MIT Brothers Charged With Exploiting Ethereum to Steal $25 Million – Dark Reading
Many cryptocurrency traders play fast and loose with the systems in place to empower decentralized finance (DeFi), using a variety of hacks to gain an advantage in their trades from sandwich attacks to rug pull scams and losses typically run into the tens of millions of dollars per month.
Yet, two traders brothers who both graduated from the Massachussetts Institute of Technology took their scheme too far, exploiting a vulnerability in a common component used by traders on the Etherium blockchain to score nearly $25 million in an attack that lasted 12 seconds, the US Department of Justice charged on May 16. The two brothers Anton Peraire-Bueno of Boston and James Peraire-Bueno of New York discovered the software flaw in 2022, prepared and planned the attacks for months, and then executed the theft in April 2023, law enforcement alleges.
The attack worried traders and technologists, calling "the very integrity of the blockchain into question," Damian Williams, US attorney for the Southern District of New York, said in a statement from the Justice Department announcing the indictment.
"The brothers, who studied computer science and math at one of the most prestigious universities in the world, allegedly used their specialized skills and education to tamper with and manipulate the protocols relied upon by millions of Ethereum users across the globe," he said. "And once they put their plan into action, their heist only took 12 seconds to complete. This alleged scheme was novel and has never before been charged."
Cryptocurrency has gained legitimacy over the past decade and a half, but continues to in many ways be a Wild West. In 2023, more than $24 billion in transactions ended up in illicit cryptocurrency wallets or addresses although more than half of the total belonged to sanctioned organizations and nations, and the total rate of fraud is only 0.34%, according to Chainalysis, a blockchain intelligence firm.
While ransomware gangs prefer Bitcoin, Ethereum has seen its fair share of attacks, from the $60 million DAO hack in 2016 that led to a hard fork a rewriting of the Ethereum ledger to the more than $600 million in Ethereum stolen from game players on the Ronin Network.
In many ways, the ecosystem behind cryptocurrencies is undergoing the growing pains that the Internet faced over the past three decades, says Oded Vanunu, chief technologist for Web 3.0 and head of product vulnerability research at cybersecurity firm Check Point Software Technologies.
"It's crazy, because we are seeing tactics that are being done already in Web 2 platforms that are taking a different shape in the Web 3 protocols," he says.
Cryptocurrency transfers, the proposal of a smart contract, and the execution of smart contracts are all transactions that are recorded on the blockchain in Ethereum's case, a public distributed state machine. However, before being recorded, every transaction is placed in a memory pool, or mempool, pending its validation and execution, which typically takes a few steps.
A participant in the ecosystem known as a "block builder" will create a bundle or block of transactions and get paid by the originator of each transaction for completion, while a "block proposer" chooses blocks based on the fees advertised by the builder, validates them, and sends those transactions to its peers on the blockchain network. Typically, a builder is attempting to structure blocks based on a strategy of maximal extractable value (MEV), seeking to maximize profits.
Dividing participants into proposers and builders what's called a proposer-builder separation (PBS) splits the responsibility of validating transactions to limit the monopolization of the process by large traders who could order transactions in specific ways to drive profits. MEV bots help traders identify and create bundles of transactions that maximize their profits from a transaction.
Yet, there is still a lot that traders can do to tilt the playing field. In a sandwich attack, for example, the trader profits from the natural price increases or decreases caused by large cryptocurrency transactions. When a large buy order appears, a builder could place a buy order for the cryptocurrency in front of the order, and a matching sell order after, profiting from the price change caused by the original buy order.
For many DeFi participants, MEV traders are little better than the equivalent of modern ticket scalpers, but they do serve a critical role, says Adam Hart, product manager at Chainalysis.
"To many, MEV strategies look like hyper-sophisticated, deep-pocketed traders using their resources to profit by forcing less sophisticated traders to take worse prices," he says. "However, others argue that MEV is inevitable in an open, transparent blockchain network, and that MEV traders play a positive role by ensuring that arbitrage opportunities are exploited quickly so that asset prices remain aligned across protocols."
