According to Nick Percoco, chief security officer at Kraken, the exchange has administered to return his funds after what he described as an “extortion” attempt. He has only lost a small amount of money in commissions.
According to Nick Percoco, chief security officer at Kraken, the exchange has administered to return his funds after what he described as an “extortion” attempt. He has only lost a small amount of money in commissions.
As reported by U.TodayA security researcher from an undisclosed company notified the exchange about a critical bug that made it possible to effectively print money from this air by receiving funds without completing deposits.
Instead of submitting a bug report, the researcher initially informed two other people about the vulnerability, causing Kraken to lose $3 million from its treasury.

Investigators refused to return the money and demanded a call to the company’s sales representatives. Kraken accused the company of extortion and contacted authorities.
In another twist, well-known blockchain security company CertiK revealed that it was responsible for discovering the bug. He claimed that Kraken had begun demanding a mismatched amount of funds while threatening its employees. CertikK added that the multi-million dollar withdrawals were actually part of their tests. “The real question should be why Kraken’s deep defense system failed to detect so many test transactions,” the firm said.
In his original X thread, Percoco claimed that Kraken never had problems with “legitimate” researchers.
CertiK later clarified that he did not actually participate in the Kraken bounty program and was not seeking a bounty. Furthermore, he insists that the exchange was informed about the vulnerability in a timely manner. However, the amount of funds he has returned is different from the original sum requested by Kraken.
This is not the first time that CertiK has become a source of controversy. Previously, the company attracted criticism and ridicule after multiple projects that passed its audits ended up being hacked.