The security director of the American crypto exchange Kraken said that a group of anonymous white hat hackers took advantage of the Kraken Bug Bounty loyalty program and illegally took possession of digital assets worth about $3 million.

According to Nick Percoco, a team of security specialists identified a critical bug that, under certain circumstances, allowed an attacker to receive a deposit and withdraw funds without completing the transaction completely. If bugs are discovered, white hat hackers can claim a reward under the Kraken Bug Bounty loyalty program of 1 BTC or more, depending on the severity of the identified vulnerability.

However, in this case, white hat hackers took advantage of the bug to withdraw digital assets to their accounts. When the Kraken team requested a full report on the activity and demanded the return of the withdrawn assets, the self-proclaimed crypto security researchers refused, demanding large compensation in the amount of damage that the error would have caused.

“They have not agreed to return any funds until we provide the desired dollar compensation. This is not white hat hacking, this is extortion! We will not disclose information about this research group because it does not deserve recognition. We are treating this incident as a criminal offense and have contacted law enforcement,” wrote on social network X Nick Percoco.

The top manager clarifies that the cryptocurrency was stolen directly from the accounts of the Kraken exchange, and user funds were not affected.

Earlier, the developers of the Blast blockchain game Super Sushi Samurai reported a hack and withdrawal of assets worth about $4.6 million. According to preliminary data, an anonymous white hacker withdrew funds to his account, allegedly to protect user assets.