MIT students stole $25M in seconds by exploiting ETH blockchain bug, DOJ says

Gone in 12 seconds —

Brothers charged in novel crypto scheme potentially face decades in prison.

MIT students stole $25M in seconds by exploiting ETH blockchain bug, DOJ says

Within approximately 12 seconds, two highly educated brothers allegedly stole $25 million by tampering with the ethereum blockchain in a never-before-seen cryptocurrency scheme, according to an indictment that the US Department of Justice unsealed Wednesday.

In a DOJ press release, US Attorney Damian Williams said the scheme was so sophisticated that it “calls the very integrity of the blockchain into question.”

“The brothers, who studied computer science and math at one of the most prestigious universities in the world, allegedly used their specialized skills and education to tamper with and manipulate the protocols relied upon by millions of ethereum users across the globe,” Williams said. “And once they put their plan into action, their heist only took 12 seconds to complete.”

Anton, 24, and James Peraire-Bueno, 28, were arrested Tuesday, charged with conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering. Each brother faces “a maximum penalty of 20 years in prison for each count,” the DOJ said.

The alleged scheme was launched in December 2022 by the brothers, who studied at MIT, after months of planning, the indictment said. The pair seemingly relied on their “specialized skills” and expertise in crypto trading to fraudulently gain access to “pending private transactions” on the blockchain, then “used that access to alter certain transactions and obtain their victims’ cryptocurrency,” the DOJ said.

The indictment goes into detail explaining that the scheme allegedly worked by exploiting the ethereum blockchain in the moments after a transaction was conducted but before the transaction was added to the blockchain.

These pending transactions, the DOJ explained, must be structured into a proposed block and then validated by a validator before it can be added to the blockchain, which acts as a decentralized ledger keeping track of crypto holdings. It appeared that the brothers tampered with this process by “establishing a series of ethereum validators” through shell companies and foreign exchanges that concealed their identities and masked their efforts to manipulate the blocks and seize ethereum.

To do this, they allegedly deployed “bait transactions” designed to catch the attention of specialized bots often used to help buyers and sellers find lucrative prospects in the ethereum network. When bots snatched up the bait, their validators seemingly exploited a vulnerability in the process commonly used to structure blocks to alter the transaction by reordering the block to their advantage before adding the block to the blockchain.

When victims detected the theft, they tried to request the funds be returned, but the DOJ alleged that the brothers rejected those requests and hid the money instead.

The brothers’ online search history showed that they studied up and “took numerous steps to hide their ill-gotten gains,” the DOJ alleged. These steps included “setting up shell companies and using multiple private cryptocurrency addresses and foreign cryptocurrency exchanges” that specifically did not rely on detailed “know your customer” (KYC) procedures.

They also researched the “very crimes charged in the indictment,” the DOJ said. Among search terms found in the brothers’ history during the planning phase of the alleged scheme were phrases like “how to wash crypto” and “exchanges with no KYC.” Later, seemingly attempting to prepare for any legal consequences from the scheme, the brothers allegedly searched for things like “top crypto lawyers,” and “money laundering statute of limitations,” and “does the United States extradite to [foreign country].”

To uncover the scheme, the special agent in charge, Thomas Fattorusso of the IRS Criminal Investigation (IRS-CI) New York Field Office, said that investigators “simply followed the money.”

“Regardless of the complexity of the case, we continue to lead the effort in financial criminal investigations with cutting-edge technology and good-ol’-fashioned investigative work, on and off the blockchain,” Fattorusso said.

The indictment comes the same month that the Securities and Exchange Commission (SEC) is expected to decide whether to approve an ethereum exchange-traded fund (ETF). According to CNBC, the alleged fraud could fuel SEC skepticism as it reviews the ethereum ETF.

SEC Chair Gary Gensler, a noted crypto skeptic, wants to ensure investors are protected before approving any potentially dangerous listings, CNBC noted.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
New MacBook Pro, October 12 announcement theory emerged. It's coming soon !? thumbnail

New MacBook Pro, October 12 announcement theory emerged. It's coming soon !?

2021.10.04 19:3020,737 小暮ひさのり Image: Appleもういくつ寝ると…な段階かも?iPhoneとiPad miniが発売されて、すでに満たされている方も多いかもしれませんが、おかわりが間近な雰囲気。そう、MacBook Proです。Appleのプロダクトに精通したBloombergのMark Gurman(マーク・ガーマン)氏によると、Appleは今月中にMacイベントを計画しているとのこと。また、台湾の経済日報では10月12日にイベントを行ない、新型のMacBook Pro・Mac mini・AirPods 3を発表すると、さらに具体的に報じています。12日とか言ったらもう来週じゃないですかー!これまでの噂によると新型のMacBook Proは16インチと14インチで、CPUは「M1X」。ボディデザインも変更され、HDMI端子が復活するとか、MagSafeが復活するとか、Touch Barが廃止されるとかしないとか…。今のところまだ未確定要素だらけですけど、現行の「M1」搭載MacBook AirやMac miniの評価が高いだけに、MacBook Proへの期待は否応なしに高まります。果たしてどのへんで「Pro感」を出してくるのか? めっちゃ期待だよ!Source: MacRumors, 経済日報
Read More
Singapore to set up digital intelligence unit as cyber threats intensify thumbnail

Singapore to set up digital intelligence unit as cyber threats intensify

Singapore is building a new digital intelligence unit within its armed forces that will look to boost the country's defence against cyber threats. The government has described the move as necessary, with online threats growing in volume and sophistication and attacks targeting both physical and digital domains. The new digital and intelligence service (DIS) unit will…
Read More
Jaké problémy Dying Light 2 mají pro vývojáře prioritu? thumbnail

Jaké problémy Dying Light 2 mají pro vývojáře prioritu?

No u mě je to více zabugovanější než jsem měl Cyberpunk, kde to spíše byly jen grafické glitche, které pobavili. U DL2 jsem už párkrát musel znovu načíst save. Několikrát jsem skočil na zombíky s cílem do nich kopnout, ale místo toho jsem nad nimi lítal. Vřískači, nebo jak se jim v češtině říká (btw…
Read More
The Rundown: What Omnicom Media Group’s newest acquisition means for performance marketing thumbnail

The Rundown: What Omnicom Media Group’s newest acquisition means for performance marketing

October 7, 2021 by Michael Bürgi Omnicom Media Group yesterday announced the purchase of performance marketing agency Jump 450, signaling a few new wrinkles in the agency holding companies’ efforts to diversify and modernize their practices. It’s another sign that brand marketing and performance marketing overlap enough that the lines are getting blurred. And that…
Read More
Index Of News
Total
0
Share