Bug Bounty Turned Standoff: CertiK and Kraken Trade Extortion Claims Over $3M Exploit
A vulnerability disclosure between security firm CertiK and exchange Kraken has spiraled into a public dispute, with each side accusing the other of extortion and intimidation.
According to Kraken's Chief Security Officer Nick Percoco, the exchange received an initial bug bounty alert from a security researcher in early June 2024. CertiK later confirmed it was the firm behind the disclosure.

CertiK contends that instead of working cooperatively to resolve the issue, Kraken responded by threatening CertiK staff and issuing demands the firm considered unreasonable. Kraken disputes this characterization, and the two accounts of what happened next diverge sharply — turning into a public back-and-forth in which neither side's version can be fully verified independently. Additional details were shared by security commentators tracking the dispute.
01The Bug
Percoco described the flaw as an isolated defect that, under specific conditions, let an attacker initiate a deposit onto Kraken's platform and have the corresponding funds credited to their account without ever completing the deposit process. Kraken says it patched the issue within one hour and 47 minutes of identifying it.
CertiK, however, claims its own investigation went further and surfaced more serious problems than the initially reported bug. The firm says its testing showed it was possible to fabricate deposits into essentially any Kraken account and withdraw fabricated crypto worth more than $1 million without triggering any internal alerts — for several days running.
CertiK says that after it responsibly reported these findings — which Kraken itself classified at its highest severity tier — the exchange turned around and threatened CertiK personnel, demanding repayment of a "mismatched amount" of crypto within an unreasonable window, without even supplying the wallet addresses funds should be sent to. CertiK maintains these threats came only after it had already helped Kraken identify and fix the vulnerabilities, and says it is going public now to protect users and to push back against what it sees as retaliation against good-faith researchers.
Kraken's framing is different: it has characterized the resulting $3 million incident as straightforward extortion by bad actors, rejecting CertiK's account that its own disclosure practices were responsible and coordinated throughout.
02How the Money Moved
Kraken's subsequent investigation found that the bug had, in fact, already been exploited in the days prior — across three separate accounts linked to associates of the original researcher. One of those accounts made an initial deposit of just $4, apparently to confirm the bug worked before scaling up.
From there, exploitation of the same flaw allowed more than $3 million to be withdrawn from Kraken's corporate wallets over a five-day period. CertiK's position is that these were test transactions conducted for research purposes, with the millions withdrawn simply to demonstrate the scope of the flaw rather than for personal gain. CertiK has stated that the crypto involved was effectively minted from nothing, and that no genuine Kraken customer assets were touched in the process.
CertiK also points out that despite multiple days of fabricated tokens being created and swapped for legitimate cryptocurrency, no automated risk controls flagged or blocked the activity until CertiK itself raised the issue with Kraken.
When Kraken asked for the funds to be returned in line with its bug bounty terms, the researchers declined, instead requesting a payment tied to a hypothetical worst-case loss scenario rather than the actual amount extracted — the basis for Kraken's extortion accusation. CertiK counters that this demand was a reaction to Kraken's own threats after it disclosed the more severe set of vulnerabilities. Worth noting: Kraken's published bug bounty policy caps critical-severity payouts at $1.5 million, well below the $3 million figure at the center of the dispute.
03A Tornado Cash Wrinkle
Adding a further complication, the same address responsible for the "test" transactions reportedly sent three deposits to Tornado Cash roughly two weeks prior to the incident:

If CertiK-linked funds did pass through Tornado Cash — a mixing service under U.S. Treasury sanctions — the legal exposure for those involved could be considerable.
04Unresolved
Both Kraken and CertiK maintain they acted appropriately: Kraken says it took reasonable defensive steps once ethical lines were crossed, while CertiK insists it followed standard industry practice for responsible disclosure and coordinated appropriately throughout. Caught in between are Kraken's users and the wider crypto security community, watching to see which account holds up.
Some observers have also raised the possibility that a rogue actor — potentially operating outside CertiK's sanctioned research — could have played a role independent of the firm's official position, a scenario neither side has ruled out.
Beyond the immediate financial dispute, the episode raises broader concerns about how vulnerability disclosure is handled in crypto: overly aggressive responses to good-faith bug reports could discourage researchers from coming forward at all, while ambiguity about what counts as "testing" versus unauthorized withdrawal leaves plenty of room for disputes like this one to recur.
Get new scam files the moment we publish them — usually 2–3 emails a week.