You're assuming they had proper security in place on the system they used to create the keys and disposed of it correctly. If it was ever connected to a network, anybody on the planet with an internet connection could have downloaded the information - not that it removes their responsibility. Also, if the system was sold off and not properly wiped - recovery of files could have taken place later and they'll never know the culprit.
We don't have to assume, we know: they very obviously did not have proper security in place.
You have two good ideas there that they can use in the investigation (was the system connected, were any disk drives thrown away, etc.) very good lines of inquiry.
As far as responsibility goes they are putting a reimbursement procedure in place and, in fact, have already sent out some reimbursements. He is taking out a loan to by the BTC necessary to do all the reimbursements. He has taken full responsibility while working to find the thief or thieves.