MIT Brothers Charged With Exploiting Ethereum to Steal $25 Million – Dark Reading
Many cryptocurrency traders play fast and loose with the systems in place to empower decentralized finance (DeFi), using a variety of hacks to gain an advantage in their trades from sandwich attacks to rug pull scams and losses typically run into the tens of millions of dollars per month.
Yet, two traders brothers who both graduated from the Massachussetts Institute of Technology took their scheme too far, exploiting a vulnerability in a common component used by traders on the Etherium blockchain to score nearly $25 million in an attack that lasted 12 seconds, the US Department of Justice charged on May 16. The two brothers Anton Peraire-Bueno of Boston and James Peraire-Bueno of New York discovered the software flaw in 2022, prepared and planned the attacks for months, and then executed the theft in April 2023, law enforcement alleges.
The attack worried traders and technologists, calling "the very integrity of the blockchain into question," Damian Williams, US attorney for the Southern District of New York, said in a statement from the Justice Department announcing the indictment.
"The brothers, who studied computer science and math at one of the most prestigious universities in the world, allegedly used their specialized skills and education to tamper with and manipulate the protocols relied upon by millions of Ethereum users across the globe," he said. "And once they put their plan into action, their heist only took 12 seconds to complete. This alleged scheme was novel and has never before been charged."
Cryptocurrency has gained legitimacy over the past decade and a half, but continues to in many ways be a Wild West. In 2023, more than $24 billion in transactions ended up in illicit cryptocurrency wallets or addresses although more than half of the total belonged to sanctioned organizations and nations, and the total rate of fraud is only 0.34%, according to Chainalysis, a blockchain intelligence firm.
While ransomware gangs prefer Bitcoin, Ethereum has seen its fair share of attacks, from the $60 million DAO hack in 2016 that led to a hard fork a rewriting of the Ethereum ledger to the more than $600 million in Ethereum stolen from game players on the Ronin Network.
In many ways, the ecosystem behind cryptocurrencies is undergoing the growing pains that the Internet faced over the past three decades, says Oded Vanunu, chief technologist for Web 3.0 and head of product vulnerability research at cybersecurity firm Check Point Software Technologies.
"It's crazy, because we are seeing tactics that are being done already in Web 2 platforms that are taking a different shape in the Web 3 protocols," he says.
Cryptocurrency transfers, the proposal of a smart contract, and the execution of smart contracts are all transactions that are recorded on the blockchain in Ethereum's case, a public distributed state machine. However, before being recorded, every transaction is placed in a memory pool, or mempool, pending its validation and execution, which typically takes a few steps.
A participant in the ecosystem known as a "block builder" will create a bundle or block of transactions and get paid by the originator of each transaction for completion, while a "block proposer" chooses blocks based on the fees advertised by the builder, validates them, and sends those transactions to its peers on the blockchain network. Typically, a builder is attempting to structure blocks based on a strategy of maximal extractable value (MEV), seeking to maximize profits.
Dividing participants into proposers and builders what's called a proposer-builder separation (PBS) splits the responsibility of validating transactions to limit the monopolization of the process by large traders who could order transactions in specific ways to drive profits. MEV bots help traders identify and create bundles of transactions that maximize their profits from a transaction.
Yet, there is still a lot that traders can do to tilt the playing field. In a sandwich attack, for example, the trader profits from the natural price increases or decreases caused by large cryptocurrency transactions. When a large buy order appears, a builder could place a buy order for the cryptocurrency in front of the order, and a matching sell order after, profiting from the price change caused by the original buy order.
For many DeFi participants, MEV traders are little better than the equivalent of modern ticket scalpers, but they do serve a critical role, says Adam Hart, product manager at Chainalysis.
"To many, MEV strategies look like hyper-sophisticated, deep-pocketed traders using their resources to profit by forcing less sophisticated traders to take worse prices," he says. "However, others argue that MEV is inevitable in an open, transparent blockchain network, and that MEV traders play a positive role by ensuring that arbitrage opportunities are exploited quickly so that asset prices remain aligned across protocols."
