Kraken Accuses Security Research Firm of Theft and Extortion; Certik Slams Threats Against Employees

Kraken Accuses Security Research Firm of Theft and Extortion; Certik Slams Threats Against Employees

N
News Editor 01
2026-07-08 20:34:15
Kraken CSO claims a security research firm stole $3 million and attempted to extort more; Certik identifies itself as the firm, accusing Kraken of threatening employees and demanding a mismatched crypto return.
KrakenCertikbug bountysecurity researchcryptocurrency

U.S. cryptocurrency exchange Kraken has accused an unnamed security research firm of illegally siphoning $3 million from its treasury and attempting to extort additional funds. Nick Percoco, Kraken’s Chief Security Officer, revealed in a post on X (formerly Twitter) that the actions of the alleged white hat hackers deviated from normal bug bounty program rules. However, blockchain security firm Certik soon confirmed it was the research firm involved, accusing Kraken of threatening its employees with an unreasonable demand to return a “mismatched amount of crypto.”

Kraken: White Hat Hackers Turn Criminal

Percoco stated that in its ten-year bug bounty history, Kraken had never encountered researchers who refused to follow the rules. Participants are required to promptly return any extracted funds when identifying bugs, provide a proof of concept, and avoid excessive exploitation. Instead of complying, the research firm accused Kraken of being “unreasonable” and “unprofessional.”

“As a security researcher, your license to ‘hack’ a company is enabled by following the simple rules of the bug bounty program you are participating in. Ignoring those rules and extorting the company revokes your ‘license to hack.’ It makes you, and your company, criminals,” Percoco emphasized. He added that Kraken has contacted law enforcement agencies but withheld the firm’s name because it does not deserve recognition.

Certik Strikes Back: Kraken’s Threats

Hours later, Certik published a response, confirming it was the research firm. Certik claimed Kraken demanded the return of “a mismatched amount of crypto” within an unreasonable timeframe, without providing repayment addresses. The security firm urged Kraken to cease threats and pledged to transfer the crypto to an account accessible by Kraken based on its own records.

“Since Kraken has not provided repayment addresses and the requested amount was mismatched, we are transferring the funds based on our records to an account that Kraken will be able to access,” Certik stated. In later updates, Certik questioned why Kraken’s vaunted defense system failed to detect so many test transactions, arguing that continuous large withdrawals from different testing accounts were part of a legitimate testing process.

The standoff highlights the grey areas in bug bounty programs: Where is the line between ethical hacking and extortion? Are platforms’ security measures adequate? Both sides remain entrenched in their positions, and the incident continues to unfold.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.