Fun

Kraken-CertiK saga turns murky as part of exploited funds go ‘missing’

News Feed - 2024-06-20 06:06:28

Prashant Jha5 hours agoKraken-CertiK saga turns murky as part of exploited funds go ‘missing’Kraken is planning to take legal action against security firm CertiK as the “white hat” operation by the security firm turns into a legal blunder.1022 Total views23 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksThe Kraken-CertiK saga has taken another turn. Security firm CertiK claims it carried out a white hat operation on specific Kraken accounts not belonging to customers, draining nearly $3 million, according to Kraken. However, the exchange claims the total exploited amount was not returned to it, while CertiK claims to have returned all funds as per their record.


On June 20, CertiK took to X to give an update on the situation and claimed it had returned 734 Ether (ETH), 29,001 Tether (USDT) tokens and 1,021 Monero (XMR) coins, while Kraken requested 155,818 Polygon (MATIC) tokens, 907,400 USDT, 475.5 ETH and 1,089.8 XMR.Kraken claims exploit, CertiK says white hat operation


The Kraken-CertiK saga began on June 9, when Kraken claimed it had received a bug bounty program alert from an alleged security researcher. The alert highlighted a bug in Kraken’s system that allowed users to inflate their account balances. When the crypto exchange rushed to patch the bug, it discovered three accounts that had leveraged the flaw, stealing $3 million from Kraken’s account.


Kraken found that one of the three accounts was Know Your Customer (KYC) verified and used the bug to credit $4 to their account.


Kraken chief security officer Nick Percoco said that this would have been enough to prove the bug and claim the bounty, but the account allegedly then shared the flaw with two other accounts, with all three pocketing $3 million from the exchange in the days that followed.


When the crypto exchange asked the alleged “security researcher” to return the funds and collect its bounty after offering the required onchain proofs, the white hat hacker allegedly refused to entertain the request and asked for the bounty to be paid first. Although Kraken didn’t reveal the name of the security firm behind the “white hat” exploit, CertiK revealed that it was behind the Kraken exploit.


CertiK claimed that its employee who discovered the vulnerability was threatened to return the stolen funds, but did not receive a wallet address to send the funds to. Ronghui Gu, co-founder at CertiK, told Cointelegraph:“The verbal consensus reached during our meeting was not confirmed afterward. Ultimately, they [Kraken] publicly accused us of theft and even directly threatened our employees, which is completely unacceptable.”


CertiK reportedly sent the stolen funds to crypto mixing service Tornado Cash to avoid having them frozen by crypto exchanges. The move triggered much criticism from the crypto community, which questioned CertiK’s motive behind the “white hat” operation.


Related: Crypto phishing attacks reached ‘alarming levels’ — CertiK co-founderCrypto community calls out CertiK


The crypto community raised questions about why CertiK researchers moved millions of dollars worth of funds when a single transaction could have proven the vulnerability. Others reminded them that Tornado Cash is an Office of Foreign Assets Control (OFAC)-sanctioned tool, and using it could attract legal trouble for the security firm. Others questioned whether it planned to return the funds and why it sent them to Tornado Cash.Crypto community calls out CertiK. Source: X


A majority of the crypto community sided with Kraken on the issue and called out CertiK for its ruthless behavior. Many accused them of “stealing” and blackmailing Kraken for the bounty.Crypto community reaction to Kraken Certik saga. Source: X


Kraken told Cointelegraph that it is in touch with law enforcement agencies regarding the situation.


Update: This article will be updated with comments from Kraken and CertiK.


Magazine:Crypto audits and bug bounties are broken: Here’s how to fix them# Blockchain# Kraken# Cryptocurrencies# Hackers# Cybersecurity# Hacks# DeFi# RegulationAdd reaction

News Feed

Boerse Stuttgart and SBI Partner to Expand Crypto Services in Europe and Asia
Boerse Stuttgart and SBI Partner to Expand Crypto Services in Europe and Asia Germany’s second-largest stock exchange and a major financial services group in Japan have par
LayerZero identifies over 800K addresses in sybil self-reporting phase
Amaka Nwaokocha11 hours agoLayerZero identifies over 800K addresses in sybil self-reporting phaseInitially, the team identified over two million addresses as potential sybils but later refined their criteria to minimize
Bank of America, Goldman Sachs, JPMorgan, UBS Share Predictions About Further Fed Rate Hikes
Bank of America, Goldman Sachs, JPMorgan, UBS Share Predictions About Further Fed Rate Hikes Bank of America, Goldman Sachs, JPMorgan, and UBS have shared their predictions about t
WWE digital collectibles on Panini, Sports Illustrated NFT tickets on Avalanche: Nifty Newsletter
Ezra Reguerra4 hours agoWWE digital collectibles on Panini, Sports Illustrated NFT tickets on Avalanche: Nifty NewsletterCollectible firm Panini announced the launch of World Wrestling Entertainment’s digital Donruss E
Dogecoin’s Darkest Hour? Sentiment Tanks, Whales Accumulate
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Bitcoin’s ‘euphoria phase’ cools, but a BTC bottom could be near — Glassnode
Nancy Lubale2 hours agoBitcoin’s ‘euphoria phase’ cools, but a BTC bottom could be near — GlassnodeData suggests that newer investors are behind Bitcoin’s sell-off, but sell-side exhaustion will eventually mark
Crypto trader turns $3K into $46M in one month as PEPE price soars
Zoltan Vardai7 hours agoCrypto trader turns $3K into $46M in one month as PEPE price soarsThe savvy cryptocurrency trader is up over 15,000 fold on his initial $3,000 Pepe investment in just one month.9639 Total views18
Auditing Firms Claim Crypto.com Lost $15 Million in Incident as Users Report Suspicious Activity
Auditing Firms Claim Crypto.com Lost $15 Million in Incident as Users Report Suspicious Activity Crypto.com, a leading cryptocurrency exchange, experienced an incident on January 1
New record: Bitcoin ETFs hit $1B in daily inflow
Arijit Sarkar25 minutes agoNew record: Bitcoin ETFs hit $1B in daily inflowAs a direct result of the massive inflows into the Bitcoin ETFs and a supporting bull run, the daily inflows of capital being stored by the Bitco
BBVA Switzerland Launches ‘New Gen’ Digital Account With Integrated Crypto Wallet
BBVA Switzerland Launches ‘New Gen’ Digital Account With Integrated Crypto Wallet Clients of BBVA Switzerland will be able to buy, store, and trade crypto assets with a digital
Ex-Head of Crypto Exchange Wex Released in Poland
Ex-Head of Crypto Exchange Wex Released in Poland Former chief executive of the Russian cryptocurrency exchange Wex, Dmitry Vasiliev, has been released from arrest in Warsaw earlie
US Treasury Seeks Public Comments on Crypto-Related Illicit Finance and National Security Risks
US Treasury Seeks Public Comments on Crypto-Related Illicit Finance and National Security Risks The U.S. Department of the Treasury is seeking public input on “digital-asset