By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Kraken Crypto Exchange Hit by $3 Million Theft Exploiting Zero-Day Flaw
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Kraken Crypto Exchange Hit by $3 Million Theft Exploiting Zero-Day Flaw
Tech News

Kraken Crypto Exchange Hit by $3 Million Theft Exploiting Zero-Day Flaw

By Viral Trending Content 4 Min Read
Share
SHARE

Jun 19, 2024NewsroomCybercrime / Crypto Security

Zero-Day Flaw

Crypto exchange Kraken revealed that an unnamed security researcher exploited an “extremely critical” zero-day flaw in its platform to steal $3 million in digital assets and refused to return them.

Details of the incident were shared by Kraken’s Chief Security Officer, Nick Percoco, on X (formerly Twitter), stating it received a Bug Bounty program alert about a bug that “allowed them to artificially inflate their balance on our platform” without sharing any other details

The company said it identified a security issue within minutes of receiving the alert that essentially permitted an attacker to “initiate a deposit onto our platform and receive funds in their account without fully completing the deposit.”

Cybersecurity

While Kraken emphasized that no client assets were at risk of the issue, it could have enabled a threat actor to print assets in their accounts. The problem was addressed within 47 minutes, it said.

It also said the flaw stemmed from a recent user interface change that allows customers to deposit funds and use them before they were cleared.

On top of that, further investigation unearthed the fact that three accounts, including one belonging to the supposed security researcher, had exploited the flaw within a few days of each other and siphon $3 million.

“This individual discovered the bug in our funding system, and leveraged it to credit their account with $4 in crypto,” Percoco said. “This would have been sufficient to prove the flaw, file a bug bounty report with our team, and collect a very sizable reward under the terms of our program.”

“Instead, the ‘security researcher’ disclosed this bug to two other individuals who they work with who fraudulently generated much larger sums. They ultimately withdrew nearly $3 million from their Kraken accounts. This was from Kraken’s treasuries, not other client assets.”

In a strange turn of events, on being approached by Kraken to share their proof-of-concept (PoC) exploit used to create the on-chain activity and to arrange the return of the funds that they had withdrawn, they instead demanded that the company get in touch with their business development team to pay a set amount in order to release the assets.

Cybersecurity

“This is not white hat hacking, it is extortion,” Percoco said, urging the concerned parties to return the stolen funds.

The name of the company was not disclosed, but Kraken said it’s treating the security event as a criminal case and that it’s coordinating with law enforcement agencies about the matter.

“As a security researcher, your license to ‘hack’ a company is enabled by following the simple rules of the bug bounty program you are participating in,” Percoco noted. “Ignoring those rules and extorting the company revokes your ‘license to hack.’ It makes you, and your company, criminals.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

How can derailments in workplace leadership cause a toxic triangle?

Amazon vs Perplexity AI: Legal Battle over AI Browser Shopping Access

5 Reasons Why the Motorola Edge 70 is the Super-slim Phone To Buy

Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions

Feeling the Effects of the Time Change? We Asked Experts How to Get Back on Track

TAGGED: Bug Bounty Program, cryptocurrency, Cyber Security, Cybersecurity, Extortion, Internet, Vulnerability, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article Adobe Says It Won’t Train AI Using Artists’ Work. Creatives Aren’t Convinced
Next Article Flipster and TON Announce Exciting New Partnership
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Kingdom Come: Deliverance 2 Director Lambasts the “Static, Scripted” Nature of The Outer Worlds 2
Gaming News
New Five Nights at Freddy's 2 trailer shows off Springtrap, Balloon Boy, and more
Gaming News
Today in History: November 5, Susan B. Anthony defies law and casts vote for president
World News
Meet Mira Nair, Zohran Mamdani’s 68-year-old mother who hit it big in Hollywood directing critical darlings like ‘Monsoon Wedding’
Business
Monero (XMR) jumps to 5-month high as privacy coins lead surprise market rally
Crypto
Strategy’s Bitcoin Position Is Bear-Proof, Analyst Says
Crypto
Should I follow Michael Burry’s lead and sell my red-hot Nvidia stock?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Kingdom Come: Deliverance 2 Director Lambasts the “Static, Scripted” Nature of The Outer Worlds 2

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Kingdom Come: Deliverance 2 Director Lambasts the “Static, Scripted” Nature of The Outer Worlds 2
November 5, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?