Did Kraken Just Get Extorted Over a Critical Bug? The Full Story

Kraken, a leading cryptocurrency exchange, has levelled serious accusations against three security researchers. According to Kraken, the trio discovered a critical bug, exploited it to siphon millions in digital currency, and then attempted to extort the exchange.

Kraken’s chief security officer, Nicholas Percoco, explained that the exploit allowed users to artificially inflate their account balances without completing a deposit.

Broker Review Regulators Min Deposit Website
🥇 Read Review ASIC, FSA, CBI, BVI, FSCA, FRSA, CySEC, ISA, JFSA USD 100 Visit Broker >>
🥈 Read Review FMA, FSA USD 50 Visit Broker >>
🥉 Read Review FSCA, CySEC, DFSA, FSA, CMA USD 0 Visit Broker >>
4 Read Review ASIC, BaFin, CMA, CySEC, DFSA, FCA, SCB USD 200 Visit Broker >>
5 Read Review FCA, CySEC, FSCA, SCB USD 100 Visit Broker >>
6 Read Review FCA, FINMA, FSA, ASIC USD 0 Visit Broker >>
7 Read Review CySEC, FCA, FSA, FSCA, Labuan FSA USD 100 Visit Broker >>
8 Read Review CBCS, CySEC, FCA, FSA, FSC, FSCA, CMA USD 10 Visit Broker >>
9 Read Review ASIC, CySEC, FSCA, CMA USD 100 Visit Broker >>
10 Read Review IFSC, FSCA, ASIC, CySEC USD 1 Visit Broker >>

This was made possible by a recent user experience (UX) change aimed at simulating real-time trades. Unfortunately, this change was not thoroughly tested for such vulnerabilities.

The Incident: How the Bug Was Exploited

In a public statement, Percoco detailed the sequence of events. “The researchers did not provide details in their bug bounty report, but our team identified the bug within an hour,” Percoco said on X (formerly Twitter).

The issue stemmed from a UX update that prematurely credited user accounts before asset clearance, creating an illusion of real-time transactions.

Instead of simply reporting the bug, the primary researcher shared the vulnerability with colleagues, who then withdrew nearly $3 million from Kraken’s treasury.

“These funds were taken from Kraken’s reserves, not client accounts,” Percoco clarified. The researchers allegedly refused to disclose the full extent of their actions or return the stolen funds unless Kraken agreed to a speculative dollar amount for the potential damages.

The Response: CertiK Fires Back

The situation took another turn when CertiK, a blockchain security firm based in the US, identified itself as the other party in the dispute. CertiK countered Kraken’s accusations, claiming that they never withheld the funds and had always intended to return them.

They accused Kraken of misconduct, stating, “After initially cooperating on fixing the bug, Kraken’s team threatened our employees to repay an unreasonable amount in a very short time, without providing repayment addresses.”

CertiK’s statement on X highlighted that they had tried to resolve the issue amicably. However, public opinion on social media has been harsh.

Many accused CertiK of using sanctioned cryptocurrency mixers like TornadoCash and crypto-swapping platforms such as ChangeNOW. Others pointed out discrepancies between CertiK’s public statements and blockchain records.

The Fallout: What Happens Next?

As of now, Kraken has recovered most of the funds, minus some lost to blockchain fees. However, the crypto community remains divided. While Kraken insists that the researchers’ actions constitute extortion, CertiK maintains their innocence and claims Kraken has exaggerated the situation.

“This is not white-hat hacking; it is extortion!” Percoco asserted, adding that Kraken is treating the matter as a criminal case and has involved law enforcement.

The incident underscores the complex and often contentious relationship between cryptocurrency exchanges and security researchers.

As regulatory scrutiny of the crypto industry intensifies, both parties’ actions in this case could set a precedent for future interactions.

Check out our free forex signals
Follow the top economic events on FX Leaders economic calendar
Trade better, discover more Forex Trading Strategies
ABOUT THE AUTHOR See More
Avatar
Arslan Butt
Index & Commodity Analyst
Arslan Butt serves as the Lead Commodities and Indices Analyst, bringing a wealth of expertise to the field. With an MBA in Behavioral Finance and active progress towards a Ph.D., Arslan possesses a deep understanding of market dynamics. His professional journey includes a significant role as a senior analyst at a leading brokerage firm, complementing his extensive experience as a market analyst and day trader. Adept in educating others, Arslan has a commendable track record as an instructor and public speaker. His incisive analyses, particularly within the realms of cryptocurrency and forex markets, are showcased across esteemed financial publications such as ForexCrunch, InsideBitcoins, and EconomyWatch, solidifying his reputation in the financial community.
Related Articles
Comments
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments