U.S. cryptocurrency exchange Kraken has escalated a dispute with an unnamed security research firm, accusing it of stealing $3 million from its treasury and attempting to extort additional funds. Nick Percoco, Kraken’s Chief Security Officer, detailed the allegations in a post on X (formerly Twitter), stating that the firm's actions violate the fundamental rules of white-hat hacking.
Kraken: Violation of Bug Bounty Rules
According to Percoco, Kraken has operated a bug bounty program for ten years and never encountered researchers who refused to follow its guidelines. Participants are required to promptly return any funds extracted while identifying vulnerabilities, provide proof of concept, and avoid excessive exploitation. However, the security firm in question allegedly failed to fully disclose transaction details of the bug and made no arrangements to return the stolen funds. Instead, it accused Kraken of being “unreasonable” and “unprofessional.”
“As a security researcher, your license to ‘hack’ a company is enabled by following the simple rules of the bug bounty program you are participating in. Ignoring those rules and extorting the company revokes your ‘license to hack.’ It makes you, and your company, criminals,” Percoco stated. He added that Kraken has contacted law enforcement but declined to name the firm, as it does not deserve recognition.
Certik Responds: Threats and Unreasonable Demands
Hours after Kraken’s accusations, blockchain security firm Certik revealed itself as the entity involved. In a statement, Certik accused Kraken of threatening its employees by demanding the return of a “mismatched amount of crypto” within an unreasonable timeframe, without providing repayment addresses. Certik emphasized that Kraken should cease making threats and pledged to transfer the mismatched funds to an account accessible by the exchange.
“Since Kraken has not provided repayment addresses and the requested amount was mismatched, we are transferring the funds based on our records to an account that Kraken will be able to access,” Certik said. In subsequent updates, Certik questioned how Kraken’s vaunted defense system failed to detect multiple test transactions, asserting that continuous large withdrawals from different test accounts were part of its testing methodology.
Industry Implications
The incident has sparked debates within the crypto security community about the boundaries of white-hat hacking and the obligations of bug bounty programs. Kraken insists that strict adherence to program rules is non-negotiable, while Certik views its actions as legitimate testing and criticizes Kraken’s lack of cooperation. As both parties continue to trade accusations, the resolution may depend on legal intervention or industry-wide standards.

