U.S. cryptocurrency exchange Kraken has accused an unnamed security research firm of illegally siphoning $3 million from its treasury and attempting to extort additional funds. Nick Percoco, Kraken’s Chief Security Officer, revealed in a post on X (formerly Twitter) that the actions of the alleged white hat hackers deviated from normal bug bounty program rules. However, blockchain security firm Certik soon confirmed it was the research firm involved, accusing Kraken of threatening its employees with an unreasonable demand to return a “mismatched amount of crypto.”
Kraken: White Hat Hackers Turn Criminal
Percoco stated that in its ten-year bug bounty history, Kraken had never encountered researchers who refused to follow the rules. Participants are required to promptly return any extracted funds when identifying bugs, provide a proof of concept, and avoid excessive exploitation. Instead of complying, the research firm accused Kraken of being “unreasonable” and “unprofessional.”
“As a security researcher, your license to ‘hack’ a company is enabled by following the simple rules of the bug bounty program you are participating in. Ignoring those rules and extorting the company revokes your ‘license to hack.’ It makes you, and your company, criminals,” Percoco emphasized. He added that Kraken has contacted law enforcement agencies but withheld the firm’s name because it does not deserve recognition.
Certik Strikes Back: Kraken’s Threats
Hours later, Certik published a response, confirming it was the research firm. Certik claimed Kraken demanded the return of “a mismatched amount of crypto” within an unreasonable timeframe, without providing repayment addresses. The security firm urged Kraken to cease threats and pledged to transfer the crypto to an account accessible by Kraken based on its own records.
“Since Kraken has not provided repayment addresses and the requested amount was mismatched, we are transferring the funds based on our records to an account that Kraken will be able to access,” Certik stated. In later updates, Certik questioned why Kraken’s vaunted defense system failed to detect so many test transactions, arguing that continuous large withdrawals from different testing accounts were part of a legitimate testing process.
The standoff highlights the grey areas in bug bounty programs: Where is the line between ethical hacking and extortion? Are platforms’ security measures adequate? Both sides remain entrenched in their positions, and the incident continues to unfold.

