financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
White
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
White
Jun 19, 2024 9:32 PM

Leading cryptocurrency exchange Kraken’s chief security officer Nick Percoco has revealed that an undisclosed white-hat hacker group has refused to return digital assets worth roughly $3 million, which they stole from the platform’s treasury by exploiting a bug in its system.

In a series of X posts, Percoco said the security researchers are demanding that the crypto exchange provide a speculated amount of money it could have lost if they had not disclosed the bug before they could return the stolen funds.

Security Researchers Disclose Kraken Bug

According to Percoco, a security researcher sent a Bug Bounty program alert to Kraken on June 9, claiming that they had found an “extremely critical” bug that allowed users to inflate their balance on the platform artificially. While the exchange was wary of receiving multiple fake bug bounty reports daily, it took the claim seriously and assembled a team to investigate the issue.

The team found a bug that allowed cybercriminals to initiate deposits on Kraken and receive funds in their accounts without completing the deposits. Although the bug did not put customer funds at risk, an attacker could print assets in their accounts and place withdrawals that could be extracted from Kraken’s treasury.

The issue was contained in less than two hours of identifying it. The team discovered that the bug stemmed from a flaw in Kraken’s latest user experience (UX). Upon further investigation, Kraken found that three accounts had already exploited the flaw. One account was linked to a user who claimed to be a security researcher.

It turns out the researcher found the bug first, leveraged it to credit their Kraken account with $4 in crypto, and rather than file a bug bounty report with the appropriate team, informed his two colleagues, who exploited the flaw for larger sums. Collectively, they withdrew roughly $3 million in crypto from their accounts.

Bug Bounty Turned Extortion

When Kraken contacted the security researchers and requested an account of their activities and the return of the assets they withdrew, they refused. They called Kraken unreasonable and unprofessional and demanded that the platform provide estimated damage the bug could have caused.

Percoco said Kraken has taken the case up with law enforcement agencies as the case is one of extortion.

“We are treating this as a criminal case and are coordinating with law enforcement agencies accordingly. We’re thankful this issue was reported, but that’s where that thought ends,” Percoco stated.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
This Crypto Investor Lost Nearly $4M in Ethereum (ETH) to Armed Robbers
This Crypto Investor Lost Nearly $4M in Ethereum (ETH) to Armed Robbers
Jun 18, 2024
A cryptocurrency investor based in London has lost almost all his digital asset investments to armed robbers following a physical attack in his home. An X post by the victim, pseudonymously named Ram, revealed that the three thieves were armed with machetes and forced him to transfer all his crypto to certain accounts. Investor Loses $4M Crypto to Robbers According...
Bitcoin Retail Crowd Still Missing, Can They Push BTC Above $70K?
Bitcoin Retail Crowd Still Missing, Can They Push BTC Above $70K?
Jun 18, 2024
Bitcoins price has been trapped within a range below $70,000 for quite some time now. Attempts to surpass this level have been brief and unsuccessful as the digital asset failed to maintain the upward momentum. Interestingly, new research revealed that the retail crowd is not here yet. Bitcoin Retail Crowd Not Here Yet According to CryptoQuants latest analysis, the current...
Meme Coin Frenzy Fuels Explosive Base DEX User Growth
Meme Coin Frenzy Fuels Explosive Base DEX User Growth
Jun 18, 2024
Coinbase Ethereum layer-2 network Base has clinched a new record in terms of the number of daily active users on decentralized exchanges (DEX), reaching 270,000 on June 17th. Compared to the previous day, the figure jumped by approximately 9%. Uniswap Dominates Base With 85% User Share According to data compiled by Dune Analytics, with the latest all-time high of active...
Ethereum Reigns Supreme: L1 Blockchains and DeFi Protocols Dominate Crypto Fee Generation
Ethereum Reigns Supreme: L1 Blockchains and DeFi Protocols Dominate Crypto Fee Generation
Jun 18, 2024
Ethereum generated the most fees among the top twenty protocols over the past 30 days with around $180 million, according to new data from Token Terminal. On June 17, the crypto analytics platform reported that Ethereum was way ahead of other blockchains, which were dominated by layer-1 chains and DeFi protocols, with only one layer-2 blockchain in the top 20. The...
Copyright 2023-2026 - www.financetom.com All Rights Reserved