Select how you’d like to proceed with your insurance needs.
Talk to a real insurance expert on your time.
15-minutes consultation with licensed advisors
Perfect if you’re unsure about coverage needs
Get personalised recommendations
Already have coverage? Let’s simplify your service
Keep your current carriers & policies
Simple digital authorisation process
Seamless transition to better service

Crypto businesses do not fail in one direction. A single incident can produce several separate losses at once: client assets gone, incident response costs, client lawsuits, regulatory scrutiny, and claims against your directors.
That is why crypto startup insurance is usually a stack rather than a policy. And it is why the most common mistake is holding a technology policy that covers the system failure but excludes the digital asset loss. upcover arranges blockchain insurance in Australia and crypto business insurance for blockchain and crypto businesses, as a Corporate Authorised Representative of an AFSL holder.
Six covers do most of the work. Which of them you can get, and how easily, depends mostly on whether client assets pass through your control.
No single policy covers that whole stack. Technology PI and cyber are often available in a combined technology wording. Crime and digital asset custody may require separate sections, endorsements or policies. Web3 insurance and digital asset insurance are descriptions rather than products. Both phrases cover combinations of the above. What you can actually arrange depends on your model, your controls and your licensing position.
This is the biggest fork in crypto insurance. It is not the only question that matters, but it changes more than any other single fact about your business.
Because custody can change three things at once, which is unusual in technology.
It changes your regulator. Holding client assets pulls you toward financial services licensing and, depending on the service, AML registration. Building software usually does not.
It changes what you can lose. A software failure costs a client money. Losing client assets means the loss is the asset itself, which most technology wordings were never built to answer.
It changes your insurance market. Non-custodial risk sits with insurers who write technology every day. Client asset risk sits with a much smaller group, sometimes outside Australia.
That is why an insurer asks about custody before almost anything else. It tells them which of those three worlds you are in.
Custody is the biggest fork, but it is not the only regulatory question. Token issuance, advice, staking, transfers and financial product features can all matter even where you never hold a client's assets. Not sure which row you are in? Talk it through with upcover before you assume you are uninsurable.
Sometimes, and this is where founders get caught. A technology policy can look right and exclude the exact thing you do. Some technology, cyber and crime wordings exclude or restrict cryptocurrency, virtual currency, digital assets, or the value of those assets. Sometimes it is a named exclusion. Sometimes it sits in how the policy defines money or property.
So you can hold a good cyber policy, get compromised, lose client crypto, and find the policy answers the incident but not the loss.
Insurance does not cover the price going down. It covers assets being taken, systems failing and people suing you.
The short version, in three lines. AUSTRAC applies according to the designated service you provide. Current financial product law may already require licensing today. And the new platform and custody regime starts on 9 April 2027, with transition provisions. Two regulators, two timetables, and the position keeps moving. Everything below was checked in August 2026 and should be confirmed against the regulator before you rely on it.
AUSTRAC regulates anti-money laundering. Its designated services for virtual assets cover five things: exchanging virtual assets for money, exchanging one for another, safekeeping, transferring on a customer's instruction, and participating in certain offers or sales.
Notably, the sole act of issuing a virtual asset is not automatically captured. Issuing a token does not by itself put you inside the AML regime, though what you do around it may. Incidental sending or receiving of virtual assets may also fall outside registration, so assess the actual designated service and the Australian connection.
Three dates matter:
The old digital currency exchange label is gone, replaced by virtual asset service provider, or VASP, meaning a business providing one or more designated services. Existing registered providers were rolled into VASP registration. AUSTRAC also publishes a public VASP register, so you can check a business before dealing with it.
This is a separate question from AML, and it is the one that decides whether you need an Australian Financial Services Licence under current law.
ASIC updated Information Sheet 225 in October 2025 to clarify how existing law applies. Its position is that financial product definitions are broad and technology neutral. The High Court reinforced a substance-over-label approach in the Block Earner appeal, unanimously finding that the fixed-yield product in question was a financial product. That decision did not classify every wallet, stablecoin or custody arrangement.
Classification turns on the rights attached to the token and the service around it, not the technology. Stablecoins, tokenised securities, pooled products, custody and trading arrangements are all more likely to be caught. This is a legal question for your specific model.
