Key Takeaways
CryptoSlate reports how software flaws can drain Bitcoin reserves even when private keys remain secure, exposing limits in insurance and customer reimbursement policies.

According to CryptoSlate, keeping private keys secure does not always prevent cryptocurrency theft. Nearly 4,000 Bitcoin recently left Liquid's reserve through an approved withdrawal without any private keys being stolen. TRM Labs reported that attackers exploited a software flaw to create L-BTC tokens without backing them with actual Bitcoin, exchanging those tokens for real coins.
Crypto insurance can cover losses without guaranteeing full customer reimbursement, and policies may calculate compensation in dollars rather than Bitcoin. Coinbase similarly warns that total losses can exceed insurance recoveries, and that its crime insurance protects only a portion of digital assets while excluding unauthorized access from compromised user credentials. Furthermore, the FDIC does not insure digital assets even when bought through an insured bank.
Relm offers digital asset crime coverage for infrastructure exploits and smart contract thefts, alongside technology errors and omissions coverage. However, recovering assets and assigning responsibility remain distinct challenges. Liquid noted that attackers returned 3,400 BTC, and Blockstream subsequently rejected a bounty demand. CryptoSlate emphasizes that security reduces loss risks, while financial protection determines how those losses are shared among parties.
Source & Fact-Check Note
https://cryptoslate.com/who-pays-when-bitcoin-disappears-without-anyone-stealing-the-keys/

