Key Takeaways
In crypto, breaches usually start with code. This one didn’t.
Kraken, one of the largest U.S.-based exchanges, is dealing with a different kind of threat—an extortion attempt built on insider access, not a traditional hack.
On April 13, Chief Security Officer Nick Percoco disclosed that a criminal group is threatening to release internal videos showing client data unless Kraken meets its demands.
The post quickly spread across X, turning the incident into one of the most closely watched security stories in crypto this year.
The message from Kraken was immediate and unambiguous: no payment, no negotiation.
What makes this case unusual is where it started.
According to Kraken, the issue stems from two separate incidents involving unauthorized access to customer support systems: one in February 2025 and another more recently.
These were not breaches of core infrastructure, but limited exposures tied to internal tools.
Roughly 2,000 accounts were affected, representing about 0.02% of Kraken’s user base.
The company said the data exposure was limited and confirmed that no funds were ever at risk.
Kraken has already contacted affected users directly.
Still, the nature of the threat—insiders or compromised credentials—highlights a growing weak point in crypto security.
As exchanges harden their external defenses, attackers are increasingly looking inward.
The attackers’ strategy is simple but effective.
Instead of stealing funds, they allegedly recorded videos of internal systems displaying client information.
Those recordings have now become leverage.
The group is threatening to release the footage publicly, through media outlets or social platforms, if Kraken does not comply with its demands.
The company has not disclosed the ransom amount, but similar cases in the industry have involved demands in the tens of millions.
In crypto, where trust can shift markets overnight, even a limited data exposure can carry outsized consequences.
The risk isn’t just financial—it’s reputational.
A leak, regardless of scale, can trigger user panic, withdrawals, and regulatory scrutiny.
Kraken’s response has been consistent with a broader shift among major exchanges.
“Our systems were never breached; funds were never at risk; we will not pay these criminals. We will not ever negotiate with bad actors,” Percoco wrote.
Rather than engage, the company has escalated the matter to law enforcement across multiple jurisdictions.
Kraken says it has gathered evidence that could help identify those responsible.
This approach reflects a deliberate strategy. Paying ransoms may resolve one incident, but it signals vulnerability and invites more.
Kraken’s case follows a pattern that has become increasingly common.
In May 2025, Coinbase faced a similar situation involving insider-linked data access.
The attackers demanded $20 million. Coinbase refused, instead offering a $20 million reward for information leading to arrests.
Other exchanges have dealt with variations of the same playbook—insider access, leaked data, and ransom demands paid in crypto.
Some firms have chosen to pay quietly. Others, like Coinbase and Kraken, are taking a public stand.
Industry-wide data suggests this shift may be working.
While reported ransomware payments declined in 2025, attempted attacks rose sharply.
The message from law enforcement and major platforms is increasingly aligned: don’t pay.
The incident points to a broader change in how threats are emerging.
For years, crypto security focused on external exploits—smart contract bugs, exchange hacks, and infrastructure vulnerabilities.
Those risks remain, but insider threats are now competing for attention.
Access to internal tools, support systems, or employee credentials can expose sensitive data without ever breaching the core network.
In response, exchanges are tightening controls, adopting zero-trust frameworks, strengthening employee vetting, and increasing monitoring of internal activity.
For users, the implications are more practical.
Even when funds are safe, data exposure can still carry risks.
Security increasingly depends on both platform safeguards and individual habits.
For now, Kraken says no data has been publicly released, and funds remain secure.
But the episode is a reminder of how crypto risks are evolving. Not every attack targets wallets directly. Some aim at trust itself.
As the industry grows, so does the incentive to exploit its weakest links—whether that’s code, infrastructure, or people.
Kraken’s refusal to pay may not end this incident immediately. But it sets a precedent.
In a market where attacks are becoming more sophisticated, the response is starting to change just as quickly.
Prashant Jha is a seasoned crypto journalist based in Delhi, India, with a Bachelor’s Degree in Computer Science Engineering. Passionate about the evolving world of blockchain and cryptocurrencies, he has been a dedicated voice in the industry since 2018. Prashant’s expertise lies in regulatory reporting, where he unravels complex legal and financial developments with clarity and precision. Before joining CCN in 2024, he honed his craft at Cointelegraph, establishing himself as a trusted name in crypto journalism.
His coverage spans major industry events, including the high-profile collapses of FTX, Three Arrows Capital (3AC), and LUNA, offering readers insightful analyses of their regulatory and market implications. Prashant’s technical background enables him to bridge the gap between intricate blockchain technology and its real-world applications, making his work accessible to novices and experts.
Beyond his professional pursuits, Prashant is an avid music enthusiast, often exploring diverse genres to unwind. A sports lover, he has a particular passion for cricket and frequently engages in discussions about the game. His multifaceted interests and sharp journalistic instincts make him a valuable contributor to CCN, where he continues shaping the crypto landscape's narrative.
You’re All Set!
Thanks for signing up. We’ll be in touch soon with the latest insights.
