MIT Brothers Charged With Exploiting Ethereum to Steal $25 Million – Dark Reading
Many cryptocurrency traders play fast and loose with the systems in place to empower decentralized finance (DeFi), using a variety of hacks to gain an advantage in their trades from sandwich attacks to rug pull scams and losses typically run into the tens of millions of dollars per month.
Yet, two traders brothers who both graduated from the Massachussetts Institute of Technology took their scheme too far, exploiting a vulnerability in a common component used by traders on the Etherium blockchain to score nearly $25 million in an attack that lasted 12 seconds, the US Department of Justice charged on May 16. The two brothers Anton Peraire-Bueno of Boston and James Peraire-Bueno of New York discovered the software flaw in 2022, prepared and planned the attacks for months, and then executed the theft in April 2023, law enforcement alleges.
The attack worried traders and technologists, calling "the very integrity of the blockchain into question," Damian Williams, US attorney for the Southern District of New York, said in a statement from the Justice Department announcing the indictment.
"The brothers, who studied computer science and math at one of the most prestigious universities in the world, allegedly used their specialized skills and education to tamper with and manipulate the protocols relied upon by millions of Ethereum users across the globe," he said. "And once they put their plan into action, their heist only took 12 seconds to complete. This alleged scheme was novel and has never before been charged."
Cryptocurrency has gained legitimacy over the past decade and a half, but continues to in many ways be a Wild West. In 2023, more than $24 billion in transactions ended up in illicit cryptocurrency wallets or addresses although more than half of the total belonged to sanctioned organizations and nations, and the total rate of fraud is only 0.34%, according to Chainalysis, a blockchain intelligence firm.
While ransomware gangs prefer Bitcoin, Ethereum has seen its fair share of attacks, from the $60 million DAO hack in 2016 that led to a hard fork a rewriting of the Ethereum ledger to the more than $600 million in Ethereum stolen from game players on the Ronin Network.
In many ways, the ecosystem behind cryptocurrencies is undergoing the growing pains that the Internet faced over the past three decades, says Oded Vanunu, chief technologist for Web 3.0 and head of product vulnerability research at cybersecurity firm Check Point Software Technologies.
"It's crazy, because we are seeing tactics that are being done already in Web 2 platforms that are taking a different shape in the Web 3 protocols," he says.
Cryptocurrency transfers, the proposal of a smart contract, and the execution of smart contracts are all transactions that are recorded on the blockchain in Ethereum's case, a public distributed state machine. However, before being recorded, every transaction is placed in a memory pool, or mempool, pending its validation and execution, which typically takes a few steps.
A participant in the ecosystem known as a "block builder" will create a bundle or block of transactions and get paid by the originator of each transaction for completion, while a "block proposer" chooses blocks based on the fees advertised by the builder, validates them, and sends those transactions to its peers on the blockchain network. Typically, a builder is attempting to structure blocks based on a strategy of maximal extractable value (MEV), seeking to maximize profits.
Dividing participants into proposers and builders what's called a proposer-builder separation (PBS) splits the responsibility of validating transactions to limit the monopolization of the process by large traders who could order transactions in specific ways to drive profits. MEV bots help traders identify and create bundles of transactions that maximize their profits from a transaction.
Yet, there is still a lot that traders can do to tilt the playing field. In a sandwich attack, for example, the trader profits from the natural price increases or decreases caused by large cryptocurrency transactions. When a large buy order appears, a builder could place a buy order for the cryptocurrency in front of the order, and a matching sell order after, profiting from the price change caused by the original buy order.
For many DeFi participants, MEV traders are little better than the equivalent of modern ticket scalpers, but they do serve a critical role, says Adam Hart, product manager at Chainalysis.
"To many, MEV strategies look like hyper-sophisticated, deep-pocketed traders using their resources to profit by forcing less sophisticated traders to take worse prices," he says. "However, others argue that MEV is inevitable in an open, transparent blockchain network, and that MEV traders play a positive role by ensuring that arbitrage opportunities are exploited quickly so that asset prices remain aligned across protocols."
The Peraire-Bueno brothers discovered a vulnerability in an open source component of a common tool, known as a MEV-Boost relay, according to a postmortem analysis of the incident. MEV-Boost is a protocol for limiting the centralization of the two components of the Ethereum blockchain proposers and builders and the monopolization of profits, which historically could have resulted in a few players dominating the blockchain process.
A key criteria of the MEV-Boost protocol is that the proposer commits to validating a block based on price, before knowing its contents. The brothers allegedly found that signing the header gave them the information in the block, even if the signature was invalid, the postmortem stated.
"The attack ... was possible because the exploited relay revealed block bodies to the proposer, so long as the proposer correctly signed a block header," the analysis stated. "However, the relay did not check if the block header that was signed was valid."
While the vulnerability could have continued to cause problems for traders, this was not an attack on the Ethereum network or its validators directly, but rather on a specific albeit, common third-party component, says Mario Rivas, blockchain security global practice lead at NCC Group.
"The attack exploited a vulnerability in the relay's code, which caused the relay to send private transactions to the block builder when it signed a block with invalid headers," he says. "This vulnerability was promptly addressed, mitigating the risk of similar attacks unless other vulnerabilities are identified."
The investigation and indictment, however, is a win for the DOJ. US law enforcement is increasingly cracking down on cryptocurrency scams, hacking, and other questionable practices. In August, for example, the US Securities and Exchange Commission charged a correctional officer for creating a worthless cryptocurrency and selling it to other members of law enforcement.
Yet, other attacks have remained below the threshold for legal action. In a 2021 attack, for example, one trader acknowledged selling a non-liquid token to a rival in something referred to as a Salmonella attack and making money off his rival's automated system buying the worthless coin, according to a Forbes report.
The alleged attack by the two brothers stands apart from those contentious tactics, says Check Point's Vanunu.
"In essence, while both types of attacks are harmful, the MIT brothers' actions were explicitly illegal due to their direct and unauthorized exploitation of vulnerabilities to steal funds, whereas [a] Salmonella attack leverage[s] market manipulation and deception, staying within the murkier boundaries of legality in the crypto world," he says.
The investigation of the scheme and subsequent indictment underscores that government officials and their private partners are keeping pace with the latest innovative attacks. Despite the sophistication of the exploit and laundering of the proceeds, the investigators traced the funds, identified two suspects, and made their arrests, Chainalysis' Hart says.
"The Peraire-Bueno brothers' exploit is an incredibly innovative, technically sophisticated attack, and it represents the first time a bad actor has managed to abuse the MEV system widely used by Ethereum block builders in this way and to this degree," he says. "Thats what makes this indictment so impressive, and a promising sign for the future in the fight against cryptocurrency-based crime."
Go here to read the rest:
MIT Brothers Charged With Exploiting Ethereum to Steal $25 Million - Dark Reading
- Houstons Be Someone mural painted over with graffiti promoting cryptocurrency Mog Coin - Houston Chronicle - April 1st, 2025 [April 1st, 2025]
- Meet the Fram2 crew: A cryptocurrency entrepreneur, a cinematographer, a robotics engineer and an Arctic explorer - Spaceflight Now - April 1st, 2025 [April 1st, 2025]
- Exploring the future of finance: Q&A with a cryptocurrency researcher - Missouri S&T - April 1st, 2025 [April 1st, 2025]
- 6 Ways To Make Money Fast With Cryptocurrency in 2025 - Yahoo Finance - April 1st, 2025 [April 1st, 2025]
- 12 Most Popular Types Of Cryptocurrency - Bankrate - April 1st, 2025 [April 1st, 2025]
- Report highlights surprising shift in cryptocurrency's future: 'The technology that some feared ... is now helping' - The Cool Down - April 1st, 2025 [April 1st, 2025]
- Cryptocurrency in 2025: Exploring Bitcoin Growth, AI, and the Next Wave of Tools - Hackread - April 1st, 2025 [April 1st, 2025]
- Cryptocurrency will not save the Democratic party | Alex Bronzini-Vender - The Guardian - April 1st, 2025 [April 1st, 2025]
- How Bitcoin Influences the Broader Cryptocurrency Market: Macroeconomic Factors and Beyond - The Bismarck Tribune - April 1st, 2025 [April 1st, 2025]
- The Future of Cryptocurrency: 10 Predictions and Trends - The Shib Daily - April 1st, 2025 [April 1st, 2025]
- Brazil Bans Retirement Funds From Investing in Cryptocurrency - Bitcoin.com News - April 1st, 2025 [April 1st, 2025]
- If You Only Buy 1 Cryptocurrency This Year, Make It Bitcoin - The Motley Fool - April 1st, 2025 [April 1st, 2025]
- Milk Road Highlights the Rewards of Holding Cryptocurrency - Blockchain News - April 1st, 2025 [April 1st, 2025]
- Jason Simon Shares Expert Insights on Agile Solutions Reshaping the Cryptocurrency Landscape in 2025 - WebWire - April 1st, 2025 [April 1st, 2025]
- Incredible Technology's Impact on Cryptocurrency Trading by Milk Road - Blockchain News - April 1st, 2025 [April 1st, 2025]
- DOJ seizes cryptocurrency intended to fund Hamas - Homeland Preparedness News - April 1st, 2025 [April 1st, 2025]
- Blockchain Beyond Cryptocurrency: Real-World Applications Transforming Industries - Entrepreneur - April 1st, 2025 [April 1st, 2025]
- United States DOJ and FBI Seize Cryptocurrency in Major Disruption of Hamas Terrorist Financing Scheme - Chainalysis - April 1st, 2025 [April 1st, 2025]
- Can AI Agents become the next trend in cryptocurrency? The key is to move from narrative to practicality - ChainCatcher - April 1st, 2025 [April 1st, 2025]
- 57% of Institutional Cryptocurrency Investors Are Bullish About This Set of Catalysts for XRP and Solana - The Motley Fool - April 1st, 2025 [April 1st, 2025]
- Stillwater moves to ban cryptocurrency ATMs after series of scams - St. Paul Pioneer Press - March 15th, 2025 [March 15th, 2025]
- Gov. Pillen Signs Bill Creating Protections from Cryptocurrency Fraud - Governor Pete Ricketts - March 15th, 2025 [March 15th, 2025]
- 1 Tech Stock With More Potential Than Any Cryptocurrency - Nasdaq - March 15th, 2025 [March 15th, 2025]
- New Cryptocurrency Coins to Flourish as Coinbase Partners With 145 US Government Agencies - Bitcoinist - March 15th, 2025 [March 15th, 2025]
- How to Invest in Ethereum. Earn Cryptocurrency with the Best Cloud Mining in 2025 - GlobeNewswire - March 15th, 2025 [March 15th, 2025]
- Goldman Sachs Mentions Cryptocurrency For The First Time In Annual Letter - TronWeekly - March 15th, 2025 [March 15th, 2025]
- Banks In The USA Should Be Permitted To Own Cryptocurrency - Forbes - March 15th, 2025 [March 15th, 2025]
- Thailands Regulator Recognizes Tethers USD as an Approved Cryptocurrency in Major Step for Digital Assets - Tether.io - March 15th, 2025 [March 15th, 2025]
- 1 Top Cryptocurrency to Buy Before It Soars at Least 66% Within 10 Months, According to Fundstrat's Tom Lee - The Motley Fool - March 15th, 2025 [March 15th, 2025]
- Top Cryptocurrency News and Analysis - MarketPulse - March 15th, 2025 [March 15th, 2025]
- Cryptocurrency Project Related to Trump Speaks Out About Rumors of Collaboration with Binance - Binance - March 15th, 2025 [March 15th, 2025]
- San Antonio now accepting donations in the form of cryptocurrency - San Antonio Current - March 15th, 2025 [March 15th, 2025]
- How money laundering probe led to seizure of Tk45cr cryptocurrency - The Business Standard - March 15th, 2025 [March 15th, 2025]
- Ripple (XRP) Has Soared 15,000%. Can It Make You a Millionaire After Becoming the World's Fourth-Largest Cryptocurrency? - The Motley Fool - March 15th, 2025 [March 15th, 2025]
- Office of Public Affairs | Garantex Cryptocurrency Exchange Disrupted in International Operation - Department of Justice - March 9th, 2025 [March 9th, 2025]
- As the Cryptocurrency Industry Tumbles, Here Are 3 Coins I'm Keeping My Eye On - The Motley Fool - March 9th, 2025 [March 9th, 2025]
- White House to hold first-ever cryptocurrency summit - Fox News - March 9th, 2025 [March 9th, 2025]
- Trump wants to establish an official cryptocurrency reserve. How would that work? - Northeastern University - March 9th, 2025 [March 9th, 2025]
- Introducing the National Cryptocurrency Association to Help Americans Make Sense of Crypto - Business Wire - March 9th, 2025 [March 9th, 2025]
- Trump is going to create a cryptocurrency reserve. Here's how that would actually work - KUOW News and Information - March 9th, 2025 [March 9th, 2025]
- Trump is going to create a cryptocurrency reserve. Here's how that would actually work - WRKF - March 9th, 2025 [March 9th, 2025]
- U.S. works with Germany, Finland to disrupt terror-supporting cryptocurrency exchange - UPI News - March 9th, 2025 [March 9th, 2025]
- NC lawmakers reverse themselves, move ahead with bill to invest State Pension Plan in cryptocurrency - WRAL News - March 9th, 2025 [March 9th, 2025]
- March 7 Will Be a Big Day for Cryptocurrency. Here's Why. - The Motley Fool - March 9th, 2025 [March 9th, 2025]
- Here's How Smart Investors Evaluate Their Cryptocurrency Investments - MSN - March 9th, 2025 [March 9th, 2025]
- Trump attempts to bail out his wealthy cryptocurrency backers with 'U.S. crypto reserve' - Mashable - March 9th, 2025 [March 9th, 2025]
- HTXMining Unveils Profitable Staking Opportunities for Easy Earnings in the Cryptocurrency Era - GlobeNewswire - March 9th, 2025 [March 9th, 2025]
- LifeHack Review: Latest Movie In Computer Screenlife Genre Is Best Yet, A Rocking And Riveting Cryptocurrency Heist Film SXSW - Deadline - March 9th, 2025 [March 9th, 2025]
- New Proposal From Japan's Ruling Party Aims To Cap Cryptocurrency Tax at 20% - Yahoo Finance - March 9th, 2025 [March 9th, 2025]
- Cryptocurrency Stocks To Keep An Eye On March 7th - Defense World - March 9th, 2025 [March 9th, 2025]
- [Key Economic and Cryptocurrency Events for the Week] US January JOLTS Report & More - - March 9th, 2025 [March 9th, 2025]
- Got $1,000? Avoid These 2 Meme Coins and Buy This Cryptocurrency Instead - The Motley Fool - March 3rd, 2025 [March 3rd, 2025]
- The Cryptocurrency Scam That Turned a Small Town Against Itself - The New York Times - March 3rd, 2025 [March 3rd, 2025]
