Liquid network loses 4,000 Bitcoin to software flaw without private key compromise
Cryptocurrency held at custodians and exchanges faces a novel liability gap: software failures that drain reserves without compromising private keys can still result in user losses that insurance may not fully cover. Understanding what “insured” actually means requires reading the fine print most platforms do not provide.
- Nearly 4,000 Bitcoin left Liquid’s reserve on September 6 through an approved withdrawal despite private keys never being stolen.
- Attackers exploited a software flaw to create L-BTC tokens without depositing backing Bitcoin, then exchanged them for real coins.
- Insurance policies protecting custodians may not fully compensate individual customers, and contractual terms determine whether repayment occurs in coins or dollars.
- 3,400 BTC returned by attackers on September 7, reducing reserve shortfall
- $319M in Bitcoin drained from Liquid Network in September 2024
- $250K FDIC deposit insurance limit per account at insured banks
- Sept. 6 date software-approved Liquid withdrawal exploiting infrastructure flaw
According to CryptoSlate, a critical vulnerability in the Liquid network’s withdrawal approval process resulted in the loss of approximately 4,000 Bitcoin on Sunday, September 6, 2024, without any compromise to the private keys that authorize transactions. The attack exposed a fundamental gap in cryptocurrency security assumptions: protecting cryptographic secrets no longer guarantees protection of funds when software itself can approve incorrect transactions.
Software failure bypasses key Security without triggering theft protections
According to TRM Labs’ reconstruction, attackers exploited a flaw in Liquid’s code to create L-BTC tokens, which represent Bitcoin held in a shared reserve, without depositing the corresponding Bitcoin to back them. The tokens were then exchanged for real coins from the reserve. Liquid operates as a sidechain designed for faster and more private transactions, holding Bitcoin in a pooled wallet while issuing L-BTC to users one-to-one with their deposits.
The operators responsible for approving withdrawals trusted software output that was fundamentally false. The vulnerability bypassed the assumption that holding private keys guarantees control: the keys functioned correctly, yet the system used them to authorize a payment that should never have occurred. TRM Labs reported that attackers subsequently returned 3,400 BTC on September 7, reducing but not eliminating the loss. Blockstream, which operates Liquid, rejected a demand for a bounty on September 12 (September 12).
Insurance covers the company, not necessarily the customer
The Liquid incident raises an immediate question that custody losses always pose: when funds disappear, who bears the cost? The answer depends on layers of agreements that customers typically never see. Insurance can help, but policies insure the company holding the assets, not the customer directly, and contractual terms govern what gets repaid and to whom.
Coinbase’s public insurance disclosure illustrates the gap between having a policy and having full coverage. The company states that its crime insurance protects a “portion” of digital assets held across its storage systems against theft, including cybersecurity breaches, but explicitly warns that total losses could exceed insurance recoveries. The policy also excludes losses from unauthorized access to individual accounts caused by compromised or lost login credentials, meaning the same outcome—missing funds—triggers different coverage depending on how the loss occurred.
A company’s insurance agreement is with its insurer, not with its customers. Whether customers can claim directly and how payments reach them depends on legal arrangements customers cannot inspect.
Repayment in dollars versus coins creates unequal outcomes
Even when a company agrees to repay a loss, the contract determines what “repayment” means. If compensation is specified in dollar terms rather than coins, price movements between loss and payment can shift who bears the economic risk. A customer receiving $80,000 in compensation for one Bitcoin stolen when Bitcoin cost $80,000 per coin would receive only 0.8 Bitcoin if the price rises to $100,000 by the time payment is made. The dollar obligation is satisfied while the original Bitcoin holding remains incomplete.
Insurance agreements must also address recovered funds. When attackers return Bitcoin, as happened with Liquid’s 3,400 BTC on September 7, the contract must specify whether recovered coins go to the insurer, the company, or are allocated among customers. The technical fact of coins being returned does not automatically establish who is entitled to them. Customers unable to access funds during the recovery period may also suffer costs—missed payments, inability to reposition savings—that replacing the asset itself does not address.
Disclosure gaps leave customers unable to assess Risk
The comparison between cryptocurrency insurance and traditional banking illustrates why disclosure matters. The FDIC protects eligible deposits to at least $250,000 per account at insured banks when a bank fails, a clear public guarantee. The FDIC does not insure digital assets even when they are purchased through an insured bank, meaning a customer seeing dollars and Bitcoin side by side in a mobile app may not realize they carry entirely different protections.
Most cryptocurrency custodians do not publish the terms of their insurance policies or their obligations if insurance proves insufficient.
Industry practice diverges sharply from banking’s transparency standard. A customer can learn bank fees, minimum balances, and deposit insurance limits from public disclosures. Cryptocurrency platforms often advertise that they are “insured” without stating whose losses the insurance covers, whether it covers all losses or only a portion, or what the company itself has committed to cover if insurance recovers less than the total loss. This gap places responsibility for risk assessment on customers unable to inspect the software they rely on or negotiate the contracts between their provider and its insurer.
The BlockWest read. Liquid’s loss reveals that custody risk now exceeds the traditional definition of theft. A company holding Bitcoin faces infrastructure risks—software bugs, logic flaws, operational errors—that insurance products for digital asset crime may address separately or not at all. Platforms should compete on transparency about what they will repay and with what capital, not on vague insurance claims.
The open question is whether regulators or industry standards will mandate disclosure of insurance terms and company obligations. Platforms including Coinbase have published partial information, but no consistent requirement exists, and no platform has committed to explaining repayment mechanisms in plainly accessible terms. Watch for whether any major custodian publishes a full insurance policy summary or establishes a public funding reserve separate from insurance to close any customer payout gap.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
