CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
    • Spanish
    • Turkish
    • German
    • Bulgarian
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • CryptoPotato Spanish
  • CryptoPotato Turkey
  • CryptoPotato Germany
  • CryptoPotato Bulgaria
  • Market Updates
  • BTC Analysis
  • ETH Analysis
  • XRP Analysis
  • Interviews
CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
    • Spanish
    • Turkish
    • German
    • Bulgarian
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • CryptoPotato Spanish
  • CryptoPotato Turkey
  • CryptoPotato Germany
  • CryptoPotato Bulgaria
Home » Crypto News » White-Hat Hackers Refuse to Return $3M Stolen From Kraken’s Treasury

White-Hat Hackers Refuse to Return $3M Stolen From Kraken’s Treasury

Author: Mandy Williams

Last Updated Jun 19, 2024 @ 17:33

The white-hat hackers found a bug that allowed users to artificially inflate their balance on Kraken.

Getting your audio player ready...

Leading cryptocurrency exchange Kraken’s chief security officer Nick Percoco has revealed that an undisclosed white-hat hacker group has refused to return digital assets worth roughly $3 million, which they stole from the platform’s treasury by exploiting a bug in its system.

In a series of X posts, Percoco said the security researchers are demanding that the crypto exchange provide a speculated amount of money it could have lost if they had not disclosed the bug before they could return the stolen funds.

Security Researchers Disclose Kraken Bug

According to Percoco, a security researcher sent a Bug Bounty program alert to Kraken on June 9, claiming that they had found an “extremely critical” bug that allowed users to inflate their balance on the platform artificially. While the exchange was wary of receiving multiple fake bug bounty reports daily, it took the claim seriously and assembled a team to investigate the issue.

The team found a bug that allowed cybercriminals to initiate deposits on Kraken and receive funds in their accounts without completing the deposits. Although the bug did not put customer funds at risk, an attacker could print assets in their accounts and place withdrawals that could be extracted from Kraken’s treasury.

The issue was contained in less than two hours of identifying it. The team discovered that the bug stemmed from a flaw in Kraken’s latest user experience (UX). Upon further investigation, Kraken found that three accounts had already exploited the flaw. One account was linked to a user who claimed to be a security researcher.

It turns out the researcher found the bug first, leveraged it to credit their Kraken account with $4 in crypto, and rather than file a bug bounty report with the appropriate team, informed his two colleagues, who exploited the flaw for larger sums. Collectively, they withdrew roughly $3 million in crypto from their accounts.

Bug Bounty Turned Extortion

When Kraken contacted the security researchers and requested an account of their activities and the return of the assets they withdrew, they refused. They called Kraken unreasonable and unprofessional and demanded that the platform provide estimated damage the bug could have caused.

Percoco said Kraken has taken the case up with law enforcement agencies as the case is one of extortion.

“We are treating this as a criminal case and are coordinating with law enforcement agencies accordingly. We’re thankful this issue was reported, but that’s where that thought ends,” Percoco stated.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Tags: Hacking Kraken
Enjoy reading? Share with your friends
Facebook Twitter LinkedIn Telegram

About The Author

Mandy Williams
More posts by this author

Mandy Williams is a full-time reporter at CryptoPotato. She joined the cryptocurrency space in early 2017 during her search for financial freedom and has remained devoted to the industry.
Contact Mandy: Twitter

Join Our Community

FacebookX YouTubeTelegram


Editorials
5 Best Meme Coin Presales to Watch in May 2025

5 Best Meme Coin Presales to Watch in May 2025

Toobit Review 2025: Is Toobit a Safe Crypto Exchange?

Toobit Review 2025: Is Toobit a Safe Crypto Exchange?

Hyperliquid Bridge: How to Bridge USDC to Hyperliquid

Hyperliquid Bridge: How to Bridge USDC to Hyperliquid

11 Best Crypto Presales to Consider in May 2025

11 Best Crypto Presales to Consider in May 2025

Need for Speed – Only Ultra-Fast Blockchains Will Win the Adoption Race (Opinion)

Need for Speed – Only Ultra-Fast Blockchains Will Win the Adoption Race (Opinion)

The 5 Best Bitcoin Mining Pools in 2025: Complete Guide

The 5 Best Bitcoin Mining Pools in 2025: Complete Guide

The 5 Best Crypto Staking Platforms in 2025: Everything You Need to Know

The 5 Best Crypto Staking Platforms in 2025: Everything You Need to Know

Join Our Newsletter
Become a CryptoPotato VIP
One Weekly Email Can Change Your Crypto Life.
Sign-up FREE to receive our extended weekly market update and coin analysis report
We NEVER send spam. You can unsubscribe at any time.
Invalid email address
Thanks for subscribing!
Footer Logo
About
Advertise on CryptoPotato
About Us | Contact Us | Careers
Editorial Policy
Terms of service | Privacy Policy | GDPR
More Sections
IEO List | Evaluations
Airdrops
Scholarship
Disclaimer
Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. Full disclaimer
© Copyright CryptoPotato 2016 - 2025
Scroll to top
One Daily Email Can Change Your Crypto Life.

Sign-up FREE to receive our extended daily market update and coin analysis report

We never send SPAM. You can unsubscribe at any moment
Invalid email address
Thanks for subscribing!