Published October 2026.
Direct answer: Theft of cryptocurrency and other digital assets is rarely covered by a standalone cyber policy alone; recovery usually depends on crime or fidelity forms, specialized custody insurance for held assets, and explicit social-engineering or funds-transfer fraud endorsements when deepfake voice or video authorizes a wire. Intellectual property theft sits in a different coverage tower from cyber theft of data or credentials. Standard cyber, crime, and D&O programs leave predictable gaps—voluntary parting, uninsured custodial failure, and pure IP misappropriation—unless limits and endorsements are mapped to how assets are actually held and how payments are authorized.
For how carriers are pricing impersonation and AI-driven fraud alongside cyber limits, see Cyber Insurance Market Evolution: AI-Driven Threats, Deepfake (2026).
Why digital asset losses split across policy types
Insurers classify most digital losses by the mechanism of harm and the type of property, not by the label on the asset. Unauthorized access that leads to ransomware or data exfiltration triggers cyber insuring agreements built for privacy liability, forensics, and business interruption. Theft of private keys, drained exchange accounts, or fraudulent instructions that cause an employee to send coins or cash to a thief usually routes through crime, fidelity, or financial institution bonds—or through nothing at all if the form excludes digital currency or treats the loss as voluntary transfer.
The same incident can produce a denied cyber claim and a contested crime claim depending on whether the carrier defines the loss as computer fraud or social engineering. Documenting custody arrangements, who holds keys, and who can authorize outbound transfers is the starting point for any risk assessment that includes digital assets.
Crime and fidelity: when they respond to crypto theft
Commercial crime policies and fidelity bonds cover employee theft, forgery, and computer fraud that causes direct loss of money, securities, or other property. Digital assets enter the picture when the insuring agreement or endorsement expressly includes virtual currency, digital tokens, or property held in electronic form, and when the loss fits a covered peril rather than an excluded voluntary parting.
Computer fraud and funds transfer fraud
Computer fraud coverage typically requires that an unauthorized party manipulate an insured’s computer system to cause a transfer. Social engineering coverage, when bought, responds when a thief deceives an employee into sending funds without hacking the system. Crypto thefts after phishing or malware that captures wallet credentials may align with computer fraud if the policy treats the transaction as system-directed; losses where an employee sends assets to a fraudulent address after a convincing call often fall under social engineering or fall outside coverage entirely.
Carriers differ on whether stolen cryptocurrency qualifies as money or securities. Some forms schedule digital assets with sublimits and require proof of ownership, wallet addresses, and blockchain tracing in the proof of loss. Others exclude virtual currency or cap recovery at a nominal amount. Read the definition section and any digital asset endorsement on the crime part of your commercial insurance program.
Fidelity and employee dishonesty
Fidelity coverage responds when a covered person steals the insured’s property. If an employee misappropriates keys or abuses access to a corporate wallet, fidelity may respond subject to discovery periods, retention, and exclusions for trading or speculative activity. Treasury teams holding crypto need alignment between fidelity, crime, and any D&O tower so one set of facts does not fall between asset theft and management liability.
Custody insurance for exchanges, funds, and custodians
Organizations that do not self-custody rely on exchanges, qualified custodians, or fund administrators. Custody insurance—often placed by the custodian—covers specified causes of loss to assets in the custodian’s care, such as theft or insider abuse, subject to cold versus hot wallet limits, aggregate caps, and exclusions for smart contract bugs or protocol failure unless specifically bought.
End customers and limited partners should not assume a custodian’s policy names them as insureds or that a platform loss automatically creates a claim they can file. Contracts may allocate recovery to the custodian’s insurer with pass-through only by agreement. Corporate treasurers should obtain certificates and clarity on whether their own crime coverage responds when third-party insurance falls short.
Deepfake social engineering and which endorsements respond
Deepfake-driven fraud uses synthetic voice or video to impersonate an executive, vendor, or counsel and authorize urgent transfers. Insurers generally classify these losses as impersonation or social engineering, not as network intrusion under a standard cyber insuring agreement. A cyber policy may offer no coverage, or a low sublimit for fraudulent instruction, unless a dedicated endorsement is bound and its warranties are met.
Social-engineering endorsements versus cyber forms
Social-engineering fraud endorsements on crime or cyber manuscripts typically cover loss caused by reliance on fraudulent instructions that appear to come from a trusted source, sometimes including executive impersonation. They often require dual authorization, callback to a verified number, and thresholds for new payees. Deepfake-specific language remains uneven in 2026; compare whether the endorsement mentions synthetic media or voice cloning rather than limiting the medium to email alone.
Cyber policies that advertise funds transfer fraud may share sublimits with phishing or exclude voluntary transfers after a live conversation. Many programs pair cyber with a crime social-engineering limit rather than assuming one tower covers system compromise and human deception.
Claims handling for impersonation losses
These claims turn on authorization records and whether controls matched policy warranties. Preserving recordings, chat logs, email threads, and bank confirmations from the first hour supports coverage analysis and law enforcement referral. The FBI Internet Crime Complaint Center at ic3.gov accepts business email compromise and related fraud reports; carriers still apply policy terms regardless. Align notice and documentation with claims management practice and expect scrutiny consistent with how carriers evaluate and adjust financial loss claims.
