Kraken Reveals Extortion Demands After Client Data Incident: ‘We Will Not Pay’, Security Chief Says

bitcoinistОпубликовано 2026-04-14Обновлено 2026-04-14

Введение

Kraken, a major US crypto exchange, has publicly refused extortion demands from a criminal group following two incidents of unauthorized access to limited client support data. Chief Security Officer Nick Percoco stated the exchange identified and terminated access for individuals involved, emphasizing that no systems were breached and user funds remained safe. Approximately 2,000 client accounts (0.02% of users) were affected. Kraken is cooperating with law enforcement and industry partners to investigate what it describes as insider recruitment efforts targeting multiple sectors. The incident has sparked community concerns over insider threats and data security, drawing comparisons to a similar past event at Coinbase.

Kraken, the US’s second-largest crypto exchange, has rejected extortion threats from a criminal group after two incidents of unauthorized access to limited client support data in the past year, reigniting investors’ concerns about insider threats.

Kraken Fights Back Extortion Demands

On Monday, Kraken’s Chief Security Officer (CSO), Nick Percoco, revealed that a criminal group is extorting the crypto exchange, threatening to release videos of their systems exposing client data.

In a security update, the CSO affirmed that Kraken had identified and shut down two instances of inappropriate access to limited client support data since 2025. Per the post, the crypto exchange received a tip about a video shared on a criminal forum. The video reportedly showed access to Kraken’s client support system.

The exchange “immediately launched an investigation and quickly identified the individual involved as a member of our support team,” Percoco explained, “Their access was revoked immediately, a full investigation was conducted, additional security controls were put in place and a limited number of affected clients were notified.”

More recently, they received another tip with a new video showing similar activity, prompting a new investigation to identify the parties involved, terminate their access, and notify the affected clients.

“Shortly after access was terminated, we began receiving extortion demands,” the security chief stated. “The criminals threatened to distribute materials from both the February 2025 incident and the recent incident to media outlets and on social media if we did not comply.”

Percoco emphasized that the exchange’s systems were never breached and funds were never at risk. In addition, he noted that “only a very small number” of client accounts, approximately 2,000 or 0.02% of clients, were potentially viewed across both incidents.

Kraken has now publicly rejected the criminal demands, declaring that they “will not pay these criminals” and “will not ever negotiate with bad actors.”

In the announcement, the exchange highlighted that it has been collaborating with industry partners and law enforcement to “investigate and disrupt insider recruitment efforts targeting not only crypto companies, but also gaming and telecommunications organizations.”

Based on intelligence gathered from the two incidents and extensive analysis, Kraken believes there is sufficient evidence to identify and arrest all individuals involved, but did not share additional details as the investigation continues. However, they urged anyone with relevant information to contact the exchange directly.

This incident comes just a month after Kraken scored a major victory for the crypto industry, becoming the first crypto company with direct access to the Federal Reserve’s core payment system after winning the Kansas City Fed’s approval for a Fed master account.

Crypto Community Raises Insider Access Concerns

Crypto investors and Kraken users online reacted to the news, questioning the exchange about the details of the two incidents and criticizing the exchange for offshoring customer support staff.

“So, basically, you outsourced it to shady third-party companies (or even worse, your internal recruiters are sleeping), and you got hacked twice or more. You made your customers vulnerable to wrench attacks,” an X user wrote under Percoco’s post.

However, details of whether the inappropriate data access was from an in-house support team or an overseas third-party support staff have not been revealed yet.

Another crypto community member pushed back on Kraken’s “very small number” of clients clarification, asserting that “this is not the metric you think it is... of those 2000 accounts, they are probably the ones with balances worth wrench attacking.”

Others drew a parallel between this incident and Coinbase’s data breach controversy from last year. For context, Coinbase CEO Brian Armstrong revealed in May 2025 that malicious actors had bribed a handful of support contractors overseas to access the company’s internal tools.

This led to the leak of names, email addresses, limited transaction records, and partial Social Security numbers of around 1% of the exchange’s users. Then, the attackers attempted to blackmail Coinbase using the breached information, demanding a $20 million Bitcoin (BTC) ransom for the sensitive data.

Reuters later alleged that Coinbase had been aware of the customer data leak months before it disclosed it, also raising concerns about transparency and insider threats.

The total crypto market capitalization is at $2.43 trillion in the one-week chart. Source: TOTAL on TradingView

Связанные с этим вопросы

QWhat did Kraken's Chief Security Officer reveal about the extortion demands?

AKraken's CSO Nick Percoco revealed that a criminal group is extorting the crypto exchange by threatening to release videos of their systems exposing client data, and that Kraken will not pay or negotiate with these criminals.

