Kraken Reveals Extortion Demands After Client Data Incident: ‘We Will Not Pay’, Security Chief Says

bitcoinistPublicado a 2026-04-14Actualizado a 2026-04-14

Resumen

Kraken, a major US crypto exchange, has publicly refused extortion demands from a criminal group following two incidents of unauthorized access to limited client support data. Chief Security Officer Nick Percoco stated the exchange identified and terminated access for individuals involved, emphasizing that no systems were breached and user funds remained safe. Approximately 2,000 client accounts (0.02% of users) were affected. Kraken is cooperating with law enforcement and industry partners to investigate what it describes as insider recruitment efforts targeting multiple sectors. The incident has sparked community concerns over insider threats and data security, drawing comparisons to a similar past event at Coinbase.

Kraken, the US’s second-largest crypto exchange, has rejected extortion threats from a criminal group after two incidents of unauthorized access to limited client support data in the past year, reigniting investors’ concerns about insider threats.

Kraken Fights Back Extortion Demands

On Monday, Kraken’s Chief Security Officer (CSO), Nick Percoco, revealed that a criminal group is extorting the crypto exchange, threatening to release videos of their systems exposing client data.

In a security update, the CSO affirmed that Kraken had identified and shut down two instances of inappropriate access to limited client support data since 2025. Per the post, the crypto exchange received a tip about a video shared on a criminal forum. The video reportedly showed access to Kraken’s client support system.

The exchange “immediately launched an investigation and quickly identified the individual involved as a member of our support team,” Percoco explained, “Their access was revoked immediately, a full investigation was conducted, additional security controls were put in place and a limited number of affected clients were notified.”

More recently, they received another tip with a new video showing similar activity, prompting a new investigation to identify the parties involved, terminate their access, and notify the affected clients.

“Shortly after access was terminated, we began receiving extortion demands,” the security chief stated. “The criminals threatened to distribute materials from both the February 2025 incident and the recent incident to media outlets and on social media if we did not comply.”

Percoco emphasized that the exchange’s systems were never breached and funds were never at risk. In addition, he noted that “only a very small number” of client accounts, approximately 2,000 or 0.02% of clients, were potentially viewed across both incidents.

Kraken has now publicly rejected the criminal demands, declaring that they “will not pay these criminals” and “will not ever negotiate with bad actors.”

In the announcement, the exchange highlighted that it has been collaborating with industry partners and law enforcement to “investigate and disrupt insider recruitment efforts targeting not only crypto companies, but also gaming and telecommunications organizations.”

Based on intelligence gathered from the two incidents and extensive analysis, Kraken believes there is sufficient evidence to identify and arrest all individuals involved, but did not share additional details as the investigation continues. However, they urged anyone with relevant information to contact the exchange directly.

This incident comes just a month after Kraken scored a major victory for the crypto industry, becoming the first crypto company with direct access to the Federal Reserve’s core payment system after winning the Kansas City Fed’s approval for a Fed master account.

Crypto Community Raises Insider Access Concerns

Crypto investors and Kraken users online reacted to the news, questioning the exchange about the details of the two incidents and criticizing the exchange for offshoring customer support staff.

“So, basically, you outsourced it to shady third-party companies (or even worse, your internal recruiters are sleeping), and you got hacked twice or more. You made your customers vulnerable to wrench attacks,” an X user wrote under Percoco’s post.

However, details of whether the inappropriate data access was from an in-house support team or an overseas third-party support staff have not been revealed yet.

Another crypto community member pushed back on Kraken’s “very small number” of clients clarification, asserting that “this is not the metric you think it is... of those 2000 accounts, they are probably the ones with balances worth wrench attacking.”

Others drew a parallel between this incident and Coinbase’s data breach controversy from last year. For context, Coinbase CEO Brian Armstrong revealed in May 2025 that malicious actors had bribed a handful of support contractors overseas to access the company’s internal tools.

