IE 11 Not Supported

For optimal browsing, we recommend Chrome, Firefox or Safari browsers.

How did two brothers steal $25 million in cryptocurrency?

Answer: By altering pending transactions.

Double exposure of lines of code over a stack of $100 bills.
Two brothers were just arrested for stealing $25 million in cryptocurrency in April 2023. The most concerning part of the story is how they were able to do it, which calls into question the integrity of blockchain technology, long considered virtually unhackable.

Anton Peraire-Bueno, 24, and James Peraire-Bueno, 28, used a “novel” method of stealing cryptocurrency from the Ethereum blockchain, according to U.S. authorities. They spent months planning, but the heist itself only took about 12 seconds to carry out. They were able to successfully exploit a vulnerability in the MEV-boost software used by the Ethereum blockchain to validate transactions before adding them.

This allowed them to redirect the flow of the cryptocurrency on pending transactions, sending it to them instead of the intended recipient. This is reportedly the first time such a fraud has been the subject of U.S. criminal charges. “As we allege, the defendants’ scheme calls the very integrity of the blockchain into question,” said U.S. Attorney Damian Williams.