On the 20th, blockchain security company CertiK announced that it had found a bug in the platform of cryptocurrency exchange Kraken.
According to the announcement, CertiK discovered a vulnerability that could allow millions of dollars to be withdrawn from Kraken accounts as a white hat hacker, and actually withdrew the funds.
Meanwhile, Kraken announced that approximately $3 million (approximately 474 million yen) was withdrawn from its wallet in connection with this vulnerability, but did not disclose the companies involved. It then explained that the security company that pointed out the vulnerability "withdrew approximately $3 million and refused to return it without even checking the amount of the reward."
Furthermore, while not disclosing the specific company's name, it expressed its displeasure, saying, "A certain security company has requested an unfair reward." CertiK has criticized Kraken's stance, and the conflict between the two is deepening.
According to Kraken's Chief Security Officer Nick Percoco, the withdrawn funds were not from customer accounts, but were held by Kraken. The vulnerability appears to have been fixed quickly.
Percoco claimed that two people connected to an unnamed research firm were behind the withdrawals, and that if the bug was not reported, Kraken would refuse to return the funds until Kraken disclosed the extent of the vulnerability. This research firm is believed to be Certic.
Certic said that no alerts were triggered during the testing period, which lasted several days, and Kraken only locked the test accounts several days after the disclosure.
Then, after the vulnerability was fixed, Kraken's security team threatened to repay a disproportionate amount of cryptocurrency in an unreasonable time without sharing the address to which the funds should be returned. Certic then said, "We transferred the funds to an address that Kraken has access to based on our records."
Reference: Certic announcement,Kraken announcement
Image: Shutterstock
DMM Bitcoin raises 55 billion yen to fully guarantee stolen Bitcoin
KyberSwap hacking incident: hackers demand complete control, including transfer of management rights