All we're saying to Kraken is: remove bad security options that confuse users. Stop offering fake 2fa. Send email confirmation for withdrawal like every other exchange out there. Enforce 2fa on login, so 2fa on withdrawal can't be disabled without access to the token. These are basic, basic issues that make Kraken look laughable in this space.
people have been telling them this for years. i'm not sure why they haven't done anything about it by now. maybe they think that having all the security "options" is a valuable sell point to their customers. they haven't learned yet -- keep it simple, stupid. maybe all these recent "phishing attacks" on their customers will open their eyes.
Maybe it is in their interests to maintain their default security options in a state that will always offer 'plausible deniability', when the rat at Kraken, scurries around selectively emptying customer accounts?
Perhaps like many other exchanges, Kraken have been robbed.
Bitstamp and Poloniex were robbed, there response was to admit they had been robbed, and opt to pay all their customers back.
Bitfinex was robbed, their response was to admit they had been robbed, and give all their customers a 36% haircut.
Perhaps Kraken have been robbed, and their response has been to keep the fact out of the public domain, and rebalance their books by slowly selectively draining customer accounts?