Last Update: October 2022
Though Beefy does not offer insurance coverage directly to our users, there are a number of available products which offer cover for our protocol, smart contracts and users' portfolios. This page summarises the key types of DeFi insurance products that are available at present, some of the risks associated with them, and the different Beefy products that are available right now (including from our official partners and unaffiliated products).
On a simple level, insurance can feel like a counterintuitive concept in DeFi, as the pace of change and technology development necessarily makes DeFi an inherently risky pursuit. But digging a bit deeper, we can observe that insurance is actually one of the earliest forms of decentralised financial products, in that it seeks to socialise risk and cost among thousands of willing participants, to ensure neither is concentrated at an individual level.
At Beefy, we recognise that insurance is a requisite component of a stable, modern financial system, as it safeguards against massive damage and disruption arising from unlikely or unknowable, but retrospectively inevitable risks and events. Insurance allows users to enter the DeFi ecosystem and interact with this technology in a safer and more measured way, with protection against downside risks. It also helps to facilitate institutional capital, which may have more stringent risk management requirements that would otherwise isolate them from the space. As such, we think insurance helps to develop and extend DeFi, paving the way for mass adoption.
However, insurance is a complicated area of finance. Each and every underwritten policy is ultimately unique and deals with different types and levels of risk. As a result, it is vitally important that our users do their own research before buying insurance, and ensure their chosen products are suitable for them and priced fairly. It is always prudent to make sure to: (a) read the provider’s documentation and policy documents; (b) research the provider's financial position/backing to ensure it has sufficient liquidity to cover a pay out; and (c) check to ensure the policy's coverage is appropriate for the kinds of risks you wish to ensure against.
As DeFi expands, the list of available insurance products is growing in tandem, including from both corporate and decentralised providers. Some of the key types include:
- Smart Contact Coverage - covers a specific smart contract-based product for a range of common issues like contract bugs, multi-sig failures and economic attacks. For example: InsurAce's Smart Contract Vulnerability Cover.
- Token Coverage - covers a specific token product (e.g. an LP or autocompounding vault) for cross-stack risks in the underlying assets and protocols that the insured product is built on. For example: Nexus's Yield Token Cover (e.g. Convex 3CRV), which covers failures in the issuing protocol (Convex), the LP/farm protocol (Curve) and the underlying tokens (DAI, USDC, USDT and CRV).
- Portfolio Coverage - covers a particular wallet up to a specified value of loss, including all applicable assets from insured protocols which the wallet holds. For example: Solace's Portfolio Insurance cover.
- De-peg Coverage - covers risks in an individual token product that arise as a result of the value of the asset de-pegging (i.e. failing to hold market value in line with the underlying assets that it is supposed to reflect). For example: InsurAce's Stablecoin De-Peg Risk Cover and Nexus's Yield Token Cover, which includes a number of specific de-peg risks.
- Staking Coverage - covers several risks that arise out of blockchain network staking and validating, such as missed rewards and slashing losses. For example: Nexus's ETH2 Staking Cover, which specifically covers Ethereum's proof-of-stake beacon chain.
- Bundled Product Coverage - covers a combination of different protocols, products or different risks to create a single product that covers the users' overarching needs. For example: InsurAce.io's CRV+CVX Bundled Cover, which targets Convex users with additional coverage for failures in Curve (which Convex is built on).
Though Beefy advocates for the benefits of insurance, we also warn our users that insurance products themselves give rise to a number of risks which may result in your investment in the products being lost. In particular, we'd suggest users consider:
- Coverage Amount - insurance products typically require that you state upfront the amount of coverage that you want to purchase, typically denominated in fiat currencies. You may be encouraged to buy coverage up to the current value of your investment, or even above that. The coverage amount is typically not a guarantee of the amount you will be paid out, but does limit the maximum value of a pay-out. Furthermore, as the value of your assets change, the suitability of your coverage level will be impacted. For instance a sharp drop in the value of your portfolio will reduce the likelihood of claiming for the full coverage amount you obtained beforehand. Be sure to actively monitor your coverage levels.
- Coverage Limitations - coverage tends to be constrained to a closed list of claimable risk events (e.g. smart contract vulnerability covers "malfunction or programming flaw, or unauthorized, malicious, criminal attacks, hacks or exploits of any malfunction or programming flaw"). This may mean certain foreseeable events that you want cover for are not included in the product (e.g. a de-peg does not fall within the above definition, so is not covered by smart contract vulnerability cover).
- Captured Products - insurance products do not always seek to actively point out the limitations of their coverage and which products aren't captured. For instance, portfolio coverage may be tied to products which can be identified by the protocol, and may miss newer products or blockchains, resulting in inadequate coverage for your needs. As the product is general and the UI is user-friendly, you likely won't be told until your claim is rejected that specific products weren't captured in the coverage you purchased.