The Peraire-Bueno brothers discovered a vulnerability in an open source component of a common tool, known as a MEV-Boost relay, according to a postmortem analysis of the incident. MEV-Boost is a protocol for limiting the centralization of the two components of the Ethereum blockchain proposers and builders and the monopolization of profits, which historically could have resulted in a few players dominating the blockchain process.
A key criteria of the MEV-Boost protocol is that the proposer commits to validating a block based on price, before knowing its contents. The brothers allegedly found that signing the header gave them the information in the block, even if the signature was invalid, the postmortem stated.
"The attack ... was possible because the exploited relay revealed block bodies to the proposer, so long as the proposer correctly signed a block header," the analysis stated. "However, the relay did not check if the block header that was signed was valid."
While the vulnerability could have continued to cause problems for traders, this was not an attack on the Ethereum network or its validators directly, but rather on a specific albeit, common third-party component, says Mario Rivas, blockchain security global practice lead at NCC Group.
"The attack exploited a vulnerability in the relay's code, which caused the relay to send private transactions to the block builder when it signed a block with invalid headers," he says. "This vulnerability was promptly addressed, mitigating the risk of similar attacks unless other vulnerabilities are identified."
The investigation and indictment, however, is a win for the DOJ. US law enforcement is increasingly cracking down on cryptocurrency scams, hacking, and other questionable practices. In August, for example, the US Securities and Exchange Commission charged a correctional officer for creating a worthless cryptocurrency and selling it to other members of law enforcement.
Yet, other attacks have remained below the threshold for legal action. In a 2021 attack, for example, one trader acknowledged selling a non-liquid token to a rival in something referred to as a Salmonella attack and making money off his rival's automated system buying the worthless coin, according to a Forbes report.
The alleged attack by the two brothers stands apart from those contentious tactics, says Check Point's Vanunu.
"In essence, while both types of attacks are harmful, the MIT brothers' actions were explicitly illegal due to their direct and unauthorized exploitation of vulnerabilities to steal funds, whereas [a] Salmonella attack leverage[s] market manipulation and deception, staying within the murkier boundaries of legality in the crypto world," he says.
The investigation of the scheme and subsequent indictment underscores that government officials and their private partners are keeping pace with the latest innovative attacks. Despite the sophistication of the exploit and laundering of the proceeds, the investigators traced the funds, identified two suspects, and made their arrests, Chainalysis' Hart says.
"The Peraire-Bueno brothers' exploit is an incredibly innovative, technically sophisticated attack, and it represents the first time a bad actor has managed to abuse the MEV system widely used by Ethereum block builders in this way and to this degree," he says. "Thats what makes this indictment so impressive, and a promising sign for the future in the fight against cryptocurrency-based crime."
Go here to read the rest:
MIT Brothers Charged With Exploiting Ethereum to Steal $25 Million - Dark Reading
- 1 Unstoppable Cryptocurrency to Buy Before It Soars 31,243%, According to Strategy's Michael Saylor - Yahoo Finance - April 8th, 2026 [April 8th, 2026]
