FCA registration under the Money Laundering Regulations confirms only anti-money-laundering requirements. It is not FCA authorisation. It does not make crypto activity acceptable to an insurer.
What cyber cover pays for crypto businesses
Cyber cover can fund the operational damage of a digital-asset attack. It does not automatically insure the token balance itself.
Cyber, crime and custody are different
| Loss event | Policy most likely to respond | Common gap to check |
| Ransomware locks trading systems | Cyber cover | Waiting period before interruption cover starts |
| Employee tricks finance staff into sending funds | Crime insurance | Voluntary or authorised-transfer exclusion |
| Private key theft from an insured wallet | Custody or specie cover | Named-wallet, hot-wallet or key-control conditions |
| Client alleges faulty wallet software caused loss | Technology E&O | Contractual liability assumed beyond common law |
A stolen key is not always insured
A private key is the secret code that approves a blockchain transfer. A criminal may obtain it through phishing. Cyber cover may fund investigation and notice costs. Missing tokens may remain outside cover. Direct digital-asset theft cover must be stated in the policy.
Practical test: Ask the broker to identify the clause that pays for theft from each wallet type. Test named hot wallets, cold wallets and MPC arrangements. MPC, or multi-party computation, splits signing power. No single device holds the complete key.
The wording decides whether the insurer pays. The product label does not decide this. A policy called crypto wallet cover may exclude an approved transfer after impersonation. A real employee may have approved the payment. Cryptocurrency crime cover may respond only when social-engineering cover was bought.
Check the schedule for private key theft cover, hot wallet protection and cold wallet cover. Check named-wallet limits and valuation dates too.
Common cyber exclusions include market loss, token volatility and exchange insolvency. They can also include stablecoin issuer insolvency, sanctions, war and known unpatched flaws. Digital asset custody cover should state whether third-party custodians are included. It should also address staking and subcontracted key-management firms.
The policy wording matters more than the product name.
FCA registration does not prove cover exists
FCA registration under UK anti-money-laundering rules does not mean FCA authorisation. It does not guarantee that insurance is available.
Registration is not authorisation
The FCA registration check asks if the firm has suitable anti-money-laundering systems. It also checks counter-terrorist-financing systems. An underwriter asks different questions. They ask who can approve transfers and where keys are held.
They also ask what happens after a vendor breach. They ask what value could leave in one event.
Compliance can affect the price
For UK firms, regulatory controls also act as underwriting evidence. FCA registration under the Money Laundering Regulations matters. Insurers usually look beyond registration. They review transaction monitoring, wallet screening and sanctions escalation.
They also review written anti-money-laundering rules. The UK Travel Rule sets data duties for relevant cryptoasset businesses. Firms must obtain, hold and send set originator and beneficiary data. These duties apply to qualifying transfers.
Weak Travel Rule processes can raise fraud, sanctions and counterparty risk. A firm with clear customer checks is easier to assess. The same applies to sanctions screening and suspicious-activity escalation. Records of high-risk transfer approvals also help.
These controls do not create insurance cover. Poor controls can affect premium, retention, sub-limits or quote availability.
Registration is a compliance check, not proof of cover.
Match the policy to your operating model
The right insurance mix depends on control. It does not depend on whether the business calls itself a crypto firm.
| Business type | Main peak exposure | Cover to test first | Critical control |
| Exchange or custodian | Client assets and withdrawals | Custody, crime, cyber | MPC or multisignature approval |
| Wallet provider | Key compromise and software claims | Cyber and technology E&O | Secure development and MFA |
| DeFi protocol team | Smart-contract exploit | E&O and D&O, if available | Independent code review |
| Corporate treasury | Hot-wallet transfer or custodian failure | Cyber, crime, custody review | Transfer limits and segregation |
| Miner or blockchain supplier | Outage and customer claim | Cyber and technology E&O | Back-ups and supplier checks |
A hot wallet connects to the internet and supports faster transfers. A cold wallet keeps signing material offline. Think of it as a spare house key in a locked safe. It is not left beside the front door.
DeFi risks can sit outside cover
A claim follows the loss, not the marketing label
1. Trigger
Hack, fraud, outage or exploit
→
2. Asset
Data, cash, token or client claim
→
3. Policy
Cyber, crime, custody or E&O
→
4. Conditions
Controls, limits and exclusions
📦
Available on Amazon
A hardware wallet can keep a small treasury’s signing keys offline. The business still needs written approval rules and recovery procedures. Check that the insurance wording recognises the storage method.
