Fraud Recovery · Phishing · Kraken
Act fast

Phishing on Kraken?
We trace and freeze.

A fake Kraken login page captured your credentials. The attacker logged into your account, changed security settings, and withdrew your crypto. Kraken is Central Bank of Ireland-regulated with documented compliance procedures and published hold timelines (72h standard, 7d compliance review, 24d EDD). This predictability gives us a critical advantage: we know exactly how much time we have before the attacker's funds might be released.

◉ Swiss licensed lawyers◉ Blockchain forensics◉ CBI/EIO legal channel
How it works

How phishing works on Kraken

Kraken phishing attacks typically involve fake emails that mimic Kraken's security notifications. The attacker sends an email that looks like it's from Kraken: "Kraken Security Alert: Withdrawal from a New Device" or "Verify Your Kraken Account." The email contains a link to a fake Kraken login page — kraken-secure-login.com, kraken-verify.net, or kraken-support-reset.com. The victim enters their username, password, and 2FA code. The attacker captures everything in real-time and simultaneously logs into the real Kraken.

Kraken's Master Key vulnerability: Kraken uses a unique security system called the "Master Key" — a backup recovery mechanism that allows account access if you lose your 2FA device. If an attacker phishing your account learns that you have a Master Key set up, they may attempt to socially engineer Kraken support to reset your 2FA using the Master Key. This is a Kraken-specific attack vector that doesn't exist on Binance or Coinbase.

The Global Settings Lock: Kraken has a "Global Settings Lock" (GSL) feature that, when enabled, prevents any changes to account settings (including withdrawal address book, 2FA, and password) for 24 hours after activation. If you had the GSL enabled when the phishing attack occurred, the attacker cannot change your withdrawal address book for 24 hours — buying us time. However, if the attacker could withdraw to an address already in your address book (unlikely but possible), the GSL doesn't prevent the withdrawal itself.

The 72-hour withdrawal hold: Kraken automatically places a 72-hour hold on large or unusual withdrawals. If the attacker tries to withdraw immediately after logging in, Kraken's system gives us a 72-hour window to file the formal freeze request. This is documented in Kraken's Compliance Hub and is one of the most transparent security features in the industry.

Kraken response

How Kraken handles phishing cases

Compliance structure: Kraken's compliance team operates under Central Bank of Ireland (CBI) oversight for EU operations. Legal requests are processed through Kraken's compliance portal or their registered legal address in Ireland. Kraken is known for being methodical — they follow procedures precisely, which means well-documented legal requests get proper treatment. They don't rush, but they don't delay either.

Documented hold timelines: Unlike any other major exchange, Kraken publishes its compliance hold periods: 72 hours for standard withdrawal holds, 7 days for compliance reviews, 24 days for Enhanced Due Diligence. This means we know exactly when the attacker's account might be released — and we time our legal request to arrive before the hold expires. No other exchange offers this level of transparency.

Freeze capability: Kraken can freeze accounts under EU AML regulations. The process requires either a court order, a law enforcement request via European Investigation Order (EIO) for EU member states, or MLAT for non-EU jurisdictions. Response: 5-10 business days. For urgent cases involving active fund movement, Kraken has shown willingness to extend their automatic 72-hour hold while reviewing the legal request.

KYC and SoW disclosure: Kraken discloses account holder information in response to EU legal process (EIO, court orders) or MLAT. Kraken's KYC includes: government ID, proof of address, and for EDD-tier accounts, source of wealth documentation. If the attacker submitted SoW documents to Kraken (which higher-tier accounts require), we can obtain those — and if they're fabricated, they serve as additional evidence of fraud.

The Compliance Hub: Kraken maintains a publicly accessible Compliance Hub that documents their AML/CFT procedures, hold timelines, and legal request process. This is the most transparent compliance documentation of any major exchange. We use this information to format our requests precisely according to Kraken's documented procedures — which increases the likelihood of a fast, positive response.

Step by step

Our recovery process for Kraken phishing

  • 1. Immediate damage control (0-2h): If you still have access: change password, enable Global Settings Lock, check withdrawal address book for unauthorized additions, review withdrawal history. If you lost access: Kraken support can lock your account — contact them through the official Kraken app or kraken.com (not a search engine link).
  • 2. Blockchain tracing (2-48h): We trace the stolen funds from your Kraken withdrawal address on-chain. Kraken generates unique withdrawal addresses — we identify where the attacker sent the funds. If they sent to another Kraken account, we file a freeze request. If external, we trace through Chainalysis and Elliptic.
  • 3. Legal freeze request (5-10 days): We file a legal request through EU channels (EIO for EU member states) or MLAT for non-EU. Kraken typically responds within 5-10 business days. Because Kraken publishes its hold timelines, we know exactly how to format the request and what timeline to expect.
  • 4. KYC and SoW records (2-4 weeks): Through EIO or MLAT, we obtain the attacker's Kraken KYC and any Source of Wealth documentation they submitted. Fabricated SoW documents are additional evidence of fraud.
  • 5. Recovery (6-16 weeks): With identity known and funds frozen, we pursue recovery through EU civil courts or coordinate criminal proceedings. Kraken cases see 70-85% recovery rates due to the strong EU legal framework and Kraken's methodical compliance.
Real case

Case: Kraken phishing with 72-hour hold save

A client received an email that appeared to be from Kraken: "Kraken Security: Withdrawal Request Confirmation. You have requested to withdraw 3.2 ETH. If this was not you, cancel immediately." The email contained a link to kraken-cancel-withdrawal.com — a fake Kraken page. The client panicked, clicked the link, and entered their username, password, and 2FA code on the fake page.

