February 25, 2026

Capitalizations Index – B ∞/21M

Crypto Custodian BitGo Exaggerated Insurance Coverage, Underwriter Claims

Crypto custodian bitgo exaggerated insurance coverage, underwriter claims

Crypto Custodian BitGo Exaggerated Insurance Coverage, Underwriter Claims

Crypto custodian bitgo exaggerated insurance coverage, underwriter claims

One of the underwriters behind BitGo’s $100 million cryptocurrency insurance policy has accused the custodian of exaggerating the scope of its coverage by using “ambiguous language” in public statements.

The controversy boils down to three words. In its February 20 press release, BitGo listed “third-party hacks” among the risks covered by a group of 10 Lloyd’s of London underwriters.

That was misleading, according to one of the group’s 10 members, since it implies the policy covered hacks of “hot,” or online wallets. In fact, the policy strictly covers theft or loss of assets kept in “cold storage,” meaning the cryptographic keys are kept offline.

In an email to insurance brokers obtained by CoinDesk, this underwriter said,

“ … the BitGo Specie policy absolutely does NOT provide any cover for remote ‘third party hacks.’ […] Cover is only provided for ‘storage media’ in secure storage. In other words, there is no cover for any loss of sensitive information (private keys) resulting from the generation, transportation or transaction phases of the private keys’ life cycle.”

As such, the coverage is limited to “hacks” of “offline private keys,” requiring the third party to obtain direct physical access to them, noted the underwriter, whose email was shared with CoinDesk on the condition that his company not be identified.

The official went on to describe the language in the announcement as “ambiguous,” but added that since his firm did not lead this policy, it had “no say over the language used in the press release.”

When contacted by CoinDesk, BitGo argued it had used clear and specific wording, noting that right before the line about “third-party hacks,” the press release stated the insurance “covers digital assets where the offline private keys are held 100% by” the custodian (emphasis added here). The company also said Lloyd’s had reviewed and approved this wording.

BitGo told CoinDesk in a statement,

“Working with our insurance underwriters, it is understood that a hack in the cold storage context includes unauthorized access or theft of private keys. This refers not only to the hardware but more specifically to the cryptographic series of alphanumeric characters generated, which permits the release of cryptocurrency from a Public Address.”

Due to the nature of digital assets, the inherent threat is the use of a computer, USB device, frequency reader, etc. to hack or breach cold wallet hardware, software, or processes, said BitGo.

“Cold storage involves devices and cryptographic keys that are not exposed to online networks removing the threat vector of remote network access, but there are other attack vectors that would involve technology,” it said.

More than semantic

It might be tempting to dismiss the underwriter’s complaints as sour grapes or pedantry. But it’s understandable why an underwriter would be worried about its risks being misconstrued.

Stepping back, specialist insurance policies such as those for crypto are handled by groups of underwriters, known in industry parlance as “towers.” The lead underwriter, which understands the risk deeply, will offer the first $10 million of losses, say, and then the rest of the capital gets filled out by the other syndicates further up the tower, which will demand a smaller premium.

All this is negotiated at the Lloyd’s of London market, which sets rules for conduct among participants.

In the case of the BitGo policy, AMTrust was the lead underwriter and the only one that the company identified when it announced the coverage. The underwriter who wrote the email was one of the syndicates taking on a smaller exposure. (Both Lloyd’s and AMTrust declined to comment.)

It’s also important to remember that crypto insurance is thin on the ground and a large amount of cover for hot wallets, which are typically the target of third-party hacks, is especially hard to come by.

Some large exchanges simply hold disaster funds of bitcoin to cover these losses themselves. According to insurance industry sources, there is a stark disparity in premiums depending on whether the crypto being insured is in a hot or cold wallet – the hot ones carrying the more expensive price tag.

Hence, if anyone who read BitGo’s announcement had incorrectly inferred that “third-party hacks” meant hot wallet coverage, as the underwriter feared, they might draw unrealistic conclusions about the market.

“As a public relations event, the press release may have been a success, but there is certainly nothing newsworthy with respect to the scope of the cover,” said Jerry Pluard, the president of Safe Deposit Box Insurance Coverage, an insurance broker in the Chicago area who arranges crypto policies for custodians.

The underwriter said in his email he would meet with Lloyd’s “in an attempt to obtain some consistency in their approach to media communications going forward,” concluding:

“At the end of the day a responsible and clear press release would benefit not only the crypto industry but Lloyd’s as well.”

BitGo CEO Mike Belshe image via CoinDesk archives

Published at Tue, 05 Mar 2019 08:10:41 +0000

Previous Article

Fehlersuche bei Binance: Bitcoin-Börse bietet 100.000 US-Dollar für DEX-Tester

Next Article

Are Governments Trying to Attack Roger Ver’s Bitcoin.com?

You might be interested in …

North Korea Behind Recent YouBit Hack?

Cybercrime experts are attributing the most recent bitcoin heist to North Korea. The Wall Street Journal report that the South Korean cryptocurrency exchange YouBit is the latest victim of a malicious hacking, and that their northern neighbours are to blame. YouBit have been forced to declare themselves bankrupt after 17 percent of their digital assets were stolen. They are allowing customers to immediately withdraw three quarters of the funds in their accounts. The remaining sums will be paid out following the liquidation of the exchange.

The allegations come just one day after the US laid the blame for the WannaCry cryptographic worm attack on North Korea. ARS Technica report that White House National Security Adviser Tom Bossert stated yesterday:

“We do not make this allegation lightly. It is based on evidence. We are not alone with our findings, either. Other governments and private companies agree. The United Kingdom attributes the attack to North Korea, and Microsoft traced the attack to cyber affiliates of the North Korean government.”

The WannaCry ransomware attack targeted users of the Windows operating system this Spring. It’s estimated to have infected over 300,000 computers across the globe. Computers and their contents were frozen and a demand of bitcoin was then made to those affected.

These examples are not the first time that the communist dictatorship of North Korea have been implicated in such heists. Just this year, three additional attacks have been made against South Korean exchanges that are being blamed on operatives working under Kim Jong Un. The largest of which was on Yapizon, YouBit’s predecessor. They were compromised back in April. This digital heist saw even larger sums of cryptocurrency lifted.

A report issued back in September by cyber security firm FireEye acknowledged the motive behind North Korea’s interest in digital currency. The fact that cryptocurrencies offer permission-less movement of funds across the planet makes them ideal for the purpose of laundering money and evading sanctions. Hackers can then use coin tumbling services to “clean” funds. Alternatively, they can exchange bitcoin involved in a hack for a much less traceable currency like the anonymity coin Monero. It’s believed that this is what occurred following the WannaCry outbreak.

For a country trying to fight off aggressive international sanctions and continue their militarisation, cryptocurrency seems to present an obvious solution to traditional financial channels being closed off to them. ARS Technica estimate that some $16 billion have been lifted by North Korea to finance their foreign policy objectives. Whilst this is pittance when compared with the over $612 billion market cap of all of cryptocurrency, for a nation that are currently in the midst of economic strangulation, it’s certainly worth going after.

 

Image: PixaBay

 

 

 

The post North Korea Behind Recent YouBit Hack? appeared first on NEWSBTC.