before wallets will use a ledger, the operator spends the reserves to a multisig of quorum members. so during operation, the operator controls "truth"...
before wallets will use a ledger, the operator spends the reserves to a multisig of quorum members. so during operation, the operator controls "truth", but the quorum controls "funds".
a bad operator cannot steal, they can only misattribute.
the majority of a quorum can steal, but in doing so reveal themselves to be dishonest. it is required that quorum members have their own ledgers with their own quorums of at least half the size, so by colluding to steal, a minimum of 2 or 3 other ledgers are at risk
since quorum membership is visible, wallets can choose ledgers where dishonesty would cause maximum fan-out of liability