- 1 Top Cryptocurrency to Buy Before It Soars 337%, According to Cathie Wood - The Motley Fool - March 3rd, 2025 [March 3rd, 2025]
- The Sunday Read: The Cryptocurrency Scam That Turned a Small Town Against Itself - The New York Times - March 3rd, 2025 [March 3rd, 2025]
- RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector - Unit 42 - March 3rd, 2025 [March 3rd, 2025]
- Trump Crypto Reserve: What are Ripple, Cardano and Solana? (BTC-USD:Cryptocurrency) - Seeking Alpha - March 3rd, 2025 [March 3rd, 2025]
- VOA Spanish: What happened to cryptocurrency created by Maduro? - Voice of America - March 3rd, 2025 [March 3rd, 2025]
- 1 Top Cryptocurrency to Buy Before It Soars 635%, According to Cathie Wood - The Motley Fool - March 3rd, 2025 [March 3rd, 2025]
- Trump's Upcoming Address to Congress: Potential Impact on Cryptocurrency Markets - Blockchain.News - March 3rd, 2025 [March 3rd, 2025]
- 4 ways to invest in cryptocurrency stocks - Britannica - March 3rd, 2025 [March 3rd, 2025]
- Analysis of Eric Trump's Influence on Cryptocurrency Markets - Blockchain.News - March 3rd, 2025 [March 3rd, 2025]
- Comparison of Cryptocurrency Market Performance: Last Week vs This Week - Blockchain.News - March 3rd, 2025 [March 3rd, 2025]
- The Impact of the Two Koreas on Global Cryptocurrency Markets - Blockchain.News - March 3rd, 2025 [March 3rd, 2025]
- Analysis of Unverified Information in Cryptocurrency Markets - Blockchain.News - March 3rd, 2025 [March 3rd, 2025]
- AltcoinGordon Highlights Competitive Nature of Cryptocurrency Trading - Blockchain.News - March 3rd, 2025 [March 3rd, 2025]
- Crypto market sharply rebounds after Trump said that US cryptocurrency reserve - FXStreet - March 3rd, 2025 [March 3rd, 2025]
- From Volatility to Fraud, Is Investing in Cryptocurrency Just Too Risky? - The Motley Fool - March 3rd, 2025 [March 3rd, 2025]
- Dead Taneytown teacher accused of Ponzi scheme has more than $23,000 in cryptocurrency, Sun found - Baltimore Sun - February 14th, 2025 [February 14th, 2025]
- State police help recover $180,000 in cryptocurrency pig butchering scam - Eyewitness News 3 - February 14th, 2025 [February 14th, 2025]
- Operation Level-Up: How the FBI Is Saving Victims from Cryptocurrency Investment Fraud - Federal Bureau of Investigation - February 14th, 2025 [February 14th, 2025]
- State police recover $180,000 for Willimantic resident after cryptocurrency scam - NBC Connecticut - February 14th, 2025 [February 14th, 2025]
- Cryptocurrency scams on the rise: Beware of social media investment traps - Turn to 10 - February 14th, 2025 [February 14th, 2025]
- Donate Bitcoin and Cryptocurrency to Charity - Save the Children - February 14th, 2025 [February 14th, 2025]
- The Trump admin will encouragenot hinderU.S. leadership in blockchain technology and cryptocurrency. We must seize the moment - Fortune - February 14th, 2025 [February 14th, 2025]
- Whats next for Coinbase share price as bitcoin and cryptocurrency rises lead to improved earnings? - Yahoo News Australia - February 14th, 2025 [February 14th, 2025]
- BBB Warns about AI and Cryptocurrency Usage in Romance Scams - WSIU - February 14th, 2025 [February 14th, 2025]
- Crypto NFT Today: The Latest News in Blockchain, Cryptocurrency, & NFTs- February Week 2 - Innovation & Tech Today - February 14th, 2025 [February 14th, 2025]
- Michigan submits cryptocurrency reserve bill allowing state government to invest up to 10% of funds in cryptocurrency - ChainCatcher - February 14th, 2025 [February 14th, 2025]
- Analysis: cryptocurrency is a better investment in 2025 than ever before - Arizona Digital Free Press - February 14th, 2025 [February 14th, 2025]