Kraken disclosed on June 19, 2024 that it had patched an isolated flaw in its deposit and funding systems after a security-research company used the weakness to create artificial account balances. CertiK then identified itself as the researcher, turning a technical incident into a public dispute over how far bug-bounty testing may go and when extracted assets must be returned.
Kraken said no client assets were affected or vulnerable. Its chief security officer, Nick Percoco, said nearly $3 million had nevertheless been withdrawn from Kraken’s treasury through three accounts. CertiK described the activity as white-hat testing and disputed Kraken’s account of the repayment discussions. The amount, intent and conduct were therefore claims by the parties on June 19, not findings from an independent forensic report or court.
A balance appeared before a deposit settled
Kraken’s description identified the core failure: under certain conditions, a user could initiate a deposit and receive credit in a Kraken account without fully completing the deposit. That credited balance could then be used to withdraw assets that did exist.
The distinction matters. The surviving record does not show a break in Bitcoin, Ethereum or another blockchain’s consensus rules. It describes a flaw in a centralized exchange’s internal deposit-crediting workflow—the accounting and software boundary that decides when an external transfer is final enough to support an exchange balance.
According to Percoco’s June 19 account, Kraken received a bug-bounty alert on June 9. The initial report called the issue extremely critical but provided few specifics. Kraken said its team found the bug within minutes and mitigated it in less than an hour. The exchange later said a third-party research company had exploited the flaw for financial gain before reporting it.
CertiK supplied a different chronology. It said its Skyfall team discovered the vulnerability on June 5, conducted testing over several days and notified Kraken. CertiK claimed the test showed that more than $1 million in fabricated crypto value could be withdrawn and that Kraken’s controls did not trigger alerts during the tests. Those assertions came from CertiK itself and were not independently reproduced in the public material reviewed for this reconstruction.
The bug-bounty boundary became the story
Kraken’s position was that a legitimate proof of concept should exploit only what is necessary, disclose complete testing details and promptly return extracted assets. Percoco alleged that the original reporter shared the method with two other people, that the resulting withdrawals were omitted from the first report and that the group refused to return funds until Kraken supplied an estimate of the bounty. He characterized that conduct as extortion.
CertiK rejected the accusation. On June 19 it said Kraken had demanded a mismatched amount without first supplying repayment addresses and had threatened individual employees. CertiK also said it would transfer the assets to an account Kraken could access. The event-day record did not yet establish completed repayment, the precise mix of assets, transaction hashes, the dollar-valuation timestamp or whether either side’s characterization of the negotiations was complete.
That uncertainty does not erase the institutional significance. Exchanges rely on external researchers to find defects before criminal attackers do, but bounty programs depend on tightly bounded authorization. Removing millions of dollars to demonstrate impact can look like evidence collection to one side and unauthorized appropriation to the other. The Kraken-CertiK dispute exposed how quickly that line can fail when scope, custody and repayment are not agreed before testing escalates.
What June 19 established
By June 19, Kraken had publicly confirmed and patched a deposit-crediting vulnerability, while CertiK had publicly acknowledged performing the testing. No cryptocurrency price claim is needed to show why the event mattered, and the available sources do not isolate any market reaction caused by the disclosure.
Later context should not be read back into the event-day dispute. On August 16, 2024, CertiK said it had made errors in judgment and communicated poorly, and that it was strengthening its bug-bounty processes with outside counsel. That later acknowledgment clarifies CertiK’s institutional response; it does not independently resolve every June 19 allegation or establish legal liability.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

