This is a stern warning. if you are still using Kraken. Without a doubt add any security features ON TOP of 2FA, now....(or whatever layers of security they're now saying you should use to be able to "use" their site confidently..like stones built on sand)....
Over the last week I've been trying to gain access to my Kraken account again, hadn't used for a month or two, it's been a process to say the least, culminating in a video chat review of me and my documents. etc. (which is somewhat alarming since their own security guidelines say they will "never ask you to download software", three emails in with their techs.... they asked me to "please download Zoom". anyways I did let them know that doesn't seem to fall in line with their own guidelines. lol) Finally I was allowed access again tonight.
I went through the whole process just to gain access again (which I appreciate being extra secure, it's only laughable when seeing what little the hackers had to do to infiltrate my account without having my 2FA).
How this started, I noticed they updated the "look" of their site, a few days ago, so I decided to sign in to see the UI, I don't keep much coin on there, 100-150$ worth max.
"Account locked" weird. I submit a ticket which involves me answering a bunch of security questions.
It's at this point I decide to filter my older emails I received from Kraken,
[email protected], these were not spoofs nor phishing attempts, I never click links etc.
It turns out I had about 7 emails in a row on 1-27 while my kraken account was seemingly being hacked, and WITHOUT my 2FA. My 2FA has been enabled with Kraken since 2015. The email chain starts with the hackers requesting my username.!! wth.. I'm assuming all the hackers had was my email address at this point.
I of course go full lockdown, business class anti-virus check, malware, all nothing (I don't surf and click stuff, use nothing but hefty 100bit+ PWs etc.)
I then tried to communicate with the techs (fearing there might be a bug and people need to know what's up) but of course since my account was locked they wouldn't discuss anything.
I thought could my email been hacked?
Even though this wouldn't answer for the 2FA being bypassed with Kraken.. I never have my 2FA out of my possession.
Well...... my email also has 2FA and has zero logs from any IP other than mine. I also double-checked with the email provider tech, zero bad actor logins, only my IP, the IP used for every attempt with Kraken was different than mine, but always the same.
I've had back and forth with their tech with zero answers as to how my 2FA could have been bypassed and my funds withdrawn (both have 2FA enabled) and now feel obligated to let everyone know. This happened on 1-27 , so sorry for the delay but wasn't sure I was actually hacked until tonight when they restored my account and I could login and see it actually had been.
From their website I can see my 2FA is still enabled, wow, the funding 2FA is disabled, which goes along with the 2nd to last email which said funding would be locked for now...(really, do you think I'd be adding funds after this..
)
they announced their entire website update on 1-29? could there have been a bug, something overlooked while transferring over, something in API? I honestly don't know but I would say to all users,
Proceed with absolute caution.!!!
Update from Kraken as I write this!....... The only answers/recourse Kraken has given me.... "file a police report". lol. wow..
(Sidenote: May be part of the bug? In 2018 after some back and forth with their tech dept. as to why I couldn't fund my account any longer, I surmised I needed to add their "funding" 2FA as well. This was a bit frustrating because no one in tech nor on their website would answer if adding the 2FA "funding" option would affect my original 2FA I've had since 2015 and had used for funding many times. But it turns out that's all I needed to do and I could then do funding and my original 2FA also worked as always to login.)