CertiK: All held funds have been returned, but the total amount differs from Kraken's request
ChainCatcher message, CertiK announced a series of Q&A regarding the CertiK-Kraken white hat incident on platform X. CertiK stated that no assets of actual Kraken users were directly involved in the research activities. In communications with Kraken (via email and video conference), CertiK consistently assured them that funds would be returned. All funds currently held have been returned, but the total amount differs from Kraken's request. CertiK made refunds based on its own records.
CertiK disclosed the details of the vulnerability to Kraken and received a fix within 47 minutes. After the testing concluded, CertiK promptly notified Kraken through various means and sent a detailed report. CertiK did not participate in Kraken's bounty program and did not mention any bounty requests, focusing instead on ensuring the issue was resolved.
Additionally, CertiK stated that it conducted multiple large-scale tests to assess the limits of Kraken's protection and risk control. After several days of repeated testing and nearly three million in cryptocurrency, no alarms were triggered, and they still have not figured out the limitations.