105. Meet Nick Percoco, Kraken’s CSO, SpiderLabs founder at Trustwave, and organizer of Chicago’s THOTCON hacker event—your go-to expert for cryptocurrency security breaches, hacking insights, and cybersecurity investigations.

Insights from the Frontlines of Cybersecurity: An AMA with Nick Percoco

Hello, cybersecurity enthusiasts!

I’m Nick Percoco, currently serving as the Chief Security Officer at Kraken, one of the leading global digital asset exchanges. With over 25 years in the realm of security and technology, my journey has been both fulfilling and dynamic. Additionally, I am the founder of SpiderLabs at Trustwave and the co-founder of THOTCON, a renowned hacker conference in Chicago.

My career has spanned various critical roles in cybersecurity. Before taking the helm at Kraken, I held the position of CSO at Uptake, a cutting-edge industrial AI company, and served as the Vice President of Global Services at Rapid7, a prominent cybersecurity firm. Throughout my career, I have shared my expertise on subjects such as security breaches, malware threats, mobile security, and current trends in information security. My speaking engagements have included renowned conferences like Black Hat, DEF CON, and OWASP, as well as presentations to esteemed organizations including the Department of Homeland Security, US-CERT, Interpol, and the United States Secret Service.

My passion for technology ignited at an early age; I was coding by the time I was seven, using a Timex Sinclair 1000 computer. Throughout the late 80s and early 90s, I immersed myself in the thriving Chicagoland bulletin board systems, employing various machines from the classic Commodore 64 to an Intel 386 PC running Linux.

For several decades, I’ve been closely involved in the vibrant Chicago hacker scene and have organized THOTCON, which will be celebrating its 12th event in 2023. Over these years, I’ve also been instrumental in investigating some of the largest data breaches recorded in history. In my current role at Kraken, I have been dedicated to developing robust programs aimed at safeguarding the cryptocurrency exchange against potential cyber threats.

I invite you to join me in a conversation! Whether you have questions about my experiences, industry insights, or specific topics within cybersecurity, feel free to ask. Let’s dive into this engaging discussion and explore the fascinating world of cryptocurrency security together!


Note: I had an amazing time answering questions during my recent Reddit AMA and look forward to continuing the conversation. I will be checking back throughout the day to engage with more inquiries. Thank you for your interest!

Share this content:

One Comment

  1. Hi Nick, thank you for sharing such an insightful overview of your career and expertise in cybersecurity. If you’re looking for assistance with safeguarding cryptocurrency exchanges like Kraken, here are some technical tips:

    • Implement multi-factor authentication (MFA) across all user accounts to prevent unauthorized access.
    • Utilize hardware security modules (HSMs) to secure private keys and sensitive cryptographic operations.
    • Regularly conduct security audits and vulnerability assessments to identify and remediate potential weaknesses.
    • Monitor transaction patterns and set up real-time alerts for suspicious activities to detect potential breaches early.
    • Stay updated with the latest threat intelligence related to cryptocurrency-specific attacks, such as wallet hacks or phishing campaigns.
    • Apply strong encryption standards for data at rest and in transit, ensuring compliance with industry regulations.
    • Train your team regularly on security best practices and threat awareness, especially regarding targeted attacks in the crypto space.

    If you need assistance with specific implementations or configuring cybersecurity tools for your environment, feel free to ask! Maintenance of a secure infrastructure is an ongoing process that benefits greatly from proactive strategies and continuous monitoring.

Leave a Reply

Your email address will not be published. Required fields are marked *