This led to the leak of names, email addresses, limited transaction records, and partial Social Security numbers of around 1% of the exchange’s users. Then, the attackers attempted to blackmail Coinbase using the breached information, demanding a $20 million Bitcoin (BTC) ransom for the sensitive data.

Reuters later alleged that Coinbase had been aware of the customer data leak months before it disclosed it, also raising concerns about transparency and insider threats.

The total crypto market capitalization is at $2.43 trillion in the one-week chart. Source: TOTAL on TradingView

Preguntas relacionadas

QWhat did Kraken's Chief Security Officer reveal about the extortion demands?

AKraken's CSO Nick Percoco revealed that a criminal group is extorting the crypto exchange by threatening to release videos of their systems exposing client data, and that Kraken will not pay or negotiate with these criminals.

QHow many client accounts were potentially affected by the unauthorized access incidents at Kraken?

AApproximately 2,000 client accounts, or 0.02% of Kraken's clients, were potentially viewed across both incidents.

QWhat was the nature of the security incidents at Kraken, according to the company?

AThe incidents involved two instances of unauthorized access to limited client support data by individuals who were members of the support team, but the company's core systems were never breached and client funds were never at risk.

QHow did the crypto community react to Kraken's announcement of the security incidents?

AThe community questioned the details of the incidents, criticized the exchange for potentially offshoring customer support staff, and expressed concern that the affected accounts might be high-value targets for 'wrench attacks'.

QWhat parallel was drawn between this Kraken incident and another crypto exchange?

AThe incident was compared to Coinbase's data breach from May 2025, where malicious actors bribed overseas support contractors to access internal tools, leading to a data leak and a subsequent extortion attempt.

Lecturas Relacionadas

Near Returns to the AI Stage: Transformation into a Public Chain Due to 'Payroll Difficulties,' Agent and Privacy Emerge as New Growth Narratives

NEAR Returns to AI Origins: From Payroll Struggles to Blockchain, Now Focusing on AI Agents and Privacy NEAR Protocol's journey began not with grand blockchain ambitions, but from a practical hurdle: its AI startup founders, including Transformer paper co-author Illia Polosukhin, couldn't efficiently pay international developers in 2017. This led them to pivot and build a high-performance, scalable blockchain. After years navigating various crypto narratives like sharding and cross-chain interoperability, NEAR is now leveraging its AI roots to re-enter the AI arena. A key driver is its "NEAR Intents" layer, which abstracts complex cross-chain transactions. Users simply state their goal (e.g., swap BTC for ETH), and a solver network finds the optimal route. This system has processed over $20B in cross-chain volume, generating significant fee revenue. A major growth area is private transactions via "Confidential Intents/Swaps," which hide trade details until settlement to protect against MEV and front-running. Remarkably, private swaps recently accounted for over 40% of NEAR's transaction volume, highlighting strong demand but also potential regulatory scrutiny. With its AI-founder pedigree, NEAR is positioning itself at the intersection of blockchain, AI agents, and privacy, aiming to become infrastructure for the emerging agent economy while navigating the challenges of its rapid adoption.

marsbitHace 1 hora(s)

Near Returns to the AI Stage: Transformation into a Public Chain Due to 'Payroll Difficulties,' Agent and Privacy Emerge as New Growth Narratives

marsbitHace 1 hora(s)

From Ethereum to AI's 'CROPS': What Exactly is This Set of 'Slow Variables' That Vitalik Repeatedly Emphasizes?

