24/7 Cryptocurrency News

Just In: Kraken Responds to Extortion Attempt Following Security Breach

Kraken addresses a $3M security breach and extortion attempt, reinforcing its bug bounty program and tightening security protocols.
Published by
Just In: Kraken Responds to Extortion Attempt Following Security Breach

Highlights

  • Kraken managed a security breach involving a $3 million exploit after a bug bounty report became an extortion attempt.
  • The flaw allowed account balance inflation and was quickly fixed by Kraken's security team within two hours.
  • The vulnerability originated from a recent update that enabled immediate trading before verifying deposited funds.

Kraken, a major cryptocurrency exchange, recently managed a security breach and potential extortion attempt after a supposed bug bounty report became a demand for money. Chief Security Officer Nick Percoco outlined the events, noting a flaw was exploited to inflate account balances artificially. This incident has prompted an investigation involving law enforcement and emphasized the importance of adhering to ethical practices in security research.

Advertisement

Kraken Responds to $3 Million Security Breach

Upon receiving a bug bounty report on June 9, 2024, Kraken‘s security team, led by Percoco, sprung into action. They quickly discovered that the vulnerability had already been exploited, leading to the unlawful withdrawal of nearly $3 million from the exchange’s reserves. Although initially an act attributed to a security researcher—who claimed a mere $4 to demonstrate the flaw—the situation escalated when it was revealed that this individual had shared the bug with accomplices who extracted much more significant amounts.

Kraken’s team rectified the security loophole within two hours of detection. The bug originated from a recent update intended to enhance the user experience by allowing immediate trading before thoroughly verifying deposited funds. However, this change inadvertently created a vulnerability. Percoco stressed that no client assets were at risk at any time, as the flaw only allowed the inflating of balances within the perpetrators’ accounts.

Also Read: Binance Rolls Out HODLer Airdrops For BNB Holders

Advertisement

Kraken Reinforces Policies After Security Breach

Following the discovery, the perpetrators refused to cooperate with Kraken’s investigation, demanding to speak with the business development team, a move Percoco labeled as extortion. This incident has highlighted the critical nature of following ethical guidelines in bug bounty programs. Kraken’s longstanding policy is clear: researchers must not exploit vulnerabilities beyond what is necessary to prove their existence and should promptly return any unauthorized funds.

Kraken has a nearly decade-long history of operating its bug bounty program, designed to encourage white-hat hackers to help identify and fix security gaps responsibly. This program has functioned smoothly with cooperation from the security research community, and this is the first instance of such a severe breach of trust and protocol. 

Despite the unsettling events, Kraken remains dedicated to its bug bounty program, recognizing its value in enhancing the security of the cryptocurrency ecosystem. The exchange has taken steps to reinforce its systems against similar vulnerabilities by implementing stricter testing protocols, particularly following feature updates affecting account transactions.

Also Read: XRP Lawsuit: SEC’s Ethereum Investigation Conclusion Bolsters Ripple’s Position

Advertisement

Share
Maxwell Mutuma

Maxwell is a crypto-economic analyst and Blockchain enthusiast, passionate about helping people understand the potential of decentralized technology. I write extensively on topics such as blockchain, cryptocurrency, tokens, and more for many publications. My goal is to spread knowledge about this revolutionary technology and its implications for economic freedom and social good.

Published by
Why trust CoinGape: CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journalists and analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Recent Posts

  • 24/7 Cryptocurrency News

Senate Committee to Hold Hearing on Crypto Taxation on October 1

The Senate Finance Committee will hold a crypto taxation hearing as the Trump administration continues…

September 25, 2025
  • 24/7 Cryptocurrency News

XRP DeFi Gets Major Boost as Flare’s ‘FXRP’ Goes Live

Flare has introduced FXRP, a wrapper of XRP which allows the token to be utilized…

September 24, 2025
  • 24/7 Cryptocurrency News

$1.6T Franklin Templeton Expands Tokenized Platform To BNB Chain Following Binance Partnership

Franklin Templeton has expanded its Benji Technology Platform to BNB Chain, aiming to reach more…

September 24, 2025
  • 24/7 Cryptocurrency News

SEC Chair Paul Atkins Rejects CFTC Role Amid SEC-CFTC Crypto Coordination

SEC Chair Paul Atkins has firmly rejected speculation that he could step in as chair…

September 24, 2025
  • 24/7 Cryptocurrency News

Bessent Faults Powell for Not Signaling 150 bps Fed Rate Cut by Year-End

U.S. Treasury Secretary Scott Bessent has again criticized Jerome Powell over his failure to signal…

September 24, 2025
  • 24/7 Cryptocurrency News

Toobit Adds German Language Support to Ease Market Access On Trading Platform

A top crypto exchange, Toobit, is now fully supporting German on its platform. Traders can…

September 24, 2025