Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Kraken recovers $3M as criticism mounts against CertiK

Kraken recovers $3M as criticism mounts against CertiK

Cryptopolitan2024/06/21 01:55
By:By Ol

Share link:In this post: Blockchain security firm CertiK revealed that it was the security firm that exploited a vulnerability on Kraken to move funds. The firm’s action has attracted steep criticism from the crypto community, who described the events as criminal. Kraken’s chief security officer Nick Percoco revealed that the firm has recovered the funds.Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provide

The crypto community has heavily criticized blockchain security firm CertiK for its issues with the crypto exchange Kraken. On June 19, the company revealed itself as the ‘security research’ company Kraken had attributed a theft worth $3 million worth of digital assets to. 

Also read: Kraken reveals bug allowed rogue ‘security researchers’ to exploit $3M

Kraken’s chief security officer Nick Percoco had revealed that an unnamed “security researcher” had exploited a bug on the crypto exchange to steal millions in digital assets. Percoco continued that the researcher had refused to return the stolen funds and instead chose to extort the exchange for a speculative amount.

Kraken recovers stolen funds

A few hours after Kraken’s revelation, CertiK stated that it had informed Kraken of the exploit that allowed it to withdraw the funds from the exchange’s accounts. The security firm posted a timeline of the events and claimed that Kraken threatened its employees. It stated:

“After initial successful conversations on identifying and fixing the vulnerability, Kraken’s security operation team has THREATENED individual CertiK employees to repay a MISMATCHED amount of crypto in an UNREASONABLE time even WITHOUT providing repayment addresses.”

Kraken recovers $3M as criticism mounts against CertiK image 0 CertiK’s Timeline of issues with Kraken. (Source: CertiK)

Nevertheless, CertiK revealed that it would transfer the “stolen” funds to an account that Kraken can access. By June 20, Percoco confirmed that Kraken had received all the funds, less the transaction fees.

CertiK’s actions attract criticism

While Kraken would be celebrating fixing a critical bug and recovering funds, CertiK is now facing a barrage of criticism from the crypto community for its role in the events. Taylor Monahan, a crypto security expert, questioned why the blockchain security firm performed more than one test transaction to prove the existence of the vulnerability.

Also read: Kraken Considers Delisting USDT in Response to New EU Regulations

Furthermore, the community questioned CertiK’s motive in moving some of the Kraken funds through the OFAC-sanctioned crypto mixer Tornado Cash and its use of ChangeNOW, a non-custodial crypto exchange with lax know-your-customers processes.

However, CertiK insists that it made the right decision. The firm noted that its test lasted for five days and was on such a grand scale because it was trying to discover how weak the Kraken security system was. It stated:

“The real question should be why Kraken’s in-depth defense system failed to detect so many test transactions. This is indeed what we were testing. You often heard from a weak exchange’s response to a security bug finding with a brag of their strong risk control and in-depth defense system (that they claim would prevent any significant loss). CertiK put this to the test with Kraken, and they failed miserably.”

It also denied ever asking for a bounty and claimed it consistently assured Kraken of its plan to return the funds.

Cryptopolitan reporting by Oluwapelumi Adejumo

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!