Kraken Accuses Certik of Stealing $3M in Bug Bounty Dispute, Certik Fires Back

Kraken Accuses Certik of Stealing $3M in Bug Bounty Dispute, Certik Fires Back

N
News Editor 01
2026-07-08 20:34:15
Kraken CSO claims Certik illegally siphoned $3 million during a bug test and attempted extortion; Certik admits involvement but accuses Kraken of making unreasonable demands without providing repayment addresses.
KrakenCertikwhite hat hackerbug bountycrypto security

U.S. cryptocurrency exchange Kraken has escalated a dispute with an unnamed security research firm, accusing it of stealing $3 million from its treasury and attempting to extort additional funds. Nick Percoco, Kraken’s Chief Security Officer, detailed the allegations in a post on X (formerly Twitter), stating that the firm's actions violate the fundamental rules of white-hat hacking.

Kraken: Violation of Bug Bounty Rules

According to Percoco, Kraken has operated a bug bounty program for ten years and never encountered researchers who refused to follow its guidelines. Participants are required to promptly return any funds extracted while identifying vulnerabilities, provide proof of concept, and avoid excessive exploitation. However, the security firm in question allegedly failed to fully disclose transaction details of the bug and made no arrangements to return the stolen funds. Instead, it accused Kraken of being “unreasonable” and “unprofessional.”

“As a security researcher, your license to ‘hack’ a company is enabled by following the simple rules of the bug bounty program you are participating in. Ignoring those rules and extorting the company revokes your ‘license to hack.’ It makes you, and your company, criminals,” Percoco stated. He added that Kraken has contacted law enforcement but declined to name the firm, as it does not deserve recognition.

Certik Responds: Threats and Unreasonable Demands

Hours after Kraken’s accusations, blockchain security firm Certik revealed itself as the entity involved. In a statement, Certik accused Kraken of threatening its employees by demanding the return of a “mismatched amount of crypto” within an unreasonable timeframe, without providing repayment addresses. Certik emphasized that Kraken should cease making threats and pledged to transfer the mismatched funds to an account accessible by the exchange.

“Since Kraken has not provided repayment addresses and the requested amount was mismatched, we are transferring the funds based on our records to an account that Kraken will be able to access,” Certik said. In subsequent updates, Certik questioned how Kraken’s vaunted defense system failed to detect multiple test transactions, asserting that continuous large withdrawals from different test accounts were part of its testing methodology.

Industry Implications

The incident has sparked debates within the crypto security community about the boundaries of white-hat hacking and the obligations of bug bounty programs. Kraken insists that strict adherence to program rules is non-negotiable, while Certik views its actions as legitimate testing and criticizes Kraken’s lack of cooperation. As both parties continue to trade accusations, the resolution may depend on legal intervention or industry-wide standards.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.