Fun

Kraken recovers $3 million from CertiK, ending bug bounty saga

News Feed - 2024-06-20 11:06:31

Zoltan Vardai9 minutes agoKraken recovers $3 million from CertiK, ending bug bounty sagaCertik has returned the funds to Kraken exchange, putting a happy end to the bug bounty-related saga.61 Total viewsListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksCryptocurrency exchange Kraken has recovered missing funds following a high-profile bug bounty exploit fiasco. 


Kraken confirmed the return of the stolen digital assets worth nearly $3 million, putting an end to the Kraken-Certik saga that started on June 9.


The recovery of the funds, minus transaction fees, was confirmed by Nicholas Percoco, chief security officer of Kraken, in a June 20 X post:“Update: We can now confirm the funds have been returned (minus a small amount lost to fees).”


Kraken’s CSO first announced the $3 million worth of missing funds on June 19, when he claimed that a “security researcher” maliciously withdrew them from the treasury after discovering and sharing an existing bug.


Kraken claimed that it was extorted by the security researcher who was refusing to return the funds, demanding a reward and a call with the exchange’s business development team.


Related:Nomura crypto arm Laser Digital bags Abu Dhabi licenseCertiK"s side of the story


Shortly after Kraken’s post about the missing funds, blockchain security firm CertiK publicly identified itself as the “security researcher” that Kraken claimed stole $3 million of digital assets.


In a June 19 X post, CertiK said it had informed Kraken of an exploit that allowed it to remove millions of dollars from the exchange’s accounts. Certik also claimed to have been threatened by the exchange’s team:“After initial successful conversions on identifying and fixing the vulnerability, Kraken’s security operation team has THREATENED individual CertiK employees to repay a MISMATCHED amount of crypto in an UNREASONABLE time even WITHOUT providing repayment addresses.”


The security firm posted a timeline of events, starting with identifying the exploit on June 5 and ending with claims Kraken threatened a CertiK employee on June 18. In a statement to Cointelegraph, CertiK said it planned to transfer the funds “to an account that Kraken will be able to access.”Bug bounty saga timeline. Source: CertiK


Related:Bitcoin ETFs legitimized the crypto industry for investors — Storm PartnersWhy did CertiK withdraw nearly $3 million?


Kraken’s CSO initially said that the first malicious transfer, worth just $4, would have been sufficient to prove the bug and collect “sizable rewards” from Karken’s bounty program.


However, the security researcher, which was later disclosed as CertiK, had minted nearly $3 million into their Kraken accounts.


In a post following the return of the $3 million, CertiK said that the multi-million sum was necessary to test the limits of the exchange:“We want to test the limit of Kraken’s protection and risk controls. After multiple tests across multiple days and close to $3 million worth of crypto, no alerts were triggered and we still haven’t figured out the limit.”


Moreover, CertiK claims that it didn’t initially request a bounty, but it was something mentioned by the exchange:“We never mentioned any bounty request. It was Kraken who first mentioned their bounty to us, while we responded that the bounty was not the priority topic and we wanted to make sure the issue was fixed.”


CertiK added that no Kraken user funds were endangered since the exploited funds were “minted out of air.”


Magazine:Ethereum’s recent pullback could be a gift: Dynamo DeFi, X Hall of Flame# Kraken# Altcoin# Business# Hackers# Cryptocurrency Exchange# Cybersecurity# Hacks# DeFiAdd reaction

News Feed

Greens’ push to end German cryptocurrency tax exemption sparks debate
Veronika Rinecker10 hours agoGreens’ push to end German cryptocurrency tax exemption sparks debateThe Greens think the current one-year holding tax exemption for crypto is unfair and are seeking to abolish it.632 Total
Abkhazia Lifts Two-Year Ban on Bitcoin Mining, Moves to Regulate the Sector
Abkhazia Lifts Two-Year Ban on Bitcoin Mining, Moves to Regulate the SectorAbkhazia, the self-governing but disputed territory of just 245,000 people sandwiched between Russia and G
SEC approves Grayscale Bitcoin Mini Trust for Trading on NYSE Arca
Alex O’Donnell1 hour agoSEC approves Grayscale Bitcoin Mini Trust for Trading on NYSE ArcaGrayscale must await final regulatory signoff on its registration filing before listing the fund821 Total views30 Total sharesLi
EU Nears Agreement on Crypto Regulations, Report Reveals
EU Nears Agreement on Crypto Regulations, Report Reveals Authorities in the EU are moving closer to a deal on a legislative package tailored to comprehensively regulate the crypto
Billionaire ‘Bond King’ Jeffrey Gundlach Warns of ‘Painful Outcomes’ in Next Recession
Billionaire "Bond King" Jeffrey Gundlach Warns of "Painful Outcomes" in Next Recession Billionaire Jeffrey Gundlach, aka the “Bond King,” has warned of “painful o
Helen Partz10 hours agoProShares announces launch of short Ether-linked ETFProShares’s new Short Ether Strategy ETF is set to start trading on the NYSE Arca under the ticker symbol SETH.1718 Total views11 Total sharesL
Tanzania Officials Want Global Clarity on CBDCs and Crypto Assets
Tanzania Officials Want Global Clarity on CBDCs and Crypto Assets Officials from Tanzania’s financial sector have called for a clearer global consensus on central bank digit
Nivesh Rustgi13 hours agoBitcoin price dips below $25K — Opportunity, or sign of incoming disaster?BTC"s price peers over the cliff at $25,000. Should investors look for shelter or perceive an opportunity?9501 Total vi
Bitfinex CTO Paolo Ardoino States Salvadoran Bitcoin Bonds to Be Further Delayed
Bitfinex CTO Paolo Ardoino States Salvadoran Bitcoin Bonds to Be Further Delayed The launch of El Salvador’s bitcoin bonds, issued to finance part of the construction of the
2 in 1 – Learn How to Trade on Derivatives for Free and Win Apple Prizes From CoinDeal Derivatives
2 in 1 – Learn How to Trade on Derivatives for Free and Win Apple Prizes From CoinDeal DerivativesDerivatives trading is one way of generating huge profits in a very short time. T
Arkham transfers $487M ARKMs to Coinbase Prime for tax compliance
Amaka Nwaokocha14 hours agoArkham transfers $487M ARKMs to Coinbase Prime for tax complianceAs the unlocking process progresses, Coinbase Custody will play a crucial role in managing the vesting of these tokens.4429 Tota
Jesse Coghlan8 hours agoSEBA Bank secures in-principle nod for crypto services in Hong KongSEBA Hong Kong’s approval joins a flurry of regulated crypto activity that’s taken place over the past month.6350 Total views