Small Businesses
Tech Companies
Motor & Fleet
Insurance Basics

What insurance do crypto and Web3 businesses need in Australia?

August 7, 2026
a list item
15 Mins Read
What insurance do crypto and Web3 businesses need in Australia?

Crypto businesses do not fail in one direction. A single incident can produce several separate losses at once: client assets gone, incident response costs, client lawsuits, regulatory scrutiny, and claims against your directors.

That is why crypto startup insurance is usually a stack rather than a policy. And it is why the most common mistake is holding a technology policy that covers the system failure but excludes the digital asset loss. upcover arranges blockchain insurance in Australia and crypto business insurance for blockchain and crypto businesses, as a Corporate Authorised Representative of an AFSL holder.

What insurance can crypto businesses get in Australia?

Six covers do most of the work. Which of them you can get, and how easily, depends mostly on whether client assets pass through your control.

  • Technology professional indemnity for claims that your software or service caused a client financial loss. The starting point for most non-custodial businesses
  • Cyber for the incident itself: forensics, restoration, business interruption and third-party privacy claims
  • Crime or fidelity for theft, including by your own people. Central where you hold assets
  • Digital asset custody or specie for specified losses involving client assets and private key material. Specialist, and often engineered rather than off the shelf
  • Directors and officers, or management liability for claims against the people running the business
  • Financial institutions professional indemnity where you are a licensed financial services business

No single policy covers that whole stack. Technology PI and cyber are often available in a combined technology wording. Crime and digital asset custody may require separate sections, endorsements or policies. Web3 insurance and digital asset insurance are descriptions rather than products. Both phrases cover combinations of the above. What you can actually arrange depends on your model, your controls and your licensing position.

Do you hold client crypto, or only build the technology?

This is the biggest fork in crypto insurance. It is not the only question that matters, but it changes more than any other single fact about your business.

What you do The regulatory question Where insurance starts
Infrastructure, nodes, RPC Usually none new, but check the service Technology PI and cyber
Analytics or compliance tooling Usually none new Technology PI and cyber
Wallet software without key control Depends whether you can move assets Technology PI and cyber
Protocol or smart contract developer Depends what the protocol does Technology PI, with wording checks
Staking or validator operations Depends on the arrangement Technology PI, plus slashing exposure
NFT or token platform Is the product a financial product? Depends on the answer
Token issuer Depends on the token's rights and structure Specialist, legal advice first
Payments or fiat on-ramp AML and payments rules apply Specialist, licensing first
Exchange or trading platform Licensing, and client asset holding Crypto exchange insurance is a specialist placement, licensing first
Custodian or wallet provider Are you holding client assets? Specialist, crime and custody
Business holding its own treasury Usually none Crime and cyber, subject to controls

Swipe left or right to see the full table.

Why this one question dominates

Because custody can change three things at once, which is unusual in technology.

It changes your regulator. Holding client assets pulls you toward financial services licensing and, depending on the service, AML registration. Building software usually does not.

It changes what you can lose. A software failure costs a client money. Losing client assets means the loss is the asset itself, which most technology wordings were never built to answer.

It changes your insurance market. Non-custodial risk sits with insurers who write technology every day. Client asset risk sits with a much smaller group, sometimes outside Australia.

That is why an insurer asks about custody before almost anything else. It tells them which of those three worlds you are in.

Custody is the biggest fork, but it is not the only regulatory question. Token issuance, advice, staking, transfers and financial product features can all matter even where you never hold a client's assets. Not sure which row you are in? Talk it through with upcover before you assume you are uninsurable.

Does cyber or technology PI cover stolen crypto?

Sometimes, and this is where founders get caught. A technology policy can look right and exclude the exact thing you do. Some technology, cyber and crime wordings exclude or restrict cryptocurrency, virtual currency, digital assets, or the value of those assets. Sometimes it is a named exclusion. Sometimes it sits in how the policy defines money or property.

So you can hold a good cyber policy, get compromised, lose client crypto, and find the policy answers the incident but not the loss.

Four questions, and get the answers in writing

  1. Does this wording exclude or restrict digital assets? If so, how is a digital asset defined, because some definitions are narrow and some catch everything.
  2. How does this wording treat a crypto asset? As money, as property, or as neither. This is about the policy definition, not how Australian law classifies it, and it decides which section responds.
  3. Does the insured-services definition cover what we build? Protocol development and smart contract work are often not inside a standard software wording.
  4. Is loss of the asset covered, or only loss of value? Not the same thing, and the difference matters more in crypto than anywhere else.
Your exposure What a standard policy may say What to ask for
Client assets stolen Digital assets excluded or restricted Crime and custody cover
Private key compromised May be a cyber event, may be excluded Explicit key compromise wording
Smart contract exploited Often not contemplated Protocol development in insured services
Employee takes client assets Often outside cyber Crime cover including employee dishonesty
Regulator investigates you Sometimes a sublimit Regulatory investigation costs
Token price falls Not insurable Nothing. This is market risk
A protocol you depend on fails Usually silent Dependent provider wording

Swipe left or right to see the full table.

Insurance does not cover the price going down. It covers assets being taken, systems failing and people suing you.

What crypto rules apply in Australia in 2026?

The short version, in three lines. AUSTRAC applies according to the designated service you provide. Current financial product law may already require licensing today. And the new platform and custody regime starts on 9 April 2027, with transition provisions. Two regulators, two timetables, and the position keeps moving. Everything below was checked in August 2026 and should be confirmed against the regulator before you rely on it.

Which services require AUSTRAC registration?

AUSTRAC regulates anti-money laundering. Its designated services for virtual assets cover five things: exchanging virtual assets for money, exchanging one for another, safekeeping, transferring on a customer's instruction, and participating in certain offers or sales.

Notably, the sole act of issuing a virtual asset is not automatically captured. Issuing a token does not by itself put you inside the AML regime, though what you do around it may. Incidental sending or receiving of virtual assets may also fall outside registration, so assess the actual designated service and the Australian connection.

Three dates matter:

  • 31 March 2026 — reforms commenced for existing reporting entities, and registered digital currency exchanges were rolled into VASP registration
  • 1 July 2026 — obligations began for newly regulated virtual asset services, including Travel Rule requirements
  • 29 July 2026 — newly regulated providers needed to apply by this date to keep operating while AUSTRAC considered the application

The old digital currency exchange label is gone, replaced by virtual asset service provider, or VASP, meaning a business providing one or more designated services. Existing registered providers were rolled into VASP registration. AUSTRAC also publishes a public VASP register, so you can check a business before dealing with it.

Is your token, wallet or platform a financial product?

This is a separate question from AML, and it is the one that decides whether you need an Australian Financial Services Licence under current law.

ASIC updated Information Sheet 225 in October 2025 to clarify how existing law applies. Its position is that financial product definitions are broad and technology neutral. The High Court reinforced a substance-over-label approach in the Block Earner appeal, unanimously finding that the fixed-yield product in question was a financial product. That decision did not classify every wallet, stablecoin or custody arrangement.

Classification turns on the rights attached to the token and the service around it, not the technology. Stablecoins, tokenised securities, pooled products, custody and trading arrangements are all more likely to be caught. This is a legal question for your specific model.

What does the 2027 Digital Assets Framework change?

The Corporations Amendment (Digital Assets Framework) Act 2026 passed Parliament on 1 April 2026 and received Royal Assent on 8 April 2026. It commences on 9 April 2027.

It creates two categories. A digital asset platform involves an operator possessing digital tokens for or on behalf of clients. A tokenised custody platform involves an operator holding an underlying asset and issuing a digital token that carries a right to redeem or direct delivery of it. Both count as financial products, subject to qualifications and exemptions, which means an AFSL for many platforms and custody providers.

Three things worth knowing:

It is not a blanket requirement. The Act includes a limited platform exemption subject to strict conditions: no financial products held through the platform, no more than $10 million of transactions over 12 months, no more than $5,000 of entry value per client, and notice lodged with ASIC. Those thresholds can be increased later by regulation.

There is a transition. Six months, with continued operation where an application is lodged in that window until ASIC decides it.