The Corporations Amendment (Digital Assets Framework) Act 2026 passed Parliament on 1 April 2026 and received Royal Assent on 8 April 2026. It commences on 9 April 2027.
It creates two categories. A digital asset platform involves an operator possessing digital tokens for or on behalf of clients. A tokenised custody platform involves an operator holding an underlying asset and issuing a digital token that carries a right to redeem or direct delivery of it. Both count as financial products, subject to qualifications and exemptions, which means an AFSL for many platforms and custody providers.
Three things worth knowing:
It is not a blanket requirement. The Act includes a limited platform exemption subject to strict conditions: no financial products held through the platform, no more than $10 million of transactions over 12 months, no more than $5,000 of entry value per client, and notice lodged with ASIC. Those thresholds can be increased later by regulation.
There is a transition. Six months, with continued operation where an application is lodged in that window until ASIC decides it.
The standards are still being built. ASIC can develop asset holding, transaction and settlement standards, and has signalled financial requirements. The final content is not settled yet.
This is the part that changed most recently, so check it before relying on any summary including this one. ASIC issued a class no-action letter in October 2025, alongside the INFO 225 update. It was due to expire on 30 June 2026. On 25 June 2026 ASIC extended it to 30 September 2026 and widened its scope.
A no-action letter is not immunity. ASIC states it does not presently intend to take action, in the circumstances and subject to the conditions set out in the letter. It is not a guarantee, it can be withdrawn, and it does not affect the rights of third parties. The pathways under the extended letter are specific:
Not every general exemption qualifies under the letter, so read the current version rather than a summary. ASIC reported receiving approximately 30 licence applications from digital asset businesses since October 2025.
Registration and licensing status is commonly one of the first things an insurer asks about. That is the practical takeaway from all of the above. Known or admitted unlicensed activity, where a licence is required, creates serious eligibility and exclusion problems. Insurers commonly assess licence and registration status when underwriting. Allegations may be treated differently from final findings.
So three practical positions:
If you are licensed, or have an application lodged, say so early. In our experience it is among the most useful things you can tell a broker.
If you think you may need a licence and do not have one, that is a lawyer conversation before an insurance one.
If you genuinely never needed one, say that clearly and be ready to explain why. Non-custodial businesses often assume they are tainted by association. They usually are not.
If you hold client assets, this is your real exposure, and crypto custody insurance is where the specialist market lives.
Crime or fidelity cover is one of the primary covers to assess, and it is not one thing. Ask how the wording treats each of these separately:
Employee dishonesty, meaning your own people taking client assets. Employee collusion is a significant underwriting exposure.
Third-party computer crime, meaning external attackers.
Social engineering, where someone is tricked into transferring assets. Often carries its own limit, excess or conditions.
Authorised transfers, where a customer instruction turns out to be fraudulent.
Client property liability versus first-party loss, because these sit in different places.
Many crime wordings also require a direct loss, which can matter where the chain of causation is long.
Specie cover protects assets held in a specified secure location rather than answering a liability claim. Digital asset custody or specie solutions may protect against specified losses. Those can include cold storage arrangements, physical theft, private key material and employee collusion. Some structures using multi-party computation can be covered.
These are engineered placements rather than standard SME products. The cover follows your specific custody arrangement rather than a general category.
Three practical questions that shape terms:
What is your hot, warm and cold split? Hot wallets are connected and can transact; cold storage is offline. They may carry different limits, retentions and conditions.
Who can move assets? Signature requirements, withdrawal limits and time delays.
Who else is in the chain? If you use an MPC provider or an outsourced custodian, their compromise can create a first-party loss, a contractual liability or a client claim. The wording needs to reach it.
Custody underwriting is a document exercise. Businesses that can answer these get looked at properly.
Sometimes, and it is genuinely unsettled. There is no established rule, so the answer turns on wording and how the claim is framed.
A coding bug looks more like a professional error. The code did something you did not intend, which is closer to what technology professional indemnity was built for.
An exploit of logic that worked as written is harder to frame. Nobody made a mistake in the traditional sense, which makes causation the argument.
Insurance wordings were written for software you can patch and services you can re-perform. Immutable code sits awkwardly in both.
