0XTHANER × ASSECURA

Who carries the risk?

Nexus Mutual, Part 1: The shared till and the people who assess the risk

VERSION
2.0
READING TIME
17 minutes
0xthaner × Assecura
PART ONE

The problem, and the idea

01

There is risk on the blockchain too

Anyone who puts money into a protocol is relying on a chain of things that all have to work. The contract holding the money has to be free of bugs. The price feed the collateral hangs on has to deliver correct numbers. The stablecoin everything is denominated in has to hold its peg. The exchange something is kept at has to pay out when you come to collect.

Every one of those has already failed at least once in recent years. A contract is exploited and emptied. A price feed reports a wrong rate for a few blocks, and a perfectly healthy position is liquidated. A stablecoin slips away from a dollar. A custodian halts withdrawals and files for bankruptcy weeks later.

So a blockchain does not make risk smaller. It only moves it: away from the bank, towards code and dependencies. What it does change on top of that is visibility. A hack is there in the chain. A liquidation is a transaction. A depeg is a row of numbers. Where an ordinary insurer first has to establish laboriously whether anything happened at all, here anyone can go and look.

Which leaves the same question as with any insurance: who takes on this risk, and what does it cost?

02

A community that carries risk together

Nexus Mutual is not an insurance company. It is a community of members who pool capital and use it to carry each other’s risk. There are no shareholders taking the profit; the money belongs to the members jointly.

The form is familiar from the traditional insurance world: a mutual. Nexus describes itself as a “decentralized insurance alternative that allows members to join and share risk”.

Two things about it matter, because both are often reported wrongly.

First: no machine decides about losses. With a blockchain application many people expect a program to measure a trigger and then pay out by itself. That is not how it works here. A loss is assessed, and it is assessed against the published terms of the particular cover. That people do the judging is deliberate, not a weakness of the system.

Second: you do not become a member by clicking. It takes an identity check, agreement to a membership document and a small one-off fee. So Nexus is not anonymous.

That easily produces a misunderstanding, though, and we will clear it out of the way next: not everyone who buys cover has to be a member first.

03

How you get hold of cover at all

There are two routes. The direct one: you become a member and buy on the Nexus site. And a second one, which is less well known.

Nexus lets other providers build the purchase of cover into their own application. The developer documentation puts the consequence for the end user plainly: “you can allow users to buy cover directly in your frontend. Users don’t have to join the Mutual when they buy cover.”

That is an important statement. Nexus does not have to be the website somebody buys on. Nexus can sit in the background while the customer is talking to an entirely different application: a wallet, a dashboard, a DeFi interface.

The division of labour is cleanly cut. Nexus provides the risk, the capital and the terms. The provider in front provides the interface, the selection, the explanation and the comparison. Think of a shop selling goods it does not manufacture itself.

One difference remains, though, and it matters: buying cover and filing a claim are two different things.

When buyingUser, point of sale, Nexus cover. Nexus carries the risk. Membership is not needed for this step.
When a loss occursFile the claim, become a member to do so, assessment, possible payout.

Because for the second step the house rule applies again: “in the event of a loss, you will be required to join as a member of Nexus Mutual to file your claim.”

Where CoverRaccoon sits in this

CoverRaccoon is the project this piece is written from, and it sits in exactly this position: in front of a provider like Nexus, not in its place. A layer like that can explain risks, make products comparable, present the terms in plain language, point out what is and is not included, accompany the purchase, show existing cover and remind you about renewals.

What it does not do: carry the risk. The risk, the terms and the decision about a loss stay with the provider, here with Nexus Mutual. CoverRaccoon insures nobody. It is the layer between the user and whoever takes the risk.

PART TWO

How it works inside

04

The shared till

Nexus has, put simply, two layers. The first is one single large pot, the Capital Pool. That is where the community’s money sits, in ETH, USDC and cbBTC.

Into that pot flows what members pay for their cover, what somebody pays in to get NXM, and what the community earns on its capital. Out of it flows above all one thing: an accepted claim is actually paid from the Capital Pool.

There is nothing more you need to know about this layer for now. It is the till. How much has to sit in it as a minimum so that all live cover can be served is worked out by Nexus under fixed rules; the formula is in the appendix and is not needed to understand the thing.

The more interesting question is the one this pot cannot answer on its own.

05

The risk assessors

The second layer is the staking pools. In practice such a pool is a person or a team with experience in risk, plus the capital they and others entrust to it.

Whoever runs a pool decides four things: which risks the pool takes on at all, how much NXM it puts behind them, how much cover should come out of that, and at what minimum price. In the insurance world a good part of that activity would be called underwriting.