In recent discussions, Vitalik Buterin has frequently emphasized the concept of "CROPS," a framework defining core values for Ethereum's development. CROPS stands for Censorship Resistance, Capture Resistance, Open Source, Privacy, and Security. Initially outlined in the Ethereum Foundation's "EF Mandate," it represents a commitment to user sovereignty, ensuring that the network resists external control, remains open, protects privacy, and prioritizes security. The relevance of CROPS extends beyond Ethereum's foundational principles, becoming crucial in the context of AI integration. As AI agents begin handling wallet operations and automated transactions, the risk increases that users may cede control over their digital assets, privacy, and intentions to centralized AI service providers. A "CROPS AI" would therefore emphasize local execution where possible, privacy-preserving remote model calls (e.g., using zero-knowledge proofs), and transparent, verifiable processes to maintain user agency. Vitalik highlights a significant convergence between "CROPS Ethereum access layer" and "CROPS AI." Both address the same fundamental challenge: how users can access powerful services—be it blockchain data via RPCs or AI models—without exposing sensitive information or relinquishing ultimate control. This intersection points toward a future digital entry point that is more private, secure, and user-controlled. Ultimately, CROPS is not merely an abstract ideal but a practical guidepost. It steers development—from protocol resilience and wallet design to AI agent safety—towards a future where users retain self-sovereignty even as digital systems grow more complex and powerful. In an era of accelerating AI adoption, these "slow variables" of censorship resistance, openness, privacy, and security may define Ethereum's enduring value.

marsbitHace 1 hora(s)

From Ethereum to AI's 'CROPS': What Exactly is This Set of 'Slow Variables' That Vitalik Repeatedly Emphasizes?

marsbitHace 1 hora(s)

Silicon Valley 'Startup Guru' Steve Hoffman: Web3 + AI Could Be a Trap

Silicon Valley investor and "Godfather of Startups" Steve Hoffman warns that combining Web3 with AI is likely a trap, not a promising venture. In an interview, Hoffman argues that while AI is a foundational technology touching all industries, Web3 adds complexity, friction, and regulatory risk without solving mainstream consumer or business needs. He advises founders to focus on deep, specialized applications where startups can out-iterate giants, rather than on generic features easily replicated by large tech companies. Hoffman observes that Silicon Valley will lead foundational AI research, while China excels at rapid, large-scale application and commercialization, particularly in robotics. He stresses that AI-driven autonomous agents capable of collaborative, multi-step tasks are 2-4 years away, which will cause significant job displacement. The solution is not to slow AI but to redesign business models around human-AI collaboration and reform social systems like education and retraining. For startups, Hoffman recommends focusing on vertical, expertise-heavy domains to build defensibility. He sees major opportunities in AI fraud detection and cybersecurity. Key founder mindsets include systemic thinking over feature-focus, relentless customer centricity, building adaptive teams, and deeply understanding AI's capabilities and limits. Hoffman is also leading a non-profit initiative to establish university centers aimed at training future leaders in responsible, human-value-aligned AI innovation.

marsbitHace 3 hora(s)

Silicon Valley 'Startup Guru' Steve Hoffman: Web3 + AI Could Be a Trap

marsbitHace 3 hora(s)

Token Inefficient, Economy Tokenless

The article "Tokens Aren't Economical, Economics Aren't Tokenized" analyzes a pivotal shift in the AI industry from a technology-driven narrative to one dominated by capital efficiency. It highlights two concurrent trends: a severe capital shortage due to the exorbitant and recurring costs of compute (e.g., OpenAI's high burn rate) and a wave of corporate spin-offs where major tech companies are separating their AI units (like Kuaishou's Kling and Baidu's Kunlunxin). The core argument is that AI's "anti-internet" business model, where user growth increases costs rather than profits, has created a disconnect between high valuations and actual cash flow. Spin-offs address this by allowing AI assets to be valued independently. Within a parent company, they are seen as cost centers, but as standalone entities, they are priced based on their growth potential and scarcity in the primary market, leading to massive valuation premiums (e.g., Kling's estimated value tripling post-spin-off). The industry is at an inflection point, moving from "model worship" to "value realization." The competition is evolving from a pure compute (GPU) race to a broader focus on systemic efficiency and full-stack engineering (involving CPUs and orchestration) to achieve viable commercialization. The year 2026 is framed as a critical moment where the industry must definitively answer how to economically translate AI capability into tangible business value, reshaping the sector's future power structure.

marsbitHace 3 hora(s)

Token Inefficient, Economy Tokenless

marsbitHace 3 hora(s)

Trading

Spot
Futuros
活动图片