One sequence, illustrative rather than a real matter. A team deploys a lending protocol. Six months later someone drains a pool using a price oracle the contract trusted, in a way the code permitted. What the team faces immediately is not a court case. It is a forensic investigation to establish what happened, users demanding recovery, a regulator asking questions, and a decision about whether to compensate.
Technology professional indemnity and cyber are the covers to assess, subject to the insured-services definition, the digital asset exclusions and the cause of the incident. Whether either responds turns on four things: whether protocol development sits inside the insured services, how the wording treats an exploit that used the contract as written, whether the oracle counts as a dependency the policy reaches, and whether the lost assets are covered or only the resulting liability.
Four related exposures worth raising with any smart contract insurance discussion: front-end compromise, multisig or governance failure, emergency pause controls, and chain reorganisation or consensus attack.
Few Australian guides explain how these difficulties change the placement process, so here it is straight.
Unlicensed activity where a licence is required. The hardest of the group, for the reasons above.
Custody at scale. Cover exists, but capacity for large asset values commonly involves markets outside Australia, which means longer timelines and different terms.
Token issuance. The exposure sits between securities, technology and reputation, and standard wordings commonly do not contemplate it.
Protocols without a recent independent audit. Security audits are a significant underwriting input, and some insurers require a recent independent one. A clean audit does not guarantee cover. Its absence narrows your options considerably.
Unresolved classification. If you cannot tell an insurer whether your product is a financial product, that uncertainty gets priced in or declined.
Anything touching restricted jurisdictions. Sanctions screening is not optional, and weak screening can materially affect appetite.
It is not a reason to stop asking. Two things are true at once. Parts of this market are hard to place. And a lot of crypto businesses assume they are uninsurable when they are not. Infrastructure providers, analytics tools, compliance software, node operators and developer platforms are often ordinary technology risks. Check the insured-services definition and the digital asset exclusions first. If you never hold client assets, start there rather than from the opposite assumption.
Earlier than in any other tech vertical, because nothing here moves fast.
Before your first client asset. The single biggest change in your risk profile, and the point where your options narrow.
When you register with AUSTRAC, or work out that you need to.
When you lodge an AFSL application. An application in progress is a much better story than nothing.
Before a token launch. Specialist conversation, and it needs lead time.
Before your first institutional counterparty. They will ask for evidence and may specify limits you do not hold.
After your first security audit. A completed independent audit can improve the options available to you.
When you appoint an external director. Appetite for crypto boards can be limited, so start the directors and officers conversation early.
If you become an AFS licensee. Licensees providing financial services to retail clients generally need compensation arrangements. That commonly means adequate professional indemnity cover, or another arrangement ASIC approves. That is a licensing requirement, not just a commercial choice.
For the general picture, see when does a startup need insurance.
Two groups, and the difference matters. Some things sit outside cover or are legally restricted. Others depend entirely on how your policy is written.
The price going down. Market risk is not insurable, and no product in this market changes that.
Deliberate acts by the business. Though crime cover may address dishonest acts by employees, which is a different thing.
Regulatory penalties, in most cases. These may be legally uninsurable, may be excluded, or may be covered only where the law permits. Investigation costs are a separate question and may be available.
Assets you never held or controlled. If a user loses their own keys, that is generally not your policy, though check how the wording defines assets in your care.
Known vulnerabilities. A flaw you were aware of before the policy started.
Lapsed conditions. If an audit or a security control is a policy condition and it slips, that can affect a claim.
Restricted jurisdictions and sanctions breaches.
Prior known circumstances and late notification. Professional indemnity commonly works on a claims-made and notified basis. See claims-made vs occurrence insurance.
If you are comparing digital asset insurance options, these lines decide which is actually better.
Ask your insurer or broker to confirm in writing whether the wording excludes or restricts digital assets, and how a digital asset is defined. Everything else is secondary to that answer.
Ask whether you can get it before you ask what it costs. For a lot of crypto businesses availability is the real constraint, and price only becomes a question once someone is willing to quote.
There is no reliable public benchmark for this market, and any single figure would mislead. What follows is what moves the number.
Whether client assets pass through your control. Nothing else comes close.
Licensing and registration status. Increasingly a gate rather than a discount.
Wallet architecture and controls. Hot versus cold split, signing requirements, withdrawal limits, outsourced dependencies.
