15 April 2024

Former Amazon engineer sentenced for hacking and crypto theft


Former Amazon engineer sentenced for hacking and crypto theft

Shakeeb Ahmed, a former security engineer at Amazon, has been sentenced to three years in prison for his involvement in hacking two decentralized cryptocurrency exchanges, leading to the theft of digital assets worth over $12 million.

According to court documents, Ahmed took advantage of vulnerabilities in blockchain contracts to carry out theft. He used sophisticated schemes to manipulate pricing data and exploit flaws in smart contracts. Specifically, he targeted Cream Finance and Nirvana Finance, making away with $9 million and $3.6 million, respectively.

Ahmed disguised his hacks as vulnerability research and even attempted to negotiate the return of stolen funds in exchange for substantial “bug bounties.” However, Nirvana Finance ceased operations when negotiations failed to reach an agreement on the return of its assets.

Ahmed utilized elaborate laundering techniques to conceal the origins and ownership of the stolen cryptocurrency, including token-swap transactions, bridging fraud proceeds between different blockchains, and converting funds into Monero, an anonymized cryptocurrency designed to be untraceable.

In addition to the three-year prison term, Ahmed, 34, was sentenced to three years of supervised release. He was also ordered to forfeit approximately $12.3 million, along with a significant quantity of cryptocurrency. Moreover, Ahmed has been mandated to pay restitution to both Cream Finance and Nirvana Finance, totaling over $5 million.


Back to the list

Latest Posts

New Cuttlefish malware steals credentials from SOHO routers

New Cuttlefish malware steals credentials from SOHO routers

Cuttlefish implements the functionality that allows it to execute HTTP and DNS hijacking.
1 May 2024
ZLoader malware resurfaces with anti-analysis feature

ZLoader malware resurfaces with anti-analysis feature

The trojan made a comeback around September 2023 after lying dormant for almost two years.
1 May 2024
Large-scale malware campaigns plant malicious content in Docker Hub repos

Large-scale malware campaigns plant malicious content in Docker Hub repos

Nearly 20% of all Docker Hub repositories analyzed hosted malware or malicious content.
1 May 2024