The standards are still being built. ASIC can develop asset holding, transaction and settlement standards, and has signalled financial requirements. The final content is not settled yet.

What is ASIC's current no-action position?

This is the part that changed most recently, so check it before relying on any summary including this one. ASIC issued a class no-action letter in October 2025, alongside the INFO 225 update. It was due to expire on 30 June 2026. On 25 June 2026 ASIC extended it to 30 September 2026 and widened its scope.

A no-action letter is not immunity. ASIC states it does not presently intend to take action, in the circumstances and subject to the conditions set out in the letter. It is not a guarantee, it can be withdrawn, and it does not affect the rights of third parties. The pathways under the extended letter are specific:

  • Apply for or vary an AFSL by 30 September 2026
  • Operate under, or enter, an eligible authorised representative arrangement with an AFS licence holder
  • Use an eligible intermediary authorisation arrangement
  • For market or clearing and settlement licensing, satisfy the notification and pre-meeting conditions

Not every general exemption qualifies under the letter, so read the current version rather than a summary. ASIC reported receiving approximately 30 licence applications from digital asset businesses since October 2025.

What this means for your insurance

Registration and licensing status is commonly one of the first things an insurer asks about. That is the practical takeaway from all of the above. Known or admitted unlicensed activity, where a licence is required, creates serious eligibility and exclusion problems. Insurers commonly assess licence and registration status when underwriting. Allegations may be treated differently from final findings.

So three practical positions:

If you are licensed, or have an application lodged, say so early. In our experience it is among the most useful things you can tell a broker.

If you think you may need a licence and do not have one, that is a lawyer conversation before an insurance one.

If you genuinely never needed one, say that clearly and be ready to explain why. Non-custodial businesses often assume they are tainted by association. They usually are not.

How do you insure crypto custody and private keys?

If you hold client assets, this is your real exposure, and crypto custody insurance is where the specialist market lives.

Crime and fidelity

Crime or fidelity cover is one of the primary covers to assess, and it is not one thing. Ask how the wording treats each of these separately:

Employee dishonesty, meaning your own people taking client assets. Employee collusion is a significant underwriting exposure.

Third-party computer crime, meaning external attackers.

Social engineering, where someone is tricked into transferring assets. Often carries its own limit, excess or conditions.

Authorised transfers, where a customer instruction turns out to be fraudulent.

Client property liability versus first-party loss, because these sit in different places.

Many crime wordings also require a direct loss, which can matter where the chain of causation is long.

Cold storage and specie

Specie cover protects assets held in a specified secure location rather than answering a liability claim. Digital asset custody or specie solutions may protect against specified losses. Those can include cold storage arrangements, physical theft, private key material and employee collusion. Some structures using multi-party computation can be covered.

These are engineered placements rather than standard SME products. The cover follows your specific custody arrangement rather than a general category.

Hot wallets, MPC and outsourced custody

Three practical questions that shape terms:

What is your hot, warm and cold split? Hot wallets are connected and can transact; cold storage is offline. They may carry different limits, retentions and conditions.

Who can move assets? Signature requirements, withdrawal limits and time delays.

Who else is in the chain? If you use an MPC provider or an outsourced custodian, their compromise can create a first-party loss, a contractual liability or a client claim. The wording needs to reach it.

What an insurer will ask about

  • Wallet architecture, hot, warm and cold
  • Key management, and how many signatures move assets
  • Whether you use multi-party computation or hardware security modules
  • Omnibus versus segregated wallets
  • Outsourced custody arrangements and provider dependencies
  • Recovery and key ceremony procedures
  • Withdrawal limits and time delays
  • Security audit reports, and how recent they are
  • Maximum asset values at risk
  • Sanctions and jurisdiction screening

Custody underwriting is a document exercise. Businesses that can answer these get looked at properly.

Does insurance cover smart contract exploits?

Sometimes, and it is genuinely unsettled. There is no established rule, so the answer turns on wording and how the claim is framed.

A coding bug looks more like a professional error. The code did something you did not intend, which is closer to what technology professional indemnity was built for.

