A former security engineer for an international tech company pleaded guilty in federal court to hacking two decentralized cryptocurrency exchanges.
As a result of these hacks in July 2022, U.S. citizen Shakeeb Ahmed, 34, illegally obtained over $12 million, according to the U.S. Department of Justice.
Ahmed agreed to forfeit those funds, including more than $5 million in restitution to victims.
Ahmed exploited vulnerabilities in the smart contracts of the two exchanges: one called Nirvana Finance and another unspecified exchange based on the currency Solana.
Smart contracts are digital agreements with the terms of the contract directly written into code.
Decentralized exchanges allow people to trade cryptocurrency directly, peer-to-peer, with an intermediary.
Ahmed's case is the first-ever conviction involving an attack on a smart contract, said Damian Williams, the U.S. attorney for the Southern District of New York.
In his first attack on the unnamed crypto exchange, Ahmed exploited a vulnerability in one of its smart contracts by inserting fake pricing data, causing the contract to generate approximately $9 million in inflated fees.
After withdrawing these fees, Ahmed agreed to return all of the stolen funds, except for $1.5 million, if the crypto exchange agreed not to refer the attack to law enforcement.
Although the targeted platform wasn't named, several cryptocurrency experts previously linked Ahmed's previous indictment to the July 2022 attack on Crema Finance, where about $9 million in cryptocurrency was stolen.
A few weeks after his first hack, Ahmed also targeted Nirvana Finance by using an exploit in its smart contract to purchase the platform's own crypto token at a low price and sell it back to the platform at a high price.
In this way, he obtained approximately $3.6 million in illegal profit, almost all the funds possessed by the exchange.
Nirvana offered him a bounty of up to $600,000, but Ahmed demanded more.
With no agreement reached, Ahmed kept all the stolen funds, leading to the platform's shutdown.
In a statement on Friday, Nirvana Finance said that if Ahmed returns the stolen money, the cash will be distributed to those affected by the hack based on their exposure at the time of the theft.
At the time of both attacks, Ahmed worked for a tech company in New York.
His resume stated that he was well-versed in reverse engineering of smart contracts and blockchain audits - skills he used to execute the hacks.
Ahmed tried to cover his tracks by exchanging the stolen money for Monero - a cryptocurrency designed to offer enhanced privacy and anonymity for its users, making transactions difficult to trace.
He also utilized cryptocurrency mixers, switched between different blockchains, and used overseas crypto exchanges.
Worried about getting caught, he considered leaving the U.S. Police discovered that he searched online for information about his hacks, as well as websites related to his ability to flee the U.S., avoid extradition, and keep his stolen cryptocurrency.
This Cyber News was published on therecord.media. Publication date: Fri, 15 Dec 2023 16:25:27 +0000