Kraken’s chief security officer, Nick Percoco, confirmed that the crypto exchange recovered $3 million after a bug vulnerability led to funds being stolen. On June 20, Kraken announced the recovery, initially attributing the theft to Certik, a security research firm.
Certik had identified the bug and then exploited it to withdraw $3 million, demanding Kraken honor the bug bounty. Kraken labeled this as extortion rather than ethical hacking. Despite initial resistance, Certik later offered to return the funds, which Kraken confirmed they had accessed, minus some fees.
This incident underscores the critical nature of cybersecurity in the crypto world, highlighting the fine line between ethical hacking and exploitation. Ensuring robust security measures can prevent such vulnerabilities and foster trust in digital asset exchanges.