• Book Dewayne Hart
  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
  • Speaker Bio
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
  • Home
  • About
  • Speaker
  • Books
  • Podcast
  • Contact
Facebook-f Linkedin-in Youtube X-twitter Globe
Order books

Kraken Crypto Exchange Hit by $3 Million Theft Exploiting Zero-Day Flaw

Posted on June 19, 2024 by admin

[ad_1]

Jun 19, 2024NewsroomCybercrime / Crypto Security

Zero-Day Flaw

Crypto exchange Kraken revealed that an unnamed security researcher exploited an “extremely critical” zero-day flaw in its platform to steal $3 million in digital assets and refused to return them.

Details of the incident were shared by Kraken’s Chief Security Officer, Nick Percoco, on X (formerly Twitter), stating it received a Bug Bounty program alert about a bug that “allowed them to artificially inflate their balance on our platform” without sharing any other details

The company said it identified a security issue within minutes of receiving the alert that essentially permitted an attacker to “initiate a deposit onto our platform and receive funds in their account without fully completing the deposit.”

Cybersecurity

While Kraken emphasized that no client assets were at risk of the issue, it could have enabled a threat actor to print assets in their accounts. The problem was addressed within 47 minutes, it said.

It also said the flaw stemmed from a recent user interface change that allows customers to deposit funds and use them before they were cleared.

On top of that, further investigation unearthed the fact that three accounts, including one belonging to the supposed security researcher, had exploited the flaw within a few days of each other and siphon $3 million.

“This individual discovered the bug in our funding system, and leveraged it to credit their account with $4 in crypto,” Percoco said. “This would have been sufficient to prove the flaw, file a bug bounty report with our team, and collect a very sizable reward under the terms of our program.”

“Instead, the ‘security researcher’ disclosed this bug to two other individuals who they work with who fraudulently generated much larger sums. They ultimately withdrew nearly $3 million from their Kraken accounts. This was from Kraken’s treasuries, not other client assets.”

In a strange turn of events, on being approached by Kraken to share their proof-of-concept (PoC) exploit used to create the on-chain activity and to arrange the return of the funds that they had withdrawn, they instead demanded that the company get in touch with their business development team to pay a set amount in order to release the assets.

Cybersecurity

“This is not white hat hacking, it is extortion,” Percoco said, urging the concerned parties to return the stolen funds.

The name of the company was not disclosed, but Kraken said it’s treating the security event as a criminal case and that it’s coordinating with law enforcement agencies about the matter.

“As a security researcher, your license to ‘hack’ a company is enabled by following the simple rules of the bug bounty program you are participating in,” Percoco noted. “Ignoring those rules and extorting the company revokes your ‘license to hack.’ It makes you, and your company, criminals.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



[ad_2]

Recent Posts

  • Proactive Protection Wins: What Real-World Breaches Teach Leaders
  • CTEM vs ASM vs Vulnerability Management: What Security Leaders Need to Know in 2025
  • Chinese Hackers Target Taiwan’s Semiconductor Sector with Cobalt Strike, Custom Backdoors
  • Cisco Warns of Critical ISE Flaw Allowing Unauthenticated Attackers to Execute Root Code
  • Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms

Recent Comments

No comments to show.

Archives

  • February 2026
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023

Categories

  • Cyber News
  • Uncategorized

Book Dewayne Hart for your next event

  • Dewaynehart@dewaynehart.com
  • (470) 409 8316
Facebook-f Linkedin-in Youtube X-twitter Globe
© 2025 Dewayne Hart | Cybersecurity Leadership & Innovation