Rustler catches panics before they crash the VM and raises them on the elixir side as an exception. So your process might crash but the vm wont
I wrote this recently about Go, but it equally applies to any Rust application that tries to recover from a panic.
This is based on the acknowledgment that if you have a large number of longer running processes at some point something will crash anyway, so you may quite as well be good at managing crashes ;-)
https://dev.to/adolfont/the-let-it-crash-error-handling-stra...
It's also not like there is much of a choice here. Unwinding across FFI boundaries (e.g. out of the NIF call) is undefined behaviour, so the only other option is aborting on panics.
I am still interested in the situation you observed.