Liquid loses 3,960 Bitcoin to software flaw despite securing private keys

BlockchainCrypto Coin Show News Team·September 20, 2026·5 min read

Nearly 4,000 Bitcoin left Liquid’s reserve on September 6 despite private keys remaining secure, exposing a gap between cryptographic protection and financial accountability that insurance alone cannot bridge. Institutional custodians and exchanges must now clarify whether customers are covered for losses from software flaws, and whether compensation means replacing coins or paying a dollar amount.

  • Attackers exploited a software flaw to create L-BTC without depositing Bitcoin, then redeemed those tokens for real coins from the reserve.
  • Coinbase’s crime insurance covers only a “portion” of digital assets and excludes losses from compromised login credentials, with total losses potentially exceeding recoveries.
  • Compensation agreements may specify dollars rather than coins, meaning a customer repaid in full dollar terms could receive fewer Bitcoin if the price has risen.
  • ~3,960 BTC withdrawn from Liquid reserve on September 6 despite secure private keys
  • 3,400 BTC returned by attackers on September 7, reducing shortfall but not determining liability
  • $250,000 FDIC deposit insurance limit per account, not applicable to digital assets

Software accepted a withdrawal that should never have qualified. According to TRM Labs’ reconstruction of the attack, Liquid operators approved the transaction despite consulting incorrect account balances, much as multiple signers might authorize a payment based on shared false data. The lesson inverts the axiom that protecting private keys protects crypto. Cryptographic security means nothing when the software authorizing those keys approves the wrong payment. That raises the billion-dollar question: who pays to put the money back?

Coinbase Insurance Covers Only a Portion and Excludes Credential Breaches

Crypto insurance exists, but the gap between “insured” and “fully protected” is vast. Coinbase’s public disclosure of its crime insurance states that coverage protects a “portion” of digital assets against theft and cybersecurity breaches. The policy also warns that total losses could exceed insurance recoveries, and excludes losses from unauthorized account access caused by compromised or lost login credentials. Two customers might face identical account depletion with completely different insurance outcomes depending on how the breach occurred.

The insurer’s agreement is with the company holding your Bitcoin, not with you.

If a loss exceeds insurance proceeds, the custodian must fund the gap from its own capital or negotiate with the insurer. Neither obligation is visible from your account balance. Whether you can claim directly, what payout mechanism applies, and how long reimbursement takes all depend on contracts you cannot see.

A provider might promise to replace specified losses and hold enough capital to cover an insurance shortfall; another might make a far more limited commitment despite advertising the same word: “insured.”

FDIC Protects Bank Deposits But Not Digital Assets Held Through Banks

The U.S. regulatory framework creates a false sense of security for customers who buy Bitcoin through an insured bank. The FDIC protects eligible deposits when an insured bank fails. That protection does not extend to digital assets, even when they are purchased through an insured institution and appear in the same app as cash. A customer seeing Bitcoin and dollars side by side has no way to know they carry fundamentally different protections.

Digital assets fall outside the federal safety net that covers traditional deposits.

Private insurance fills that gap, but private policies are negotiated between businesses, not mandated by law. The result is a patchwork where two crypto services can both advertise insurance coverage and deliver radically different levels of customer protection.

Institutional investors comparing custodians cannot rely on the word “insured” alone; they must read the actual policy terms, assess the provider’s capital reserves, and understand whether repayment is measured in coins or dollars.

Software Errors Can Trigger Liability Claims, But Recovery Takes Time

When software fails, multiple insurance claims may overlap and compete. Relm, a specialist insurer for crypto firms, offers digital asset crime coverage for infrastructure exploits and theft via smart contracts, alongside technology errors and omissions policies. A storage provider hit by a withdrawal software flaw might claim against its own crime policy, pursue a claim against the software vendor’s liability coverage, and face customer demand for immediate repayment. Each claim serves a different purpose and moves at different speed.

Liquid shows why recovering assets and assigning responsibility are separate tasks. According to Bitquery’s investigation, attackers returned 3,400 BTC on September 7. Blockstream later rejected a bounty demand, as reported by CryptoSlate.

Every coin recovered reduces the shortfall, but repayment by an attacker does not determine who must fund any remaining gap. That turns on obligations which the transaction record alone cannot establish.

Compensation Agreements May Promise Dollars, Leaving Customers Short of Coins

Even a binding payout must specify what is being replaced. A customer who lost one Bitcoin worth $80,000 might sign an agreement promising $80,000 in compensation. If Bitcoin costs $100,000 when payment is made, that customer receives the promised dollars but can buy only 0.8 BTC. The dollar amount has been repaid in full while a fifth of the original Bitcoin holding is still gone.

If the price falls during the wait, the same dollars buy more Bitcoin; the risk of price movement passes to whoever the contract assigns it to.

Getting coins back into a wallet is not the same as resolving the loss.

Allocating recovered coins among people entitled to repayment is a separate problem from getting them into custody. Someone who eventually receives every coin back may have spent weeks unable to meet a payment or move savings, and replacing the asset does not automatically compensate for those consequences.

These complications expose a hard limit to the instruction that customers should do their own research. Few people can inspect the software approving their Bitcoin withdrawals or compare its possible failures against an insurance policy negotiated between their provider and a third party, neither of which they may ever see.

The CCS read. We hold that institutional custodians should be required to publish not just that they are insured, but the specific losses they will repay and whether repayment is in coins or dollars. This disclosure should also state how they would fund a gap between customer obligations and insurer proceeds. Market competition for institutional deposits would then reward clarity and capital strength, not opaque marketing of the word “insured.”

Institutional investors should demand that any potential custodian provide written confirmation of which specific loss categories are covered, the amount of insurance in force, whether the provider will fund gaps from its own capital, and whether compensation is measured in coins or dollars, and require that commitment in the customer agreement before moving assets.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe