Advertisement

Why DeFi Needs Onchain Insurance: The $100 Billion Coverage Gap

Presented by Sentora
DeFi carries close to $100 billion in total value locked, and under 2% of that is covered by anything resembling insurance. Firelight's Connor Sullivan argues the real gap isn't missing coverage but coverage nobody outside the deal can verify.
Why DeFi Needs Onchain Insurance: The $100 Billion Coverage Gap

DeFi carries close to $100 billion in total value locked. Under 2% of that is covered by anything resembling insurance.

Gilbert Loomis had a problem in 1897. The Massachusetts mechanic had just finished building his own automobile, a steam-powered contraption that spooked every horse it passed, and he wanted it insured before something went wrong. There was one catch: nobody had ever insured a car before. Travelers took the request anyway. They pulled out their standard policy for horse teams and carriages and wrote in "auto." $7.50 for $1,000 of liability coverage, on paper designed for an entirely different situation.

For about a decade, the fastest, most dangerous machines on American roads were covered by rules built to price the risk of a horse walking down a lane.

That coverage wasn't fraudulent or worthless. It was just aimed at the wrong century. The underwriting logic behind it had been refined over a hundred years of watching horses, not cars, and a car breaks that logic in ways a spreadsheet built for horses can't see.

DeFi is living through the same mismatch, just with a different vehicle. Insurance that was built for banks, corporations, and slow-moving risk is now trying to cover a market that moves at the speed of a blockchain, and mostly it's doing what Travelers did in 1897: crossing out an old word and writing in a new one.

The audience for this problem just got much bigger

Onchain cover has historically been a small market, in part because DeFi users are relatively comfortable underwriting risk themselves. That changed once onchain yield began appearing inside consumer apps used by people who had never interacted with a crypto wallet.

Robinhood's July 2026 rollout of Robinhood Earn is the clearest example yet. Eligible US users can lend USDG through a self-custody wallet built into the main app, at a headline rate near 7% APY. Deposits flow into a Morpho vault and get routed across onchain lending markets. To the user, it looks like a savings account. Structurally, it's onchain credit infrastructure reaching 27.7 million funded customers.

For this audience, insurance isn't a feature bolted on after launch. It's the thing that makes the product legible as safe in the first place. A retail saver comparing an "Earn" product to a bank account assumes, the way they assume about a bank, that someone has already dealt with the risk. So Robinhood arranged cover through Lloyd's of London and RELM for cyber incidents and smart contract exploits, and Johann Kerbrat, who leads crypto there, called it one of the largest insurance programs ever assembled for a crypto product.

That's notable on its own terms: Lloyd's made its name insuring cargo ships, and it's now underwriting a Morpho vault. It's also a clear demonstration of where the old model runs out of road.

What the coverage includes, and what it can't

Robinhood's Onchain Lending Disclosure says more than most crypto insurance programs bother to say publicly. The policy covers specific technical failures, outages, and security incidents, including cyber intrusions and smart contract exploits. It does not cover losing money because the market moved, a borrower defaulted, or the protocol hit a liquidity crunch or governance failure. Coverage sits under one shared limit across the entire user base, and Robinhood is upfront that a large enough incident could exhaust that limit before everyone is made whole. That's an unusually transparent disclosure, but transparency about the existence of limits isn't the same as visibility into what they are.

Nobody outside the deal can see the dollar figure of the limit, the policy wording, the triggers, the retentions, or the sublimits. Nobody can see the premium, the single most informative figure in the arrangement, since it's the insurer's own priced view of the risk. And nobody can confirm whether the capital behind the policy is committed and liquid, or what happens if two insured programs claim against the same exposure in the same week.

None of this is a criticism of Robinhood specifically, since every actor in the chain, insurer, broker, and fintech alike, is behaving rationally inside an industry built on private contracts and confidential wordings; the depositor is simply the one left holding "insured" as an article of faith, by design rather than by anyone's failure.

