Liquid Lost Nearly 4,000 Bitcoin Through a Software Flaw, Exposing Limits of Crypto Insurance

Liquid Lost Nearly 4,000 Bitcoin Through a Software Flaw, Exposing Limits of Crypto Insurance

How Liquid lost nearly 4,000 Bitcoin without a key theft

Nearly 4,000 Bitcoin left Liquid's reserve on Sept. 6 through a withdrawal the network approved, even though the private keys used to authorize it had not been stolen. A software flaw allowed the withdrawal to go through when it should have been rejected.

Liquid operates as a platform that lets users move a Bitcoin-backed token called L-BTC on a separate blockchain designed for faster, more private transactions. Users deposit Bitcoin into a shared reserve and receive L-BTC tokens in return, each meant to represent one BTC. When users redeem those tokens, the corresponding Bitcoin comes out of the reserve.

What happened, step by step

According to TRM Labs' reconstruction of the attack, attackers exploited a software flaw to create L-BTC without putting in the Bitcoin to back it, then exchanged those tokens for real coins. The operators responsible for approving withdrawals essentially relied on incorrect information.

Even though private keys were not compromised, the software used those keys to approve the wrong transactions. Several parties effectively signed off on a withdrawal while consulting the same incorrect account balance.

According to Bitquery's investigation, the attackers returned 3,400 BTC on Sept. 7. On Sept. 12, CryptoSlate reported that Blockstream, the company behind Liquid's development, rejected a demand for a bounty. Every coin returned reduces the amount needed to restore the reserve, but repayment from an attacker does not determine who must cover any remaining shortfall.

Why insurance may not protect customers

Crypto insurance can help after a loss, but having a policy does not guarantee that every customer receives full reimbursement. The policy may cover the company rather than the individual customer. Even when an insurer pays, the amount may fall short of what it takes to replace all missing coins.

Coinbase's public disclosure offers a useful example. The company says its crime insurance protects a portion of digital assets held across its storage systems against theft, including cybersecurity breaches. It also warns that total losses could exceed insurance recoveries, leaving customers with losses even when the incident is covered. The policy excludes losses from unauthorized access caused by compromised login credentials, meaning two customers with the same outcome could receive different levels of coverage depending on how the loss occurred.

To compare, in the US, the FDIC protects eligible deposits when a bank fails, but it does not insure digital assets, even when bought through an insured bank. Cash and crypto can appear next to each other in an app and come with very different protections.

Relm, a specialist insurer serving crypto businesses, describes digital asset crime coverage that can respond to infrastructure exploits and theft involving smart contracts. It also offers technology errors and omissions coverage, which addresses claims about problems with a company's products or services. That type of coverage serves a different purpose from directly reimbursing the business for lost assets.

Getting dollars back is not the same as getting Bitcoin back

Even when a payout is agreed upon, the terms determine what is being replaced. Customers who held Bitcoin may expect to receive the same number of coins, but a compensation agreement might instead specify a dollar amount.

For example, if a loss of one Bitcoin was valued at $80,000 and compensation is fixed at that amount, but Bitcoin's price is $100,000 when the payment is made, the recipient gets the promised $80,000, which buys only 0.8 BTC. The dollar amount has been repaid, but the customer still holds fewer Bitcoin than before. If the price falls during the wait, the same dollars could buy more Bitcoin. The agreement determines who bears the risk of those price movements.

What this means for crypto users

Security reduces the chance of a loss, while financial protection determines how that loss is shared. The Liquid incident shows that protecting private keys is not enough; software can still approve the wrong transactions.

Most customers cannot inspect the software approving their withdrawals, nor can they compare its possible failures against an insurance policy they may never see, negotiated between their provider and another business. Providers should explain reimbursement as plainly as they explain fees, stating which losses they undertake to repay and whether repayment means coins or dollars.

What remains unclear

It is not fully clear how the remaining shortfall will be funded or what obligations exist between the parties involved. Whether customers will be reimbursed in Bitcoin or in dollars, and what valuation method will be used, depends on arrangements that the transaction record alone cannot establish.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!