Your daily dose of crypto news

Kraken Recovers $3M from CertiK, Closes Bug Bounty Saga

3 min read
5a22b174dd0a504c1e9e463a1b555716 CryptoForDay

Kraken Recovers $3M from CertiK, Closes Bug Bounty Saga

Cryptocurrency exchange Kraken has successfully recovered almost $3 million worth of digital assets that went missing due to a security breach. This marks the conclusion of a dramatic episode involving Kraken and the blockchain security firm, CertiK, which began on June 9. Nicholas Percoco, Kraken’s Chief Security Officer (CSO), confirmed the return of the funds in a social media update on June 20, mentioning that a small portion was lost due to transaction fees.

The ordeal began on June 19 when Percoco announced that approximately $3 million had been illegitimately withdrawn from Kraken’s treasury by a “security researcher.” According to Percoco, the funds were taken after the researcher discovered and reported an existing bug. The situation escalated when Kraken alleged that the researcher was attempting to extort the company by refusing to return the stolen funds, demanding a reward and a discussion with Kraken’s business development team.

CertiK, a blockchain security firm, identified itself as the “security researcher” implicated in the incident. CertiK publicly stated on June 19 that it had notified Kraken of an exploit, which allowed it to extract millions from Kraken’s accounts. CertiK further accused Kraken of threatening its employees following the discovery of the bug, stating that Kraken’s security team demanded the return of an incorrect amount of crypto within an unreasonable timeframe, even without providing repayment addresses.

CertiK provided a detailed timeline of events, beginning with the identification of the bug on June 5 and culminating in claims that Kraken threatened a CertiK employee on June 18. In a communication with , CertiK disclosed its intention to transfer the funds to an account accessible by Kraken.

The big question lingering was why CertiK withdrew nearly $3 million. Percoco initially pointed out that a minor transfer of just $4 would have sufficed to demonstrate the bug and earn a reward from Kraken’s bounty program. CertiK took nearly $3 million, arguing that this substantial amount was necessary to thoroughly test Kraken’s security systems and protective measures. They revealed that despite multiple tests over several days and close to $3 million worth of transactions, no alerts were triggered, leaving them unable to determine the breach’s limit.

Adding to the controversy, CertiK stated it did not initially request a bounty; instead, Kraken brought up the bounty after CertiK reported the exploit. CertiK clarified that their primary focus was on ensuring the issue was fixed, not on receiving a reward.

CertiK assured that the funds used in the exploit were not actual user funds from Kraken. They were, in CertiK’s words, “minted out of air,” meaning no user assets were at risk during the testing period. This clarification was likely intended to alleviate concerns from Kraken users about the safety of their assets.

The return of the funds and the explanations provided by both parties bring a complex and contentious chapter to a close. It underscores the ongoing challenges within the cryptocurrency sector related to security, ethical hacking, and the limits of bug bounty programs. The incident serves as a critical case study for both crypto exchanges and security firms on how to handle vulnerabilities and disputes professionally and transparently.

33 thoughts on “Kraken Recovers $3M from CertiK, Closes Bug Bounty Saga

  1. Too much drama for just returning the funds. Let’s be clear: a $4 transfer would’ve done the job just fine. Suspicious .

  2. Props to Kraken on their quick recovery and to CertiK for highlighting the vulnerability! What a collaboration!

  3. Great to hear Kraken managed to recover the missing assets. Love the transparency and dedication shown! 💬✨

  4. Why do these ‘security researchers’ always seem to think its okay to walk off with millions? Just report the bug and get rewarded fairly .

  5. Three cheers for Kraken and CertiK! Fantastic job recovering the funds and maintaining trust. 🥳🔐

  6. Kraken’s and CertiK’s handling of this incident is a perfect example of how NOT to manage security and ethical concerns in crypto .

  7. The fact that CertiK had to extract nearly $3M to ‘test the security’ just seems ridiculously excessive. Not buying it .

  8. So much drama and finger-pointing. Just shows how immature the whole crypto space still is .

  9. A small portion lost to transaction fees? Thats not the takeaway here. The whole incident is a security fiasco .

  10. Security issues happen but it’s how you handle them. Kraken showed true professionalism and resilience!

  11. Impressed by how Kraken handled the breach. Kudos to CertiK too! Much respect for both teams.

  12. What a rollercoaster ride! Happy to see a positive end to this chapter for Kraken and CertiK. 🎢👍

  13. Great news! Kraken turning a potential nightmare into a big win for security protocols. 🙌💥

  14. Incredible resilience shown by Kraken and CertiK in recovering the funds. Lessons learned for sure!

  15. Big shoutout to Kraken and CertiK for swiftly resolving the issue and ensuring no user funds were at risk!

  16. What a journey! Happy to see the funds safely back. Krakens handling of this situation is commendable!

  17. Glad to see Kraken bouncing back from this challenge stronger than ever! Here’s to more secure exchanges. 🚀🔒

  18. Props to Kraken for their transparency and teamwork with CertiK! Security first!

  19. Does anyone feel safe leaving their assets in Kraken after this debacle? Well, I sure dont .

  20. CertiK’s explanation doesn’t sit right with me. Steal first, then ask questions later? Sounds like a terrible tactic 🤯.

  21. The transparency from Kraken during this operation has been top-notch! Way to go team!

  22. Reading this gives me confidence in the crypto exchange space. Kudos to Kraken and CertiK!

  23. Reading this feels like watching a thriller! Glad it had a happy ending. Excellent work Kraken and CertiK!

  24. Amazing news! Kraken recovered almost $3M. Huge shoutout to their CSO Nicholas Percoco and CertiK for their efforts!

  25. CertiK claims they didn’t put user assets at risk, but honestly, this whole action feels super reckless and irresponsible .

  26. So Kraken gets hacked, and then the ‘researcher’ tries to justify stealing a huge amount? This sounds shady as heck .

  27. Krakens treasury gets compromised and all they lost is some transaction fees? That’s not the point. Where are the repercussions?

  28. This entire ordeal sounds like a poorly written thriller novel. Transparency? Hah, more like confused blames 👎.

  29. Excellent teamwork and quick resolution! Kraken and CertiK set a great example for the crypto world. 🌍💪

  30. Kudos to Kraken and CertiK for resolving this issue. Great teamwork under pressure! 👏👏

  31. Kraken threatening CertiK employees? This drama cannot get any more unprofessional. Grow up, people .

  32. This whole incident is embarrassing for both Kraken and CertiK. Makes me lose trust in crypto security .

Leave a Reply

Copyright © All rights reserved.