Post
Topic
Board Exchanges
Re: I've been Kraken'ed...Hacked. 1-27. with 2FA enabled!!.. Warning!
by
Kraken-Septimus
on 15/02/2019, 15:00:40 UTC
Hi PaulyC. I'm so sorry to hear that your account was compromised. Security is our top priority at Kraken and this is the last thing we'd ever want to hear from any of our clients. If you could please provide your ticket number I'll have a look further into this for you. You're welcome to post it here or send me a quick PM.

I've made a note of the fact that you're asked to download Zoom while we ask that you never download software. I can confirm that Zoom is used for these calls and is an independent end-to-end encrypted option for us to conduct video calls with clients that need their identity confirmed. Thanks for pointing that out.

I would also like to note that we have not seen any mass compromise of accounts since the new UI was released. It also sounds like the attack took place on January 27th and the website UI was updated on the 29th, meaning the attack took place before any changes to our website's UI.

As for the funding 2FA, this would be a completely different 2FA from login 2FA. Adding funding 2FA to your account has no affect on your login 2FA and you can use the same method or a different method. For example, if you have a static 2FA (password 2FA) for your login, you could use Google Authenticator for your funding 2FA. We also offer 2FA on trades, a Global Settings Lock so that your information cannot be changed for X days (including adding new withdrawal addresses) and a Masterkey to bypass your 2FA. You can read more about our security features at https://support.kraken.com/hc/en-us/articles/201396837-Securing-Your-Account.

Again, I'm so sorry to hear about your account being compromised. We'll look into what exactly happened in this case and work with you to ensure that this never happens again.