The Peraire-Bueno brothers discovered a vulnerability in an open source component of a common tool, known as a MEV-Boost relay, according to a postmortem analysis of the incident. MEV-Boost is a protocol for limiting the centralization of the two components of the Ethereum blockchain proposers and builders and the monopolization of profits, which historically could have resulted in a few players dominating the blockchain process.
A key criteria of the MEV-Boost protocol is that the proposer commits to validating a block based on price, before knowing its contents. The brothers allegedly found that signing the header gave them the information in the block, even if the signature was invalid, the postmortem stated.
"The attack ... was possible because the exploited relay revealed block bodies to the proposer, so long as the proposer correctly signed a block header," the analysis stated. "However, the relay did not check if the block header that was signed was valid."
While the vulnerability could have continued to cause problems for traders, this was not an attack on the Ethereum network or its validators directly, but rather on a specific albeit, common third-party component, says Mario Rivas, blockchain security global practice lead at NCC Group.
"The attack exploited a vulnerability in the relay's code, which caused the relay to send private transactions to the block builder when it signed a block with invalid headers," he says. "This vulnerability was promptly addressed, mitigating the risk of similar attacks unless other vulnerabilities are identified."
The investigation and indictment, however, is a win for the DOJ. US law enforcement is increasingly cracking down on cryptocurrency scams, hacking, and other questionable practices. In August, for example, the US Securities and Exchange Commission charged a correctional officer for creating a worthless cryptocurrency and selling it to other members of law enforcement.
Yet, other attacks have remained below the threshold for legal action. In a 2021 attack, for example, one trader acknowledged selling a non-liquid token to a rival in something referred to as a Salmonella attack and making money off his rival's automated system buying the worthless coin, according to a Forbes report.
The alleged attack by the two brothers stands apart from those contentious tactics, says Check Point's Vanunu.
"In essence, while both types of attacks are harmful, the MIT brothers' actions were explicitly illegal due to their direct and unauthorized exploitation of vulnerabilities to steal funds, whereas [a] Salmonella attack leverage[s] market manipulation and deception, staying within the murkier boundaries of legality in the crypto world," he says.
The investigation of the scheme and subsequent indictment underscores that government officials and their private partners are keeping pace with the latest innovative attacks. Despite the sophistication of the exploit and laundering of the proceeds, the investigators traced the funds, identified two suspects, and made their arrests, Chainalysis' Hart says.
"The Peraire-Bueno brothers' exploit is an incredibly innovative, technically sophisticated attack, and it represents the first time a bad actor has managed to abuse the MEV system widely used by Ethereum block builders in this way and to this degree," he says. "Thats what makes this indictment so impressive, and a promising sign for the future in the fight against cryptocurrency-based crime."
Go here to read the rest:
MIT Brothers Charged With Exploiting Ethereum to Steal $25 Million - Dark Reading
- Bitcoin values hit record highs. Should you invest in cryptocurrency? Here's how it works - USA TODAY - November 24th, 2024 [November 24th, 2024]
