Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Beyond Private Keys: Who Pays When Crypto Custody Fails

A software flaw at Liquid that approved unauthorized withdrawals of nearly 4,000 Bitcoin reveals a critical gap in crypto protection. Even when private keys remain secure, customers may face losses if insurance and company obligations don't fully cover the damage.
1 hour ago 6 views
Beyond Private Keys: Who Pays When Crypto Custody Fails

Nearly 4,000 Bitcoin left Liquid's reserve on September 6 through a withdrawal the network approved despite no theft of private keys. According to TRM Labs, attackers exploited a software flaw to create L-BTC tokens without corresponding Bitcoin backing, then exchanged the tokens for real coins from the reserve.

The incident exposes a fundamental challenge in crypto custody: protecting private keys is necessary but insufficient. Software can approve incorrect transactions even when cryptographic credentials remain secure. Private keys authorize transactions, but faulty logic can cause that authorization to execute wrongly—much like multiple signatories approving a withdrawal based on incorrect account balance information.

Insurance Protections Have Limits

When custody failures occur, the question of compensation becomes complex. Crypto insurance can help, but policies often contain significant limitations. Coinbase, for example, publicly discloses that its crime insurance covers only a "portion" of digital assets against theft and cybersecurity breaches. The policy also warns that total losses could exceed insurance recoveries, leaving customers with uncompensated losses even when an incident is covered.

Coverage varies by loss type. Coinbase's policy excludes losses from unauthorized account access caused by compromised credentials. Two customers experiencing identical missing funds could face different coverage depending on how the loss occurred.

This contrasts with traditional banking protections. In the U.S., the FDIC protects eligible deposits when an insured bank fails, but it does not insure digital assets, even when purchased through an insured bank. Cash and crypto can appear side-by-side in an app while carrying entirely different protections.

The Gap Between Company Insurance and Customer Repayment

Private insurance policies typically cover the insured party—in this case, the custody provider—not individual customers directly. The insurer's obligation is to the company holding the Bitcoin, not to account holders. Whether customers can claim directly and how any payout reaches them depends on arrangements and applicable law, details that customers cannot see from their account balance alone.

A company's obligations to customers are separate from its insurance coverage. If the company owes customers more than its insurer will pay, it must find another source to cover the difference. Simply knowing a company carries insurance does not establish what any particular customer will receive.

Relm, a specialist insurer for crypto businesses, offers digital asset crime coverage that can respond to infrastructure exploits and smart contract theft, as well as technology errors and omissions coverage. However, these policies serve different purposes. One might pay for defending claims and settlements; another might directly reimburse the business for lost assets.

Defining What Gets Replaced

Even when compensation is agreed upon, the definition of replacement matters significantly. A customer who loses one Bitcoin may expect to recover the same number of coins. However, a compensation agreement might instead specify a dollar amount. If one Bitcoin is valued at $80,000 when the loss occurs but costs $100,000 when payment is made, the customer receives the promised $80,000 but can now purchase only 0.8 Bitcoin. The dollar amount has been repaid in full while part of the original holding remains missing.

Recovery agreements must also address what happens if missing Bitcoin is later returned. The policy must specify who receives recovered coins. Additionally, compensation for the period during which customers could not access their funds—potentially lasting weeks—requires a separate basis for repayment and may not be automatically included.

Liquid's Unresolved Questions

At Liquid, attackers returned 3,400 Bitcoin on September 7, according to Bitquery's investigation. Every coin returned reduces the shortfall but does not determine responsibility for any remaining gap. In September, Blockstream rejected a demand for a bounty, leaving unresolved the question of who ultimately funds any loss that insurance and recovered assets do not cover.

The incident demonstrates that software failures and asset recovery are separate from the assignment of financial responsibility. Transaction records, however detailed, cannot establish obligations on their own.

What Customers Should Know

Few customers can inspect the software approving their Bitcoin withdrawals or compare its possible failures against insurance policies negotiated between their provider and insurers. Crypto providers should explain reimbursement as clearly as they explain fees: stating which losses they undertake to repay, whether repayment means coins or dollars, and how they would fund gaps between customer obligations and insurance payments. Such disclosure would let customers judge the price of accepting additional risk themselves.

Security reduces the probability of loss; financial protection determines how that loss is shared. Customers deserve to know their share before being asked to bear it.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $80,920.79-0.11% EthereumETH $2,625.56-0.04% Tether USDUSDT $0.9997-0.05% BNBBNB $766.04+0.97% XRPXRP $1.40-0.71% USDCUSDC $1.00-0.02% SolanaSOL $110.00-0.53% TRONTRX $0.3428+0.99% HyperliquidHYPE $92.69+1.37% ZcashZEC $1,485.15+0.69%
Prices by Coinranking. Informational only.