Crypto News

Kraken Confirms Return Of Funds From CertiKs Controversial Whitehat Hack

Kraken Confirms Return Of Funds From CertiKs Controversial Whitehat Hack
© Copyright Image: CryptoPotato

Crypto exchange Kraken says it got its money back from the security researchers that took $3 million from the platform this year.

Update: We can now confirm the funds have been returned (minus a small amount lost to fees), tweeted Nick Percoco, Chief Security Officer for Kraken, on Thursday.

Kraken Gets Its Money Back

Though Kraken first refused to identify the culprits, blockchain security experts at CertiK outed themselves on Wednesday as the ones behind the hack.

Earlier that day, Percoco revealed that Kraken had recently patched a bug that let technically sophisticated individuals artificially inflate their balance on the platform, effectively letting them steal any amount of money from the exchange since January.

CertiK experts notified them of the vulnerability in June, but not before draining $3 million from Krakens Treasury as a demonstration. Within a few hours, the issue was completely fixed and could not reoccur again, Percoco clarified, noting that no clients assets were ever at risk.

While CertiK characterized its actions as a whitehat operation to help reinforce Krakens security, the way the company went about its actions did not sit well with Kraken nor the wider crypto community.

These include having failed to follow Krakens standard whitehat bounty program procedures, such as not immediately returning all funds once stolen, and arguably stealing far more money than necessary to demonstrate the vulnerability.

When asked to return the funds, CertiK explicitly refused until provided with an estimate of how much money was at risk had the company not identified the vulnerability, according to Kraken.

CertiKs Explanation For The Hack

By contrast, CertiK said it had consistently assured them that we would return the funds.

Krakens security operation team has threatened individual CertiK employees to repay a mismatched amount of crypto in an unreasonable time even without providing repayment addresses, CertiK contested over Twitter.

The company confirmed on Thursday that all funds had been returned, though in a different crypto amount than Kraken had commanded. It also justified the size of its attack as necessary to test the limit of Krakens alerts and risk controls which still never went off after losing millions.

We never mentioned any bounty request, CertiK added. It was Kraken which first mentioned their bounty to us, while we responded that the bounty was not the priority topic and we wanted to make sure the issue was fixed.

The post Kraken Confirms Return Of Funds From CertiKs Controversial Whitehat Hack appeared first on CryptoPotato.

Read more: https://cryptopotato.com/kraken-confirms-return-of-funds-from-certiks-controversial-whitehat-hack/

Text source: CryptoPotato

Disclaimer: Financial information and news are not financial advice, read the disclaimer.
Buy & sell Crypto in minutes

Join BINANCE!

The world's largest crypto exchange

You're just steps away from receiving your reward.

The most complete Crypto News Center.

Search Stories:

Latest top stories