My Kraken account got emptied 36 hours ago. Lost about 12k Euro of BTC.
I am now in discussion with them on this, similar status.
Who and how did they compromize my account? I do not know.
I did not have the sms verification setup - my mistake.
But, the IP that withdrew funds is on the other side of the world (Somewhere in canada/us?) And definitely i was not warned of the transaction prior to it. Only got an email after the funds were sent...
So within the same timeframe as I was robbed, which suggests to me that Kraken has been compromised...and most likely, from within.
Sure, they can say that they have given us the tools to make our accounts more secure, and point out that we haven't made use of them, but what I would say to that is that customer security is primarily their business, and their responsibilty before it is Joe Public's. Even if all they done was straightforward email confirmation before sending any funds, like what practically every other exchange does, then neither your funds, nor my funds would have been stolen.
It seems to me that Kraken's default settings are designed to faciliate theft, only for them to be in the position to turn around and say 'but you never used advanced security options so fuck you".
Like everything else in crpyto land....dodgy as fuck, and I have zero faith that it isn't Kraken staff themselves who are executing these thefts on 'n00bs' who have not made use of more advanced security features.
I totally agree with your point of Almost all the exchanges are requesting the email confirmation of withdraw by default and their is no point of changing this security on this exchanges which make good security for the hackers as if they are not able to hack your email id then this type of hacking could have been stopped. Kraken being a big exchange they are asking so many details before opening the account and coming to security part they are so big lame in blaming fully on customers who have not opted for 2fa security , but they should have automatically have taken the email verification of withdraw security by default like other exchanges.
so this is a lesson for all the users who are using exchanges as wallet to store bitcoin and if like this any thing happen they can do nothing but to feel sorry for this type of loss.