Kraken’s $3 million bug exploit leads to criminal investigation

Share This Post

Crypto exchange Kraken reported that a rogue security research company has unilaterally held on to $3 million in digital assets they exploited from a bug on its platform.

Kraken’s Chief Security Officer Nick Percoco detailed the incident on X, revealing that on June 9, the company received an anonymous tip from a “security researcher” about a critical bug affecting its funding system.

The bug

According to Percoco, the flaw, stemming from the exchange’s recent UX change, would allow a malicious actor to inflate their account balances artificially. He explained:

“Our team identified a flaw from a UX change that credited accounts prematurely, allowing users to trade in real time before asset clearance. This change was not adequately tested against this specific vulnerability… [So,] a malicious attacker could effectively print assets in their Kraken account.”

After fixing the bug, Kraken found that three accounts had exploited this flaw within a few days. Percoco disclosed that the security researcher had shared the information with two associates, who subsequently withdrew nearly $3 million from Kraken’s treasury.

Extortion?

Percoco stated that Kraken contacted these individuals for a full report and to return the withdrawn funds.

However, these requests were ignored. Instead, the researchers demanded a speculative sum for the potential damages the bug could have caused if undisclosed.

Percoco condemned these actions as unethical and criminal, stating:

“As a security researcher, your license to ‘hack’ a company is enabled by following the simple rules of the bug bounty program you are participating in. Ignoring those rules and extorting the company revokes your ‘license to hack.’ It makes you, and your company, criminals.”

Consequently, Kraken is now treating this incident as criminal and is working with law enforcement authorities.

Kraken has yet to respond to CryptoSlate’s request for additional commentary as of press time.

The post Kraken’s $3 million bug exploit leads to criminal investigation appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Ripple Lawsuit News: SEC to Decide if XRP Deserves Same Treatment as Ethereum

The post Ripple Lawsuit News: SEC to Decide if XRP Deserves Same Treatment as Ethereum appeared first on Coinpedia Fintech News The legal battle between the US Securities and Exchange Commission

XRP Price Hints At Symmetrical Triangle, But A Crash Could Come Before The Surge

Crypto analyst CW23 has revealed that the XRP price is hinting at a symmetrical triangle, which provides a bullish outlook for the crypto However, he warned that a price crash could occur before XRP

Turkey Tightens Crypto Regulations, Grants CMB Oversight

Turkey has introduced new cryptocurrency regulations that give the Capital Markets Board (CMB) full oversight of crypto platforms The FATF Gray Listing Issue Turkey has unveiled new cryptocurrency

XRP News: New Proposal Seeks SEC Settlement with Ripple by Classifying XRP as a Payment Network

The post XRP News: New Proposal Seeks SEC Settlement with Ripple by Classifying XRP as a Payment Network appeared first on Coinpedia Fintech News On March 14, Maximilian Staudinger presented a

Ethereum Price Consolidates and Eyes Recovery—Is a Bounce Incoming?

Ethereum price started a recovery wave above the $1,820 zone ETH is now consolidating and facing hurdles near the $1,950 resistance Ethereum started a recovery wave above the $1,820 level The price

$90K Emerges As Bitcoin Psychological Battleground – Key Level Dictates Market Sentiment

Bitcoin (BTC) has been trapped below crucial price levels for the past few days, following its loss of the $85,000 mark last Sunday Now trading at its lowest levels since November 10, 2024, BTC