A pool operator is in effect saying: “I consider this protocol good enough. I am willing to put my own NXM behind it.” Another can turn the same protocol down. Both are allowed to, and neither is declared right. What counts is how much cover comes about in the end, and at what price.

That is the real reason for this second layer. Without it, some central body would have to decide for every protocol, every exchange and every stablecoin whether to take the risk and at what price. That is exactly the work of an insurance company, and it is expensive and slow. In a market where new protocols appear every month it would barely be feasible.

06

Getting paid, and being able to lose

That leaves the question of why anyone would voluntarily take on somebody else’s risk. The answer has two halves, and they belong together.

The first half: whoever takes on risk gets paid for it. When Nexus sells cover, the stakers of the pools the cover came from receive a reward. It runs over the term of the cover and can be collected at any time; the pool operator keeps an agreed share of it.

The second half: whoever gets it wrong loses. When a claim is accepted and paid, part of the NXM that was put behind exactly this risk is destroyed. Not the NXM of all stakers, but that of the ones who underwrote this particular risk.

The two together are the core of the system. The reward is not interest and not payment for computing work, of the kind you know from staking a blockchain. It is the price for somebody being willing to lose something if a loss occurs. Anyone who takes the yield without assessing the risk has seen only the number, not the position.

IN DETAILWhere the cover fee goes, and where the reward comes from
Two processes that are easily confused. What the buyer pays, the cover fee, flows entirely into the Capital Pool: “All cover fees are paid into the Capital Pool in full.” The stakers’ reward is something else, namely newly created NXM worth 50 percent of that fee.

This is why the common line “the premium goes to the stakers” is wrong. The money goes into the shared till; the stakers receive tokens.

The sources are IMPRECISE here. Three official pages put it differently. The cover page says the fee is “converted to NXM […] and this NXM is streamed to stakers”. The capital pool page says all fees flow into the Capital Pool in full. The staking page speaks of 50 percent being minted as NXM rewards. The only reading under which all three sentences agree is the one described above. That resolution is mine, not the source’s.
07

How that turns into cover you can buy

Now the case from the beginning can be played through: 100,000 USDC in a lending protocol, 50,000 of it to be covered.

1Nexus lists this protocol as a product. So there are published terms for what is covered and what is not.
2One or more pool operators consider the protocol underwritable and put NXM behind it.
3That creates available cover. How much cover a given stake can produce is worked out by Nexus under fixed capacity rules; the exact formula does not matter here.
4As long as enough of it is still free, our user can cover their 50,000 USDC. They choose the amount and the term and pay.
5If nothing happens, the cover expires. The stakers keep their reward, the user has paid for peace of mind.
6If a covered exploit happens and the claim is accepted, the Capital Pool pays.
7At the same time, NXM of the pools that carried this risk is destroyed.

One point about this deserves attention: Nexus does not set the price centrally. There is no department working out 2.6 percent a year for a protocol. The pool operators each set a floor, and demand decides what happens above it.

The mechanism behind it is simple: the more of the available cover has already been bought, the more expensive the next piece becomes. If nobody buys, the price sinks back towards the floor over time. That makes cover dearer exactly when many people want it at once, which may well be the moment when something is in the air.

08

When the loss happens

The sequence is quickly told. The user files the claim and supplies evidence. It is assessed against the published terms of that particular cover, not against a general feeling of what would be fair. If the claim is accepted, Nexus pays from the Capital Pool.

At the same time those who had taken on this risk are charged for it: part of the NXM they had put behind it is destroyed.

This split in two is the real trick. If every loss were simply spread across everyone, nobody would have a reason to choose carefully; the prudent would carry the same burden as the careless. If, the other way round, each pool were responsible for its own cases alone, a large loss would quickly run it out of money. Nexus does both: the shared till makes sure the money is there, and the targeted destruction makes sure a misjudgement lands with whoever made it.

BACKGROUNDWho decides about losses has changed twice
Who decides about a loss at Nexus has not always been the same group. That matters, because almost every older explanation on the web describes a procedure that no longer exists in that form.

From 2019 to March 2023 any member could stake NXM and vote, with an approval threshold of 70 percent. From March 2023 to November 2025 a stake-weighted majority decided. Since November 2025 a committee of three publicly named experts decides, with a window of 72 hours per case; two approvals out of three are enough. For individual products a specifically appointed assessor can be responsible instead.

This development solves a real problem, namely lay votes on complicated loss questions with money on both sides. But it also creates a new one: a small, named group now decides about losses. This is one of the points at which the word “decentralised” applies to Nexus only in a limited sense.
PART THREE

What comes of it

09

What you can insure against

Nexus currently lists a good dozen products. More important than the catalogue is which kinds of problem can be covered at all.

Faults in protocolsThe origin of the whole thing: a contract is exploited, a price feed fails, a construction turns out to be flawed. Example: the Euler exploit in March 2023, around 2.4 million dollars paid out.
Custodians and exchangesTheft or blocked withdrawals at a central party. Example: FTX in November 2022, a good 4.9 million dollars.
Stablecoins losing their pegCover against precisely defined depeg events, for instance on USDe, USDT, crvUSD or WBTC.
SlashingLosses on staked amounts when a validator is penalised or the infrastructure behind it fails.
Liquidation of leveraged positionsFor strategies where the damage is not done by the depeg itself but by the liquidation it triggers.
Whole portfolios and special casesCover that bundles several positions, plus specialities such as bug bounty cover.

Since 2019 Nexus says it has underwritten cumulatively more than 7 billion dollars of cover and paid out more than 18.5 million dollars in claims. Cover live at any one time runs in the low tens of millions per product group.

Two things can be read from that. What began as cover against contract faults has become something broader. That does not make it a large market yet: measured against traditional speciality insurers these sums are small.

10

A marketplace for risk

Put the pieces together and you see something other than a website where you buy crypto insurance.

There is the risk, which arises at particular protocols and custodians. There is the capital, which sits in the shared till. There is the knowledge of the people who decide what may come in and at what price. And there is the demand, which meets all of it through price and available cover.

Because different assessors are allowed to judge the same risk differently, a market emerges from it. A risk many consider manageable attracts a lot of cover and becomes cheaper. One that is hard to judge attracts little and becomes expensive. And one nobody wants to underwrite simply is not coverable.

Whether those prices are good, whether they get anywhere near how likely a loss really is, is another matter. The history is too short for that, and shaped by too few large cases.

11

And why is NXM worth anything?

That completes the basic model. A shared till that pays out. Above it, people who decide which risk may come in, who are paid for that and who can lose. In between, a price that comes out of supply and demand.

What is interesting about it is not so much that a policy is replaced by software. The more interesting question is whether the selection of risks can be organised as an open market at all, instead of inside a firm. At Nexus the capital is visible, the risk assigned to individual assessors, the price the product of demand, and the assessment of a loss there to be read.

Whether that holds will not show in good years. It will show on the day several large losses arrive at once.

And in the middle of it one thing is doing a striking number of jobs at the same time. NXM is the stake with which risk is taken on. NXM is the reward paid for doing so. NXM is what gets destroyed when a loss occurs. And behind NXM stands the shared till.

So why does NXM have any value at all?

12

Appendix: terms, numbers and sources

Here are the figures deliberately left out of the text, because understanding it does not require them. Anyone who wants to do the arithmetic will find them here; anyone who has understood the model does not need them.

Capital PoolHolds ETH, USDC and cbBTC and belongs to all members jointly: “The Capital Pool is jointly owned by all Nexus Mutual members.” Claims are paid from it.
Minimum capital, MCRThe minimum the Mutual needs in order to be highly confident it can pay all claims. Calculated as total live cover in ETH divided by a factor, currently 4.8. The full model behind it runs off-chain and is adjusted by governance vote.
CapacityHow much cover a stake produces: the stake multiplied by a fixed factor of 2.0 and by the product’s target weight, less any throttling. If live cover on a single listing approaches 20 percent of the minimum capital, it can be throttled.
Multiple allocationThe same NXM can be put behind several products at once, up to twentyfold. That rests on the assumption that not all covered events occur at the same time.
PriceThe pool operator sets a floor between 1 and 100 percent. Every purchase raises the price by 0.05 percentage points per percent of capacity used; after that it falls back towards the floor at 2.0 percent a day.
Destruction when a loss occursWhat is destroyed is the value of the payout divided by the NXM price and by the capacity factor. The documentation’s example: a 50 ETH loss at 0.1 ETH per NXM and a factor of 2 gives 250 NXM.
Buying and selling NXMThrough the Ratcheting AMM: two virtual pools on top of the Capital Pool, through which the Mutual buys and sells NXM at a price it sets itself. It replaced the earlier bonding curve in 2023.
MembershipIdentity check under KYC and AML, agreement to the membership document, a one-off 0.0020 ETH.

All mechanisms come from the Nexus Mutual documentation, retrieved on 29 September 2026: the overview and membership pages, the protocol pages on cover, pricing, capacity, capital pool, minimum capital, staking and claims assessment, the page on point-of-sale integrations, and the claims history including the separate page on FTX. The product catalogue is at nexusmutual.io/product-index.

The figures on live cover, claims paid and revenue come from two blog posts by Nexus Mutual itself, the year in review of 15 January 2026 and a post on cumulative cover of 6 July 2026. Provider figures, not independently audited.