DeFi insurance and cover
DeFi insurance or cover exchanges a premium for a conditional payout claim tied to specified loss events, exclusions, limits, assessment, and available capital.
Category: RiskWarning cross category cue
System record
Start with the economic purpose, participants, resources, and entitlements before studying implementation detail.
Why it exists
Users and protocols may prefer to transfer a defined loss exposure to a capital pool or underwriter rather than retain the entire smart-contract, custody, or operational risk.
Traditional-finance analogy
Mutual or specialty insurance cover is the closest comparison recorded for this concept.
Where the analogy stops
- Some on-chain products are discretionary mutual cover or parametric contracts rather than regulated insurance, and legal rights vary by entity, wording, and jurisdiction.
- Claims can depend on governance votes, oracles, staking pools, membership, or contract state, while capital assets and payout liquidity can themselves carry crypto risk.
Main actors
- ActorCover buyer and beneficiary
- ActorCapital provider, staker, underwriter, or mutual member
- ActorClaims assessor, oracle, governance, or committee
- ActorCover contract, pool, administrator, and legal entity when present
Assets and claims
Assets — controlled or transformed resources
Assets are resources the mechanism moves, holds, values, or transforms.
- AssetPremium asset and cover capital
- AssetPayout asset and capital-provider stake
Claims — entitlements and corresponding dependencies
Claims are rights to value, repayment, redemption, control, or another party's performance; each depends on an obligation or system that must honor it.
- ClaimConditional payout entitlement under stated cover wording
- ClaimCapital-provider claim on premiums and residual pool assets after losses
DeFi insurance or cover turns a defined loss exposure into a conditional payout claim funded by premiums and risk capital.
Why it exists
Section titled “Why it exists”Users and protocols may not want to retain the full loss from a contract exploit, custody failure, depeg, or other specified event. A cover system pools or allocates capital and states when that capital should compensate a claimant.
Traditional-finance analogy
Section titled “Traditional-finance analogy”Mutual or specialty insurance is a useful analogy. It can be legally inaccurate: some products are discretionary mutual cover or parametric smart contracts, and rights vary by wording, entity, membership, and jurisdiction. On-chain claims may depend on oracle values, governance votes, assessors, staking pools, or contract state, while the capital pool can hold risky crypto assets.
Actors, assets, and claims
Section titled “Actors, assets, and claims”Buyers pay premiums and hold cover positions. Capital providers or stakers bear accepted losses and may earn premiums or rewards. Assessors, oracles, committees, or governance decide whether conditions hold. The cover claim is distinct from the underlying asset and from capital-provider ownership. Its value depends on wording, evidence, assessment, limits, exclusions, solvency, and payout access.
Mechanism and flows
Section titled “Mechanism and flows”- Define covered product, beneficiary, event, exclusions, amount, asset, period, evidence, assessment, and limits.
- Price capacity and collect a premium from the buyer.
- Allocate capital from underwriters, stakers, a mutual pool, or a reserve.
- Let the holder submit evidence after a claimed loss.
- Apply oracle, assessor, governance, or deterministic trigger rules.
- If accepted, reduce remaining cover and transfer the payout from available capital under the stated queue and priority.
Capital flow moves premiums and risk capital into accepted payouts. Claim flow starts when cover is issued and ends through expiry, cancellation, or payout. Return flow pays capital providers from buyer premiums and sometimes token issuance. Control flow follows product wording, assessment, governance, pause, and upgrade roles. Risk flow reaches claimants when coverage is excluded, disputed, undercapitalized, illiquid, or legally unenforceable.
State and loss allocation
Section titled “State and loss allocation”| State | Buyer position | Capital position |
|---|---|---|
| Active cover | Conditional payout claim | Capital is exposed within stated limits |
| No covered event | Premium is spent | Capital provider retains premium share |
| Claim pending | Evidence and assessment unresolved | Capital remains reserved or exposed |
| Claim accepted | Payout becomes redeemable or transfers | Pool or allocated stake absorbs loss |
| Capital shortfall | Valid claim may not be fully payable | Claimant bears residual loss unless another layer exists |
Cover does not eliminate risk; it reallocates a specified part. The buyer pays the premium, capital providers earn it for bearing risk, and claimants retain excluded, excess, disputed, delayed, or insolvent loss.
Beginner lens
Section titled “Beginner lens”Read what event is covered, for how much, during which dates, who decides, and what capital pays. The word “insurance” alone does not guarantee a payout.
Practitioner lens
Section titled “Practitioner lens”Review wording, membership or eligibility, claim evidence, assessment incentives, waiting and appeal periods, capacity, capital assets, correlated exposure, reinsurance, limits, exclusions, payout liquidity, legal entity, jurisdiction, and governance.
Engineer or auditor lens
Section titled “Engineer or auditor lens”Nexus Mutual is one protocol-specific design in which a buyer purchases cover, claims enter assessment, and accepted payouts interact with cover and pooled capital contracts. Its membership, product wording, staking, voting, and claim rules are specific to that system; do not generalize them to all cover products.
Security review notes
Section titled “Security review notes”Bind cover identity, beneficiary, asset, amount, period, trigger, evidence, and remaining limit. Test duplicate claims, ownership transfer, expiry boundaries, partial payouts, assessment manipulation, oracle failure, capital correlation, queue exhaustion, pause, upgrade, and insolvency.
Common misunderstandings
Section titled “Common misunderstandings”- “Buying cover removes the risk.” Exclusions, limits, assessment, liquidity, and counterparty solvency remain.
- “On-chain cover is automatically regulated insurance.” Legal characterization depends on the actual product and jurisdiction.
- “A capital pool guarantees full payment.” Correlated claims and asset losses can exhaust available capital.
Prerequisites and learn next
Section titled “Prerequisites and learn next”Read asset versus claim and governance. Continue to solvency risk and oracle risk to inspect payout dependencies.
Sources
Section titled “Sources”- Nexus Mutual, Cover contract documentation — one protocol-specific cover purchase and capital-allocation interface (accessed 2026-08-09).
- Nexus Mutual, Cover buyer and claims flow — one protocol-specific assessment and payout lifecycle (accessed 2026-08-09).
- The supplied DeFi seed, sections 9.1, 9.4, 10, and 12 — insurance controls, oracle dependencies, and loss-allocation analysis.
Machine-readable model
Key equations
Canonical expressions come from the structured concept record. KaTeX renders the notation, while the plain-text expression and variable table keep its meaning and units inspectable without JavaScript. Read the narrative above for the model's domain, assumptions, and rounding rules.
This concept does not require one canonical equation. Its mechanism and state transitions remain the authoritative explanation; do not invent a formula merely to make the topic look quantitative.
Assurance contract
Security properties
These structured statements define desired behavior. Their stable IDs can bind tests, invariants, specifications, audit findings, or proof results without turning descriptive review advice into an assurance claim.
Desired · not evaluated: No test, audit, or proof result is implied until scoped evidence is linked to this property.
Cover amount, beneficiary, asset, period, trigger, exclusions, evidence, assessment, limits, and payout process are explicit before purchase
Accepted claims cannot exceed the remaining covered amount or available obligation under the selected capital model
Premium, capital, outstanding exposure, accepted claims, and paid claims reconcile without double counting
Claims and emergency authority cannot bypass disclosed assessment, appeal, waiting-period, and solvency constraints
Knowledge check
Quiz
Answer in your own words, then open the model answer.
Which loss remains with the buyer?
Model answer
Any loss outside the covered event, period, amount, evidence, assessment, exclusions, available capital, or enforceable payout process remains with the buyer or another explicit backstop.