QHow many client accounts were potentially affected by the unauthorized access incidents at Kraken?

AApproximately 2,000 client accounts, or 0.02% of Kraken's clients, were potentially viewed across both incidents.

QWhat was the nature of the security incidents at Kraken, according to the company?

AThe incidents involved two instances of unauthorized access to limited client support data by individuals who were members of the support team, but the company's core systems were never breached and client funds were never at risk.

QHow did the crypto community react to Kraken's announcement of the security incidents?

AThe community questioned the details of the incidents, criticized the exchange for potentially offshoring customer support staff, and expressed concern that the affected accounts might be high-value targets for 'wrench attacks'.

QWhat parallel was drawn between this Kraken incident and another crypto exchange?

AThe incident was compared to Coinbase's data breach from May 2025, where malicious actors bribed overseas support contractors to access internal tools, leading to a data leak and a subsequent extortion attempt.

Похожее

How Many Tokens Away Is Yang Zhilin from the 'Moon Chasing the Light'?

The article explores the intense competition between two leading Chinese AI companies, DeepSeek and Kimi (Moon Dark Side), and the mounting pressure on Yang Zhilin, the founder of Kimi. While DeepSeek re-emerged after 15 months of silence with its powerful V4 model—boasting 1.6 trillion parameters and low-cost, long-context capabilities—Kimi has been focusing on long-context processing and multi-agent systems with its K2.6 model. Yang faces a threefold challenge: technological rivalry, commercialization pressure, and investor expectations. Despite Kimi’s high valuation (reaching $18 billion), its revenue heavily relies on a single product with low paid conversion rates, while DeepSeek’s strategic silence and open-source influence have strengthened its market position and valuation prospects, now targeting over $20 billion. Both companies reflect broader trends in China’s AI ecosystem: Kimi aims for global influence through open-source contributions and agent-based advancements, while DeepSeek prioritizes foundational innovation and hardware independence, notably shifting to Huawei’s chips. Their competition is seen as vital for China’s AI progress, with the gap between top Chinese and U.S. models narrowing to just 2.7% on the Elo rating scale. Ultimately, the article argues that this rivalry, though anxiety-inducing for leaders like Zhilin, is essential for driving innovation and solidifying China’s role in the global AI landscape.

marsbit5 ч. назад

How Many Tokens Away Is Yang Zhilin from the 'Moon Chasing the Light'?

marsbit5 ч. назад

TechFlow Intelligence Bureau: ChatGPT Helps Amateur Mathematician Crack 60-Year-Old Problem, CFTC Sues New York Regulator Over Coinbase and Gemini

An amateur mathematician, with the assistance of ChatGPT, has solved a combinatorial mathematics puzzle originally proposed by Hungarian mathematician Paul Erdős in the 1960s. This marks another milestone in AI-aided mathematical research, demonstrating the evolving capabilities of large language models in formal reasoning. In other AI developments, OpenAI introduced a new privacy filter tool for enterprise API usage, automatically screening sensitive data. Meanwhile, the Qwen3.6-27B model achieved 100 tokens per second on a single RTX 5090 GPU using quantization, significantly lowering the cost barrier for local AI deployment. In crypto and Web3, the U.S. CFTC sued New York’s financial regulator, challenging its oversight of Coinbase and Gemini—a first-of-its-kind federal-state regulatory clash. Following a vulnerability, KelpDAO and major DeFi protocols established a recovery fund. Tether froze $344 million in assets linked to Iran’s central bank upon U.S. Treasury request, highlighting the centralized control risks in stablecoins. Separately, Litecoin underwent a 3-hour chain reorganization to undo a privacy-layer exploit. In the U.S., former President Trump invoked the Defense Production Act to address power grid bottlenecks affecting AI data centers and dismissed the entire National Science Board, raising concerns over research independence. A retail trader gained 250% on a $600k Intel options bet amid AI-related speculation. Xiaomi announced its first performance electric vehicle, targeting rivals like Tesla. Meanwhile, iPhone users reported devices automatically reinstalling a hidden app daily, suspected to be MDM-related. A Chinese securities report noted that A-share institutional crowding has reached its second-longest streak since 2007, signaling high valuations and potential style rotation. The day’s developments reflect a dual narrative: AI is enabling unprecedented individual breakthroughs, while centralized power structures—whether governmental or corporate—are becoming more assertive, underscoring that decentralization is as much a political-economic challenge as a technical one.

marsbit5 ч. назад

TechFlow Intelligence Bureau: ChatGPT Helps Amateur Mathematician Crack 60-Year-Old Problem, CFTC Sues New York Regulator Over Coinbase and Gemini

marsbit5 ч. назад

Торговля

Спот
Фьючерсы
活动图片