If so, this is either:
1. one heckuva Mickey Mouse operation
2. a smokescreen
The statement never mentions Bitcoin, but let's assume that this is the "cryptocurrency" being referred to.
That Bitcoin private keys were being stored on a "server" strains credulity. There's very little reason to do so, and every reason not to.
Payments can be received and orders fulfilled by a server - without private keys. Multiple addresses can be watched in read-only mode.
The only reason for a server to hold private keys is if that server is capable of making automated payments, and that capability is a crucial part of the operation.
Bitcoin's history is littered with the corpses of people who messed up the management of their own cryptographic keys. Any reasonably competent operator would know about them and would never, under any circumstances hold private keys on a server.
Which leaves Option 2. Smokescreen. Make it look like all the loot was lost, try to throw investigators off the trail.
If so, it's a lame attempt.
One other possibility comes to mind. The ransom itself was the smokescreen.
The amount of the ransom was nothing for a company the size of Colonial. And it's about 1/10 of the annual salary of some developers. Why risk the prospect of life in prison for such as small payoff?
The reason is, of course, to make this operation look like something it's not. A Mickey Mouse band of idiots who can't manage their own private keys or servers. Lots of reasons to do this, starting with the notion that the attackers are trying to conceal their identities. And maybe that this was a test operation. Throw in the trinkets of ransom to make it look believable to the public.