NexFlow › Is Kraken safe
Is Kraken safe? The exchange that invented proof of reserves — and stayed unbreached
Kraken is the conservative's answer: founded 2011, zero user-fund breaches in 14+ years — and it didn't just stay lucky, it invented the proof-of-reserves practice the industry copied (first Merkle-tree PoR audit March 2014, now AICPA-attested, $21.5B+ covered). The one documented incident — CertiK's $3M treasury-side bug dispute — never touched a user.
What Kraken is
Kraken is one of the oldest continuously operating crypto exchanges — founded 2011, US-rooted, custodial in the classic CEX shape. Its safety claim rests on two things no peer combines: 14+ years without a user-fund breach, and the fact that it invented the practice every transparent venue now performs — cryptographic proof of reserves.
The PoR pioneer credential
On March 24, 2014 — eight years before FTX made reserve proofs fashionable — Kraken passed the world's first cryptographic proof-of-reserves audit, a Merkle-tree verification conducted by Stefan Thomas letting customers individually verify their balance was included. Since January 2022 it runs recurring PoR under AICPA attestation standards, performed by an independent registered CPA firm (The Network Firm; Armanino previously), with client self-verification in-account. The November 2024 attestation covered over $21.5 billion in client assets across BTC, ETH, SOL, USDC, USDT and XRP — spot, margin, futures and on-chain staking positions. Add ISO/IEC 27001:2022 certification and a SOC 2 Type 1 examination, and Kraken has the deepest accountability stack in the major-CEX class.
June 2024: the one incident on the record
The closest thing to a hack in Kraken's history is a dispute, not a breach. A researcher — later publicly identified as CertiK — reported a bug through the bounty channel: a deposit-processing flaw that could, under the right circumstances, credit funds before the deposit fully completed. Accounts associated with the finding withdrew ~$3 million — explicitly from Kraken's treasury, not client assets — and declined to return it pending a bounty amount, which Kraken's CSO Nick Percoco publicly called extortion (CertiK counter-claimed it was threatened). The bug was fixed within days; user funds were never at risk; the funds were ultimately returned.
Read honestly, the episode proves two things at once: Kraken's codebase had a real treasury-side vulnerability — bugs exist even on 14-year-old venues — and the incident never reached the custody layer users care about. It is a footnote compared to the class's actual breaches — a dispute over bounty etiquette after a contained treasury hit, on a venue whose headline number has stayed at zero user funds lost since 2011.
What 'never hacked' is worth
The unbroken record is real evidence — 14 years of attackers trying the largest venues includes Kraken, and nothing has drained it — with one honest adjustment the corpus applies everywhere: 'never hacked' measures the past, and every breached exchange in history had a clean record the day before its incident. What raises Kraken's record above marketing is that it is paired with verification: you don't have to believe the claim — the attestation is published, the methodology is open, and your inclusion is checkable from your account.
The risk stack, ranked
| Layer | Status | Read |
|---|---|---|
| Custodial counterparty | 14yr clean + attested PoR | Strongest in class — still a custodian |
| Own-code vulnerabilities | 2024 treasury bug (no user impact) | Real but contained; bounty pipeline worked |
| Account-level phishing | Endemic on all CEXes | Your side — hardware-key 2FA, anti-phish codes |
| Regulatory | 2023 SEC staking settlement | Jurisdiction/product risk, not custody |
How to read the attestations
Kraken's PoR cadence deserves one honest qualifier, the same one this family applies to OKX and Binance: an attestation proves that on a given date, covered client assets existed and a third-party CPA firm verified wallet control under AICPA agreed-upon procedures. It does not publish the liability side (what the company owes beyond client balances), and it says nothing about behavior under stress — the thing Bybit accidentally proved. What distinguishes Kraken's version is longevity and continuity: it has been doing this since 2014 — eight years before FTX's collapse made reserve proofs a marketing requirement — and it kept doing it through the post-FTX era as an attestation process under accounting standards rather than an announcement, which is the difference between a reporting practice and a press release.
Where Kraken stands
The dated read: the benchmark for custodial track-record + verifiability — 14 years unbreached at the custody layer, the inventor of PoR still publishing attestations, and one disclosed treasury-side bug that proved the bounty pipeline instead of the bug. If a custodian must be chosen on documented history alone, this is the reference point.
The verdict in one line: Kraken invented proof of reserves, has the longest unbroken custody record in the class, and its only public incident never touched a user — the safest custodial exchange by documented history, which still means 'the least-risky way to hold someone else's promise'.
Frequently asked questions
Is Kraken a legitimate exchange?
Yes — Kraken, founded 2011, is one of the oldest operating crypto exchanges and carries the class's cleanest record: no user funds ever lost to a breach across 14+ years. It also invented the reserve-transparency practice others copied — running the world's first cryptographic proof-of-reserves audit in March 2014 — and still publishes third-party attested PoR, holds ISO/IEC 27001:2022 certification, and has completed a SOC 2 Type 1 examination.
Has Kraken ever been hacked?
Not in the sense that matters: no breach has ever taken user funds. The closest documented event is June 2024 — a security researcher (later identified as CertiK) found a deposit-processing bug, and associated accounts withdrew ~$3M from Kraken's treasury (explicitly not client assets), then demanded bounty terms before returning it — Kraken called it extortion; CertiK claimed it was threatened. The bug was fixed within days, user funds were never exposed, and the funds were returned. A treasury-side researcher dispute is categorically different from a custody breach.
What is Kraken's proof of reserves?
Kraken pioneered PoR in crypto: the first Merkle-tree cryptographic reserve audit in 2014 (conducted by Stefan Thomas), resumed regularly since January 2022 under AICPA attestation standards performed by an independent accounting firm (The Network Firm, previously Armanino). The Nov-2024 attestation covered $21.5B+ in client assets across BTC/ETH/SOL/USDC/USDT/XRP including staked positions — and clients can self-verify inclusion in their account. It remains a snapshot of assets, not a disclosure of liabilities — but Kraken has the longest, most credentialed history of doing it.
Who holds your crypto on Kraken?
Kraken does — a custodial CEX in the classic shape, with the longest clean operating record in the class: balances are claims, custodied in wallets the attestations verify. The honest frame: you are trusting a 14-year-old regulated venue with an unbroken custody record and published reserve attestations — the strongest version of 'trust a custodian' the CEX class offers, and still a custodian.
What are Kraken's real risks?
In order: (1) the standing custodial set — counterparty risk, withdrawal integrity, operational dependencies — mitigated by the record but never zero; (2) account-level phishing/SIM-swap — the vector that hits users of every exchange regardless of venue security; (3) regulatory posture — Kraken settled an SEC staking case in 2023 (program shut for US users) — jurisdiction risk, not custody risk; (4) its own bug-surface — the 2024 deposit-inflation bug showed treasury-side vulnerabilities exist; researchers found it before criminals did.
Is Kraken safer than Binance or Coinbase?
On documented custody record: Kraken's is the cleanest — 14 years, zero user-fund breaches, PoR invented and continuously published. Binance carries a bigger target plus the battle-tested SAFU fund; Coinbase carries public-company disclosure and US regulatory perimeter. The honest ordering: Kraken leads on unbroken record + reserve verifiability; the others lead on insurance buffer size and disclosure obligations respectively. All three are in the top tier; none is riskless.