
Cryptocurrency exchange Kraken is being blackmailed by a criminal organization that claims to have videos showing access to the company's internal systems. According to reports from CoinDesk and Bloomberg, the platform has vowed not to pay any ransom and maintains that customer funds remain safe. The exchange emphasized there had been no systemic breach of its trading infrastructure or wallets, describing the incident as a targeted abuse of internal access rather than a successful hack of core systems. Chief security officer Nick Percoco confirmed on the X social network that client funds were never at risk and that the company is actively working with federal law enforcement across multiple jurisdictions to pursue all individuals involved.
The episode stems from improper access by individuals linked to Kraken's customer service operation in two separate incidents, which together exposed limited data on around 2,000 accounts, or roughly 0.02% of its total user base. As reported by Bloomberg, some limited client information — including names and addresses — may have been stolen when client support staffers took photos and videos of the data during the 2025 and earlier this year incidents. Those users have been notified, while the people involved have had their credentials revoked and been cut off from internal tools as Kraken tightens monitoring and access controls. A spokesperson for Cheyenne, Wyoming-based Payward Inc., which operates under the name Kraken, declined to comment on what client information was exposed.
According to Kraken's description, the attack reflects a rising pattern of 'internal infiltration + social engineering', in which outsiders work to compromise or recruit people inside service organizations in order to gain read-only access, reconnaissance footage or limited customer data rather than directly attacking hardened wallet systems. Earlier this year, a dark-web listing claiming $1 access to Kraken's internal support panel and KYC data prompted similar concerns, though the exchange did not confirm a breach and security researchers warned that even read-only access to support tools could be weaponized for phishing and targeted scams. As TRM Labs' Ari Redbord noted, 'What we are seeing is a shift toward the human layer' as technical defenses get stronger, with the focus moving to people inside the system.
The new extortion attempt follows a separate March incident in which a Kraken user reportedly lost about 7,784 ETH and 26.5 BTC — worth roughly $18.2 million — to a sophisticated social-engineering scheme before the funds were moved to HitBTC. As reported by CoinDesk, blockchain analytics firm EmberCN and others have noted that even where exchange treasuries and hot wallets remain uncompromised, lapses in human controls — from customer-support access to user opsec — can still translate into large losses and reputational damage. The incident comes amid increased fear among crypto owners of being targeted by criminals, with physical attacks against crypto holders known as 'wrench attacks' increasing last year according to Chainalysis.