- The Case for Ethereum as the Most Useful Cryptocurrency in Existence - The Motley Fool - April 8th, 2026 [April 8th, 2026]
- 1 Unstoppable Cryptocurrency to Buy Before It Soars 31,243%, According to Strategy's Michael Saylor - The Motley Fool - April 8th, 2026 [April 8th, 2026]
- Mainstream Interest in Bitcoin: Insight Into the Cryptocurrency Market - The Daily Progress - April 8th, 2026 [April 8th, 2026]
- The Case for Owning Just 1 Cryptocurrency -- and Which One It Should Be - Yahoo Finance - April 8th, 2026 [April 8th, 2026]
- The Case for Ethereum as the Most Useful Cryptocurrency in Existence - aol.com - April 8th, 2026 [April 8th, 2026]
- The Case for Owning Just 1 Cryptocurrency -- and Which One It Should Be - The Motley Fool - April 8th, 2026 [April 8th, 2026]
- Cryptocurrency, AI and Cyber Scams Cost U.S. Almost $21 Billion in 2025 According to New FBI Internet Crime Report - Homeland Security Today - April 8th, 2026 [April 8th, 2026]
- MEMRI Cyber & Jihad Lab Continues to Monitor Uptick in ISIS-K Use of Cryptocurrency - Homeland Security Today - April 8th, 2026 [April 8th, 2026]
- Spot the Scam: Cryptocurrency scams on the rise - NBC Montana - April 8th, 2026 [April 8th, 2026]
- Leveraging technology to make smarter cryptocurrency decisions in 2026 - London Business News - April 8th, 2026 [April 8th, 2026]
- Phantom Cryptocurrency Wallet Grapples with Brief Operational Disruption Affecting Asset Displays - Crowdfund Insider - April 8th, 2026 [April 8th, 2026]
- Cryptocurrency Market Insights: Digital Assets Growth, Stablecoin Demand & Industry Forecast to 2034 - vocal.media - April 8th, 2026 [April 8th, 2026]
- FBI finds Americans lose billions to cryptocurrency scams - The Tomahawk - April 8th, 2026 [April 8th, 2026]
- Should You Forget Ethereum and Buy This Cryptocurrency Instead? - The Motley Fool - April 7th, 2026 [April 7th, 2026]
- States Weigh Pros and Cons of Investing in Cryptocurrency - pew.org - April 7th, 2026 [April 7th, 2026]
- Protection from scams: Layton City bans cryptocurrency ATMs due to fraud - standard.net - April 7th, 2026 [April 7th, 2026]
- Iran's IRGC is Charging Millions in Cryptocurrency for Hormuz Transits - The Maritime Executive - April 7th, 2026 [April 7th, 2026]
- Should You Forget Ethereum and Buy This Cryptocurrency Instead? - Yahoo Finance - April 7th, 2026 [April 7th, 2026]
- Double Spending in Cryptocurrency: What It Is, How It Works, and Historical Parallels That Changed Finance - KuCoin - April 7th, 2026 [April 7th, 2026]
- The AI Cryptocurrency That Could Benefit From the Artificial Intelligence Boom - The Motley Fool - April 7th, 2026 [April 7th, 2026]
- Best AI-Powered Cryptocurrency Trading Strategies for 2026, Helping You Easily Earn Passive Income - PR.com - April 7th, 2026 [April 7th, 2026]
- RTL Point Launches a New Hub for Real-Time Cryptocurrency News and Insights - Carroll County Mirror-Democrat - April 7th, 2026 [April 7th, 2026]
- FLOW Cryptocurrency Investor News: If You Have Suffered Losses in FLOW Cryptocurrency, You Are ... - Bluefield Daily Telegraph - April 7th, 2026 [April 7th, 2026]
- Should You Forget Ethereum and Buy This Cryptocurrency Instead? - AOL.com - April 7th, 2026 [April 7th, 2026]
- Next Big Cryptocurrency Could Deliver 150x as the Pepe Cofounder Builds Again While LINK and XRP Stall - openPR.com - April 7th, 2026 [April 7th, 2026]
- Stock futures market today: Cryptocurrency-linked firms, Soleno Therapeutics stocks to watch out on Monday - The Economic Times - April 7th, 2026 [April 7th, 2026]
- Cryptocurrency News: Pepeto Turns Macro Noise Into Signals as Tether Launches on TON and XRP Faces Pressure - openPR.com - April 7th, 2026 [April 7th, 2026]
