Skip to content
Reading depth

Each view includes the earlier layers; the complete engineer or auditor page is shown by default.

DeFi insurance or cover exchanges a premium for a conditional payout claim tied to specified loss events, exclusions, limits, assessment, and available capital.

Warning cross category cue

DeFi insurance or cover turns a defined loss exposure into a conditional payout claim funded by premiums and risk capital.

Users and protocols may not want to retain the full loss from a contract exploit, custody failure, depeg, or other specified event. A cover system pools or allocates capital and states when that capital should compensate a claimant.

Mutual or specialty insurance is a useful analogy. It can be legally inaccurate: some products are discretionary mutual cover or parametric smart contracts, and rights vary by wording, entity, membership, and jurisdiction. On-chain claims may depend on oracle values, governance votes, assessors, staking pools, or contract state, while the capital pool can hold risky crypto assets.

Buyers pay premiums and hold cover positions. Capital providers or stakers bear accepted losses and may earn premiums or rewards. Assessors, oracles, committees, or governance decide whether conditions hold. The cover claim is distinct from the underlying asset and from capital-provider ownership. Its value depends on wording, evidence, assessment, limits, exclusions, solvency, and payout access.

  1. Define covered product, beneficiary, event, exclusions, amount, asset, period, evidence, assessment, and limits.
  2. Price capacity and collect a premium from the buyer.
  3. Allocate capital from underwriters, stakers, a mutual pool, or a reserve.
  4. Let the holder submit evidence after a claimed loss.
  5. Apply oracle, assessor, governance, or deterministic trigger rules.
  6. If accepted, reduce remaining cover and transfer the payout from available capital under the stated queue and priority.

Capital flow moves premiums and risk capital into accepted payouts. Claim flow starts when cover is issued and ends through expiry, cancellation, or payout. Return flow pays capital providers from buyer premiums and sometimes token issuance. Control flow follows product wording, assessment, governance, pause, and upgrade roles. Risk flow reaches claimants when coverage is excluded, disputed, undercapitalized, illiquid, or legally unenforceable.

Cover does not eliminate risk; it reallocates a specified part. The buyer pays the premium, capital providers earn it for bearing risk, and claimants retain excluded, excess, disputed, delayed, or insolvent loss.

Read what event is covered, for how much, during which dates, who decides, and what capital pays. The word “insurance” alone does not guarantee a payout.

Review wording, membership or eligibility, claim evidence, assessment incentives, waiting and appeal periods, capacity, capital assets, correlated exposure, reinsurance, limits, exclusions, payout liquidity, legal entity, jurisdiction, and governance.

Nexus Mutual is one protocol-specific design in which a buyer purchases cover, claims enter assessment, and accepted payouts interact with cover and pooled capital contracts. Its membership, product wording, staking, voting, and claim rules are specific to that system; do not generalize them to all cover products.

Bind cover identity, beneficiary, asset, amount, period, trigger, evidence, and remaining limit. Test duplicate claims, ownership transfer, expiry boundaries, partial payouts, assessment manipulation, oracle failure, capital correlation, queue exhaustion, pause, upgrade, and insolvency.

  • “Buying cover removes the risk.” Exclusions, limits, assessment, liquidity, and counterparty solvency remain.
  • “On-chain cover is automatically regulated insurance.” Legal characterization depends on the actual product and jurisdiction.
  • “A capital pool guarantees full payment.” Correlated claims and asset losses can exhaust available capital.

Read asset versus claim and governance. Continue to solvency risk and oracle risk to inspect payout dependencies.

  • Nexus Mutual, Cover contract documentation — one protocol-specific cover purchase and capital-allocation interface (accessed 2026-08-09).
  • Nexus Mutual, Cover buyer and claims flow — one protocol-specific assessment and payout lifecycle (accessed 2026-08-09).
  • The supplied DeFi seed, sections 9.1, 9.4, 10, and 12 — insurance controls, oracle dependencies, and loss-allocation analysis.

Machine-readable model

Key equations

Canonical expressions come from the structured concept record. KaTeX renders the notation, while the plain-text expression and variable table keep its meaning and units inspectable without JavaScript. Read the narrative above for the model's domain, assumptions, and rounding rules.

This concept does not require one canonical equation. Its mechanism and state transitions remain the authoritative explanation; do not invent a formula merely to make the topic look quantitative.

Assurance contract

Security properties

These structured statements define desired behavior. Their stable IDs can bind tests, invariants, specifications, audit findings, or proof results without turning descriptive review advice into an assurance claim.

Desired · not evaluated: No test, audit, or proof result is implied until scoped evidence is linked to this property.

  1. Cover amount, beneficiary, asset, period, trigger, exclusions, evidence, assessment, limits, and payout process are explicit before purchase

  2. Accepted claims cannot exceed the remaining covered amount or available obligation under the selected capital model

  3. Premium, capital, outstanding exposure, accepted claims, and paid claims reconcile without double counting

  4. Claims and emergency authority cannot bypass disclosed assessment, appeal, waiting-period, and solvency constraints

Knowledge check

Quiz

Answer in your own words, then open the model answer.

Which loss remains with the buyer?

Model answer

Any loss outside the covered event, period, amount, evidence, assessment, exclusions, available capital, or enforceable payout process remains with the buyer or another explicit backstop.