If a bank said that customers were responsible for the money stored in the bank and that the bank could not undo transactions (from the POV of the genuine client) then we'd be demanding much stronger banking passwords.
A consequence of making that formal is that the total owned amount of bitcoin would be more than 21m, because the hacker would own bitcoin and the users would own bitcoin on the exchange.
As long as there isn't a bank run, that discrepancy would not be a problem, but it would deflate the currency, also seen as unacceptable to bitcoin purists.
edit: access -> accept.
And that evidence is pretty clear. I do not remember any hacking incidents resulting in large-scale losses to consumer, so they seem to be doing something right.