0%

Kraken Bug Bounty program patches isolated bug

2024년 6월 19일 4 분 읽기
뉴스 기사 배너 이미지

The bug was initially discovered by a third-party security research company who had exploited the flaw for financial gain before reporting it to Kraken’s Bug Bounty program. This flaw allowed certain users, for a short period of time, to artificially increase the value of their Kraken account balance without fully completing a deposit.

On discovery, a cross-functional effort at Kraken mitigated the issue in less than an hour. We then thoroughly tested the solution to guard against similar issues in the future.

Unfortunately, the third-party researchers that discovered the bug acted in bad faith and outside the rules of our established Bug Bounty program, which has been in operation for nearly a decade. Bug bounty program industry best practices generally involve careful collaboration between both parties, with security researchers expected to:

  1. Exploit only what is needed to prove a security vulnerability

  2. Promptly return assets that have been extracted

  3. Provide details of testing, such as proof-of-concept code, that allows the company to assist with the identification and remediation of the underlying flaw

We won’t be crediting the researcher of this disclosure because they didn’t comply with any of these industry expectations.

In return for bug bounty reports, developers like Kraken are expected to be attentive, patch the underlying issue quickly and publicly recognize the incredible work of the researcher. Most importantly, they’re also expected to reward the researcher with a generous bounty. We actively moved to hold up our side of this deal.

Security research is nothing new for Kraken, which has deep roots in the info-sec industry. Our Kraken Security Labs team has a track record of discovering and reporting security vulnerabilities to other crypto vendors, including Ledger and Trezor, to help them improve their products.

We understand the value that external security research can bring and how it can enhance the broader ecosystem. There’s simply no better way to secure all users on the crypto frontier than to work collaboratively.

“As a leader with roots in the hacking community, I can attest to the importance of leveraging the skills, knowledge and expertise across the security community to enhance companies’ security strategies and risk management controls,” said Nick Percoco, Kraken Chief Security Officer.

We see our Bug Bounty program as a vital shield to Kraken’s mission and a key part of our efforts to enhance our overall security systems and processes. We have worked with many talented, good faith security researchers over the years, and look forward to continuing this work in the future.

These materials are for general information purposes only and are not investment advice or a recommendation or solicitation to buy, sell, stake, or hold any cryptoasset or to engage in any specific trading strategy. Kraken makes no representation or warranty of any kind, express or implied, as to the accuracy, completeness, timeliness, suitability or validity of any such information and will not be liable for any errors, omissions, or delays in this information or any losses, injuries, or damages arising from its display or use. Kraken does not and will not work to increase or decrease the price of any particular cryptoasset it makes available. Some crypto products and markets are unregulated, and you may not be protected by government compensation and/or regulatory protection schemes. The unpredictable nature of the cryptoasset markets can lead to loss of funds. Tax may be payable on any return and/or on any increase in the value of your cryptoassets and you should seek independent advice on your taxation position. Geographic restrictions may apply.

The post appeared first on Kraken Blog.

인기 뉴스

How to Set Up and Use Trust Wallet for Binance Smart Chain
#Bitcoin#Bitcoins#Config+2 더 많은 태그

How to Set Up and Use Trust Wallet for Binance Smart Chain

Your Essential Guide To Binance Leveraged Tokens

Your Essential Guide To Binance Leveraged Tokens

How to Sell Your Bitcoin Into Cash on Binance (2021 Update)
#Subscriptions

How to Sell Your Bitcoin Into Cash on Binance (2021 Update)

What is Grid Trading? (A Crypto-Futures Guide)

What is Grid Trading? (A Crypto-Futures Guide)

Cryptohopper에서 무료로 거래를 시작하세요!

무료 사용 - 신용카드 필요 없음

시작하기
Cryptohopper appCryptohopper app

면책 조항: Cryptohopper는 규제 기관이 아닙니다. 암호화폐 봇 거래에는 상당한 위험이 수반되며 과거 실적이 미래 결과를 보장하지 않습니다. 제품 스크린샷에 표시된 수익은 설명용이며 과장된 것일 수 있습니다. 봇 거래는 충분한 지식이 있거나 자격을 갖춘 재무 고문의 조언을 구한 경우에만 참여하세요. Cryptohopper는 어떠한 경우에도 (a) 당사 소프트웨어와 관련된 거래로 인해, 그로 인해 또는 이와 관련하여 발생하는 손실 또는 손해의 전부 또는 일부 또는 (b) 직접, 간접, 특별, 결과적 또는 부수적 손해에 대해 개인 또는 단체에 대한 어떠한 책임도 지지 않습니다. Cryptohopper 소셜 트레이딩 플랫폼에서 제공되는 콘텐츠는 Cryptohopper 커뮤니티 회원이 생성한 것이며 Cryptohopper 또는 그것을 대신한 조언이나 추천으로 구성되지 않는다는 점에 유의하시기 바랍니다. 마켓플레이스에 표시된 수익은 향후 결과를 나타내지 않습니다. Cryptohopper의 서비스를 사용함으로써 귀하는 암호화폐 거래와 관련된 내재적 위험을 인정하고 수락하며 발생하는 모든 책임이나 손실로부터 Cryptohopper를 면책하는 데 동의합니다. 당사의 소프트웨어를 사용하거나 거래 활동에 참여하기 전에 당사의 서비스 약관 및 위험 공개 정책을 검토하고 이해하는 것이 필수적입니다. 특정 상황에 따른 맞춤형 조언은 법률 및 재무 전문가와 상담하시기 바랍니다.

©2017 - 2024 저작권: Cryptohopper™ - 판권 소유.