Crypto news report · source clearly identified

Software Flaw Allows Theft of Bitcoin Despite Secure Private Keys

On September 6, nearly 4,000 BTC left Liquid’s reserve after a software error created unbacked L‑BTC tokens, highlighting that protecting private keys alone does not guarantee safety and raising questions about insurance coverage and liability.

On September 6, almost 4,000 Bitcoin exited the reserve of the Liquid network through a withdrawal that the network approved, even though the private keys used to authorize the transaction had not been compromised. The loss resulted from a software flaw that allowed attackers to generate L‑BTC tokens without depositing the corresponding Bitcoin, which were then exchanged for real BTC.

How the Attack Worked

Liquid enables users to move a Bitcoin‑backed token, L‑BTC, on a separate blockchain designed for faster, more private transactions. Each L‑BTC is intended to represent one BTC held in a shared reserve. When users redeem L‑BTC, the equivalent Bitcoin is released from the reserve.

According to a reconstruction by TRM Labs, the attackers exploited a software error that let them create L‑BTC without providing the required Bitcoin. The withdrawal‑approval process trusted inaccurate balance information, allowing the creation and exchange of unbacked tokens.

Insurance and Liability Limits

Crypto insurance can mitigate losses, but policies often contain exclusions and caps. For example, Coinbase’s public disclosure states that its crime insurance covers only a portion of assets and excludes losses from unauthorized account access due to compromised credentials. Consequently, customers may still face unrecovered losses even when a provider is insured.

Private insurers such as Relm offer coverage for digital‑asset crimes arising from infrastructure exploits and smart‑contract failures. However, such policies typically address the insurer’s liability to the covered business, not direct reimbursement to individual users.

Recovery Efforts and Remaining Gaps

Bitquery’s investigation found that attackers returned about 3,400 BTC on September 7, reducing the shortfall in Liquid’s reserve. Nonetheless, the returned coins do not automatically resolve who must cover the remaining deficit, as that depends on contractual obligations and insurance terms.

Compensation may be expressed in fiat value rather than Bitcoin, introducing price‑risk considerations. If a payout is fixed in dollars, fluctuations in Bitcoin’s market price can affect the actual amount of cryptocurrency a user receives.

Implications for Users

The incident demonstrates that safeguarding private keys is necessary but insufficient; software integrity and clear insurance disclosures are equally critical. Users should seek transparent information from service providers about:

  • Which loss scenarios are covered by insurance.
  • Whether compensation is provided in coins or fiat.
  • How any shortfall between the insurer’s payout and the provider’s obligations will be funded.

Understanding these factors helps users assess the true risk of entrusting assets to third‑party platforms.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
September 20, 2026, 8:30 PM
Original headline
Why keeping your private keys safe won’t always stop crypto theft
View original report ↗