Allegedly, a Certik employee finds a serious vulnerability in the Kraken exchange and reports it and receives a bug bounty reward. But before that, he tells his fellow Certik employees about the vulnerability. Then, those employees use this vulnerability to steal nearly $3 million of Kraken's money.
https://x.com/c7five/status/1803403565865771370
Days after after Kraken noticed this exploit and demanded the stolen $3M, they refunded it. The sad part is that a reputable audit firm employees abused their powers, and if this abuse had not been noticed and the funds had not been requested, the ill-intentioned Certik employees would have gotten away with this large amount.
https://x.com/c7five/status/1803773589226995826