- Should You Forget Dogecoin and Buy a More Serious Cryptocurrency Instead? - The Motley Fool - April 7th, 2026 [April 7th, 2026]
- The Next Cryptocurrency to Explode Is Filling While BTC Demand Drops and Pepeto Proves DOGE and ADA Wrong - openPR.com - April 7th, 2026 [April 7th, 2026]
- JUST IN: SEC Chair Announces New Positive Regulations for the Cryptocurrency Market Are on the Way - Cryptonews.net - April 7th, 2026 [April 7th, 2026]
- Cryptocurrency analytics company Santiment announces that Bitcoin network profitability is at its peak! Here are the details - Cryptonews.net - April 7th, 2026 [April 7th, 2026]
- The SEC Just Made a Huge Change in Its Cryptocurrency Regulations. Does That Make Bitcoin a Buy With $1,000? - Yahoo Finance - March 26th, 2026 [March 26th, 2026]
- Grand jury indicts Columbia man on suspicion of running cryptocurrency investment scheme - KOMU 8 - March 26th, 2026 [March 26th, 2026]
- 'It's heartbreaking': Layton moves to eliminate these cryptocurrency scams from city - FOX 13 News Utah - March 26th, 2026 [March 26th, 2026]
- Cryptocurrency kiosk ban heads to House Floor as part of commerce package - Minnesota House of Representatives (.gov) - March 26th, 2026 [March 26th, 2026]
- 14-year-old charged with spying for Iran, received $1,170 in cryptocurrency - ynetnews - March 26th, 2026 [March 26th, 2026]
- 1 Type of Cryptocurrency to Avoid at All Costs in 2026 - The Motley Fool - March 26th, 2026 [March 26th, 2026]
- What are the rules on cryptocurrency donations to UK political parties? - The Guardian - March 26th, 2026 [March 26th, 2026]
- Bitcoin Is Down Around 20% in 2026. Here's Why Things Could Still Get Worse for the Cryptocurrency - Yahoo Finance - March 26th, 2026 [March 26th, 2026]
- The SEC Just Made a Huge Change in Its Cryptocurrency Regulations. Does That Make Bitcoin a Buy With $1,000? - The Motley Fool - March 26th, 2026 [March 26th, 2026]
- 1 Cryptocurrency to Buy Before Oil Hits $150 - The Motley Fool - March 26th, 2026 [March 26th, 2026]
- Neighbor of proposed power plant speaks out ahead of zoning meeting, cryptocurrency code amendment - KCRG - March 26th, 2026 [March 26th, 2026]
- Cryptocurrency Speculation Increases for Elon Musks X (Twitter)! A Significant New Development Has Occurred! - Cryptonews.net - March 26th, 2026 [March 26th, 2026]
- 5 Use Cases That Prove Cryptocurrency and Blockchain - MEXC - March 26th, 2026 [March 26th, 2026]
- Flow Cryptocurrency Investor News: If You Have Suffered - GlobeNewswire - March 26th, 2026 [March 26th, 2026]
- 14-year-old In Israel Accused Of Spying For Iran, Paid In Cryptocurrency - i24NEWS - March 26th, 2026 [March 26th, 2026]
- Starmer confirms ban on cryptocurrency donations and limit on foreign donors in blow for Reform - Sky News - March 26th, 2026 [March 26th, 2026]
- Bitcoin Casinos: How Cryptocurrency Is Reshaping Online Gaming In 2026 - KHTS Radio - March 26th, 2026 [March 26th, 2026]
- Top Cryptocurrency Stocks To Research - March 24th - MarketBeat - March 26th, 2026 [March 26th, 2026]
- The SEC just made a huge change in its cryptocurrency regulations. Does that make bitcoin a buy with $1,000? - MSN - March 26th, 2026 [March 26th, 2026]
- Methods of depositing and withdrawing funds in 2026: cryptocurrency, e-wallets, cards - Pro Hockey News - March 26th, 2026 [March 26th, 2026]
- 'Hawk Tuah' Creator Haliey Welch Says She 'Wouldn't Come Out of the House' for Months After Cryptocurrency Scandal - Yahoo News New Zealand - March 24th, 2026 [March 24th, 2026]
- Bitcoin: What's Really Happening Despite The Bear Market (Cryptocurrency:BTC-USD) - Seeking Alpha - March 24th, 2026 [March 24th, 2026]
