Nirvana Finance hacker pleads guilty, forfeits $12.3M

Charges against Shakeeb Ahmed were announced back in July

article-image

Artwork by Crystal Le

share

The Nirvana Finance hacker pleaded guilty in New York on Thursday.

Shakeeb Ahmed was connected to two hacks — Nirvana and another decentralized exchange. In 2022, DeFi protocol Nirvana was hacked for roughly $3.5 million in a flash loan exploit.

The crypto exchange attacked by Ahmed was left unnamed in the press release announcing his guilty plea. However, when the US Department of Justice first announced the charges against Ahmed, Blockworks reported that the references matched an attack made on Crema Finance in July 2022.

As part of today’s plea, Ahmed forfeited $12.3 million. Nearly $6 million of the sum in crypto. 

The plea marks the first time that the DOJ convicted someone for hacking smart contracts.

Read more: Following the money: How the SDNY caught the Crema hacker

“Five months ago, my Office announced the first ever arrest involving an attack on a smart contract. Today, senior security engineer Shakeeb Ahmed pled guilty and agreed to return all of the stolen crypto to his victims,” US attorney Damian Williams said in a press release.

The charges, announced in July, only linked Ahmed to the hacking of a crypto exchange. 

“Ahmed’s plea has also resulted in him further admitting that he carried out a previously unsolved second multi-million-dollar hack, this time of decentralized finance protocol Nirvana Finance.” 

“In the days after the hack of Nirvana, Ahmed conducted internet searches for the term ‘defi hacks prosecution’ and searches related to the charges in the Indictment, including the terms “wire fraud” and “evidence laundering,” the DOJ said.

The DOJ said that Ahmed attacked the exchange in July 2022 by exploiting a smart contract vulnerability. From there, he was able to generate roughly $9 million and withdraw those fees.

Read more: ‘Wallet drainer’ code added to Ledger library has crypto on edge

“After he stole the fees he never legitimately earned, Ahmed had communications with the Crypto Exchange in which he agreed to return all of the stolen funds except for $1.5 million if the Crypto Exchange agreed not to refer the attack to law enforcement,” the DOJ said. 

Ahmed also took to Google in an attempt to avoid legal action, using the search engine to look up “how to stop federal government from seizing assets” and also tried to research how to buy citizenship. 

Ahmed will pay $5 million in restitution to his victims, and will be sentenced in March 2024.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Unlocked by Template.jpg

Research

The BitcoinOS team is the first to have developed and posted a ZK-compressed proof on the Bitcoin network. Other proof verification efforts have been limited to the Signet or testnet deployments. Their work has resulted in the development of BitSNARK, a software library for ZK-compressed fraud proofs on the Bitcoin network. The project aims to provide a horizontal scaling solution, offering a one-stop shop for teams interested in developing a rollup on Bitcoin. This approach shares similarities with the horizontal tech stack scaling in other ecosystems like Cosmos and Optimism, particularly in its focus on simplified verification, bridging standards, and lightweight interoperability.

/

article-image

A16z’s State of Crypto report shows that DeFi has the largest number of daily active addresses, with stablecoins following closely behind

article-image

G2 is delivering real-world performance breakthroughs at 50-100 Mgas/s, Conduit says

article-image

World Liberty Financial’s token sale debuted just as an absurd AI-fueled memecoin captured crypto’s attention

article-image

Coinbase hired History Associates in 2023 to assist in retrieving records from the SEC and FDIC

article-image

Hours after pledging to support Black men’s rights to safely invest in crypto, VP Harris’s Monday night speech mentioned blockchain zero times