Fun

Kraken recovers $3 million from CertiK, ending bug bounty saga

News Feed - 2024-06-20 11:06:31

Zoltan Vardai9 hours agoKraken recovers $3 million from CertiK, ending bug bounty sagaCertiK has returned the funds to the Kraken exchange, putting a happy end to the bug bounty-related saga.1714 Total views1 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksCryptocurrency exchange Kraken has recovered missing funds following a high-profile bug bounty exploit fiasco. 


Kraken confirmed the return of the stolen digital assets worth nearly $3 million, putting an end to the Kraken-CertiK saga that started on June 9.


The recovery of the funds, minus transaction fees, was confirmed by Nicholas Percoco, chief security officer of Kraken, in a June 20 X post:“Update: We can now confirm the funds have been returned (minus a small amount lost to fees).”


Kraken’s CSO first announced the $3 million worth of missing funds on June 19, when he claimed that a “security researcher” maliciously withdrew them from the treasury after discovering and sharing an existing bug.


Kraken claimed that it was extorted by the security researcher, who was refusing to return the funds, demanding a reward and a call with the exchange’s business development team.


Related:Nomura crypto arm Laser Digital bags Abu Dhabi licenseCertiK’s side of the story


Shortly after Kraken’s post about the missing funds, blockchain security firm CertiK publicly identified itself as the “security researcher” that Kraken claimed stole $3 million of digital assets.


In a June 19 X post, CertiK said it had informed Kraken of an exploit that allowed it to remove millions of dollars from the exchange’s accounts. CertiK also claimed to have been threatened by the exchange’s team:“After initial successful conversions on identifying and fixing the vulnerability, Kraken’s security operation team has THREATENED individual CertiK employees to repay a MISMATCHED amount of crypto in an UNREASONABLE time even WITHOUT providing repayment addresses.”


The security firm posted a timeline of events, starting with identifying the exploit on June 5 and ending with claims Kraken threatened a CertiK employee on June 18. In a statement to Cointelegraph, CertiK said it planned to transfer the funds “to an account that Kraken will be able to access.”Bug bounty saga timeline. Source: CertiK


Related:Bitcoin ETFs legitimized the crypto industry for investors — Storm PartnersWhy did CertiK withdraw nearly $3 million?


Kraken’s Percoco initially said that the first malicious transfer, worth just $4, would have been sufficient to prove the bug and collect “sizable rewards” from Karken’s bounty program.


However, the security researcher, which was later disclosed as CertiK, had minted nearly $3 million into their Kraken accounts.


In a post following the return of the $3 million, CertiK said that the multimillion-dollar sum was necessary to test the limits of the exchange:“We want to test the limit of Kraken’s protection and risk controls. After multiple tests across multiple days and close to $3 million worth of crypto, no alerts were triggered and we still haven’t figured out the limit.”


Moreover, CertiK claims that it didn’t initially request a bounty, but it was something mentioned by the exchange:“We never mentioned any bounty request. It was Kraken who first mentioned their bounty to us, while we responded that the bounty was not the priority topic and we wanted to make sure the issue was fixed.”


CertiK added that no Kraken user funds were endangered since the exploited funds were “minted out of air.”


Magazine:Ethereum’s recent pullback could be a gift: Dynamo DeFi, X Hall of Flame# Kraken# Altcoin# Business# Hackers# Cryptocurrency Exchange# Cybersecurity# Hacks# DeFiAdd reaction

News Feed

El Salvador launches Bitcoin certifications for civil servants
Arijit Sarkar1 hour agoEl Salvador launches Bitcoin certifications for civil servantsEl Salvador’s government aims to upskill 80,000 employees through a comprehensive Bitcoin certification program, emphasizing strategi
Report: Russia Remains a ‘Key Market for Crypto,’ Commands the 3rd Largest Bitcoin Hashrate in the World
Report: Russia Remains a "Key Market for Crypto," Commands the 3rd Largest Bitcoin Hashrate in the WorldThe fervor for cryptocurrency assets in Russia has grown wild over the last f
Canadian Firm 3iQ’s Bitcoin Fund Listed on Gibraltar Stock Exchange
Canadian Firm 3iQ"s Bitcoin Fund Listed on Gibraltar Stock ExchangeThe Gibraltar Stock Exchange said Tuesday that it listed a new bitcoin fund belonging to 3iQ Corp, a Canadian inve
Savannah Fortis13 hours agoRobot guest-conducts the Korean National Symphony OrchestraThe android robot EveR 6 and conductor Soo-Yeoul Choi co-conducted a performance of six pieces with the Korean National Symphony Orche
Konami partners with Avalanche for Resella NFT platform launch
Ezra Reguerra4 hours agoKonami partners with Avalanche for Resella NFT platform launchKonami Digital Entertainment has teamed up with Avalanche to debut Resella, an intuitive NFT platform simplifying NFT creation, issuan
Savannah Fortis9 hours agoTether treasury receives two $50M USDT lump sums from BitfinexTwo transactions showed lump sums of $50 million in USDT transferred from Bitfinex to the Tether treasury only a few minutes apart.1
Work X – Tokenizing Your Skills
Work X - Tokenizing Your Skills press release PRESS RELEASE. Zug, Switzerland, 5 Jan 2022: For many years, getting a diploma from a university or other institution was the only way
Wind-Breaking NFTs: Reality Star Who Made $200K Selling Farts in Mason Jars Launches NFT Collection
Wind-Breaking NFTs: Reality Star Who Made $200K Selling Farts in Mason Jars Launches NFT Collection Just recently the reality star, American Youtuber, and Tiktoker Stephanie Matto
Bitcoin’s Average and Median-Sized Network Fees Rose 40% Higher in March
Bitcoin"s Average and Median-Sized Network Fees Rose 40% Higher in March In March 2023, Bitcoin’s average and median-sized fees jumped more than 40% higher after rising 122%
Jack Dorsey’s Block to shutter UK operations for Cash App
Turner Wright5 hours agoJack Dorsey’s Block to shutter UK operations for Cash AppThe app, one of the products of payments firm Block, has been operating in the United Kingdom since 2018.2609 Total views2 Total sharesLi
Federal Reserve Hikes Rate by 50bps, FOMC Signals Rate to Rise to 5.1% Next Year
Federal Reserve Hikes Rate by 50bps, FOMC Signals Rate to Rise to 5.1% Next Year The U.S. central bank’s Federal Open Market Committee (FOMC) convened on Wednesday and raise
Bitcoin large sellers 'exhausted' as $67K price holds
Ciaran Lyons3 hours agoBitcoin large sellers "exhausted" as $67K price holdsBitcoin is seeing a reduction in selling pressure from large investors as its price continues to hold above $67,000.3734 Total views12 Total sha