- Pay Out Process - all insurance products have strict conditions for paying out for a claim which must be met. For instance, some protocols require members to vote/decide on a claim before the protocol will pay out, which is a factor that is typically outside of users' control and unrelated to the pay out event. Be careful to check the process carefully when assessing whether a product is right for you, including assessing how frequently the product pays out for claims.
- For example, insurance covering Beefy's protocol or smart contracts will likely pay out if our contracts fail, but will not pay out if the underlying assets that our contracts are built on top of fail. This happened with the Terra UST collapse, where our smart contracts worked as intended, even as the underlying assets' value sank towards zero.
- Providing Coverage - some decentralised insurance providers (e.g. InsureDAO, Bridge Mutual) offer peer-to-peer insurance products, where users can provide coverage to the protocol as an investment in exchange for a share of the premiums paid by coverage purchasers. Beefy warns our users that these products expose coverage providers to an asymmetric risk of losing your entire investment if there is a pay out event under the policy.
- Providing insurance coverage is effectively a bet on the security of the underlying protocol or smart contracts. Though our SAFU practices are Beefy's top priority, we would not encourage ordinary users to bet on the security of any rapidly changing DeFi technologies.
- Where Beefy can offer you a similar rate of return on your assets whilst avoiding the pay-out risk, we know where we'd rather invest our funds...🐮🐮🐮
To bring the benefits of DeFi insurance to our users, Beefy has partnered with a selection of the leading insurance providers in the space, to create products which offer coverage over our protocol, products and contracts. At the time of writing, these are:
InsurAce is a multi-chain insurance provider deployed on a range of chains including Ethereum, BSC, Avalanche, and Polygon. It offers coverage against Beefy smart contract vulnerability over more than half of the chains Beefy is deployed on.
The precise make up of InsurAce's organisational is not entirely clear, though InsurAce has some incorporated legal forms (e.g. InsurAce Global Limited in the UK). It's protocol is made up of two parts: an insurance arm and an investment arm. The investment arm generates profits from fees collected to fund their insurance activities. Users pay a fee (typically 2-5% APY) when using covered smart contracts and are reimbursed for their deposits if it fails.
InsureAce operates a dedicated claims department that will review the different types of claims that can be submitted and vote on the outcome. The claim is first investigated by InsureAce's Advisory Board, which includes experts in Insurance, Security and Legal/Compliance. InsurAce are also aiming to develop a decentralised governance process over time, including the use of community Claim Assessors (who are $INSUR holders that have staked their tokens on the platform) to decide the outcome of claims. However, at the time of writing, the Claim Assessor page is not live, and the current state of affairs is not made clear on the protocol site.
Nexus Mutual is an Ethereum-based insurance alternative that provides coverage against specific protocols, yield tokens and custodians (i.e. centralised exchanges). It offers protocol coverage for Beefy across the vast majority of our deployed chains.
Unlike most other providers, Nexus is a discretionary mutual whose members receive insurance-like protection, though it doesn't formally sell insurance. The project uses aligned incentives to enable risk-sharing among all its members, as members act as risk and claim assessors, whilst contributing capital to the protocol. Ownership of Nexus Mutual’s token, NXM, is used to buy cover and navigate the claims and risk assessment process. Holders can also take part in the Mutual's governance too.
Nexus offers a range of products including general protocol cover (i.e. covering all different products offered by the protocol) as well as "yield token cover", which covers the full stack of a yield bearing asset (e.g. base assets, liquidity pool and autocompounding vaults). Nexus also offers other novel products such as Ethereum 2.0 staking cover, and custodian cover which protects against the risk of loss caused by keeping assets in the custody of a centralised exchange.
Solace is a decentralised, DAO-run insurance protocol, on a mission to forge innovation into intuitive protection tools for crypto explorers. It offers coverage for funds invested in Beefy as part of its all-encompassing portfolio insurance product.
By contrast to others, Solace has adopted a novel approach to claims (its optimistic payouts system), wherein users are not required to file claims following an insured event, but are instead automatically paid out where Solace's risk management team assesses that any event has occurred through on-chain analytics. For the future, Solace is also developing a parametric automated claims assessment system, which will be used to automatically quantify loss events using on-chain analytics.
Solace also provides an additional product (Solace Native) for protocols to cover their own smart contracts. This involves protocols holding underwriting tokens, which can be used to vote on a gauge allocation for their protocol among the wider underwriting pool.
As Beefy is entirely open source and public, anyone is free to build on top of our products and code. However, this transparency can cause some confusion for ordinary users as to which products are built and tested by our team, and which aren't. Some insurance providers seek to add to this confusion by stating that their products are "official" or "verified", when they are nothing to do with Beefy. It is ultimately up to the user to do your own research and check that the product is what you think it is.
Below is a list of known products insurance products that offer coverage for Beefy's products or protocol, but are not officially offered in partnership with Beefy and have not been formally verified by our teams. Use at your own risk, and always do your own research.