Skip to content

$3M Exploit: Who’s Right in Legal Battle?

Last week, Kraken revealed a critical bug that allowed security researchers to inflate their balances and withdraw nearly $3 million. The incident sparked a heated debate between Kraken and CertiK, a leading cybersecurity firm in the Web3 space.

Kraken’s Chief Security Officer, Nick Percoco, criticized CertiK for excessive withdrawals and alleged extortion, claiming the researchers extracted more funds than needed and delayed their return. CertiK defended its actions, stating that large-scale tests were necessary to assess Kraken’s vulnerabilities and emphasized that no real users were affected.

This dispute underscores the need for clear rules in cybersecurity engagements. CertiK argued that large withdrawals were crucial to test Kraken’s risk controls, suggesting that such measures could prevent larger future losses. The incident highlights potential risks in major exchanges and the importance of robust security protocols.

Share