- Ready to Invest in Cryptocurrency? 3 Tips for Mitigating Risk and Building a Successful Portfolio - The Motley Fool - November 24th, 2024 [November 24th, 2024]
- Bitcoin, Ethereum and Cryptocurrency: Ultimate Beginner's Guide to Mining - MSN - November 24th, 2024 [November 24th, 2024]
- Local leaders respond to signs of cryptocurrency expansion - The Glen Rose Reporter - November 24th, 2024 [November 24th, 2024]
- Hong Kong Zhong An Bank has launched cryptocurrency trading services today, allowing users to buy and sell Bitcoin and Ethereum using Hong Kong... - November 24th, 2024 [November 24th, 2024]
- Bitcoin at $100k: Here's Jefferies' Chris Wood advice to cryptocurrency investors - Business Today - November 24th, 2024 [November 24th, 2024]
- This Could Be the Next Cryptocurrency to Turn $1000 into Millions: The New Shiba Inu (SHIB) - Brave New Coin Insights - November 24th, 2024 [November 24th, 2024]
- Last week, there were a total of 19 public financing events in the cryptocurrency market, with a cumulative financing of approximately $1.451 billion... - November 24th, 2024 [November 24th, 2024]
- Cryptocurrency clarified to be personal property in China, remains barred for businesses - CryptoSlate - November 23rd, 2024 [November 23rd, 2024]
- What is the 'Chill Guy' meme going viral and the 'big' Cryptocurrency controversy behind it - The Times of India - November 23rd, 2024 [November 23rd, 2024]
- Which Crypto To Buy Right Now? 10 Best Cryptocurrency Coins To Buy For the Bull Run - Brave New Coin Insights - November 23rd, 2024 [November 23rd, 2024]
- Utah joins 17 other states opposing the federal regulation of cryptocurrency - Utah News Dispatch - November 23rd, 2024 [November 23rd, 2024]
- Trump Media is close to buying a cryptocurrency trading platform - Quartzy - November 23rd, 2024 [November 23rd, 2024]
- Trump team considers creating first-ever White House cryptocurrency role - Business Standard - November 23rd, 2024 [November 23rd, 2024]
- Top 5 Anime That Feature Cryptocurrency - Film Threat - November 23rd, 2024 [November 23rd, 2024]
- Best Cryptocurrency to Invest Before Trump Presidency | Top 5 Crypto Coins Whales Are Buying - Brave New Coin Insights - November 23rd, 2024 [November 23rd, 2024]
- Canadian citizen sentenced in Cleveland to 4 years in prison for $8.2 million cryptocurrency scheme - cleveland.com - November 23rd, 2024 [November 23rd, 2024]
- Bitcoin surges above $99,000 as cryptocurrency targets another milestone - News.Az - November 23rd, 2024 [November 23rd, 2024]
- Cryptocurrency Investment Products See Record $33.5 Billion Year-to-Date Inflows - CryptoGlobe - November 23rd, 2024 [November 23rd, 2024]
- Best Cryptocurrency to Invest in 2024 | Top 10 Coins for Massive ROI - Crypto News Flash - November 23rd, 2024 [November 23rd, 2024]
- Bitcoin neared $90,000 in a new record high. What to know about cryptos post-election rally - The Associated Press - November 14th, 2024 [November 14th, 2024]
- Column: Hollywood loves a scammer. But is there an appetite for a movie about a convicted cryptocurrency fraudster? - Chicago Tribune - November 14th, 2024 [November 14th, 2024]
- 1 Top Cryptocurrency to Buy Before It Soars 16,939%, According to MicroStrategy Chief and Billionaire Michael Saylor - The Motley Fool - November 14th, 2024 [November 14th, 2024]
- Cryptocurrency giant unveils dramatic shift in traditional computing tech here's why it matters - Yahoo! Voices - November 14th, 2024 [November 14th, 2024]
- Cryptocurrency gaining popularity nationally and in the Central Valley - YourCentralValley.com - November 14th, 2024 [November 14th, 2024]
- Why cryptocurrency is spiking following the presidential election? - WCNC.com - November 14th, 2024 [November 14th, 2024]
- This Cryptocurrency May Be Down 73%, but It Has Explosive Long-Term Potential - The Motley Fool - November 14th, 2024 [November 14th, 2024]
