Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • ADOPTION
  • TRADING
  • HACKING
  • SLOT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • ADOPTION
  • TRADING
  • HACKING
  • SLOT
Crypto Flexs
Home»ADOPTION NEWS»Kraken says it exploited a bug that has now been fixed, worth about $3 million.
ADOPTION NEWS

Kraken says it exploited a bug that has now been fixed, worth about $3 million.

By Crypto FlexsJune 19, 20243 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Kraken says it exploited a bug that has now been fixed, worth about  million.
Share
Facebook Twitter LinkedIn Pinterest Email

Kraken said about $3 million was taken from its wallets due to an attack related to a bug that has since been fixed.

According to Nick Percoco, Kraken’s chief security officer, the cryptocurrency exchange received a bug bounty program alert on June 9. The alert warned of a “very serious” bug that could allow attackers to artificially inflate balances on the platform.

Percoco was short on specifics in its submission, but said it had investigated the issue and discovered an isolated bug that could have allowed malicious attackers to initiate deposits on the platform and receive funds into accounts without fully completing the deposit. He pointed out that this only happens under certain circumstances.

He said the bug, derived from a flaw in a recent UX change that credited clients’ accounts before their asset deposits were fully liquidated, despite there being no client assets at risk, allowed malicious attackers to “print assets” from their Kraken accounts. “I insisted I could do it. said Percoco.

Exploited before submitting a bounty

According to Percoco, the bug was fully fixed within a few hours. However, subsequent investigation revealed that it had already been exploited on three accounts within days of each other.

Percoco claimed that one of its accounts discovered a bug and that KYC was applied to an individual who claimed to be a “security researcher.” The individual reportedly took advantage of the bug to credit $4 to his account. This is enough to prove a defect, file a bug bounty report, and demand a hefty reward, Percoco said.

However, Kraken’s CSO claimed that the researcher disclosed the bug to two other people he was working with, who subsequently withdrew much larger amounts of money from Kraken accounts, totaling $3 million. “This came from Kraken’s treasury and not from other customer assets,” Percoco said.

Percoco said Kraken had requested a full accounting of their activities and the return of the funds. However, the researchers reportedly refused to return the funds until Kraken disclosed the potential scale of the exploit if it had not disclosed the bug. “This is not white hacking, this is extortion!” Percoco said.

Percoco said the researchers criticized the cryptocurrency exchange’s request as “unreasonable” and “unprofessional” and added that Kraken would not disclose the research company involved but would consider it a bug bounty violation and handle it as a criminal case. hatchet.

“We will not disclose this research company. Because they don’t deserve recognition for their actions. We are treating this as a criminal case and coordinating with law enforcement accordingly,” Percoco said.


Disclaimer: The Block is an independent media outlet delivering news, research and data. As of November 2023, Foresight Ventures is a majority investor in The Block. Foresight Ventures invests in other companies in the cryptocurrency space. Cryptocurrency exchange Bitget is an anchor LP of Foresight Ventures. The Block continues to operate independently to provide objective, impactful and timely information about the cryptocurrency industry. Below are our current financial disclosures.

© 2023 The Block. All rights reserved. This article is provided for informational purposes only. It is not provided or intended to be used as legal, tax, investment, financial or other advice.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Microstrategy (MSTR) Analysis: Premium Evaluation and Bitcoin Strategy

May 24, 2025

The Xbox Game Pass is extended to retro classic and new PC game features.

May 24, 2025

Creating AI revolutionizes the Dynamics 365 business application

May 24, 2025
Add A Comment

Comments are closed.

Recent Posts

Solana introduces the SAS protocol to secure the official record.

May 24, 2025

Solana introduces the SAS protocol to secure the official record.

May 24, 2025

According to Senator Hagerty, this password will be the largest US Treasury holder in the world.

May 24, 2025

Microstrategy (MSTR) Analysis: Premium Evaluation and Bitcoin Strategy

May 24, 2025

Ultimate guide to protection of offline assets

May 24, 2025

Avax charges a blockchain fee, but the sleeve is quietly extracted. What does this mean?

May 24, 2025

The Xbox Game Pass is extended to retro classic and new PC game features.

May 24, 2025

Crypto, NFTS is a lifeboat of the Sinking Fiat system: Finance redefined

May 24, 2025

Creating AI revolutionizes the Dynamics 365 business application

May 24, 2025

NASDAQ composite, ETH, DOGE and PEPE Coin Heat increase in culture and pepeto

May 24, 2025

Maxwell Hardfork: BSC speeds up to 0.75 seconds block time.

May 24, 2025

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

Solana introduces the SAS protocol to secure the official record.

May 24, 2025

Solana introduces the SAS protocol to secure the official record.

May 24, 2025

According to Senator Hagerty, this password will be the largest US Treasury holder in the world.

May 24, 2025
Most Popular

Cryptocurrency stock selling ‘moderately reduced’ amid hype for spot Ethereum ETF

May 24, 2024

Bitcoin on Wheels: The Story of Bitcoinetas

March 12, 2024

FDIC Vice Chairman Knocks the SEC’s Cryptocurrency Accounting Bulletin, Calling it a ‘Drastic Deviation’ from Current Management Practices.

March 11, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2025 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.