Kraken's $3 million bug exploit leads to criminal investigation

cyptouser5 months agoCryptocurrencies News72
Crypto exchange Kraken reported that a rogue security research company has unilaterally held on to $3 million in digital assets they exploited from a bug on its platform.

Kraken’s Chief Security Officer Nick Percoco detailed the incident on X, revealing that on June 9, the company received an anonymous tip from a “security researcher” about a critical bug affecting its funding system.

The bug

According to Percoco, the flaw, stemming from the exchange’s recent UX change, would allow a malicious actor to inflate their account balances artificially. He explained:

“Our team identified a flaw from a UX change that credited accounts prematurely, allowing users to trade in real time before asset clearance. This change was not adequately tested against this specific vulnerability… [So,] a malicious attacker could effectively print assets in their Kraken account.”

After fixing the bug, Kraken found that three accounts had exploited this flaw within a few days. Percoco disclosed that the security researcher had shared the information with two associates, who subsequently withdrew nearly $3 million from Kraken’s treasury.

Extortion?

Percoco stated that Kraken contacted these individuals for a full report and to return the withdrawn funds.

However, these requests were ignored. Instead, the researchers demanded a speculative sum for the potential damages the bug could have caused if undisclosed.

Percoco condemned these actions as unethical and criminal, stating:

“As a security researcher, your license to ‘hack’ a company is enabled by following the simple rules of the bug bounty program you are participating in. Ignoring those rules and extorting the company revokes your ‘license to hack.’ It makes you, and your company, criminals.”

Consequently, Kraken is now treating this incident as criminal and is working with law enforcement authorities.

Kraken has yet to respond to CryptoSlate’s request for additional commentary as of press time.

Mentioned in this article
Kraken
The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

‘Giant buy’ signal? Crypto whales transfer $1.3B to Coinbase

‘Giant buy’ signal? Crypto whales transfer $1.3B to Coinbase

1205f261˃A total of $1.3 billion of USD Coin (USDC) in transfers from apparent whale addresses to cr...

'China is about to start bidding' — Will Hong Kong Bitcoin ETFs spark the halving rally?

'China is about to start bidding' — Will Hong Kong Bitcoin ETFs spark the halving rally?

1205f261˃The potential approval of the first batch of spot Bitcoin exchange-traded funds (ETFs) in H...

Bitfarms appoints new CEO as Riot intensifies takeover bid

Bitcoin miner Riot Platforms’ effort to take over rival Bitfarms has taken a new turn with recent de...

Dutch central bank reveals it fined Crypto.com for registration violations

Dutch central bank reveals it fined Crypto.com for registration violations

b98df8a0˃De Nederlandsche Bank (DNB), the central bank of The Netherlands, fined Crypto.com for oper...

BTC price risks $60K dive as Bitcoin bid liquidity thins on new 3% dip

BTC price risks $60K dive as Bitcoin bid liquidity thins on new 3% dip

55966e89˃Bitcoin traded below $68,000 during the June 11 Asia trading session as analysis warned of...

Trump campaign leans in on crypto with new donation page amid shifting political landscape

Former President Donald Trump has begun accepting crypto donations for his re-election campaign, mak...