An exploit of logic that worked as written is harder to frame. Nobody made a mistake in the traditional sense, which makes causation the argument.

Insurance wordings were written for software you can patch and services you can re-perform. Immutable code sits awkwardly in both.

How this plays out

One sequence, illustrative rather than a real matter. A team deploys a lending protocol. Six months later someone drains a pool using a price oracle the contract trusted, in a way the code permitted. What the team faces immediately is not a court case. It is a forensic investigation to establish what happened, users demanding recovery, a regulator asking questions, and a decision about whether to compensate.

Technology professional indemnity and cyber are the covers to assess, subject to the insured-services definition, the digital asset exclusions and the cause of the incident. Whether either responds turns on four things: whether protocol development sits inside the insured services, how the wording treats an exploit that used the contract as written, whether the oracle counts as a dependency the policy reaches, and whether the lost assets are covered or only the resulting liability.

Six things to check

  1. Is protocol development in your insured services? A wording covering software development may not reach deploying contracts that hold value.
  2. How are admin and governance keys treated? A compromised admin key is a different claim from a contract flaw.
  3. What about upgradeable contracts? Who can push an upgrade, and under what controls.
  4. Oracles and bridges. These are dependencies you do not control, and most wordings are silent on them.
  5. Is an audit a condition, or just a question? If a current audit is a condition, a lapsed one becomes a coverage problem rather than only a governance one.
  6. Loss of asset versus loss of value. After an exploit you usually have both, and only one is normally insurable.

Four related exposures worth raising with any smart contract insurance discussion: front-end compromise, multisig or governance failure, emergency pause controls, and chain reorganisation or consensus attack.

Which crypto businesses are hardest to insure?

Few Australian guides explain how these difficulties change the placement process, so here it is straight.

Unlicensed activity where a licence is required. The hardest of the group, for the reasons above.

Custody at scale. Cover exists, but capacity for large asset values commonly involves markets outside Australia, which means longer timelines and different terms.

Token issuance. The exposure sits between securities, technology and reputation, and standard wordings commonly do not contemplate it.

Protocols without a recent independent audit. Security audits are a significant underwriting input, and some insurers require a recent independent one. A clean audit does not guarantee cover. Its absence narrows your options considerably.

Unresolved classification. If you cannot tell an insurer whether your product is a financial product, that uncertainty gets priced in or declined.

Anything touching restricted jurisdictions. Sanctions screening is not optional, and weak screening can materially affect appetite.

It is not a reason to stop asking. Two things are true at once. Parts of this market are hard to place. And a lot of crypto businesses assume they are uninsurable when they are not. Infrastructure providers, analytics tools, compliance software, node operators and developer platforms are often ordinary technology risks. Check the insured-services definition and the digital asset exclusions first. If you never hold client assets, start there rather than from the opposite assumption.

When should a crypto startup arrange insurance?

Earlier than in any other tech vertical, because nothing here moves fast.

Before your first client asset. The single biggest change in your risk profile, and the point where your options narrow.

When you register with AUSTRAC, or work out that you need to.

When you lodge an AFSL application. An application in progress is a much better story than nothing.

Before a token launch. Specialist conversation, and it needs lead time.

Before your first institutional counterparty. They will ask for evidence and may specify limits you do not hold.

After your first security audit. A completed independent audit can improve the options available to you.

When you appoint an external director. Appetite for crypto boards can be limited, so start the directors and officers conversation early.

If you become an AFS licensee. Licensees providing financial services to retail clients generally need compensation arrangements. That commonly means adequate professional indemnity cover, or another arrangement ASIC approves. That is a licensing requirement, not just a commercial choice.

For the general picture, see when does a startup need insurance.

What does crypto insurance not cover?

Two groups, and the difference matters. Some things sit outside cover or are legally restricted. Others depend entirely on how your policy is written.

Generally outside cover or legally restricted

The price going down. Market risk is not insurable, and no product in this market changes that.

Deliberate acts by the business. Though crime cover may address dishonest acts by employees, which is a different thing.

