Private-key compromise survives a valid certificate

If somebody steals the private key, the certificate keeps working perfectly for them.

Nothing about the certificate reveals that anybody else has a copy. It remains valid, browsers accept it, and the attacker can impersonate the site or decrypt traffic until it is revoked or expires. Revocation is unreliable in practice, which is why certificate lifetimes keep shortening: the expiry date has become the realistic limit on the damage.

More on TLS and PKI