Most systems have an identifier and a password, and sometimes 2FA.
For bitcoin, all you have is a 256 bit key. The key points to a 160 bit address (through hashing), and allows signing transaction from that address.
This is true security by statistical obscurity, as you can generate as many keys as you want by brute force, and all of them will match and give you control of a valid address, with a non-zero chance of it being an existing address with a balance. The chance is so low that it is completely acceptable though, at around one in 2^154.
This means the bitcoins people own aren't materialized, you can't delete, download or store them. They are simply a positive balance recorded on the blockchain for an address they control.
There is no cold storage for the coins, as they are always publicly available on the chain, and anyone with a valid key to that address can spend them. The only way to lock them down is to move them to an address that only you control.
When people talk about cold storage, they're talking about the private key. You can generate and store a key on a secured machine / device, allowing you to generate signed transactions for the corresponding address. You then copy that transaction to a internet enabled machine in a secure way, and broadcast the transaction to the network.
To get away with it, he would have had to deny all knowledge of the keys -- which he could potentially do with offline storage, at the expense of opening himself to perjury if he ever got busted -- but, importantly, never spend the contents in a way that could be linked back to him by following the metadata "paper trail". That last one is pretty difficult to achieve, especially when so many coins are involved and they're already "hot". A mixer could help obfuscate the trail -- especially if there were steps involving exchanging to other cryptocurrencies or fiats, but then trust becomes a real issue -- but given the current exchange rate, it would probably be worthwhile for the Feds to do some blockchain forensics to keep track of it all.
I don't think he would have ever got away with it.
He likely got less time for agreeing to turn over his private key. That might have been a bad decision depending on how many years he would have gotten otherwise. Those 1,600 bitcoin are worth over $10 million at the moment.
More so, "possession of stolen property" is also a crime. The car doesn't magically become unstolen just because the theft went to jail.
This has absolutely nothing to do with civil forfeiture.
Civil forfeiture is when the getaway car is seized when you are robbing a bank.
Restitution is when you are ordered by a court to repay the victim for their losses that your criminal behavior caused. This case involved restitution, if he didn't comply with giving up the private keys he would be ordered to pay restitution.
Civil forfeiture doesn't impact restitution.
Or if he was careful about it he could tumble his coins, and then withdraw a small amount of cash every month or so for the rest of his life while still living in the US.
If he said "I lost the private key," he would have been ordered to pay restitution in cash. That means his assets (including his house) would be seized, when he gets out of jail his wages would be garnished forever, any inheritance he ever tried to claim would be seized, if he won the lottery that would be seized, his tax returns would be seized, etc. He would never be allowed to build any wealth at all until that restitution was paid, and it never would be because who makes enough money in their lifetime to pay a $10M restitution?
The coins are now completely worthless to him because those addresses will be watched forever, if any coins ever moved from that wallet, he would automatically go to jail. $10 million you can never spend or give away is not useful.