TLDR A dark web post claims access to Kraken’s admin panel with user data and full KYC. The access is read-only but includes support ticket creation, with no IPTLDR A dark web post claims access to Kraken’s admin panel with user data and full KYC. The access is read-only but includes support ticket creation, with no IP

Kraken Exchange Access Listed for Sale on Dark Web for Just $1: Report

2026/01/02 20:04
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

TLDR

  • A dark web post claims access to Kraken’s admin panel with user data and full KYC.
  • The access is read-only but includes support ticket creation, with no IP limits.
  • Seller says access is routed internally and valid for 1–2 months with TOTP expiring Feb 2026.
  • Security experts warn of phishing risks if attackers impersonate support using real transaction info.

A dark web forum listing is circulating that allegedly offers access to a read-only admin panel of the Kraken cryptocurrency exchange for as little as $1. The post has drawn attention from cybersecurity analysts and exchange users alike. The access allegedly allows viewing of user profiles, full transaction histories, and Know Your Customer (KYC) documents.

These documents include government-issued IDs, selfies, proof of address, and source-of-funds files. The listing claims the access is proxied through Kraken’s internal systems and has no IP restrictions. The seller states that access remains valid for up to two months, and the time-based one-time password (TOTP) linked to the session is set to expire in February 2026.

Access Description Raises Alarms from Security Analysts

According to details shared by Dark Web Informer, the access is described as view-only but includes the ability to generate support tickets. This could potentially be used to impersonate staff or phish for more information from users. Some cybersecurity experts have flagged the sale as highly suspicious, while others caution that, if true, it could expose sensitive data of Kraken customers.

“This is a major data-exposure and phishing risk for Kraken customers,” one security professional was quoted as saying. Experts warn that even read-only access can lead to major threats when sensitive data is involved. Full access to user trading activity, wallet addresses, and deposit behavior could allow attackers to conduct highly targeted phishing campaigns, SIM swaps, or credential theft.

CIFER Security, an independent cybersecurity firm, warned that attackers could use support ticket tools to imitate legitimate staff. With access to real user data, it becomes easier to manipulate users into sharing credentials or making transfers. The firm added that such attacks could target high-value individuals or those with frequent transactions.

Admin Panels in Crypto Under Threat Again

Access to internal admin tools has been a repeated focus for threat actors in the cryptocurrency space. Exchanges such as Mt. Gox, Binance, KuCoin, Crypto.com, and FTX have all faced breaches targeting internal control systems.

These incidents have led to broader concerns about centralized platforms storing customer data in environments that may be exposed through compromised credentials, insider actions, or vendor vulnerabilities. Analysts believe that this alleged Kraken breach follows a similar pattern and reflects continued risks in platform design and access control.

What Kraken Users Are Advised to Do Now

CIFER Security recommends that Kraken users take extra precautions even before any official confirmation. Users are urged to enable hardware-based two-factor authentication, lock account settings, and whitelist specific withdrawal addresses. These steps can reduce risks of unauthorized account actions.

Additionally, users should be cautious about any emails or messages claiming to be from Kraken support. If attackers have access to transaction details, they may attempt to trick users using personalized information. Monitoring for SIM swap attempts and unexpected password resets is also advised.

Moving funds to new addresses not visible in transaction histories is also being suggested. Hardware wallets are a more secure option for users with large holdings. At the time of writing, Kraken has not issued an official statement. It is unknown whether this access was obtained through stolen credentials, insider involvement, or another method. Security experts are calling for the exchange to urgently audit admin panel activity, rotate access keys, and notify users if any exposure is confirmed.

The post Kraken Exchange Access Listed for Sale on Dark Web for Just $1: Report appeared first on CoinCentral.

시장 기회
Story 로고
Story 가격(IP)
$0.5167
$0.5167$0.5167
+2.62%
USD
Story (IP) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!