- Reduces exposure from keys held on an internet-connected workstation
- Supports separation between transaction preparation and signing approval
- Creates a clear custody process for underwriting evidence
Search on Amazon →
Consider the claim route before assuming a hack has one insurance answer. Ransomware may disable an exchange’s withdrawal systems. Cyber cover may fund forensics, legal advice and ransomware business interruption. A waiting period may apply.
Cyber cover may not replace client tokens stolen from a wallet. A smart-contract exploit may drain protocol-held assets. Technology errors and omissions or D&O may address valid third-party claims. They may not pay the direct asset loss.
A compromised MPC workflow may release client assets. The result depends on the theft clause and hot-wallet sub-limit. It also depends on evidence of MPC wallet security and multisignature approval. A depeg or insolvent custodian is usually a market or credit event. Cover needs a different, express trigger.
The error most firms make is treating every hack alike.
Set limits from your worst exposure day
Set the limit from the largest credible one-event loss. Do not base it on annual turnover.
- Peak asset value: the highest daily value, not an average or year-end snapshot.
- Hot-wallet cap: the maximum tokens deliberately exposed online.
- Single-transfer limit: the most one compromised signer could release.
- Interruption cost: gross profit, specialist recovery and extra staff costs during an outage.
- Counterparty concentration: value dependent on one exchange, custodian, cloud host or key vendor.
Retentions and controls shape the deal
Specialist underwriting questions often repeat the same controls. They ask about phishing-resistant MFA, segregated keys and HSM or MPC. They also ask about multisignature approval, transfer limits and blockchain monitoring.
They may ask about tested back-ups and an incident response plan. Vendor checks are also common. Phishing-resistant MFA uses a sign-in method such as a security key. A fake website cannot simply copy it.
This framework does not fit every SME. It is not the main fit for an SME without cryptoassets. That includes firms that do not own, custody, accept or facilitate them. It does not replace legal, regulatory or insurance advice. Seek advice for FCA-regulated activity, DeFi, third-party custody, token issuance or cross-border exposure.
Frequently asked questions
Does cyber insurance cover stolen cryptocurrency?
Cyber insurance may cover theft response costs. Direct token loss needs express custody, specie or crime wording. Check private-key theft, hot-wallet limits and authorised-transfer exclusions first.
Is FCA crypto registration the same as FCA authorisation?
No, FCA registration for anti-money-laundering purposes is not broad FCA authorisation. It does not guarantee insurance or banking access. It also does not give Financial Services Compensation Scheme protection.
How much cyber insurance does a UK crypto SME need?
A UK crypto SME should base limits on peak wallet and custody exposure. Do not use turnover alone. Add the largest transfer and between 24 and 72 hours of outage costs. Add contractual liability to clients too.
Does insurance cover a stablecoin depeg?
A stablecoin depeg is usually market or asset-value loss. Policies commonly exclude it. Cover may exist for an underlying hack. The wording must directly grant that cover.
What controls do crypto insurers expect?
Crypto insurers commonly expect phishing-resistant MFA, multisignature approval, key segregation and tested incident plans. They may also require HSM or MPC controls. Blockchain monitoring and hot-wallet transfer limits may also be required.
Buy cover only after mapping the loss
The practical choice is to insure the event that could damage the business. Then test each policy’s limits and exclusions against it.
For renewal or a first purchase, list every wallet and custodian. List each transaction approval route and customer promise. Ask a broker with UK digital-asset market experience for a coverage schedule. It should show what pays for ransomware, key theft and employee fraud. It should also show how smart-contract claims and third-party breaches are covered.
The essentials:- Cyber insurance pays for many attack effects. It does not automatically pay stolen token value.
- Crime, custody, technology E&O and D&O cover different crypto business risks.
- FCA AML registration and insurance eligibility are separate assessments.
- Peak hot-wallet and custody values should set limits. Firms must evidence the controls behind them.
Next, review how much cyber insurance a UK business needs. Compare the controls insurers request before a digital-asset renewal.
Further reading
If you want to learn more about this topic, these sources may interest you: