Why keeping your private keys safe won’t always stop crypto theft

Why keeping your private keys safe won’t always stop crypto theft

Summary

A software flaw in Liquid’s withdrawal process allowed attackers to create unbacked L-BTC and withdraw nearly 4,000 BTC on Sept. 6, despite private keys remaining secure. TRM Labs reconstructed the exploit; Bitquery later reported that 3,400 BTC were returned. The incident highlights that insurance does not automatically guarantee customer repayment: coverage depends on policy terms, who is insured, exclusions, payout limits and the provider’s obligations and ability to cover any shortfall. Compensation terms also determine whether customers receive replacement coins or a fixed dollar value, and how later recoveries are allocated. Providers should clearly explain what losses they will reimburse and how they would fund gaps in insurance coverage.