The actual gap isn't that DeFi lacks insurance. It's that almost none of the insurance that exists comes with anything a user could independently verify.

That's the specific gap DeFi Cover protocols like Firelight are trying to close: collateral that can be checked onchain instead of trusted on a balance sheet nobody can see, and a cover scope written in terms plain enough that a user could actually read it before relying on it.

The case for onchain DeFi cover

Conventional underwriting leans on decades of actuarial history, on risks that evolve slowly and stay contained. Almost none of that holds onchain. Markets never close, and a loss finalizes in the time it takes to confirm a block, sometimes for nine figures at once. Risk is structurally correlated rather than isolated, since thousands of vaults run on the same handful of contracts, oracles, and bridges, so a single flaw is a flaw shared by every fork built on top of it. And the attack surface shifts faster than any insurer's annual renewal cycle can track.

The pace of that shift shows up in the numbers. 2025 losses reached $3.4 billion, driven largely by the $1.5 billion Bybit breach, which exploited a compromised third-party wallet interface rather than a smart contract bug. Sentora data shows the vast majority of incidents having an onchain attack surface, with logic bugs, oracle manipulation and access control issues being among the most common attack vectors. TRM Labs tracked 207 incidents in the first half of 2026 alone, more than double the prior year's pace, with smart contract exploits the most frequent category by count while operational failures around keys, signing, and approvals drove the largest dollar losses.

the-defiant

Source: Sentora Research

Pricing something as complex as smart contract risk correctly means reading live audits, watching onchain positions change in real time, modeling how dependent protocols are on each other, and repricing continuously rather than annually. Traditional insurance was never built to house that skill set, so insurers respond the only rational way available to them: shrink the scope, cap the payout, exclude anything too unfamiliar to model. What comes out the other end is real coverage, but thin enough that it barely matters at scale.

With nearly $100 billion in TVL and less than 2% of that being covered by anything resembling insurance, the case for insurance is clear. But what DeFi needs is a form of coverage built natively for the environment it's protecting, rather than one borrowed from traditional insurance. It has to sit onchain, alongside the protocols it insures, reading the same state that generates the risk in the first place. It would integrate directly into vaults, lending markets, and fintech front ends, so protection is a property of the product itself rather than something layered on afterward by a broker.

How Firelight Solves the Insurance Problem

Firelight is one of the more direct attempts at solving this fully onchain. Stakers deposit assets into the protocol, which is bridged onchain through Flare's FAssets, and that staked capital becomes the collateral backing coverage for other DeFi protocols. Builders buy that coverage directly against onchain vaults, stakers earn a share of the fees for backing it, and when a loss event is submitted, it goes to an independent consortium, made up of firms including Hypernative, Native, Credora, GFX Labs, and Cyfrin, for review before funds are released. The point isn't that every design decision in that model is settled. It's that the model is built to answer the four questions traditional insurance leaves open: who is pricing this, how continuously, against what verifiable evidence, and with capital anyone can actually check.

In 1897, an insurer crossed out the word "team" and wrote in "auto," and for a decade the fiction more or less held together. Then the world got faster, and the industry had no choice but to build something genuinely new. DeFi insurance is standing at the same fork today. The era of relabeled carriage policies for onchain risk is running out of room, and whatever replaces it will set the pace for how far this market is actually allowed to grow.

Connor Sullivan is Chief Strategy Officer at Firelight, where he leads the development of an onchain coverage layer for DeFi, translating smart contract and protocol risk into exposures institutions can price and manage. Before Firelight, he spent five years at Fireblocks across institutional partnerships and corporate strategy, following an earlier career in global reinsurance. He writes and speaks regularly on DeFi risk, institutional adoption, and the evolution of onchain insurance.

Advertisement

Get an edge in Crypto with our free daily newsletter

Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri

90k+ Defiers informed every day. Unsubscribe anytime.