bitcoin
Bitcoin (BITCOIN)
$84,572 -0.57%
ethereum
Ethereum (ETHEREUM)
$1,596 0.51%
binancecoin
BNB (BINANCECOIN)
$594.25 0.43%
solana
Solana (SOLANA)
$134.25 -0.35%
ripple
XRP (RIPPLE)
$2.08 0.20%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000012 3.93%
pepe
Pepe (PEPE)
$0.000007 -0.51%
bonk
Bonk (BONK)
$0.000012 1.23%
bitcoin
Bitcoin (BITCOIN)
$84,572 -0.57%
ethereum
Ethereum (ETHEREUM)
$1,596 0.51%
binancecoin
BNB (BINANCECOIN)
$594.25 0.43%
solana
Solana (SOLANA)
$134.25 -0.35%
ripple
XRP (RIPPLE)
$2.08 0.20%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000012 3.93%
pepe
Pepe (PEPE)
$0.000007 -0.51%
bonk
Bonk (BONK)
$0.000012 1.23%
bitcoin
Bitcoin (BITCOIN)
$84,572 -0.57%
ethereum
Ethereum (ETHEREUM)
$1,596 0.51%
binancecoin
BNB (BINANCECOIN)
$594.25 0.43%
solana
Solana (SOLANA)
$134.25 -0.35%
ripple
XRP (RIPPLE)
$2.08 0.20%
shiba-inu
Shiba Inu (SHIBA-INU)
$0.000012 3.93%
pepe
Pepe (PEPE)
$0.000007 -0.51%
bonk
Bonk (BONK)
$0.000012 1.23%
Disclosure
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
Kraken Hit by $3M Crypto Bug Exploit and Extortion

Highlights:

  • An alleged security researcher exploited a Kraken bug to illegally withdraw $3 million, prompting discussions on ethical hacking.
  • Kraken confirmed that the stolen funds were from its treasury, reassuring that no user funds were compromised during the breach.
  • The incident highlights a significant uptick in cryptocurrency-related hacks, with private key leaks leading to these security breaches.

Cryptocurrency exchange Kraken has recently come under fire after a supposed security researcher exploited a vulnerability, leading to a loss of $3 million in digital assets. This incident has ignited a debate over the ethical implications of hacking and the robustness of security protocols in the digital asset space.

Advertisement

Banner

Discovery and Immediate Exploitation

On June 9, an individual approached Kraken, claiming to have discovered a significant security flaw. Initially, the person demonstrated the bug with a nominal transfer of $4, suggesting a benign intent typical of white-hat hackers participating in bounty programs. However, the situation quickly escalated as two accounts linked to this researcher exploited the flaw, resulting in substantial unauthorized withdrawals from Kraken’s reserves.

Nick Percoco, Kraken’s chief security officer, took to the social media platform X to outline the gravity of the situation. He clarified that the researcher engaged in what the company considers extortion rather than a simple disclosure. The individual demanded compensation, threatening to reveal the bug’s potential for more extensive damage if their terms were not met.

Ethical Hacking vs Extortion

The controversy primarily stems from the method of disclosing the bug. Ethical hackers usually identify and report vulnerabilities without exploiting them, allowing companies to rectify the issues safely. However, the actions veered towards financial gain, in this case, deviating from accepted ethical hacking norms.

Interestingly, one of the involved accounts had passed Kraken’s rigorous Know Your Customer (KYC) verification labeled itself a security researcher. Despite this, the true identity behind the incident remains unknown, and the moral boundaries of their actions are under scrutiny.’

Impact on the Crypto Industry

While reassuring that user funds were secure, Kraken has acknowledged the broader implications of such security breaches. The firm has since shared details of the exploited bug with the wider industry to forestall similar incidents. These steps underscore Kraken’s commitment to bolstering ecosystem-wide security measures.

Moreover, this episode indicates a rising trend in crypto-related security breaches. According to the 2024 Crypto HackHub Report by Merkle Science, the early months of the year saw a staggering $542.7 million stolen across various platforms, marking a significant increase from the previous year. The report also notes a shift like these exploits, with private key leaks now surpassing smart contract vulnerabilities as the primary threat vector.

Read More

Disclaimer: Cryptocurrency is a high-risk asset class. This article is provided for informational purposes and does not constitute investment advice. You could lose all of your capital.

Buy Cryptos on eToro banner

Advertisement

Banner

Advertisement

Banner

Advertisement

Banner