Crypto Insurance Falls Short in Face of Software-Driven Theft
On September 6th, Liquid's reserve lost almost 4,000 Bitcoin through a withdrawal that was approved by its network, even though the private keys used to authorize it hadn't been stolen. This is a critical issue because it shows that software can use those keys to approve the wrong payment.
According to TRM Labs' reconstruction of the attack, attackers exploited a software flaw to create L-BTC (a token representing one BTC) without putting in the actual Bitcoin to back it. They then exchanged these tokens for real coins. The operators responsible for approving withdrawals essentially trusted information that was wrong.
This incident raises questions about who pays to put the money back and whether crypto insurance can provide sufficient protection. Liquid is insured, but the terms of its policy may not cover all losses. This highlights the need for customers to understand what they're being promised and whether the business can afford to honor it.
Crypto insurance can help, but just having a policy might not be enough. The company may be insured for certain losses or claims brought against it without promising every customer full repayment. Even when an insurer pays, the amount might fall short of what's needed to replace the missing coins.