Regulatory penalties, in most cases. These may be legally uninsurable, may be excluded, or may be covered only where the law permits. Investigation costs are a separate question and may be available.

Depends on your wording

Assets you never held or controlled. If a user loses their own keys, that is generally not your policy, though check how the wording defines assets in your care.

Known vulnerabilities. A flaw you were aware of before the policy started.

Lapsed conditions. If an audit or a security control is a policy condition and it slips, that can affect a claim.

Restricted jurisdictions and sanctions breaches.

Prior known circumstances and late notification. Professional indemnity commonly works on a claims-made and notified basis. See claims-made vs occurrence insurance.

How do you compare crypto insurance policies?

If you are comparing digital asset insurance options, these lines decide which is actually better.

What to check Why it matters
Is there a digital asset exclusion or restriction, and how is a digital asset defined? The most consequential clause in this market
How does the wording treat a crypto asset: money, property or neither? Decides which section responds
Does the insured-services definition cover protocol and smart contract work? Software wordings often stop short
Is loss of asset covered, or only loss of value? After an exploit you usually have both
How does crime cover treat employee dishonesty, computer crime and social engineering? Three different things, often three different limits
Is electronic theft covered, not just physical? Where hot wallet attacks land
What sublimits apply to hot versus cold storage? Often very different numbers
Are outsourced custody and MPC provider failures reached? Their compromise is your loss
Is a current audit a condition of cover? A lapsed audit becomes a coverage problem
Is licensing or registration a condition or a warranty? Determines what happens if your status changes
Are defence costs inside or outside the limit? Inside, defence spend reduces what is left
How are related claims aggregated? One exploit can generate many claims
Are regulatory investigation costs included, and at what limit? Separate from penalties
Territory and sanctions screening Serving restricted jurisdictions can end cover
Retroactive date and continuous cover Exploits surface long after deployment

Swipe left or right to see the full table.

If you only do one thing

Ask your insurer or broker to confirm in writing whether the wording excludes or restricts digital assets, and how a digital asset is defined. Everything else is secondary to that answer.

How much does crypto insurance cost in Australia?

Ask whether you can get it before you ask what it costs. For a lot of crypto businesses availability is the real constraint, and price only becomes a question once someone is willing to quote.

There is no reliable public benchmark for this market, and any single figure would mislead. What follows is what moves the number.

Factors that drives the price for crypto insurance cost in Australia

Whether client assets pass through your control. Nothing else comes close.

Licensing and registration status. Increasingly a gate rather than a discount.

Wallet architecture and controls. Hot versus cold split, signing requirements, withdrawal limits, outsourced dependencies.

Security audit history. Recent, independent and clean beats old and internal.

Asset values at risk.

Jurisdictions served, and how you screen them.

Governance and board experience.

Then the ordinary drivers: revenue, incident and claims history, cover level and limits.

What information do you need for a crypto insurance quote?

  • What you do, in one paragraph, without jargon
  • Whether client assets pass through your control, and how
  • Ownership and entity structure, including any foundation or offshore entity
  • AUSTRAC registration status
  • Licensing position, and any legal classification advice you hold
  • Wallet architecture and key management
  • Outsourced custody or MPC providers, and recovery procedures
  • Staking arrangements, if any
  • Security audit reports, with dates
  • Asset values at risk
  • Countries served, and sanctions screening
  • Board and governance detail
  • Any incidents, claims or exploits, including near misses

Disclose incidents. Underwriters find them anyway, and finding them later is worse than reading them upfront. For cyber pricing generally, see how much does cyber insurance cost.

How can upcover help crypto and Web3 businesses?

Two paths, and knowing which one you are on saves weeks.

Technology insurance review. For non-custodial businesses: infrastructure, tooling, analytics, developer platforms. Technology professional indemnity and cyber can often be arranged for eligible businesses, with the digital asset exclusion checked before you bind.

Specialist broker conversation. For crypto custody insurance, exchange, token issuance and payments. This needs someone who can explain your wallet architecture to an underwriter, and it may need capacity from outside Australia.