Intellectual property theft versus cyber theft of data
Stealing source code, trade secrets, product designs, or media IP is not the same insuring problem as stealing customer PII or deploying ransomware. Cyber policies focus on privacy events, security failures, and response costs; they typically do not replace an IP enforcement remedy when a competitor obtains CAD files or unreleased content.
IP insurance towers—media liability, IP infringement defense, and specialty trade secret programs where available—address different triggers: alleged infringement liability, defense costs, and sometimes loss of exclusivity or contractual indemnities. A breach that exfiltrates IP may trigger cyber forensics while leaving the economic harm of copied designs uninsured under cyber unless a separate endorsement addresses trade secret theft.
Where standard cyber, crime, and D&O policies do not respond
Cyber policies often exclude or severely sublimit criminal fraud, voluntary parting of property, and loss of digital currency unless endorsed. Crime policies may exclude blockchain protocol failures, depegging, or smart contract exploits when no theft by a covered person or computer fraud is established. D&O responds to shareholder and securities claims against directors and officers; it is not a substitute for crime coverage when treasury loses assets to a third-party scam.
General liability rarely covers pure financial loss from fraud; CGL occurrence-based coverage targets bodily injury and property damage to third parties, not a company’s own stolen digital assets. Property policies insure tangible property at scheduled locations; digital assets without explicit scheduling sit outside typical building and contents forms. Umbrella and excess layers follow underlying insuring agreements; raising cyber limits does not fill a crime social-engineering hole if the underlying crime form excludes the loss.
War and infrastructure exclusions on cyber forms may affect state-sponsored wallet draining disputes centered on attribution language. Custodial insolvency or exchange bankruptcy is a credit problem, not a theft claim, unless policies address failure of a named custodian.
Building a coherent 2026 coverage map
Start with an asset ledger: self-custodied keys, custodian-held assets, treasury workflow for outbound payments, and IP repositories that would cause material harm if copied. Match each row to crime, fidelity, custody certificates, cyber, and IP towers. Bind social-engineering or fraudulent instruction limits that reflect the largest plausible single transfer. Require endorsement language that fits how your organization authorizes wires after live calls or video conferences.
At renewal, reconcile fraud endorsement warranties with written payment procedures. Mismatch is a common basis for reservation of rights. Specialty markets offer digital asset crime extensions and enhanced impersonation limits with higher retentions; read exclusions on every form in the stack.
Frequently Asked Questions
Does a commercial crime policy cover stolen cryptocurrency?
It can, but only when the policy or a digital asset endorsement defines virtual currency as covered property and the facts match a covered peril such as employee theft, computer fraud, or a bound social-engineering insuring agreement. Many standard crime forms exclude cryptocurrency entirely or treat it under a low sublimit. Voluntary transfers to a fraudster after impersonation are often excluded unless a social-engineering endorsement responds and policy warranties were followed.
What is digital asset custody insurance?
Custody insurance is coverage typically purchased by exchanges, custodians, or fund administrators to protect digital assets held on behalf of clients against specified causes of loss, such as theft or insider dishonesty, subject to wallet-type limits and policy exclusions. End asset owners are not automatically insured unless contracts and policy structure name them or pass recovery through. Relying on a platform’s marketing claim of “insured” without reading certificates and limits creates a common gap.
Will a standard cyber policy pay for a deepfake wire transfer?
Often no, or only within a narrow fraud sublimit if one exists. Deepfake-enabled transfers are usually treated as social engineering or fraudulent instruction rather than network security failure. Meaningful coverage generally requires a crime or cyber social-engineering or funds-transfer fraud endorsement, with out-of-band verification and dual-control requirements commonly attached as conditions.
How is intellectual property theft different from cyber theft in insurance terms?
Cyber insurance centers on security incidents, privacy obligations, and related response costs when data is accessed or held for ransom. Intellectual property theft concerns misappropriation of trade secrets, designs, code, or content and the economic or legal consequences of unauthorized use. Exfiltration of IP may trigger cyber response costs while leaving the core IP loss uninsured under cyber unless separate IP or trade secret coverage applies.
What do standard policies typically exclude for digital asset losses?
Common exclusions and gaps include unendorsed virtual currency, voluntary parting with property after deception, smart contract or protocol failures without traditional theft, custodial insolvency, and pure financial loss under general liability. Cyber war and infrastructure exclusions may also apply depending on attribution language. D&O does not replace crime coverage for treasury losses caused by third-party fraud.
How should we structure coverage for crypto and impersonation fraud?
Inventory where assets sit and who can move them, then align crime and fidelity limits with digital asset endorsements where needed, confirm custodian insurance and contractual pass-through, and bind social-engineering or fraudulent instruction limits sized to maximum single transfers. Keep cyber for network and privacy events, add IP coverage for trade secret and media exposures, and verify that excess layers follow underlying fraud insuring agreements rather than assuming one cyber tower covers all digital loss.