- Is Block, Inc. (SQ) the Best Cryptocurrency Stock to Buy According to Wall Street? - Yahoo Finance - November 14th, 2024 [November 14th, 2024]
- Detroit to become largest city in U.S. to accept cryptocurrency for taxes - CBS News - November 14th, 2024 [November 14th, 2024]
- What's behind the recent surge in cryptocurrency - 11Alive.com WXIA - November 14th, 2024 [November 14th, 2024]
- Should I Invest in Cryptocurrency? Here Are 6 Game-Changing Insights! - The Cryptonomist - November 14th, 2024 [November 14th, 2024]
- Treasury probe of cryptocurrency could pose conflict for Trump aide - The Washington Post - November 14th, 2024 [November 14th, 2024]
- Cryptocurrency: Top 3 Memecoins Outperforming Bitcoin Right Now - Watcher Guru - November 14th, 2024 [November 14th, 2024]
- Cryptocurrency News: Bitcoin Tops $77,000, Trumps Record High After Election - Investor's Business Daily - November 14th, 2024 [November 14th, 2024]
- BTC to USD: Bitcoin cryptocurrency hit $80,000 after Trump win US election - BBC.com - November 14th, 2024 [November 14th, 2024]
- Tectum Partners with CryptoAutos to Advance Real-World Cryptocurrency Payments - Crypto News Flash - November 14th, 2024 [November 14th, 2024]
- Future of cryptocurrency in for a 'wild ride' following Trump's White House win - FOX 10 News Phoenix - November 14th, 2024 [November 14th, 2024]
- Professor Tonya M. Evans on Cryptocurrency, Black Wealth, and the High Stakes of Trumps Agenda 47 and Project 2025 - Savannah Tribune - November 14th, 2024 [November 14th, 2024]
- Bitcoin's Rally: The Tulips Have Done It Again (Cryptocurrency:BTC-USD) - Seeking Alpha - November 14th, 2024 [November 14th, 2024]
- Detroit to accept cryptocurrency for taxes, fees through PayPal - Detroit Free Press - November 14th, 2024 [November 14th, 2024]
- Almost 40% of This Years Top 50 ETFs Are Focused on Cryptocurrency - CryptoPotato - November 14th, 2024 [November 14th, 2024]
- ZK International Group Seeks to Accept Cryptocurrency Payments to Enhance Global Supplier, Vendor, and Customer Transactions - PR Newswire - November 14th, 2024 [November 14th, 2024]
- Trumps election win will create demand for cryptocurrency insurance - Lifeinsurance International - November 14th, 2024 [November 14th, 2024]
- Body of abducted cryptocurrency influencer Kevin Mirshahi found in Montreal park - Montreal Gazette - November 14th, 2024 [November 14th, 2024]
- Blockchain & Cryptocurrency: Transformative Applications and Challenges - TechBullion - November 14th, 2024 [November 14th, 2024]
- Billionaires Love This Soaring Cryptocurrency: Here's Why - The Motley Fool - November 14th, 2024 [November 14th, 2024]
- Detroit will accept cryptocurrency in 2025 for taxes and fees - Bridge Detroit - November 14th, 2024 [November 14th, 2024]
- $509 Million Inflows into US Spot Bitcoin ETFs Signal Growing Interest in Cryptocurrency - Coinspeaker - November 14th, 2024 [November 14th, 2024]
- Cryptocurrency industry is spending more than any other to sway California congressional races - Los Angeles Times - October 31st, 2024 [October 31st, 2024]
- Majority of Americans arent confident in the safety and reliability of cryptocurrency - Pew Research Center - October 31st, 2024 [October 31st, 2024]
- European Union/Russia/United Kingdom/Uzbekistan : Cryptocurrency haven Uzbekistan in the sights of Western hunters of Russian capital - Intelligence... - October 31st, 2024 [October 31st, 2024]
- Prediction: This 1 Phenomenal Cryptocurrency Is Set to Soar - The Motley Fool - October 31st, 2024 [October 31st, 2024]
- 1 ETF and 1 Cryptocurrency to Buy If Donald Trump Wins the Presidential Election and 2 Stocks to Buy if Kamala Harris Wins - The Motley Fool - October 31st, 2024 [October 31st, 2024]