Security audit history. Recent, independent and clean beats old and internal.
Asset values at risk.
Jurisdictions served, and how you screen them.
Governance and board experience.
Then the ordinary drivers: revenue, incident and claims history, cover level and limits.
Disclose incidents. Underwriters find them anyway, and finding them later is worse than reading them upfront. For cyber pricing generally, see how much does cyber insurance cost.
Two paths, and knowing which one you are on saves weeks.
Technology insurance review. For non-custodial businesses: infrastructure, tooling, analytics, developer platforms. Technology professional indemnity and cyber can often be arranged for eligible businesses, with the digital asset exclusion checked before you bind.
Specialist broker conversation. For crypto custody insurance, exchange, token issuance and payments. This needs someone who can explain your wallet architecture to an underwriter, and it may need capacity from outside Australia.
Either way, come with your licensing position and your audit reports. In this market those two documents do more for your outcome than anything else you can say.
upcover is a digital-first insurance broker helping Australian small businesses get the right insurance without the paperwork or phone queues. upcover arranges cover for blockchain and crypto businesses and fintechs, including technology professional indemnity, cyber, crime and management liability cover.
Related reading: fintech startup insurance, financial services insurance, the startup insurance guide, and what investors look for.
upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078.
Yes, though crypto startup insurance varies a lot by model. Non-custodial businesses can often be covered through technology professional indemnity and cyber, with the digital asset exclusion checked. Custody, exchanges and token issuers need specialist placement, and some capacity comes from markets outside Australia.
Often not the asset loss itself. Cyber may respond to incident response, forensics, business interruption and third-party claims, while some wordings exclude or restrict the digital assets. Read how the policy defines money and property, and get the position confirmed in writing.
AUSTRAC's virtual asset designated services include exchanging virtual assets for money or for other virtual assets, safekeeping, transferring on a customer's instruction, and participating in certain offers or sales. The sole act of issuing a virtual asset is not automatically captured. Check your specific services against the current AUSTRAC guidance.
It depends on whether your product or service is a financial product under current law, which turns on the rights attached to the token and the service around it. ASIC's Information Sheet 225 sets out its view, and the Digital Assets Framework adds platform and custody categories from April 2027, subject to exemptions. Take legal advice on your model.
For a non-custodial business with no client assets, often days to a couple of weeks. For custody, exchange or token issuance, expect weeks and sometimes longer, because registration status, audit reports and legal opinions all feed the underwriting.
Sometimes, and it is treated differently from cold storage. Hot wallet exposure usually attracts lower sublimits and more conditions, because that is where remote theft happens. Your hot, warm and cold split is one of the first things an underwriter will ask about.
Sometimes, and there is no established rule. A coding bug frames more easily as a professional error than an exploit of logic that worked as written. Check whether protocol development is in your insured services, how admin keys are treated, and whether a current audit is a condition.
Sometimes, and appetite can be limited. Governance quality, licensing position and whether the business holds client assets all affect the answer. Start the conversation before you appoint an external director.
Sometimes, subject to custody controls, and it is a different conversation from insuring client assets. Corporate treasury holdings, funds and institutional structures may be able to arrange cover. Assets held on a third-party exchange raise the question of whose policy responds.
This article is general information only, and the regulatory position was checked in August 2026. It does not take into account your objectives, financial situation or needs, and is not personal advice. It is not legal, financial services licensing, tax or anti-money laundering advice. Australian digital asset regulation is changing quickly and has already changed more than once during 2026: dates, obligations, exemptions and guidance may have moved since this was written. Confirm the current position with ASIC, AUSTRAC or a qualified adviser before relying on any summary here, and note that whether your business requires registration or a licence is a legal question specific to your activities. Insurance market observations describe common practice rather than universal rules, and cover, limits, inclusions, exclusions and endorsements vary between insurers, so read the relevant policy wording, schedule, endorsements and any Product Disclosure Statement where applicable before deciding whether a product suits you. upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078, and arranges insurance with selected insurers and underwriters rather than the whole market.
We are digitising commercial insurance and risk management for small, mid-market and technology businesses. We work with a global network of underwriters, challenging legacy brokers and delivering market leading coverage to our customers.