- 1 Cryptocurrency to Buy Before It Soars Over 1,300%, According to an Expert Analyst - Yahoo Finance - March 24th, 2026 [March 24th, 2026]
- DA Tucker Reports Returning $20K to Victims of Cryptocurrency ATM Scams - WHAV - March 24th, 2026 [March 24th, 2026]
- When the Email Looks Real but the Offer Isnt: Recognizing Cryptocurrency Scams - JD Supra - March 24th, 2026 [March 24th, 2026]
- Slowdown in Whale Movements, Specifically XRP, in the Cryptocurrency Market! Is a Sell-Off Coming? Here Are the Details - Cryptonews.net - March 24th, 2026 [March 24th, 2026]
- Russia Proposes Bill for Domestic Cryptocurrency Trading with Restrictions - Binance - March 24th, 2026 [March 24th, 2026]
- Boyaa Interactive Plans $70 Million in Further Cryptocurrency Acquisitions - Bitcoin.com News - March 24th, 2026 [March 24th, 2026]
- Crypto Market Daily Updates | Cryptocurrency market rebounds as Bitcoin surpasses $70,000; Strategy expands ATM financing scale, adding $44.1 billion... - March 24th, 2026 [March 24th, 2026]
- Bitmine Chairman Tom Lee Says the Bad Days Are Over for the Cryptocurrency Market! Here Are the Details - Cryptonews.net - March 24th, 2026 [March 24th, 2026]
- Fintech Stock SoFi Technologies Just Proved That the Ultimate Cryptocurrency Has a Clear Use Case - Yahoo Finance - March 24th, 2026 [March 24th, 2026]
- 'Hawk Tuah' Creator Haliey Welch Says She 'Wouldn't Come Out of the House' for Months After Cryptocurrency Scandal - People.com - March 24th, 2026 [March 24th, 2026]
- Your letters: Cryptocurrency donations, just war theory and Opus Dei - National Catholic Reporter - March 22nd, 2026 [March 22nd, 2026]
- The Tech Stock With More Potential Than Any Cryptocurrency - The Motley Fool - March 22nd, 2026 [March 22nd, 2026]
- Cryptocurrency firms suffer heavy losses in Illinois primaries after spending big - The Guardian - March 22nd, 2026 [March 22nd, 2026]
- Cryptocurrency and AI industries tested their influence in Illinois. It didn't go well - PBS - March 22nd, 2026 [March 22nd, 2026]
- 1 Cryptocurrency to Buy Before It Soars Over 1,300%, According to an Expert Analyst - The Motley Fool - March 22nd, 2026 [March 22nd, 2026]
- Wood County Sheriffs Department pushes for cryptocurrency kiosk protections - WSAW - March 22nd, 2026 [March 22nd, 2026]
- 1 Cryptocurrency to Buy Before It Soars Over 1,300%, According to an Expert Analyst - AOL.com - March 22nd, 2026 [March 22nd, 2026]
- ASML: The Foundational Tech Firm vs. Cryptocurrency Market Volatility - News and Statistics - IndexBox - March 22nd, 2026 [March 22nd, 2026]
- 2 Tech Stocks With More Long-Term Potential Than Any Cryptocurrency I've Seen - The Motley Fool - March 22nd, 2026 [March 22nd, 2026]
- The Tech Stock With More Potential Than Any Cryptocurrency - AOL.com - March 22nd, 2026 [March 22nd, 2026]
- SEC and CFTC issue final guidance for cryptocurrency - Compliance Week - March 22nd, 2026 [March 22nd, 2026]
- OCSO investigating cryptocurrency fraud that cost local resident more than $500,000 - fox10tv.com - March 22nd, 2026 [March 22nd, 2026]
- The Tech Stock With More Potential Than Any Cryptocurrency - The Globe and Mail - March 22nd, 2026 [March 22nd, 2026]
- Illinois Primaries Flooded With Money From AIPAC and Cryptocurrency - The New York Times - March 22nd, 2026 [March 22nd, 2026]
- Crypto Asset Recovery in 2026: How MiCA Regulation and Global Crypto Laws Are Changing CrossBorder Cryptocurrency Fraud Investigations - FinTech... - March 22nd, 2026 [March 22nd, 2026]
- Nearly 2,000 pounds of drugs, firearms, cryptocurrency seized in monthslong crackdown in Arizona - KJZZ - March 22nd, 2026 [March 22nd, 2026]