Digital Asset Custody & Crime Coverage
First-party crime coverage for digital assets and private keys you hold — your own, or your clients'.
This is an estimate, not a bound policy — a licensed VAB producer confirms final terms before coverage starts. Sgt. Savings can answer questions but can't quote, bind, or guarantee coverage.
Businesses that hold digital assets — for themselves or in custody for clients — face a theft risk a standard crime policy wasn't written for. This coverage is a first-party, discovery-triggered crime policy limited specifically to digital assets and private key material: employee theft of the organization's own digital assets, employee theft of digital assets held in custody for clients, and computer-fraud and fraudulent-transfer-instruction protection tied to those assets. It does not include any liability coverage — it's crime protection, full stop.
Who This Is Really For
The ideal buyer.
The ideal buyer runs a business that actually holds digital assets — either its own treasury or client assets it custodies — and has already discovered, usually the hard way, that its existing crime policy carries a blanket virtual-currency exclusion. Many of these organizations built real custody controls (cold storage, multi-signature approval, key-splitting) specifically to reduce theft risk, and are now looking for a crime policy that recognizes those controls rather than excluding the asset class outright. The trigger is often institutional: a client, lender, or auditor asking for proof of crime coverage that actually names digital assets before entrusting the business with more volume. This buyer isn't shopping for insurance in the abstract — they've usually already built the operational controls and are now closing the specific insurance gap that stands between those controls and something a counterparty will actually recognize.
- Businesses that custody digital assets on behalf of clients and need theft protection specific to that custody relationship
- Companies holding their own treasury or operating balances in digital assets, exposed to internal theft the same way any cash-holding business is
- Organizations that assumed their existing crime policy's virtual-currency exclusion meant they had no options — this is that option
- Firms wanting computer-fraud and fraudulent-transfer-instruction protection specifically for digital-asset transfers, not just fiat wire fraud
- Custodians and exchanges needing a crime program a lender, auditor, or institutional client will actually recognize
What It Covers
Coverage, broken down.
Employee Theft — organization's own digital assets
First-party, discovery-triggered coverage for theft of digital assets owned by your organization, committed by an employee.
Employee Theft — custodied digital assets
The same discovery-triggered protection extended to digital assets you hold in custody on behalf of clients — a distinct exposure from your own treasury.
Computer fraud and fraudulent transfer instructions
Related coverage agreements addressing loss from computer fraud and from fraudulent instructions that cause a transfer of digital assets or private key material.
Illustrative Scenario — How This Coverage Responds
Illustrative scenario — an employee diverts custodied digital assets
A digital asset custody firm discovers that an employee with transfer privileges diverted a portion of digital assets held for clients to a wallet the employee controlled, over a period of months before being caught. Under an illustrative Digital Asset Custody & Crime policy, the discovery-based Employee Theft of Custodied Digital Assets coverage part is what's designed to respond to that loss, subject to the policy's terms, limits, and exclusions. This is a description of how the coverage is structured to respond, not a specific claim outcome VAB is promising.
Illustrative example for education only — not a claim outcome or a promise of payment. Every claim depends on the actual policy issued and its terms.
More Than One Way In
More scenarios.
Real coverage doesn't fit one story. Here's who else this shows up for.
The custodian passing institutional due diligence
A digital asset custodian is in due diligence with an institutional client who requires proof of crime coverage specific to digital assets before entrusting the custodian with additional volume. The custodian places Digital Asset Custody & Crime coverage specifically to satisfy that requirement and close the relationship. This illustrates a common institutional trigger for this coverage, not a claim outcome.
The exchange discovering the virtual-currency exclusion
An exchange reviewing its existing general crime policy discovers, on close reading, that virtual currency loss is entirely excluded — a gap it had assumed was covered. It places this coverage specifically to address theft of its own treasury and any client assets it holds, since the general policy will never respond to that loss type. This is an illustration of a common coverage gap being discovered, not a claim scenario.
The firm formalizing key-splitting controls
A firm implements multi-signature approval and key-splitting across its custody operations as a security upgrade, and wants its crime coverage to actually reflect and reward those controls at application. Describing the real controls accurately is what lets the policy respond as intended if a loss ever occurs despite them. This illustrates how documented controls factor into coverage, not a claim outcome.
Know The Gaps
What this doesn't cover.
Every policy has limits. Knowing them before you buy is how you avoid a denied claim later.
