart-contract auditing | Code failure is direct & irreversible | Independent audits; penetration testing |
| Operational resilience | An FCA focus and a real exposure | Tested incident-response & continuity plans |
| Asset volatility | Valuation is a moving target | Sums insured reviewed; settlement basis clear |
| Business model | Exchange vs custodian vs issuer differ | Cover matched precisely to activities |
| Track record | A prior hack or action reprices cover | Evidence remediation; see our refused-cover guide |
| Jurisdiction & footprint | Multi-jurisdiction adds complexity | Clear regulatory mapping of where you operate |
| Market access | Few insurers write crypto at all | A specialist broker with Lloyd's & MGA access |
What do real crypto-business claims look like?
These three fictionalised but market-realistic case studies show how crypto-business losses actually unfold — and where the decisions made at placement decided the outcome.
Case study 1: The custody hack — £2.4m specie / crime claim
A digital-asset custodian suffered a sophisticated attack that compromised a private key controlling a hot wallet, and a large tranche of client cryptoassets was moved off-platform and could not be recovered. The firm's specie and crime cover responded to the theft, within the sub-limits and conditions attaching to its hot-storage holdings.
The numbers: around £2.4m recovered under the specie / crime section, with the settlement shaped by the policy's hot-versus-cold sub-limits and the firm's ability to evidence that its documented key-management controls had been followed.
The lesson: custody crime is the exposure the whole sector fears, and it's where the fine print bites hardest. The proportion of assets in hot storage, the sub-limits, and the evidence of controls followed all directly shaped how much of the loss was recoverable.
Case study 2: The regulatory action — £680,000 D&O defence & claim
Following concerns about a firm's conduct and disclosures as the new regime approached, the FCA opened an investigation, and investors who had backed the business brought claims against its directors alleging governance failings. The directors faced personal exposure to defence costs and potential liability.
The numbers: around £680,000 across legal defence costs and settlement under the directors' & officers' policy — cover a firm without D&O, or with a generic policy that excluded crypto, would not have had.
The lesson: under the incoming regime and SM&CR, senior managers are personally accountable, and regulatory scrutiny of crypto is intensifying. D&O geared to the sector's regulatory and investor exposures is core protection for the individuals at the top, not an optional extra.
Case study 3: The smart-contract failure — £420,000 technology liability claim
A vulnerability in a smart contract deployed by a web3 firm was exploited, and funds belonging to platform users were drained before the contract could be paused. Affected users brought claims against the firm for the loss, alleging that the code had not been adequately tested or audited.
The numbers: around £420,000 across third-party liability and defence costs under the technology / professional liability section, met because the firm carried cover geared to smart-contract and platform failure rather than a generic tech policy.
The lesson: a crypto business is a software business handling value, and code that fails can cause direct, irreversible, multi-user loss. Independent auditing reduces the risk; technology liability structured for smart-contract failure covers what remains.
What if your crypto firm has been refused cover?
Being told you're "uninsurable," refused, or offered a policy that quietly excludes crypto is the norm rather than the exception for digital-asset businesses — and it usually reflects where you've been asking, not your actual risk. Much of the mainstream market declines crypto reflexively. The workable path is the one we set out in our guides to insurance for businesses refused cover and business insurance refused elsewhere: present the whole business clearly — custody and key-management model, governance, smart-contract auditing, regulatory readiness and capitalisation — through a broker who understands digital-asset risk and can reach the specialist and Lloyd's markets that write it. Every future proposal asks whether you've been refused cover, and the duty of fair presentation makes that answer permanent, so collecting declines from generalists who were never going to engage is the worst approach. If a prior hack or regulatory action is the issue, competitive terms can still be rebuilt on a fully presented basis; and if you're an early-stage venture, our guide to small business insurance and what cover costs is a useful starting point. "Uninsurable" is rarely the real answer.
How do you manage a serious crypto incident?
A serious crypto incident — a custody hack, a smart-contract exploit, or a regulatory action — is managed, and claims are won or lost, in the first hours. This is the sequence we run with clients:
- Contain the incident and secure the keys. Move to protect remaining assets immediately — isolate compromised systems, secure or rotate private keys, pause affected contracts or withdrawals, and stop the bleeding before anything else.
- Preserve the evidence. Capture the on-chain trail, system logs, transaction records and access logs. Blockchain evidence is immutable and vital — record everything before systems are changed in response.
- Assess the scale. Establish what has been lost or exposed — which assets, whose, how much, and by what route — so the response, the notifications and the claim can be sized accurately.
- Notify your broker as soon as possible. Late notification breaches policy conditions. Your broker triggers notification across the specie/crime, cyber, D&O and technology sections as relevant, and brings in specialists who understand digital-asset claims.
- Meet regulatory obligations. Notify the FCA and, where personal data is involved, the ICO within the required timeframes. Under the new regime and the Consumer Duty, prompt, transparent regulatory engagement protects your position.
- Engage incident-response & recovery specialists. Bring in blockchain forensics and, where relevant, law-enforcement liaison to trace and, if possible, freeze stolen assets — speed materially affects any chance of recovery.
- Communicate with affected clients. Handle client and market communication carefully and honestly, with legal input — how a crypto firm communicates in a crisis shapes both its liability and its survival.
- Review and strengthen. Whatever the incident reveals — a key-management weakness, an unaudited contract, a resilience gap — correct it, document the change, and evidence it to the FCA and your underwriters at renewal.
Glossary of crypto insurance terms
- Cryptoasset
- A cryptographically secured digital representation of value or rights — including cryptocurrencies, tokens and stablecoins — now being brought within FCA regulation.
- Digital-asset custody
- Holding or safeguarding cryptoassets on behalf of clients — the activity at the heart of both the new custody rules and specie insurance.
- Specie insurance
- Cover for high-value property, adapted for cryptoassets in custody, responding to theft and loss of the assets held.
- Private key
- The secret cryptographic key that controls a cryptoasset — whoever holds it controls the asset, making its protection the central security concern.
- Hot vs cold storage
- Hot storage is connected to the internet (more accessible, more exposed); cold storage is offline (more secure). The split is a key underwriting factor.
- Multi-signature
- A control requiring multiple keys or approvals to move assets, reducing the risk of a single point of compromise.
- Smart contract
- Self-executing code that automatically performs transactions — powerful but, once deployed, potentially vulnerable and irreversible if flawed.
- D&O insurance
- Directors' & officers' liability cover, protecting individuals against claims arising from their management of the company — critical given SM&CR.
- SM&CR
- The Senior Managers & Certification Regime, which places personal accountability on named senior managers — extended to crypto firms under the new regime.
- CASS 17
- The FCA's new client cryptoasset custody rules, covering ownership, record-keeping, reconciliation and key management.
- Consumer Duty
- The FCA's overarching requirement to deliver good outcomes for retail customers, now applying to in-scope crypto firms.
- Operational resilience
- The FCA requirement to prevent, adapt to and recover from operational disruption — a live exposure for technology-dependent crypto firms.
- Authorisation gateway
- The FCA application process crypto firms must pass to carry on regulated activities under the new regime; firms that don't apply may have to run off.
- Technology / cyber liability
- Cover for losses from technology failures, code defects, hacking and data breach — closely intertwined with custody crime in crypto.
- Fair presentation
- The duty under the Insurance Act 2015 to disclose every material circumstance — custody model, governance, losses and any refused cover.







Instagram
LinkedIn