Chief Security Officer at @krakenfx, hacker, @THOTCON OPER, @IamTheCavalry, @DEFCON NOC, @SpiderLabs founder - Opinions are my own, not my employer’s

Joined April 2009
1,909 Photos and videos
Pinned Tweet
31 Aug 2024
If you are exploring #nostr, you can find me there: npub1xmp08ww7fku05qwhy3ldgshevq368qjzas628ukpqs4wunuec0gqwgqfpf
18
1
47
29,712
Nick Percoco retweeted
Ladies and gentlemen, $SPCXx is now live. The largest IPO in history, tokenized by xStocks, trading 24/7.
229
103
680
127,400
Nick Percoco retweeted
For years, access to companies like SpaceX felt out of reach. That’s changing with IPO access on Kraken via xStocks.
25
14
144
18,074
Nick Percoco retweeted
One of the most anticipated IPOs of the decade. Coming to Kraken as a tokenized equity. Full details soon. 👀
71
88
522
72,389
Nick Percoco retweeted
Institutions have gotten in at the IPO price for decades. Retail got the leftovers. xStocks just ended that. Now, retail investors worldwide can access US-listed IPO price exposure via xStocks, at the offering price. → blog.kraken.com/product/xsto…
9
13
49
8,909
Nick Percoco retweeted
Most serious traders focus on what to buy. Fewer think hard enough about how it's held, and who might be trying to take it. Kraken VIP includes private sessions with our security analysts: covering account protection, custody, and threat awareness. Check your eligibility at kraken.com/vip
6
5
49
4,394
Nick Percoco retweeted
Introducing Kraken Prop ⚡ Trade with Kraken’s capital and keep up to 90% of your profits Your downside is capped at a one-time evaluation fee The upside is based entirely on how you perform proapp.kraken.com/9f1e/Prop
74
54
544
178,771
Nick Percoco retweeted
May 27
Your Bitcoin can now earn Bitcoin! Bitcoin Vault is live. Deposit BTC, earn up to 2.5% APY paid in BTC. Get started 👇 app.kraken.com/JDNW/Vault
53
37
259
25,150
Nick Percoco retweeted
Q1 2026 @Payward Financial Highlights are out * Adjusted Revenue of $507 million, up 3% YoY * Assets on Platform: $40 billion, up 11% YoY * Funded Accounts: 6.1 million, up 47% YoY Importantly, we executed on multiple strategic initiatives to further strengthen our long term infrastructure - acquisitions of Backed, Magna, Bitnomial, and Reap, partnerships with Nasdaq and Deutsche Börse, and many new product launches. payward.com/press-release/q1…
8
12
74
12,748
Nick Percoco retweeted
May 15
I put a prompt injection into my LinkedIn bio and recruiters are messaging me in Old English and calling me Lord.
658
7,530
92,513
4,368,765
Nick Percoco retweeted
Hey @krakenfx customers 👋 Here’s how to turn crypto into cash.
6
36
150
10,644
Anyone remember this? This unit plays the “Thundering Turbo” game. Came out in 1983. Was the closest to VR at the time for kids. It was great for road trips in the 80s.
3
14
1,715
A scam blowing up this year that nobody warns you about: the recovery scam. Here’s how it works. You get scammed once. Crypto, romance, fake invoice. Doesn’t matter. You realize, you panic, maybe you tell the scammer “I’m calling the cops.” They record that call. Then they wait 4 to 8 weeks. Then a “police officer” calls. Or a “lawyer.” Or someone from a “consumer recovery agency.” They know specific details about your scam. Because they ARE the people who scammed you. They offer to help recover your money. Just need an upfront fee. Gift cards work great, apparently. Or more crypto as a “recovery bond.” Rule: Anyone who contacts YOU first about money you lost is the scammer. Government agencies and law enforcement do not work this way. Ever. Share this. Send it to anyone who might be vulnerable to getting scammed TWICE.
19
38
165
25,902
Kraken Security Update We are currently being extorted by a criminal group threatening to release videos of our internal systems with client data shown if we do not comply with their demands. It’s important to start with the most important points: our systems were never breached; funds were never at risk; we will not pay these criminals; we will not ever negotiate with bad actors. Kraken identified and shut down two instances of inappropriate access to limited client support data. In February 2025, we received a tip from a trusted source regarding a video shared on a criminal forum that appeared to show access to our client support systems. We immediately launched an investigation and quickly identified the individual involved as a member of our support team. Their access was revoked immediately, a full investigation was conducted, additional security controls were put in place and a limited number of affected clients were notified. Since then, we have been collaborating with industry partners and law enforcement to investigate and disrupt insider recruitment efforts targeting not only crypto companies, but also gaming and telecommunications organizations. More recently, we received another tip, along with a new video showing similar activity. We quickly identified the individual involved and terminated their access. As before, we acted immediately to revoke access, conduct a full investigation, and notify the small number of affected clients. Across both incidents, only a very small number of client accounts were potentially viewed - approximately 2,000 in total (0.02% of clients). Shortly after access was terminated, we began receiving extortion demands. The criminals threatened to distribute materials from both the February 2025 incident and the recent incident to media outlets and on social media if we did not comply. We will not pay these criminals. Based on intelligence gathered across both incidents, along with extensive ongoing analysis, we believe there is sufficient evidence to support the identification and arrest of those responsible. We are actively working with federal law enforcement across multiple jurisdictions to pursue all individuals involved and bring them to justice. Due to the ongoing investigation, we cannot share additional details at this time. However, anyone with relevant information is encouraged to contact us directly. The security of our clients is our highest priority, and we remain fully committed to combating the growing global threat of insider recruitment and constantly enhancing our security practices to combat new threats. Note: If you are a client potentially affected by this, you've already been notified.
247
495
3,757
1,280,202
Nick Percoco retweeted
Every security flaw discovered by AI was there before AI, waiting to be discovered either by people or by AI. The world has never been good at securing computer systems; finally with AI we are going to get good.
344
462
7,493
394,306
Nick Percoco retweeted
Scammers ruin lives for a living. It's time to ruin their day. We're sponsoring @Kitboga's Creation Jam. Build unskippable ads scammers can't escape, get them tested live on stream, and win prizes! Deadline: April 30 👇 kitboga.com/codejam26
20
16
131
21,784
Nick Percoco retweeted
I'd rather have bananas than Bitcoin 🍌
187
427
2,391
182,826
Nick Percoco retweeted
Mar 24
Your Krak home screen just got simpler. Up to 1% cashback. Up to 8% APY. Send, split, done. Same Krak. A lot less tapping.
20
4
70
4,378
Nick Percoco retweeted
xNasdaq? Soon. The xStocks framework will power a new gateway connecting @Nasdaq’s tokenized equity markets with blockchain networks. TradFi isn’t so traditional anymore.
138
203
1,304
386,601
Nick Percoco retweeted
13 Dec 2025
⚠️ It is CRITICAL that you secure your Telegram. YOU SUCK AT THIS SO LISTEN UP! They will log in with the session keys they stole so YOU MUST: - Open Telegram ON YOUR PHONE!!! - Settings -> Devices - "Terminate all other sessions" - Change pw. Add/update MFA
3
14
147
24,648