- 1 Top Cryptocurrency to Buy Before It Soars 5,300%, According to Cathie Wood - The Motley Fool - October 31st, 2024 [October 31st, 2024]
- Jason Simon Projects Emerging Trends in Cryptocurrency Adoption and Their Impact on Global Financial Markets - WebWire - October 31st, 2024 [October 31st, 2024]
- Hong Kong Unveils Regulation Roadmap, Hints at New Cryptocurrency Incentives - Bitcoin.com News - October 31st, 2024 [October 31st, 2024]
- Cryptocurrency NEAR Protocol Down More Than 3% Within 24 hours - Benzinga - October 31st, 2024 [October 31st, 2024]
- 1 Top Cryptocurrency to Buy Before It Soars 1,400%, According to Tech Billionaire Jack Dorsey - The Motley Fool - October 31st, 2024 [October 31st, 2024]
- Bybit to Host Exclusive Forum: Bridging Islamic Finance and Cryptocurrency - GlobeNewswire - October 31st, 2024 [October 31st, 2024]
- Billionaires Are Buying This Cryptocurrency That Could Soar 200% Over the Next 12 Months, According to an Investment Firm - The Motley Fool - October 31st, 2024 [October 31st, 2024]
- Man bought Tesla, Land Rover with money from cryptocurrency fraud, DOJ says - FOX 5 San Diego - October 31st, 2024 [October 31st, 2024]
- Cryptocurrency Bittensor Down More Than 6% Within 24 hours - Benzinga - October 31st, 2024 [October 31st, 2024]
- 3 Big Changes That Could Be Coming For Cryptocurrency in 2025 - The Motley Fool - October 21st, 2024 [October 21st, 2024]
- 1 Top Cryptocurrency to Buy Before It Soars 700%, According to this Wall Street Executive and Billionaire - Yahoo Finance - October 21st, 2024 [October 21st, 2024]
- Bitcoin Is Up 53% This Year, But This Cryptocurrency Is Doing Even Better - The Motley Fool - October 21st, 2024 [October 21st, 2024]
- 1 Top Cryptocurrency to Buy Before It Soars 700%, According to this Wall Street Executive and Billionaire - The Motley Fool - October 21st, 2024 [October 21st, 2024]
- Energy-hungry cryptocurrency mining is growing in Iowa. Will it help or hurt the state? - Des Moines Register - October 21st, 2024 [October 21st, 2024]
- The Rise and Fall of Cryptocurrency in Nigeria - New Lines Magazine - October 21st, 2024 [October 21st, 2024]
- Trump Tells Followers to Buy Family-Backed Cryptocurrency - Newsweek - October 21st, 2024 [October 21st, 2024]
- 1 Top Cryptocurrency to Buy Before It Soars 20,000%, According to Michael Saylor of MicroStrategy - The Motley Fool - October 21st, 2024 [October 21st, 2024]
- Predictions for cryptocurrency adoption in online games - The Upcoming - October 21st, 2024 [October 21st, 2024]
- Cryptocurrency Price Today (October 21): Bitcoin Rises Above $69,000 For The First Time In 30 Days - ABP Live - October 21st, 2024 [October 21st, 2024]
- Stablecoins and Their Vital Roles Within the Cryptocurrency Ecosystem - The Quint - October 21st, 2024 [October 21st, 2024]
- If You Invested $1,000 In Bitcoin When Tesla Bought The Leading Cryptocurrency, Here's How Much You'd Have Today - Benzinga - October 21st, 2024 [October 21st, 2024]
- 10 Best Cryptocurrency Affiliate Programs of 2024 Earn Passive Income - Blockchain News - October 21st, 2024 [October 21st, 2024]
- Ripple cryptocurrency (XRP) jumps after company to win against SEC for its security status - Trade Brains - October 21st, 2024 [October 21st, 2024]
- If I Were Just Entering the World of Cryptocurrency, This Is What I Would Buy - The Motley Fool - October 14th, 2024 [October 14th, 2024]
- 1 Top Cryptocurrency to Buy Before It Soars 2,377%, According to Cathie Wood of Ark Invest - Yahoo Finance - October 14th, 2024 [October 14th, 2024]
- The 7 Best Cryptocurrency Cloud Mining Sites to Be Most Profitable in 2024 For Everyone - Blockzeit - October 14th, 2024 [October 14th, 2024]
- FBI Creates and Deploys "NexFundAI" Cryptocurrency in Sting Operation Against Market Manipulators - Brave New Coin Insights - October 14th, 2024 [October 14th, 2024]