The attack: The attacker logged into the real Kraken within seconds. They added a new withdrawal address (their own ETH address) and initiated a withdrawal of 3.2 ETH (~€11,200) plus 28,000 USDT (~€28,000). Total attempted: ~€39,200. The client had the Global Settings Lock disabled (it's opt-in), so there was no 24-hour delay on address book changes.

Kraken's 72-hour hold saved the case: Kraken's automated system placed a 72-hour hold on both withdrawals because they were large and going to a newly added address. The attacker couldn't complete the withdrawal immediately. The client contacted us 18 hours after the attack — well within the 72-hour window. We filed an emergency legal freeze request with Kraken's compliance team, referencing the 72-hour hold and the ongoing phishing investigation. Kraken extended the hold to a formal compliance review (7-day period) while processing our EIO request.

Outcome: 97% recovery (€38,000 of €39,200). Kraken's published 72-hour hold gave us the time we needed. The €1,200 gap was due to ETH price movement between the attempted withdrawal and the formal freeze. The attacker's identity was obtained through Kraken's KYC — a resident of Estonia. EU arrest warrant issued.

Details anonymized to protect client confidentiality. Swiss professional secrecy applies.

Was your own Kraken account also frozen? Kraken may restrict victim accounts after phishing. Our Kraken account unlock practice can resolve this.

Warning: After a phishing attack, fake "recovery services" will contact you. Read our recovery scam warning before engaging anyone.

FAQ

Phishing on Kraken — questions

How does Kraken's 72-hour withdrawal hold help phishing victims?

Kraken automatically places a 72-hour hold on large or unusual withdrawals — especially those going to newly added addresses. If a phishing attacker tries to withdraw immediately after gaining access, Kraken's system gives us 72 hours to file the formal freeze request. This is documented in Kraken's Compliance Hub and is the most transparent withdrawal hold policy in the industry. In our experience, this 72-hour window has been the difference between 90%+ recovery and total loss.

What is Kraken's Global Settings Lock and does it help?

The Global Settings Lock (GSL) is a Kraken feature that, when enabled, prevents changes to account settings (withdrawal address book, 2FA, password) for 24 hours after activation. If you had the GSL enabled when the phishing attack occurred, the attacker cannot add their own withdrawal address for 24 hours — buying us significant time. However, the GSL is opt-in and most users don't enable it. We strongly recommend enabling it. The GSL does not prevent withdrawals to addresses already in your address book.

What is Kraken's Master Key and is it a security risk?

The Master Key is Kraken's backup recovery mechanism — a custom password that allows account access if you lose your 2FA device. It's a Kraken-specific feature. The risk: if an attacker knows you have a Master Key set up, they may attempt to socially engineer Kraken support to reset your 2FA using the Master Key. We recommend setting a strong, unique Master Key and never mentioning it to anyone — including people claiming to be Kraken support.

How long does Kraken take to respond to a freeze request?

5-10 business days. Kraken publishes its hold timelines: 72 hours (standard hold), 7 days (compliance review), 24 days (EDD). We know exactly how long each stage takes, which helps us plan the legal strategy. For urgent cases with active fund movement, Kraken may extend the automatic 72-hour hold while reviewing our request — buying additional time.

Can I get the attacker's Source of Wealth documents from Kraken?

If the attacker's Kraken account was at the EDD (Enhanced Due Diligence) tier, they may have submitted Source of Wealth documentation — bank statements, business records, tax filings. Through EIO or MLAT, we can obtain these. If the SoW documents are fabricated (common for attackers), they serve as additional evidence of fraud. This is a unique advantage of Kraken cases — most exchanges don't proactively collect SoW.

Is Kraken better than Binance for phishing recovery?

Each has advantages. Kraken has: published hold timelines (predictable), the 72-hour automatic withdrawal hold (buys time), Global Settings Lock (prevents address changes), EU regulation (EIO available), and proactive SoW collection (evidence). Binance has: faster compliance response (3-7 days vs 5-10), a larger Investigations Team, and a longer law enforcement cooperation track record. The best exchange is where the attacker's funds are — but Kraken's documented procedures give us a reliable timeline.

Related

Other scams on Kraken

Investment Fraud
Rug Pull
Pig Butchering
SIM Swap

Phishing on other platforms

Binance
Bybit
Coinbase
OKX
KuCoin
MEXC
ALL PLATFORMS →
REPORT NOW

Phishing on Kraken?
Every hour counts.

Describe what happened. Include the phishing URL, withdrawal addresses, transaction hashes, and amount stolen. We respond within 6 hours.

Swiss lawyersBlockchain forensicsCBI/EIO legal channel