Cryptocurrency news

Kraken Says Hackers Turned to 'Extortion' After Exploiting Bug for $3M

CoinDesk / 19.06.2024 / 15:27
Kraken Says Hackers Turned to 'Extortion' After Exploiting Bug for $3M

Crypto exchange Kraken said "security researchers" who found a vulnerability on the platform turned to "extortion" after withdrawing about $3 million from the exchange's treasury.

Nick Percoco, Kraken's chief security officer, said in a post on social media platform X (formerly Twitter) that the firm received a "bug bounty program" alert from a security researcher on June 9 about a vulnerability that allows users to artificially inflate their balance. The bug "allowed a malicious attacker, under the right circumstances, to initiate a deposit onto our platform and receive funds in their account without fully completing the deposit," Percoco added.

Unmute

North Korea Hackers Likely Exploit Cloud Mining Services to Launder Stolen Crypto: Mandiant Research

07:26Scammers Took Advantage of the Ethereum Merge to Make Millions: Chainalysis00:40$40M in Insurance 'Will Not Be Touched' to Recover Lost Funds in Hot Wallet Hack: Deribit Exec01:04Cybercriminals Are Opportunists: Former FBI Special Agent

Upon receiving the report, Kraken fixed the issue swiftly and no user funds were affected, Percoco noted.

What came after raised red flags for Kraken's team.

The security researcher, upon finding the bug, allegedly disclosed it to two other individuals, who then "fraudulently" withdrew nearly $3 million from their Kraken accounts. "This was from Kraken’s treasuries, not other client assets," Percoco said.

The initial bug report didn't mention the two other individuals' transactions, and when Kraken asked for more details of their activities, they refused.

"Instead, they demanded a call with their business development team (i.e. their sales reps) and have not agreed to return any funds until we provide a speculated $ amount that this bug could have caused if they had not disclosed it. This is not white-hat hacking, it is extortion!" Percoco wrote.

Bug bounty programs – used by many firms to strengthen their security systems – invite third-party hackers, known as "white hats," to find vulnerabilities so the company can fix them before a malicious actor exploits them. Kraken's competitor, Coinbase, has a similar program to help alert the exchange of vulnerabilities.

To be paid the bounty, Kraken's program requires a third party to find the problem, exploit the minimum amount needed to prove the bug, return the assets and provide details of the vulnerability, Kraken said in a blog post, adding that since the security researchers didn't follow these rules, they won't get the bounty.

"We engaged these researchers in good faith and, in-line with a decade of running a bug bounty program, had offered a sizable bounty for their efforts. We’re disappointed by this experience and are now working with law enforcement agencies to retrieve the assets from these security researchers," a Kraken spokesperson told CoinDesk.

Read more: Your Crypto Project Needs a Sheriff, Not a Bounty Hunter

Edited by Sheldon Reback.


Source
Recently News

© Token Radar 2024. All Rights Reserved.
IMPORTANT DISCLAIMER: All content provided herein our website, hyperlinked sites, associated applications, forums, blogs, social media accounts and other platforms (“Site”) is for your general information only, procured from third party sources. We make no warranties of any kind in relation to our content, including but not limited to accuracy and updatedness. No part of the content that we provide constitutes financial advice, legal advice or any other form of advice meant for your specific reliance for any purpose. Any use or reliance on our content is solely at your own risk and discretion. You should conduct your own research, review, analyse and verify our content before relying on them. Trading is a highly risky activity that can lead to major losses, please therefore consult your financial advisor before making any decision. No content on our Site is meant to be a solicitation or offer.