Either way, come with your licensing position and your audit reports. In this market those two documents do more for your outcome than anything else you can say.

upcover is a digital-first insurance broker helping Australian small businesses get the right insurance without the paperwork or phone queues. upcover arranges cover for blockchain and crypto businesses and fintechs, including technology professional indemnity, cyber, crime and management liability cover.

  • Access to 80+ insurance partners, including specialist and agency markets
  • 70,000+ Australian businesses covered
  • 4.9/5 customer rating
  • Instant Certificate of Currency on policy confirmation for eligible policies

Related reading: fintech startup insurance, financial services insurance, the startup insurance guide, and what investors look for.

upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078.

Frequently asked questions

Can crypto businesses get insurance in Australia?

Yes, though crypto startup insurance varies a lot by model. Non-custodial businesses can often be covered through technology professional indemnity and cyber, with the digital asset exclusion checked. Custody, exchanges and token issuers need specialist placement, and some capacity comes from markets outside Australia.

Does cyber insurance cover stolen cryptocurrency?

Often not the asset loss itself. Cyber may respond to incident response, forensics, business interruption and third-party claims, while some wordings exclude or restrict the digital assets. Read how the policy defines money and property, and get the position confirmed in writing.

Which crypto services require AUSTRAC registration?

AUSTRAC's virtual asset designated services include exchanging virtual assets for money or for other virtual assets, safekeeping, transferring on a customer's instruction, and participating in certain offers or sales. The sole act of issuing a virtual asset is not automatically captured. Check your specific services against the current AUSTRAC guidance.

Do I need an AFSL for a crypto business?

It depends on whether your product or service is a financial product under current law, which turns on the rights attached to the token and the service around it. ASIC's Information Sheet 225 sets out its view, and the Digital Assets Framework adds platform and custody categories from April 2027, subject to exemptions. Take legal advice on your model.

How long does crypto insurance take to arrange?

For a non-custodial business with no client assets, often days to a couple of weeks. For custody, exchange or token issuance, expect weeks and sometimes longer, because registration status, audit reports and legal opinions all feed the underwriting.

Can you insure crypto held in hot wallets?

Sometimes, and it is treated differently from cold storage. Hot wallet exposure usually attracts lower sublimits and more conditions, because that is where remote theft happens. Your hot, warm and cold split is one of the first things an underwriter will ask about.

Does insurance cover a smart contract exploit?

Sometimes, and there is no established rule. A coding bug frames more easily as a professional error than an exploit of logic that worked as written. Check whether protocol development is in your insured services, how admin keys are treated, and whether a current audit is a condition.

Is directors and officers cover available for crypto boards?

Sometimes, and appetite can be limited. Governance quality, licensing position and whether the business holds client assets all affect the answer. Start the conversation before you appoint an external director.

Can a business insure crypto it holds on its own balance sheet?

Sometimes, subject to custody controls, and it is a different conversation from insuring client assets. Corporate treasury holdings, funds and institutional structures may be able to arrange cover. Assets held on a third-party exchange raise the question of whose policy responds.

This article is general information only, and the regulatory position was checked in August 2026. It does not take into account your objectives, financial situation or needs, and is not personal advice. It is not legal, financial services licensing, tax or anti-money laundering advice. Australian digital asset regulation is changing quickly and has already changed more than once during 2026: dates, obligations, exemptions and guidance may have moved since this was written. Confirm the current position with ASIC, AUSTRAC or a qualified adviser before relying on any summary here, and note that whether your business requires registration or a licence is a legal question specific to your activities. Insurance market observations describe common practice rather than universal rules, and cover, limits, inclusions, exclusions and endorsements vary between insurers, so read the relevant policy wording, schedule, endorsements and any Product Disclosure Statement where applicable before deciding whether a product suits you. upcover Pty Ltd ABN 17 628 197 437 is a Corporate Authorised Representative (CAR 1299211) of Experience Insurance Services Pty Ltd ABN 41 657 596 506, AFSL 539078, and arranges insurance with selected insurers and underwriters rather than the whole market.

We are digitising commercial insurance and risk management for small, mid-market and technology businesses. We work with a global network of underwriters, challenging legacy brokers and delivering market leading coverage to our customers.