ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Crypto

Ex-Amazon Engineer Pleads Guilty to $12.3 Million Hack

Kyle by Kyle
December 16, 2023
in Crypto
Reading Time: 2 mins read
Amazon engineer pleads guilty to $12.3M crypto heist, employing sophisticated tactics. Deception, extradition plans revealed. Sentencing on March 13, 2024.
Share on FacebookShare on Twitter

In a recent legal development, former Amazon security engineer Shakeeb Ahmed has entered a guilty plea for his involvement in a hacking incident that resulted in the misappropriation of over $12.3 million from two cryptocurrency exchanges back in July 2022.

The affected entities include Nirvana Finance, a decentralized crypto exchange, and an unnamed exchange operating on the Solana blockchain platform. Ahmed, leveraging his skills in blockchain audit and smart contract reverse engineering, successfully breached the security of the latter.

The initial target of Ahmed’s hacking endeavors was an undisclosed cryptocurrency exchange. Employing his expertise, he manipulated a smart contract to introduce false pricing data, resulting in the generation of inflated fees amounting to around $9 million. Subsequently, Ahmed withdrew the funds and proposed returning all but $1.5 million, contingent upon the exchange refraining from involving law enforcement.

While the Justice Department did not explicitly name the affected exchange, the details of the attack align with a July 2022 breach that impacted the Crema Finance decentralized finance (DeFi) platform.

Following this initial exploit, Ahmed turned his attention to Nirvana Finance. Exploiting a smart contract loophole within the DeFi protocol, he executed a flash loan of ANA cryptocurrency tokens at a lower price and then sold them back at a higher rate, resulting in a profit of approximately $3.6 million.

Despite a $300,000 bounty offered for the return of the pilfered crypto assets, Ahmed retained the entire sum, which represented all the funds owned by Nirvana Finance. He demanded $1.4 million and, failing to reach an agreement, compelled the exchange to shut down.

In an attempt to escape capture and obscure the digital trail of the embezzled funds, Shakeeb Ahmed employed various cryptocurrency mixers, such as Samourai Whirlpool, and utilized both the Solana and Ethereum blockchains. Additionally, he turned to foreign exchanges to convert the millions he had stolen into Monero, a cryptocurrency known for its heightened privacy and anonymity features.

Wary of potential apprehension, Ahmed actively sought methods to avoid detection and extradition. Online evidence revealed his interest in strategies to flee the United States, evade asset seizures, and obtain citizenship in different countries, clearly indicating his intention to evade legal consequences for his actions.

U.S. Attorney Damian Williams remarked on Thursday, “Five months ago, my Office announced the first-ever arrest involving an attack on a smart contract. Today, senior security engineer Shakeeb Ahmed pled guilty and agreed to return all of the stolen crypto to his victims. That arrest is now the first-ever conviction for such a hack.”

Williams added, “Ahmed’s plea has also resulted in him further admitting that he carried out a previously unsolved second multi-million-dollar hack, this time of decentralized finance protocol Nirvana Finance. In total, Ahmed used his technical knowhow to steal over $12 million and tried to cover his tracks by swapping stolen crypto for Monero, using cryptocurrency mixers, hopping across blockchains, and utilizing overseas crypto exchanges.”

You might also like

Betterment Investment Users Targeted by “Triple Crypto” Scam Notification

Bitcoin Fog Operator Sentenced to 12.5 Years for $400M Cryptocurrency Laundering Scheme

Pump.fun Bundlers Assist in Crypto “Pump and Dump” Schemes

Ahmed entered a guilty plea for a single computer fraud charge, an offense carrying a maximum imprisonment term of five years. Moreover, he committed to compensating his victims with a sum totaling $5,071,074.23.

As part of the legal consequences, Ahmed will forfeit over $12.3 million, including approximately $5.6 million worth of fraudulently obtained cryptocurrency. The sentencing is scheduled for March 13, 2024, to be decided by United States District Judge Victor Marrero.

Previous Post

Delta Dental Hit by Cl0p Ransomware: Seven Million Customers’ Data Compromised

Next Post

MongoDB Breached: Customer Data Exposed in Corporate System Attack

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Betterment investments hacked for crypto scam

Betterment Investment Users Targeted by “Triple Crypto” Scam Notification

January 11, 2026
Roman Sterlingov Sentenced to 12.5 years

Bitcoin Fog Operator Sentenced to 12.5 Years for $400M Cryptocurrency Laundering Scheme

November 11, 2024

Pump.fun Bundlers Assist in Crypto “Pump and Dump” Schemes

October 16, 2024 - Updated on October 24, 2024

FBI’s Covert Operation Token Mirrors Exposes Massive Crypto Fraud Ring

October 11, 2024

FBI Warns of Sophisticated North Korean Social Engineering Attacks on Crypto Firms

September 4, 2024

Hackers Offered 10% of Funds Recovered After $16M Curio Smart Contract Exploit

March 26, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.