Reconciliation or inventory shortages
A discrepancy discovered during reconciliation, without proof of an actual theft event, doesn't meet the burden this crime policy requires — you generally need to show how the loss actually happened.
Trading losses
Losing value through bad trades or market moves is a business and market risk, not a crime loss — this policy doesn't function as investment-loss protection.
Breach of secure-storage warranties
If your application represented specific custody/security controls (cold storage, multi-sig, key-splitting) and you didn't actually maintain them, a resulting loss can fall outside coverage — keep your actual controls matched to what you represented.
Unexplained loss or disappearance
Assets that simply can't be accounted for, with no identifiable theft mechanism, generally aren't covered — discovery-based crime coverage needs an actual criminal act behind the loss.
Voluntary parting
If assets were transferred voluntarily based on a scheme that induced you to give them up knowingly (as opposed to a fraudulent instruction you didn't recognize as fraudulent), that can be treated differently — talk through the fact pattern with your advisor before assuming it's covered.
Wear, tear, and inherent vice
Standard property-crime exclusion carried over here — gradual loss in value or condition isn't a theft event.
Behind The Quote
What goes into the decision.
What actually moves your price and your approval — no black box.
Custody controls actually in place
If the application represents specific controls — cold storage, multi-sig, key-splitting — and those controls aren't actually maintained, a resulting loss can fall outside coverage, so keeping real practice matched to what's represented is essential, not optional paperwork.
Volume and value of assets held
Both the organization's own treasury and any client assets held in custody factor into the exposure and the limit needed, since the two are covered as distinct coverage parts with their own scope.
Employee access and transfer privileges
Since this is discovery-triggered employee theft coverage, who actually has the ability to move assets — and how tightly that access is controlled — is central to how the exposure is assessed.
How 'employee' is defined for contractors
Firms that rely heavily on contractors with asset-transfer privileges need to confirm exactly how the policy defines employee, since some programs extend that definition to certain contractors and others don't — a gap here can leave real transfer risk unaddressed.
Prior reconciliation or loss history
A documented history of reconciliation issues or prior losses factors into underwriting the same way it would for any crime policy, since this coverage still requires an identifiable theft event, not just an unexplained shortfall.
Let's get you covered.
Tell us what you need on Digital Asset Custody & Crime Coverage — a licensed VAB advisor follows up personally. No bots, no runaround.
Looking for a session that's already scheduled? Browse upcoming webinars.
Availability
Placed nationwide, with terms adjusted state by state.
Questions, answered straight
No jargon on digital asset custody & crime coverage — just what you're actually asking.
No. This is first-party crime coverage only — it pays your organization for the theft loss itself. Liability to clients arising from that same event needs separate coverage, such as a technology or professional liability policy.
Both, as two distinct coverage parts — Employee Theft of the organization's own digital assets, and separately, Employee Theft of custodied digital assets held for clients.
That's a real gap to be aware of — unexplained loss or disappearance is excluded. This policy responds to an identifiable theft event, not a shortfall you discover without being able to show how it happened.
That depends on how your policy defines 'employee' — some programs extend the definition to certain contractors, others don't. Confirm the exact definition in your schedule if you rely heavily on contractors with asset-transfer privileges.
Most standard crime policies exclude virtual currency loss entirely. This policy exists specifically to fill that gap for digital assets and private key material — it doesn't replace your general crime policy, it covers what that policy won't touch.
Beyond This Coverage
What people in your situation also need.
Related Coverage
Coverage people pair with this.
Digital Asset Protocol Coverage
Liability and loss protection built specifically for DeFi protocols, staking, and validator operations.
Learn moreCyber Liability
Coverage for a data breach, network failure, or cyber extortion — and everything it costs to respond to one.
Learn moreCrime & Fidelity Coverage
Protection against employee theft, forgery, and funds-transfer fraud — the internal-controls gap trust-based organizations feel hardest.
Learn moreReady to talk it through?
Get a quote in minutes, or ask Sgt. Savings a straight question first — no pressure, no runaround.
Insurance products described on this page are marketed by The Veteran Alliance, a licensed insurance producer, and underwritten by one or more separately licensed insurance companies, which may include Corgi Insurance Company and its affiliates. The insurer that actually underwrites your policy, its licensing status in your state, and any state-required notices will be identified in your quote and policy documents. Coverage, limits, eligibility, and pricing are determined by the underwriting insurer, may vary by state, and may change. Nothing on this page is a quote, an offer of insurance, a binder, or a guarantee of coverage — coverage takes effect only when a policy is issued.
